consolidated_actor_observables_ng
The consolidated_actor_observables_ng search table is one of the data sources for the AI Actor Profile dashboard. It checks each Actor association provided in the consolidated_actor_profiles_ng and links the corresponding observable information based on the Actor ID. The table is read-only and not subject to modification.
(Click the image to enlarge it)
| Field | Value Type | Description | Example |
|---|---|---|---|
| actor_id | numeric | ID of the Actor. | 190789.0 |
| actor_name | string | Name of the Actor. | HAZY TIGER |
| confidence | numeric | Risk score from 0 to 100, assigned by ThreatStream's predictive analytics technology to the observable. | 70 |
| created_ts | date |
Time stamp of when the observable was first created in ThreatStream. Date is specified in the following format:
|
May 05, 2024 17:15:01.000 |
| feed_name | string | Name of the threat feed that created the observable on ThreatStream. | CrowdStrike Falcon X |
| indicator | string | Indicator name associated with The Actor. |
|
| itype | string | Indicator type of the observable associated with the Actor. | mal_md5 |
| modified_ts | date |
Time stamp of when the observable was last updated in ThreatStream. Date is specified in the following format:
|
Jun 24, 2025 13:40:20.000 |
| observable_id | numeric | ID of the observable. | 57634912361 |
| severity | string |
Criticality associated with the threat feed that supplied the observable Possible values: low, medium, high, very-high. |
high |
