---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# View enrichment data for a security incident

# View enrichment data for a security incident {#ariaid-title1}

* Release version: Australia
* 
* Updated August 11, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

You can view enrichment data, such as running processes, running services, and
network statistics associated with a security incident.

## Before you begin

Role required: sn_si.basic

## Procedure

1. If it is not already open, open the security incident for which you want to view enrichment data.
2. Click the Show Enrichment Data related link.
3. Click any of the related lists to view or add information for the security incident.  
   Note:  
   Raw data details are stored in an attachment to the enrichment data record. If they exceed the field limit, displayed details are truncated.  
   {#show-enrich-data-for-si__table_hng_51r_yy__entry__2}

   | Tab | Description |
   |-|-|
   | Running Processes | Stores the records created by the Security Incident Response Get Running Processes workflow. |
   | Running Services | Stores the records created by the Security Incident Response Get Running Services workflow. |
   | Network Statistics | Stores the records created by the Security Incident Response Get Network Statistics workflow. |
   | Domain Lookups | If the WhoisXML API Integration plugin is activated, stores the records created by a Whois lookup. |
   | Firewall Logs | Stores enrichment data from firewall logs, such as the Palo Alto Network firewall logs. |
   | Compromised User Info | Stores accounts identified as being compromised through a Have I Been Pwned? lookup. |
   [ ]

   {#show-enrich-data-for-si__table_hng_51r_yy}

   Note: The Security Enrichment Data tab shows raw
   enrichment data from Security Incident Response workflows, such as
   retrieving network statistics or running processes. This tab can be viewed
   by clicking the Show All Related Lists related
   link.
4. Click any of the following related links to further update the security incident:  
   * [Show Affected
     Items](https://servicenow-prod.fluidtopics.net/v5P23O5qpqXvK~jeo5tUXw "You can view affected items, such as CIs, affected users, unmatched affected users, and affected services associated with a security incident.")
   * [Show Related
     Items](https://servicenow-prod.fluidtopics.net/5dWDw6sQ~pOrALbzetUbNg "You can view related items, such as similar and child security incidents, related users, vulnerability groups, and vulnerable items associated with a security incident.")
   * [Show IoC](https://servicenow-prod.fluidtopics.net/QiPYhovl9Rh2EBQRXKLqlA "You can view IoC information, such as observables and sightings search results associated with a security incident.")
   * [Show Response Tasks](https://servicenow-prod.fluidtopics.net/w0eTEV1T~Ug1aQGp91dl0A "You can view response task information, such as task SLAs, risk score audits and outages associated with a security incident.")
   {#show-enrich-data-for-si__ul_rxz_h1q_vz}
5. When you have completed your entries, click Submit.
{#show-enrich-data-for-si__steps_akt_2wc_wz}

