---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Supported observables for RISKIQ and RISKIQ WHOISIQ

# Supported observables for RISKIQ
and RISKIQ
WHOISIQ {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

The RISKIQ API supports
automatic SSL certificate lookups on IP address, file hash, Certificate Serial Number,
domain, and URL observables. URL and domain observables are enriched automatically with the
WHOISIQ API. For observable
enrichment on other types of observables with the WHOISIQ API, create observables and
run lookups manually from the Observables table.

## Supported observables {#riskiq_supported_obsv__section_uzb_mmq_hdb}

The following table lists the type of APIs used in this integration, and the
observables each API supports. The table also indicates whether a lookup occurs
automatically when security incidents are created, or if the lookup is run manually
from the Observables table.
{#riskiq_supported_obsv__table_ep4_jlq_hdb__entry__3}

| API | Supported observables | Lookup (automated or manual) |
|-|-|-|
| RISKIQ SSL certificate API | * IP address * File hash (certificate thumb print). See the following figure for an example of a file hash. * Certificate Serial Number, or Serial Number. This string is a unique ID for the entity. See the following figure for an example of a certificate serial number. * Domain (<kbd class="ph userinput">www.site.com</kbd>, or <kbd class="ph userinput">site.com</kbd>) * URL Note: automatic scans are run for the URL format using the <kbd class="ph userinput">https://</kbd> protocol, for example,<kbd class="ph userinput"> https://example.com/index.html</kbd> {#riskiq_supported_obsv__ul_pqc_jmq_hdb} | Automated lookup when incidents are created. Results are displayed on the SSL Certificates tab of the security incident record. |
| RISKIQ WHOISIQ API | * Domain * URL {#riskiq_supported_obsv__ul_slc_rnq_hdb} | Automated lookup when incidents are created. Results are displayed on the Observable Enrichment Results tab on the security incident record. |
| RISKIQ WHOISIQ API | * Email address * Organization name * Phone number * Mailing address {#riskiq_supported_obsv__ul_ysr_znq_hdb} | Manual lookup is run from the Observables table. Results are displayed on the Observable Enrichment Results tab on the Observable record. |
[Table 1. Supported observables and lookup]

{#riskiq_supported_obsv__table_ep4_jlq_hdb}
**Previous topic:** [RISKIQ and WHOISIQ integration](https://servicenow-prod.fluidtopics.net/u9HJEqH6uTrvBMmGHbeN5g "With the integration of RISKIQ and WHOISIQ APIs with the ServiceNow AI Platform Security Operations product, security analysts are provided with additional enrichment data and insight into the validity of websites.")  
**Next topic:** [Install and configure RISKIQ and WHOISIQ](https://servicenow-prod.fluidtopics.net/9und49zaUE3Cjrvo5xPDpg "Before you run the integration on your instance, complete the installation and configuration steps so the RISKIQ and WHOISIQ applications properly integrate with ServiceNow AI Platform Security Operations.")

