---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Load more IoC data

# Load more IoC data {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Depending on settings in two properties and a script include definition, you can load
geolocation information for IP addresses and websites in the Observables form. With further
customization, you can also add other information, such as country codes, city
names.

## Before you begin

The following two properties must be set:

* The domain name to retrieve additional information for IP addresses/URLs \[sn_ti.ip_lookup.web_site\]
* The API key to be used for the above domain, if any \[sn_ti.ip_lookup.api_key\]
{#t_LoadAdditionalIoCData__ul_zys_l1c_kv}Role required: sn_ti.admin

## Procedure

1. Navigate to AllThreat IntelligenceIoC RepositoryObservables.
2. Click the IP address or URL of the observable to which you want to view more IoC data.  
   The Location field shows the geolocation of the IoC.
3. Click the Enrich data button to load the additional IoC data.
4. You can also configure the Observable form to add other location-related fields, such as the country code and city code.  
   Note:  
   To load more location-related information, edit the ThreatAdditionalInfo script include and provide the appropriate API key from the website that provides the additional information.
{#t_LoadAdditionalIoCData__steps_kdz_krt_gv}
**Related tasks**   

* [Define an observable](https://servicenow-prod.fluidtopics.net/N_322_aca9GLw89huNJzWw "Observables are retrieved from the vendor server as STIX data. However, you can create observables, as needed.")
* [Add a related IoC to an observable](https://servicenow-prod.fluidtopics.net/7HtyAyberW_1wRBwjHGytg "In addition to importing observables as STIX data, you can add related observables to an IoC manually.")
* [Add associated tasks to an observable](https://servicenow-prod.fluidtopics.net/VdG6~9jg_L2Cj_ubFik37Q "In addition to importing associated tasks (such as changes and incidents) as STIX data, you can add them to an observable manually.")
* [Add a related observable](https://servicenow-prod.fluidtopics.net/xLYwJX5KAfYux3reXTS2ow "In addition to importing observables as STIX data, you can add related observables manually.")
* [Identify observable sources](https://servicenow-prod.fluidtopics.net/Rsn_O9wAHfRweFF~mNIA1w "If an observable has no sources defined, it uses all types of sources. However, if you add one or more threat sources to an observable, it limits the sources used.")
* [Perform lookups on observables](https://servicenow-prod.fluidtopics.net/lpoUE~l5Cuui5Nt5XCnFsA "You can perform threat intelligence lookups on one or more observables to determine whether they’re associated with known security threats. The scanning implementations that run depend on the ones you’ve activated.")
* [Perform threat enrichment on observables](https://servicenow-prod.fluidtopics.net/gmFI_mpfWoTDtoNbzR72IA "You can perform threat intelligence enrichment on one or more observables to determine whether they’re associated with known security threats. The implementations that run depend on the ones you’ve activated.")

*[\>]: and then


