---
sourceDocument: Yokohama Security Management
sourceDocumentLink: https://www.servicenow.com/docs/r/yokohama/security-management

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# (Optional) Run enrichment lookup and verify expected results for Whois

# (Optional) Run enrichment lookup and verify expected results for Whois {#ariaid-title1}

* Release version: Yokohama
* 
* Updated January 30, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Run the Whois integration to
perform enrichment lookups on the domains returned from the Reverse Whois integration.

## Before you begin

Verify that you have installed and configured the Reverse Whois and Whois plugins. Perform these
steps only after you have run the domain lookup with the Reverse Whois plugin
successfully.
Role required: sn_si.analyst

## About this task

Results are displayed on the Observable Enrichment Results tab on the Observable record.

## Procedure

1. Navigate to AllSecurity IncidentsIncidentsShow All Incidents and locate the security incident you are working with that has run the domain lookup successfully.
2. Open the record and click the Show All Related Lists related link.
3. Select the Reverse Whois Domains tab at the bottom of the record.  
   In the Domains column, the list of returned domains is displayed.
4. In the Observable column, click an observable.  
   On the Child Observables tab, the child observables are displayed. The child observables are generated only if the initial scan of the observable by the Reverse Whois application returned domains.
5. Select the child observables you want to run the observable enrichment on, and, in the Action on selected rows choice list, select Run Observable Enrichment.  
   The Run Observable Enrichment dialog box is displayed.
6. Move the Whois integration from Available to Selected and click Submit.  
   Results are displayed on the Observable Enrichment Results tab of the observable record.
7. Click the blue information icon then click Open Record in the dialog box that is displayed.  
   More information and raw data related to the original domain lookup is displayed, such as the registration date, name of registrar, and country of origin.
If you cannot locate child observables or enrichment results, verify that the Reverse Whois integration ran successfully and returned domains. Also, refer to the work notes on the record for more information.
**Previous topic:** [Verify expected results for Reverse Whois](https://www.servicenow.com/docs/aeNqX74yuHAqTn8n0wiOqg "Enrichment results are displayed on the ReverseWhois Domains tab at the bottom of the security incident record. Locate the lookup results to verify that the lookup ran successfully.")  
**Next topic:** [RISKIQ and WHOISIQ integration](https://www.servicenow.com/docs/YeebJ_8XsG4aDpXNQlLUZA "With the integration of RISKIQ and WHOISIQ APIs with the ServiceNow AI Platform Security Operations product, security analysts are provided with additional enrichment data and insight into the validity of websites.")  
**Related tasks**   

* [Install and configure Reverse Whois](https://www.servicenow.com/docs/ExYRwXlfVHD~hnq_oCzytA "Before you run the integration on your instance, complete the installation and configuration steps so the Reverse Whois application properly integrates with the Security Operations product.")
* [Verify expected results for Reverse Whois](https://www.servicenow.com/docs/aeNqX74yuHAqTn8n0wiOqg "Enrichment results are displayed on the ReverseWhois Domains tab at the bottom of the security incident record. Locate the lookup results to verify that the lookup ran successfully.")

*[\>]: and then


