---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Roll up lookup info to security incident activity

# Roll up lookup info to security incident activity {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

The Roll up lookup info to security incident activity can be used with any workflow to gather information from a threat lookup and output a summary of the contents as well as the ID of the originating
security incident in task work notes.

## Results

Possible results for this activity are:
{#r_RollUpScanInfoSI__table_lg3_dm5_vv__entry__2}

| Result | Description |
|-|-|
| Success | Lookup report summary rolled up to security incident. |
| Failure | Originating task and lookup summary report are empty. |
[Table 1. Results]

{#r_RollUpScanInfoSI__table_lg3_dm5_vv} {#r_RollUpScanInfoSI__table_pgm_tfy_jr__entry__2}

| Variable | Description |
|-|-|
| scanID\[string\] | Lookup identifier. |
[Table 2. Input variables]

{#r_RollUpScanInfoSI__table_pgm_tfy_jr}

## Output variables

The output variables contain data that can be used in subsequent activities.
{#r_RollUpScanInfoSI__table_bnj_jfy_jr__entry__2}

| Variable | Description |
|-|-|
| siId\[string\] | Security incident identifier. |
| response \[string\] | Summary of lookup results including: IoC value, Result, Failure reason, lookup reference, and so on. |
[Table 3. Output variables]

{#r_RollUpScanInfoSI__table_bnj_jfy_jr}

