---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Verify expected results for Shodan

# Verify expected results for Shodan {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Observables are generated automatically by a security incident and scanned by the
application. Enrichment results are displayed on the Observable Enrichment Results and Network Banners tabs.

## Before you begin

Role required: sn_si.analyst.

## Procedure

1. Open the security incident you're working with and verify that the lookup has run successfully.  
   Once the application is configured, the workflow launches automatically on incident creation. The execution and completion status of the lookup is displayed in the work notes in the security incident.
2. Review the work notes for more information and how to proceed if you can't verify that the lookup ran successfully.
3. Navigate to the bottom of the security incident and select the Show All Related Lists link in Related Links.  
   Results are displayed in the Observable Enrichment Results and Network Banners tabs at the bottom of the security incident.
4. With the Network Banners tab selected, select the blue information icon next to an observable.
5. In the dialog box that is displayed, select Open Record to view raw data and more details.
If you don't see results under the Observable Enrichment Results and Network Banners tabs, verify that the observable is a type that is supported for lookup by the integration.
**Previous topic:** [Install and configure Shodan](https://servicenow-prod.fluidtopics.net/HZqavH3Pk1z2CvvwenqqHQ "Before you run the integration on your instance, complete the installation and configuration steps so the Shodan application properly integrates with ServiceNow AI Platform Security Operations.")  
**Next topic:** [(Optional) Manually attach an observable for Shodan](https://servicenow-prod.fluidtopics.net/peUWCjOFJnbFezJSbKlLpA "You can manually attach observables to a security incident. You manually attach observables when you want to perform threat lookups on observables that are not attached to a security incident on the initial event trigger. Also, you might perform this task when you want more information about a related observable.")

