Skip to main content

Work with observables

Analyst

Observables are the reusable evidence at the heart of Ticketra. This guide covers the day-to-day actions you'll take on them. For the philosophy behind the design, see The observable-centric model.

Add an observable

Observables are usually created automatically when logs/alerts are ingested, but you can add one manually from within a case or the Observables registry.

  1. Open the Observables page (or a case's Observables section).

  2. Add a value and pick its type — one of:

    IP · USERNAME · HOSTNAME · HASH_MD5 · HASH_SHA1 · HASH_SHA256 · DOMAIN · URL · EMAIL · FILE_PATH · MAC_ADDRESS · PORT

If the value already exists, Ticketra records a new sighting against the existing observable rather than duplicating it.

Tag observables

Tags are how you make observables filterable and actionable.

  • Add tags manually from the observable view.
  • Enrichment can auto-tag based on threat-intel verdicts (e.g. malicious).

Filter the registry by tag to surface, say, every observable currently marked malicious.

Enrich with threat intelligence

If an admin has configured CTI providers (guide), open an observable and choose Enrich. Only these types are sent externally:

IP · DOMAIN · HASH_MD5 · HASH_SHA1 · HASH_SHA256

Private IPs are never transmitted. Verdicts are cached and shared across every case that references the observable.

Permissions

Tagging requires observables:tag; enrichment requires observables:enrich. See the permission matrix.

Pivot via correlation

From an observable you can see every case and alert it has appeared in. This is the core investigative pivot: start from one indicator and fan out to everything related.

Ticketra surfaces these correlations but never auto-links cases — you decide what's actually related.

Comments

Add comments to an observable to capture context that should travel with the indicator across cases (e.g. "known corporate VPN egress — usually benign").