---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Initiate the lookup for Reverse Whois

# Initiate the lookup for Reverse Whois {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Initiate domain lookups using search terms in observables that you manually attach to
a security incident record.

## Before you begin

Role required: sn_si.analyst

## Procedure

1. If not open, navigate to Security IncidentIncidentsShow All Incidents and open the security incident you're working with.
2. At the bottom of the record, select the Show IoC related link to display the Observables tab.  
   Note:  
   If you don't see tabs on the security incident, in the upper-right corner of the banner frame, select the Settings gear icon. In the System Settings dialog box that is displayed, select Forms and verify that Tabbed forms and With the Form are selected.
3. On the Observables tab, select New.
4. Fill in the fields.  
   {#manually-attch-an-obsvrble-reversewhois__table_hlg_h3t_ycb__entry__2}

   | Field | Description |
   |-|-|
   | Value | Unique search term for a domain. |
   | Observable type | This field is automatically cleared. |
   | Finding | This field is automatically set to Unknown. |
   [Table 1. Required fields on the record]

   {#manually-attch-an-obsvrble-reversewhois__table_hlg_h3t_ycb}
5. Select Submit.  
   You're returned to the security incident record and the flow initiates the lookup.
{#manually-attch-an-obsvrble-reversewhois__steps_j2d_pht_ycb}

## What to do next

Verify the lookup results on the security incident. See [Verify expected results for Reverse Whois](https://servicenow-prod.fluidtopics.net/ZadtOPuVBrqyqTmIRZyUTA "Enrichment results are displayed on the ReverseWhois Domains tab at the bottom of the security incident record. Locate the lookup results to verify that the lookup ran successfully.").
**Previous topic:** [(Optional) Install and configure Whois](https://servicenow-prod.fluidtopics.net/o~hiAz9liOg8WCDGc2CrWg "Install the Whois plugin to provide additional enrichment information on your domain lookups from the Reverse Whois API. This lookup provides additional enrichment data on the domain, such as the registration date, name of registrar, and country of origin.")  
**Next topic:** [Verify expected results for Reverse Whois](https://servicenow-prod.fluidtopics.net/ZadtOPuVBrqyqTmIRZyUTA "Enrichment results are displayed on the ReverseWhois Domains tab at the bottom of the security incident record. Locate the lookup results to verify that the lookup ran successfully.")

*[\>]: and then


