---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/pt-BR/security-management

 Release :

    - australia

ft:locale :

    - pt-BR

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Initiate the lookup for Reverse Whois

# Initiate the lookup for Reverse Whois {#ariaid-title1}

* Versão de lançamento: Australia
* 
* Atualizado 12 de mar. de 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 min. de leitura

Initiate domain lookups using search terms in observables that you manually attach to
a security incident record.

## Antes de Iniciar

Role required: sn_si.analyst

## Procedimento

1. If not open, navigate to Security IncidentIncidentsShow All Incidents and open the security incident you are working with.
2. At the bottom of the record, click the Show IoC related link to display the Observables tab.  
   Nota:  
   The figures in the following steps are shown with the Tabbed forms setting active in the System Settings. If you do not see tabs on the security incident, in the upper-right corner of the banner frame, click the Settings gear icon. In the System Settings dialog box that is displayed, click Forms and verify that Tabbed forms and With the Form are selected.
3. On the Observables tab, click New.
4. Fill in the fields.  
   {#manually-attch-an-obsvrble-reversewhois__table_hlg_h3t_ycb__entry__2}

   | Field | Description |
   |-|-|
   | Value | Unique search term for a domain. |
   | Observable type | This field is automatically cleared. |
   | Finding | This field is automatically set to Unknown. |
   [Tabela 1. Required fields on the new record]

   {#manually-attch-an-obsvrble-reversewhois__table_hlg_h3t_ycb}
5. Click Submit.  
   You are returned to the security incident record and the flow initiates the lookup.
{#manually-attch-an-obsvrble-reversewhois__steps_j2d_pht_ycb}

## O que Fazer Depois

Verify the lookup results on the security incident. See [Verify expected results for Reverse Whois](https://servicenow-prod.fluidtopics.net/eEhQrDllCEu5AYllRCBWxA "Enrichment results are displayed on the ReverseWhois Domains tab at the bottom of the security incident record. Locate the lookup results to verify that the lookup ran successfully.").
**Tópico anterior:** [(Optional) Install and configure Whois](https://servicenow-prod.fluidtopics.net/~ICAy1LpNFmfewULr4T~kA "Install the Whois plugin to provide additional enrichment information on your domain lookups from the Reverse Whois API. This lookup provides additional enrichment data on the domain, such as the registration date, name of registrar, and country of origin.")  
**Próximo tópico:** [Verify expected results for Reverse Whois](https://servicenow-prod.fluidtopics.net/eEhQrDllCEu5AYllRCBWxA "Enrichment results are displayed on the ReverseWhois Domains tab at the bottom of the security incident record. Locate the lookup results to verify that the lookup ran successfully.")

