---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Verify expected results for manual WHOISIQ lookups

# Verify expected results for manual WHOISIQ lookups {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Run a manual lookup on an observable when it does not automatically generate a
security incident. For observable enrichment lookups using the WHOISIQ API for email addresses,
organization names, phone numbers, or mailing addresses, initiate the lookup manually from
the Observables table.

## Before you begin

Role required: sn_si.analyst

## About this task

Create an observable for a manual lookup using the WHOISIQ API. For more information on how to create and edit an observable, see [Create an observable for manual WHOISIQ lookups](https://servicenow-prod.fluidtopics.net/_A6JIvevOpIn53o6I6dTsw "Security incident analysts use information from observable enrichment with the WHOISIQ API to learn more about the email addresses, names, and phone numbers of organizations.").

## Procedure

1. Navigate to AllIoC RepositoryObservables and locate the observable in the list you're working with.
2. Select your observable in the Value column to open the record.
3. Select the Run Observable Enrichment related link to run the lookup.
4. In the Run Observable Enrichment window, move RiskIQ Whois to the Selected list.
5. Select Submit.  
   Lookup results are displayed on the Observable Enrichment Results tab on the observable record.
If no results are returned for the observable, a message is displayed in the Summary column. If you don't see results, verify the observable is supported by the API.
**Previous topic:** [Create an observable for manual WHOISIQ lookups](https://servicenow-prod.fluidtopics.net/_A6JIvevOpIn53o6I6dTsw "Security incident analysts use information from observable enrichment with the WHOISIQ API to learn more about the email addresses, names, and phone numbers of organizations.")  
**Next topic:** [Shodan integration](https://servicenow-prod.fluidtopics.net/L6ejLtC24Fc_6EhPQt1pNA "Shodan is a search engine that analyzes service banner information from connected devices all around the globe. Service banners include information about a computer system, such as host name, device type, operating system, geographic location, and connected ISP. When integrated with the ServiceNow AI Platform Security Operations product, this service banner information provides analysts with additional enrichment data and insight for security incidents or investigations.")  
**Related reference**   

* [Supported observables for RISKIQ and RISKIQ WHOISIQ](https://servicenow-prod.fluidtopics.net/er0CYm1rBPOEf_Aobh6OQA "The RISKIQ API supports automatic SSL certificate lookups on IP address, file hash, Certificate Serial Number, domain, and URL observables. URL and domain observables are enriched automatically with the WHOISIQ API. For observable enrichment on other types of observables with the WHOISIQ API, create observables and run lookups manually from the Observables table.")

*[\>]: and then


