---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Enrich Observable WhoIs workflow

# Enrich Observable WhoIs workflow {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

The Enrich Observable WhoIs workflow performs enrichment on
selected observables. If the observables are of a type recognized by the WhoisXML API Integration, the observables are
enriched.

## Before you begin

Role required: admin

## About this task

This workflow is triggered by the [Security Operations Integration- Enrich Observable capability](https://servicenow-prod.fluidtopics.net/SFbmJuNvMEgdI67XP2~5Hg "The Enrich Observable capability allows you to enrich observables with additional information from a variety of sources using implementation flows. This capability is used during incident response investigations to contain an identified threat.") when you perform enrichment on one or more observables, and the WhoIs
implementation is selected.
Figure 1. Enrich Observable WhoIs workflow

Activities specific to this integration are described here. For more information on
other activities, see [Common Security Operations integration flows and orchestration activities](https://servicenow-prod.fluidtopics.net/VeHrUh9NzKmFfa~3wxWcqQ "Many of the flows associated with third-party integrations include the same activities. For example, activities for beginning and completing processing.").

## Observable Enrichment Lookup activity {#ariaid-title2}

The Observable Enrichment Lookup workflow activity initiates the
observable enrichment process.
The Observable Enrichment Lookup activity can be used with any
observables workflow to begin enrichment.

### Results {#observ-enrich-lookup-activity__section_ftl_n24_z1b}

Possible results for this activity are:
{#observ-enrich-lookup-activity__table_lg3_dm5_vy__entry__2}

| Result | Description |
|-|-|
| Success | The lookup is successful. |
| Fail | An error occurred while attempting to perform the lookup. More error information is available in the activity output error. |
[Table 1. Results]

{#observ-enrich-lookup-activity__table_lg3_dm5_vy}

### Input variables {#observ-enrich-lookup-activity__section_alh_hfm_3z}

Input variables determine the initial behavior of the activity.
{#observ-enrich-lookup-activity__table_pgm_tfy_jr__entry__2}

| Variable | Description |
|-|-|
| implementation_id | System identifier of the implementation used to perform the lookup. |
| domain_id | The domain identifier for the domain within which the lookup is being performed. |
| observable_ids | One or more observables to perform the desired action against. The IDs are used as a workflow input. |
| capabilityExcutionId | System identifier of the capability that launched the implementation workflow. Only required for Integration Capability implementation workflows such as Splunk, Elasticsearch. |
| task_sys_id | System identifier for any task associated with the workflow. |
[ ]

{#observ-enrich-lookup-activity__table_pgm_tfy_jr}

### Output variables {#observ-enrich-lookup-activity__section_gtl_n24_z1b}

The output variables contain data that can be used in subsequent activities.
{#observ-enrich-lookup-activity__table_bnj_jfy_jr__entry__2}

| Variable | Description |
|-|-|
| response_data | Raw data returned by the implementation's API endpoint for the given domain. |
| mapping_id | The identifier for the enrichment mapping. For example, the WhoIs integration returns data in two different format, IP and URL, with a mapping id for each. |
[Table 2. Output variables]

{#observ-enrich-lookup-activity__table_bnj_jfy_jr}

