---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/pt-BR/security-management

 Release :

    - australia

ft:locale :

    - pt-BR

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Verify expected results for manual WHOISIQ lookups

# Verify expected results for manual WHOISIQ lookups {#ariaid-title1}

* Versão de lançamento: Australia
* 
* Atualizado 12 de mar. de 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 min. de leitura

Run a manual lookup on an observable when it does not automatically generate a
security incident. For observable enrichment lookups using the WHOISIQ API for email addresses,
organization names, phone numbers, or mailing addresses, initiate the lookup manually from
the Observables table.

## Antes de Iniciar

Role required: sn_si.analyst

## Por Que e Quando Desempenhar Esta Tarefa

Create an observable for a manual lookup using the WHOISIQ API. For more information on how to create and edit an observable, see [Create an observable for manual WHOISIQ lookups](https://servicenow-prod.fluidtopics.net/7A3Uj7V2y5GSD9b81hhYKg "Security incident analysts use information from observable enrichment with the WHOISIQ API to learn more about the email addresses, names, and phone numbers of organizations.").

## Procedimento

1. Navigate to AllIoC RepositoryObservables and locate the observable in the list you are working with.
2. Click your observable in the Value column to open the record.  
3. Click the Run Observable Enrichment related link to run the lookup.  
4. In the Run Observable Enrichment window, move RiskIQ Whois to the Selected list.  
5. Click Submit.  
   Lookup results are displayed on the Observable Enrichment Results tab on the observable record.
If no results are returned for the observable, a message is displayed in the Summary column. If you do not see results, verify the observable is supported by the API.
**Tópico anterior:** [Create an observable for manual WHOISIQ lookups](https://servicenow-prod.fluidtopics.net/7A3Uj7V2y5GSD9b81hhYKg "Security incident analysts use information from observable enrichment with the WHOISIQ API to learn more about the email addresses, names, and phone numbers of organizations.")  
**Próximo tópico:** [Shodan integration](https://servicenow-prod.fluidtopics.net/RGUXa~X0MEVeXPsc5nUhOA "Shodan is a search engine that analyzes service banner information from connected devices all around the globe. Service banners include information about a computer system, such as host name, device type, operating system, geographic location, and connected ISP. When integrated with the ServiceNow AI Platform Security Operations product, this service banner information provides analysts with additional enrichment data and insight for security incidents or investigations.")  
**Referência relacionada**   

* [Supported observables for RISKIQ and RISKIQ WHOISIQ](https://servicenow-prod.fluidtopics.net/ZskEjk~~ay7hgLjz~to4Cg "The RISKIQ API supports automatic SSL certificate lookups on IP address, file hash, Certificate Serial Number, domain, and URL observables. URL and domain observables are enriched automatically with the WHOISIQ API. For observable enrichment on other types of observables with the WHOISIQ API, create observables and run lookups manually from the Observables table.")

