---
sourceDocument: Yokohama Security Management
sourceDocumentLink: https://www.servicenow.com/docs/r/yokohama/security-management

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Run Enrichment Actions from Observable

# Run Enrichment Actions from Observable {#ariaid-title1}

* Release version: Yokohama
* 
* Updated January 30, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Use this section to understand how enrichments actions are performed on observables and other objects.

## Before you begin

Role required: sn_sec_tisc.admin

## Procedure

1. Navigate to WorkspacesThreat Intelligence Security Center.
2. Click Threat Analyst Workbench icon.
3. Go to ObservablesAll Observables.
4. Click any Enrichment actions from the split button.
5. Select the available implementation(s).
6. Click Submit.  
   For example, Run Threat Lookup. The selected enrichment action will be executed and an information message is displayed that Observable enrichment execution has started on the selected observable(s). Results will be available in the detail page of respective observable(s) once the execution is complete.  
   Note:  
   Once the execution initiated or completed, a work notes is posted on the activity stream of the form view.
{#run-enrichment-actions-from-observable__steps_tmd_xdc_h1c}

*[\>]: and then


