Create an AI connection for Amazon (v1.21.)
Create an AI connection for Amazon in AI Control Tower using the AI Service Graph Connector for Amazon (version 1.2.1).
Before you begin
Role required: sn_ai_disc.discovery_admin and sn_cmdb_int_util.sgc_admin
Procedure
Navigate to Al Control Tower > Configurations > AI connections.
Click Add.
Select AWS from the available connectors.
Click Create connection.
Review setup instructions page displays.
Note: Verify to follow all the prerequisite steps.
Select Download basic scripts.
Note: Download the basic scripts and select the check box.
Select Continue.
Setup page appears.
Select Source systems.
Choose the AWS services that you want to integrate with ServiceNow.
- Amazon Bedrock
- Amazon Bedrock AgentCore
- Amazon SageMaker
- Select Submit.
Configure Amazon Bedrock
Enter the Connection Name
Enter the Access Key ID
Enter the Secret Access Key
The Access keys are long-term credentials for an IAM user or the AWS account root user. Access keys consist of two parts: an access key ID and a secret access key. For detailed information, see how to get access and secret key.
Enter the AWS Region.
Note: The region information is available in the navigation bar of the AWS management console and this can be a comma separated field. So, you can enter multiple regions.
Enter the Management Account ID
Note: The Management Account ID applies in two scenarios:
- Your IAM user is created in a Designated Member account.
- You need Organizational-level access.
- Enter the Standalone Account ID
Note: This step is optional. Provide a single account ID to test discovery against that account before enabling full Organization discovery.
Enter the STS Assume Role
The role assumed for discovery.
Select Update and test connection
Select Continue
Configure Bedrock import schedule
Open a parent schedule import
Select the Active check box
Select Run according to your preference
To run frequency by demand, select Execute Now.
Note: This is an optional step as the schedule imports run according to the schedule.
Click Continue
Configure CloudWatch logs for Bedrock
Enter the Connection Name
Enter the Access Key.
Enter the Secret Key.
Enter the AWS Region.
Enter the Log Group Names
Select Create and test connection
Select Continue.
Configure CloudWatch logs import schedule for Bedrock
Open a parent schedule import.
Select the Active check box.
Select Run according to your preference
To run frequency by demand, select Execute Now.
Note: This is an optional step as the schedule imports run according to the schedule.
Select Continue
Configure SageMaker
Enter the Connection Name
Enter the Access Key ID
Enter the Secret Access Key
Enter the AWS Region
Select Create and test connection
Select Continue
Configure SageMaker import schedule
Open a parent schedule import
Select the Active check box
Select Run according to your preference
To run frequency by demand, select Execute Now.
Note: This is an optional step as the schedule imports run according to the schedule.
Select Continue
Configure CloudWatch monitoring for SageMaker
Enter the Connection Name
Enter the Access Key
Enter the Secret Key
Enter the AWS Region
Select Create and test connection
Select Continue
Configure CloudWatch monitoring import schedules for SageMaker
Open a parent schedule import
Select Active check box
Select Run according to your preference
To run frequency by demand, select Execute Now.
Note: This is an optional step as the schedule imports run according to the schedule.
Select Continue
Select the Confirm connection setup activity to verify whether the connection was configured.
Result
Click View all connections to view the newly created connection.
The AI connection for AWS is created and configured.