IT Operations Management -- Get better visibility into your infrastructure and services, prevent service outages, and expand your organization's operational agility with ServiceNow IT Operations Management.
Install ITOM -- Setup Hub provides a guided setup experience to install and configure IT Operations Management.
ITOM/OT SU Licensing and subscriptions -- ServiceNow IT Operations Management (ITOM) licensing calculates and displays the usage of ITOM subscriptions based on subscription units.
Exploring ITOM/OT SU Licensing -- Learn more about ServiceNow ITOM/OT SU Licensing, the different ITOM subscriptions it includes, and its benefit.
Subscriptions for IT Operations Management -- The ServiceNow AI Platform uses a licensing method where your organization is billed for using the following IT Operations Management products: ServiceNow ITOM Visibility, ServiceNow ITOM Discovery, ServiceNow ITOM AIOps, ServiceNow Health Log Analytics, ServiceNow ITOM Optimization, ServiceNow ITOM Cloud Accelerate, ServiceNow Service Reliability Management, ServiceNowSLO Management, ServiceNow Service Observability, and ServiceNow synthetic monitoring.
Data collection and aggregation for licensing process -- ITOM/OT SU Licensing application counts CIs for ITOM applications and uses a daily average count for the last 90 days to produce license statistics for purchased subscription units.
ITOM/OT SU Licensing subscription types -- Purchase licensing subscriptions for ITOM products individually (a la carte), bundle several products together, or opt for both individual and bundled subscriptions.
Subscriptions for Operational Technology Management -- The ServiceNow platform uses Operational Technology Management (OTM) to manage licenses for the manufacturing industry. OTM contains the licenses that are included in IT Operations Management, as well as licenses unique to OTM.
Configuring ITOM/OT SU Licensing -- Gain the capability to efficiently manage and optimize ITOM subscriptions within the ServiceNow framework for streamlined operations.
Update ServiceNow ITOM/OT SU Licensing -- Update the ServiceNow ITOM/OT SU Licensing [com.snc.itom.license] application to ensure you use the latest licensing functionality. Updating the application installs related ServiceNow Store applications and plugins if they are not already installed.
Using ITOM/OT SU Licensing -- Ensure optimal utilization of your organization's ITOM subscriptions by analyzing the resource usage of your ITOM products.
View subscription statistics for ITOM -- View how many subscriptions for IT Operations Management applications your organization purchased and consumed.
View CIs consuming ITOM subscription units -- Generate a list of currently countable CIs for each of the ITOM applications: ITOM Visibility, Discovery, ITOM AIOps, Health Log Analytics, ITOM Cloud Accelerate, and ITOM Optimization.
ITOM/OT SU Licensing Reference -- Reference topics provide additional information about scheduled jobs, tables, subscriptions form and dashboard that you use to configure and administer ITOM/OT SU Licensing.
ITOM/OT SU Licensing dashboard -- Use the ITOM Licensing dashboard to review the statistics of the resource consumption and status against your purchased subscriptions. This dashboard contains reports for each ITOM application. The reports offer visualization of the daily usage count and of the average consumption of subscription units for 90 days.
License Report form -- Description of the fields on the License Report form.
ITOM Store upgrades -- To be able to use ITOM at its full capacity, you can deploy the latest out-of-band upgrades from the ServiceNow Store. Learn about features and enhancements available out-of-band.
ITOM Cloud Accelerate -- ITOM Cloud Accelerate workflows streamline cloud automation across the cloud adoption journey via self-service catalogs and controlled workflows. It expedites application migration by facilitating assessment, planning, and resource migration tracking.
Cloud Account Management -- Cloud Account Management simplifies account management by automating tasks like creation and provisioning. Predefined policies enable easy suspension, reactivation, and certification of accounts. Potentially reduce provisioning times from weeks to minutes by automating requests, approvals, and setups.
Explore -- The ServiceNow Cloud Account Management in Cloud Workspace application provides a framework to streamline the cloud account creation and management process.
About data visualization in Cloud Account Management -- The Cloud Account Management overview dashboard gives a clear view of all cloud accounts and their compliance status. Cloud Account Management pulls data from Cloud Configuration Governance to create a simple, visual overview of compliance. As an admin, you can take the necessary actions for the reported vulnerabilities.
About policies in Cloud Account Management -- Cloud Account Management provides policy-driven rules to automate account provisioning, approvals, and security. These policies improve governance, control costs, enhance security, and promote sustainability in cloud operations. Regular reviews promote consistency and efficiency in managing cloud infrastructure.
Configuring Cloud Account Management -- Configuring the Cloud Account Management application involves a set of required tasks, integrations, and setups to be completed before initiating service account creation and provisioning.
Configuring cloud providers -- The topics in this section cover various cloud configurations required to set up and work with Cloud Account Management in Cloud Workspace.
Setting up AWS cloud -- This section covers all the topics required to set up AWS cloud. The topics are arranged based on configuration priority.
Setting up a root email -- The app creates accounts with a unique request ID and root email, promoting distinct emails for each account and simplifying management.
Set up and verify root email in AWS -- Create a unique email address to manage several accounts. Having multiple accounts and emails can be a significant challenge for an AWS admin. A single AD email for multiple AWS accounts simplifies management.
Set up an Identity Access Manager in AWS GovCloud -- Create AWS CloudFormation Identity Access Manager (IAM) resources for three AWS account types in the management account using the CloudFormation templates (CFT) to integrate ServiceNow Cloud Account management (CAM) with AWS GovCloud.
Configuring Service Control Policy in AWS -- The AWS admin configures a Service Control Policy (SCP) and shares its ID with the ServiceNow AI Platform admin for Cloud Account Management setup. Cloud Account Management enforces the SCP via API calls to block resource creation in the account.
Set up suspension of AWS account -- Set up a restriction on cloud account creation. For example, when the account owner isn’t in the organization or if there are budget constraints. Using Cloud Account Management, admin adds the account number to the AWS organization's service control policy, promoting existing accounts to continue to function normally while blocking new account creation.
Provisioning modes for Cloud Account Management in Cloud Workspace -- Cloud Account Management in Cloud Workspace offers flexible provision modes such as Terraform and cloud native interfaces while centralizing management, enhancing security, optimizing costs, and improving governance.
Setting up Terraform and GitHub -- Simplify cloud account provisioning using Terraform. The workflow provides the basic steps involved in setting up Terraform and GitHub.
Publish Terraform templates -- Publish the Terraform template defined by the application in GitHub to enable version control, collaboration, and centralized storage.
Integrate Terraform Cloud with GitHub -- Integrate GitHub with Terraform to link workspaces to repositories, enabling version control, change tracking, and rollbacks.
Create Terraform API token -- Generating API tokens with limited permissions enhances security, enables fine-grained control, facilitates automation, and provides temporary access within your Terraform organization.
Setting up Azure cloud -- This section covers all the topics required to set up Azure cloud. The topics are arranged in order of configuration priority.
Configure account suspension in Azure -- Manage an Azure subscription using the permission and by assigning the role to a user. The role must have the permission to execute the APIs for suspending and reactivating an Azure account.
Set up Azure Service Principal credential -- Provide the Azure credentials obtained from your Azure administrator. These credentials are used to create a suspension profile and enables you to suspend temporarily or terminate Azure accounts as needed.
Set up suspension of a subscription using Azure policy -- Create the policy at the root level to lock or unlock an Azure account. As an Azure administrator, lock an Azure subscription, resource group, or resource to avoid accidental deletions and modifications.
Install Cloud Workspace -- You can install the Cloud Workspace application (sn_itom_cam) if you have the admin role. The application includes demo data and installs related ServiceNow Store applications and plugins if they are not already installed.
Create a service account -- Create a service account in CAM. A service account holds the credential and account information that you created in your provider account. Discovery uses the information to access your provider account and then obtain information on each logical datacenter that is associated with the account.
Define and run discovery schedule -- The discovery schedule is the control point for running discoveries. The schedule controls when discovery runs, defines the MID Server to use, the type of discovery that should run, and the IP addresses to query.
Review default Cloud Account Management certification policy -- Review the default certification policy provided in Cloud Account Management to validate data against the policy set. This default policy certifies all available cloud service accounts every 90 days. Administrators can customize the default policy or create one as needed.
Configure a custom name for Cloud Account Management -- Configure a custom name for Cloud Account Management. You can optionally re-brand the Cloud Account Management with your company or any custom name. The name change is applicable only on the Cloud Account Management home page and navigation.
Create a variable set for Request cloud account catalog -- Customize the Request cloud account catalog by creating or editing variable sets. Build a variable set to group related variables into a single, reusable collection. Select only the necessary variables for specific cloud account requests to promote an organized and uniform process.
Add members to the group -- Ensure accurate assignment of members to their respective groups to streamline account requests, approvals, provisioning, and certification. Grant necessary permissions through proper group assignment to prevent unauthorized access and maintain security.
Set up AWS API configuration information in ServiceNow -- The credentials provided by your AWS administrator are used in this procedure to create a suspension profile, enabling you to temporarily suspend or terminate AWS accounts as needed.
Set up Terraform API key in ServiceNow -- Add the Terraform API key to the ServiceNow instance to ensure consistent and error-free infrastructure provisioning.
Set up Azure connection -- Add and configure an Azure connection with your Azure portal. Using the connection credentials, the Cloud Account Management application creates Azure subscriptions. This is a one-time configuration step.
Set up scan configuration for data visualization -- Visualize all account violations by scanning them using the selected policy set. Display the severity of all violations on the admin dashboard to take appropriate actions.
Creating configurations -- Setting up the Cloud Account Management app is a prerequisite task before proceeding to create, suspend, or scan a service account. By configuring Cloud Account Management, you can ensure that the application is ready to effectively execute account management tasks and deliver the desired results.
Create a Terraform account configuration -- Configure the Cloud Account Management app as a foundational step before creating a service account using Terraform. Proper Cloud Account Management setup ensures the application is optimally prepared to handle account management functions and achieve desired outcomes.Define and set up Terraform-based configurations to automate cloud account provisioning, including required credentials and infrastructure templates.
Create a suspend account configuration -- Set up a suspension profile that allows temporary suspension or termination of cloud accounts to support cost control or policy enforcement.
Create a scan account configuration -- Configure the Cloud Account Management app before scanning a service account to confirm it’s ready for effective account management.
Review request policies -- Review and update request policies to confirm they align with your cloud account request process. These policies enforce data checks and conditions, promoting consistency in creating cloud subscription accounts.
Automate General Approval policy process -- Automate the general approval or rejection of requests based on predefined conditions. Requests are automatically approved when the criteria are met. Otherwise, the system waits for manual approval. You can modify the default policy to include additional conditions as needed.
Automate Budget Approval policy process -- Automate finance approvals for Cloud Account Management requests based on predefined conditions. Approve requests automatically when criteria are met. Otherwise, wait for manual approval. Modify the default policy to include additional conditions as necessary.
Automate Configuration Assignment policy process -- Automate assigning configurations and AWS organizational units in requests based on specified conditions. When conditions are met and approvals are complete, requests move forward without admin input. Update the default policy to include specific conditions and values for configuration and AWS organizational unit.
Viewing Cloud Account Management dashboards -- Cloud Account Management has two types of dashboards: one for requesters and another for admins. Depending on the logged- in user, an appropriate dashboard appears.
Viewing the requester home page -- View and manage cloud account requests on requester page. The home page provides a view of requested, approved, denied, pending, and active accounts.
Viewing the home page -- View account statuses and violations, actionable insights, and administrative controls on the home page.
Viewing the compliance dashboard -- The Cloud Workspace compliance dashboard provides insights that help security teams identify cloud resources without ownership information and flag vulnerable or at-risk resources. This information helps team members conduct security audits and confirm compliance with industry regulations across cloud environments.
Viewing the cloud asset explorer -- The dashboard helps cloud governance and operations teams monitor, track, and act on compliance and asset details more efficiently. As an asset viewer, you can view all assets and drill down to see detailed information for each configuration item (CI).
Managing the Cloud Account Management cloud asset details -- Use the cloud asset form in the Cloud Account Management to view, edit, and manage a comprehensive set of details of a cloud asset such as its attributes, its health, and its records.
Viewing cloud assets -- This page displays the Cloud assets view. It lists all compute assets across connected cloud providers such as AWS, Azure, GCP, and OCI along with location, cloud account, installation status, owner, discovered dates, ownership attestation, and cost center.
Viewing the cloud accounts page -- The Cloud accounts page displays information used to access and manage the life cycle of multiple cloud subscription accounts.
Viewing cloud account records -- The Cloud account records page is a comprehensive dashboard that provides information to help you manage a cloud account.
Creating a cloud account -- Creating a cloud account involves a requester submitting an account request, an approver approving or rejecting the request, and that admin provisioning the account.
Request a cloud account -- Request a cloud account as a requester. A notification email is sent when the requester creates an account request.
Approve a cloud account request -- Approve or deny a cloud account request as an approver. A notification email is received when the requester creates an account request. When a cloud account is requested, the table captures and retrieves the details of the request. Once the Cloud Account Management request is approved, it’s assigned to a provisioner, such as CCOE, DevOps, or SRE.
Managing cloud accounts -- Managing a cloud account enables you to accomplish a range of tasks such as canceling, suspending, or reactivating cloud accounts, and adding unmanaged accounts.
Suspend a Cloud account -- Suspend an account when there’s a budget constraint or the account owner isn’t available in the organization. Only admins and account owners can see the suspended accounts.
Reactivate a cloud account -- Reactivate an account that was previously suspended if there is a need retrieve the account. After reactivating an account, the account status changes from suspended to active. Only Cloud Account Management managed accounts can be reactivated.
Add an unmanaged cloud account -- Managing a cloud account involves tracking budgets, checking for configuration violations, and validating certificates. The procedure helps you to onboard an unmanaged cloud account.
Update cloud account details -- Keep account details up to date so you can identify and resolve policy violations effectively.
Certify an account -- A certification task represents the work of verifying and certifying the data associated with a record. The certifier reviews tasks created after data validation against the published policy. Account certification helps resolve issues like outdated ownership, inactive user profiles, and improper permissions in cloud accounts.
Cloud Account Management reference -- Reference topics provide additional information for configuring and using the Cloud Account Management in Cloud Workspace application.
Permissions required for Azure Service Principal -- This table provides the permissions needed to create, close or cancel an Azure subscription, download billing details, and tag subscriptions.
Cloud account details -- The Cloud account details table provides detailed information about each account.
Cloud Services Catalog -- With the ServiceNow Cloud Services Catalog application, you can use a simplified interface to access cloud resources. You can publish cloud offerings to a catalog and manage the usage and life cycle of those resources.
Exploring Cloud Services Catalog -- The Cloud Services Catalog application is the single place that you have to go to for automating cloud management tooling. It replaces and improves on the capabilities that were offered by Cloud Provisioning and Governance user and admin portals.
Configuring Cloud Services Catalog -- You can configure the Cloud Services Catalog application so that so can begin to automate cloud management tooling.
Install Cloud Services Catalog -- You can install the Cloud Services Catalog application purchased from the ServiceNow Store, to make it available on your instance.If the application does NOT include demo data or it does NOT install related applications and plugins, delete or revise the following sentence:The application also includes demo data and installs related to ServiceNow applications and plugins, if you don’t have them installed already.
Cloud Services Catalog setup for the Day 1 configuration task -- You're ready to do the Day 1 configuration task of setting up the Cloud Services Catalog application for the first time. You can do the optional Day 2 setup and configure procedures as needed, in any order.
Set up Amazon Web Services on Cloud Services Catalog -- Integrate Cloud Services Catalog with your Amazon Web Services account as a part of the Day 1 configuration task of setting up the application for the first time.
Integrating Azure DevOps and CI-CD tool -- You can process the release request from the Cloud Services Catalog workflow with Azure DevOps for end-to-end automation of the development process, including provisioning the resources, and deploying and monitoring the applications.
Release pipelines and Azure DevOps by Cloud Services Catalog -- Azure DevOps has release pipelines, such as the Continuous Integration-Continuous Deployment (CI-CD) pipelines, that offer a build, test, and deploy approach. You can use these fully automated processes to rapidly deploy build requests to the production environment.
Set up the Microsoft Azure DevOps console -- Set up the Microsoft Azure DevOps console as the first step before you run Discovery and order a catalog item in the Cloud Services Catalog application.
Run Discovery on Azure DevOps config provider -- Add the Azure DevOps config provider and run Discovery to discover all projects, pipelines, and pipeline variables in an organization by using the Cloud Services Catalog application.
Order a Microsoft Azure DevOps catalog item -- Provision the Microsoft Azure DevOps catalog by using the Microsoft Azure DevOps catalog order form in the Cloud Services Catalog application.
Integrating Ansible with Cloud Services Catalog -- Integrate Ansible with Cloud Services Catalog as a Day 1 activity. With this activity, you can deploy an Ansible job template via a ServiceNow catalog item.
Set up Ansible as a Day 1 task -- Set up the Ansible console as a Day 1 task before you run Discovery and deploy a job template via a ServiceNow catalog item by using the Cloud Services Catalog application.
Run Discovery on the Ansible config provider -- Add the Ansible config provider and run Discovery to discover what's in the inventory, the host group, and the available job templates.
Order an Ansible job template -- Use Cloud Services Catalog to order an Ansible job template called from the catalog item.
Cloud Services Catalog administration guide -- After you set up the Cloud Services Catalog application, you must set up some additional items so that your users can request and manage any cloud resource.
Cloud Services Catalog and Terraform Connector -- Use the Cloud Services Catalog app with Terraform Connector support with all its features that help in provisioning and managing cloud resources across various public and private clouds.
Policies and permission levels on services -- Configure policies with the necessary level of permissions to provide access to the AWS, Azure, ADO, Ansible and Google Cloud services, respectively.
Using Cloud Services Catalog -- The Cloud Services Catalog application is a dynamic portal for all your day-to-day cloud activities. It enables you to manage stacks, work with requests, and access the Out Of Box catalog items and other popular topics.
Requesting Cloud Services -- Submit a request for one of the available service catalog item in cloud services. You can find the catalogs under Browse Cloud Services.
Exploring the My Stacks tab -- Sort, view, or manage your stack of cloud resources and services as a part of the Day 2 activities by using the My Stacks tab on the Employee Center toolbar in Cloud Services Catalog.
Manage My Stacks -- Use the My Stacks tab to access all the stack properties such as the creation, update, and deletion details.
Work with stacks -- Start your Day 2 operations by starting, stopping, deprovisioning, or modifying your stacks.
View stack dependency -- Explore the details of the configuration items, services, and other tasks that are associated with the stacks and resources by using View Dependency.
Stack activities view -- Display the cloud actions on your stacks and resources by using the View Activities tab.
Actions on stacks -- Access a particular stack to perform a Day 2 or life-cycle operations such as stop, start, deprovision, ModifyLease, or ModifySchedule.
Redirection to My Stacks -- You can use redirection to your My Stacks tab as an alternate but simplified way to locate a stack from the My Requests tab. For example, you can use redirection while you're looking up a stack that was recently provisioned.
Exploring My Resources -- Observe and interact with discovered resources by using the My Resources option under More tab on the Employee Center toolbar.
Manage My Resources and resource filters -- Access the resources that you own, resources that are owned by a group, or anyone's resources by using the resource filter. You can then find the information that you need by using sorting functions, conditions, categories, and keywords.
Microsoft Azure Linux Out Of Box Catalog items -- Cloud Services Catalog Linux VM with agent client collector (ACC), up to 10 additional disks, security groups or with scalable web servers or with security groups.
Out Of Box Actions -- The Out of the Box Actions comprise OOB deployment, tagging, retrieving and post-provisioning operations. All these actions are based on Flow Designer and implemented as Integration Hub Sub-flows.
Out Of Box Policies -- The Cloud Services Catalog Out of the Box Policies comprise Approval, Naming, Lease and Quota Provisioning Policies.
CSC references -- Reference topics provide additional information about the lists and forms that you use to configure, administer and use Cloud Services Catalog.
Domain separation and Cloud Services Catalog -- Domain separation is supported in Cloud Services Catalog. Domain separation enables you to separate data, processes, and administrative tasks into logical groupings called domains. You can control several aspects of this separation, including which users can see and access data.
Stages of Azure DevOps in Release life cycle management -- The components and stages of an Azure DevOps pipeline are comprehensive and highly customizable. You can define multiple stages, tasks, and integrations based on your specific requirements and technology stack using Cloud Services Catalog.
Workaround to known issues -- The workaround steps to some of the known issues are compiled and described in the Knowledge Base.
Cloud Provisioning and Governance -- The ServiceNow Cloud Provisioning and Governance (CPG) application serves as a unified interface for accessing cloud resources, delivering cloud offerings to a catalog, and overseeing resource usage. This application is transformed as Cloud Services Catalog application, offering refined and streamlined management of usage and life cycle of cloud resources.
Request the Cloud Provisioning and Governance application -- The Cloud Provisioning and Governance application is available as a separate subscription and requires the Cloud Provisioning and Governance plugin (com.snc.cloud.mgmt).
Product Name Change -- Starting with the Paris release, the ServiceNow Cloud Management application was called ServiceNow Cloud Provisioning and Governance. The application is transformed into Cloud Services Catalog application providing improved and efficient management of the usage and life cycle of cloud resources.
Day 1 setup guide for Amazon Web Services on Cloud Provisioning and Governance -- To set up Cloud Provisioning and Governance for the very first time, you perform the procedures in this "Day 1" setup guide. Be sure to perform the procedures in order. After you have performed Day 1 setup, you can perform optional Day 2 setup and configuration procedures as needed and in any order. Detailed instructions for each procedure follow this overview.
Set up a cloud account and service account for AWS -- A service account is a secure record on your instance that stores the credential and access information for your provider account. Discovery uses the information to access your provider account to get data on each resource in each specified datacenter. A cloud account is the logical representation in Cloud Provisioning and Governance of all or part of your managed cloud infrastructure. A cloud account can include multiple service accounts — even service accounts from different providers. For each service account, you specify which datacenters to include in the cloud account.
Configure a custom AWS member role -- Customize the AWS roles that a MID Server can assume to receive temporary credentials for member accounts. You can configure additional parameters to improve security and customize the way that the member account’s role is assumed when discovering cloud resources.
Create AWS GovCloud credentials for Cloud Provisioning and Governance -- Skip this procedure if your organization does not use AWS GovCloud (US). To securely access data on your provider account, the Discovery process must present appropriate credentials. An AWS GovCloud (US) region is an isolated AWS region that meets stringent US government security and compliance requirements to host sensitive workloads. Cloud Provisioning and Governance supports all AWS GovCloud (US) services.
Create a service account for AWS GovCloud -- If your organization uses AWS GovCloud (US) region, you must create a service account in the region where you provision the resources. These credentials that you create are used for Cloud Discovery, Cloud Provisioning and Governance, and Cloud Cost Management.
Define the schedule for downloading AWS billing data -- Define the scheduled job that regularly uses a MID Server to download billing data from the provider. Cloud Provisioning and Governance saves the data in a cost table and uses the information to generate reports.
Configure the download size of AWS billing data -- A single set of cloud billing data can be large. The MID Server, therefore, sends the data to the ECC queue in manageable chunks. You can optionally configure a system property to limit the size of each chunk to avoid performance issues caused by large data transfers.
Add an AWS service account to the cloud account -- During Cloud Provisioning and Governance Day 1 setup, you added one service account to the cloud account. To compartmentalize your infrastructure or to include different datacenters, you can add another service account. A particular datacenter, however, cannot be selected in more than one service account in a cloud account.
Day 1 setup guide for Microsoft Azure Cloud on Cloud Provisioning and Governance -- To set up Cloud Provisioning and Governance for the very first time, you perform the procedures in this "Day 1" setup guide. Be sure to perform the procedures in order. After you have performed Day 1 setup, you can perform optional Day 2 setup and configuration procedures as needed and in any order. Detailed instructions for each procedure follow this overview.
Set up Microsoft Azure Government Cloud on Cloud Provisioning and Governance -- Set up Microsoft Azure Government Cloud on Cloud Provisioning and Governance for the first time. You can discover, provision, and manage Microsoft Azure Government Cloud resources using Cloud Provisioning and Governance, thereafter.
Create a Microsoft Azure service principal -- To securely access resource and billing data on your Microsoft Azure account, the Discovery process must present appropriate Microsoft Azure account credentials. You create a special programmatic account — a Microsoft Azure service principal — to generate the required credentials.
Store the Azure service principal credentials in the instance -- To securely access data on your provider account, the Discovery process must present appropriate credentials. To make the credentials available to Discovery, you first create Azure service principal credentials in the Azure Portal. You then securely store the credentials in a service account in your instance.
Add an Azure service account -- During Cloud Provisioning Day 1 setup, you added one service account to the cloud account. To compartmentalize your infrastructure or to include different datacenters, you can add another service account. A particular datacenter, however, cannot be selected in more than one service account in a cloud account. Note: Resource ID
Set up a cloud account for Azure -- A cloud account is the logical representation in Cloud Provisioning and Governance of all or part of your managed cloud infrastructure. A cloud account can include multiple service accounts — even service accounts from different providers. For each service account, you specify which datacenters to include in the cloud account.
Create Microsoft Azure credentials for billing download -- Define the scheduled job that regularly uses a MID Server to download billing data from the provider. Cloud Provisioning and Governance saves the data in a cost table and uses the information to generate reports.
Configure the download size of Microsoft Azure billing data -- A single set of cloud billing data can be large. The MID Server, therefore, sends the data to the ECC queue in manageable chunks. You can optionally configure a system property to limit the size of each chunk to avoid performance issues caused by large data transfers.
Day 1 setup guide for Google Cloud through Cloud Services Catalog Terraform Connector -- To set up Google Cloud for the first time, follow the steps in this Day 1 setup guide in the order they are presented. After completing the Day 1 setup, you can proceed with the optional Day 2 configuration steps as needed, in any order. Detailed instructions for each step are provided in the sections below.
Assign roles to Google Cloud Platform users -- You assign Cloud Provisioning and Governance roles to user groups and to individual users based on user activities and responsibilities.
Specify the credentials that CSC Terraform Connector uses to access Google Cloud Platform data -- To securely access data on your provider account, the Discovery process must present appropriate credentials. To make the credentials available to Discovery, you open the Google Cloud Console to identify the Google Cloud Platform project that will have programmatic access to your Google Cloud Platform data. You then securely store the credentials in a service account in your instance.
Set up a cloud account and service account for Google Cloud Platform -- A service account is a secure record on your instance that stores the credential and access information for your provider account. Discovery uses the information to access your provider account to get data on each resource in each specified datacenter. A cloud account is the logical representation in Cloud Provisioning and Governance of all or part of your managed cloud infrastructure. A cloud account can include multiple service accounts — even service accounts from different providers. For each service account, you specify which datacenters to include in the cloud account.
(Optional) Add a Google Cloud Platform service account to the cloud account -- During Cloud Provisioning and Governance Day 1 setup, you added one service account to the cloud account. To compartmentalize your infrastructure or to include different datacenters, you can add another service account. A particular datacenter, however, cannot be selected in more than one service account in a cloud account.
Day 1 setup guide for VMware on Cloud Provisioning and Governance -- To set up Cloud Provisioning and Governance for the very first time, you perform the procedures in this "Day 1" setup guide. Be sure to perform the procedures in order. After you have performed Day 1 setup, you can perform optional Day 2 setup and configuration procedures as needed and in any order. Detailed instructions for each procedure follow this overview.
Create the credential and service account that will access your VMware data -- To securely access data on your provider account, the Discovery process must present appropriate credentials. To make the credentials available to Discovery, you first create an account in the VMware Console. You then securely store the credentials in a service account in your instance.
Set up cloud accounts for VMware -- A cloud account is the logical representation in Cloud Provisioning and Governance of all or part of your managed cloud infrastructure. A cloud account can include multiple service accounts — even service accounts from different providers. For each service account, you specify which datacenters to include in the cloud account.
Add a datacenter to a cloud account -- At any time, you can add a logical datacenter to the cloud infrastructure that is represented by a cloud account.
Additional Cloud Provisioning and Governance setup on day 2 -- After you have performed Day 1 setup, you can perform optional setup and configuration procedures as needed and in any order. Detailed instructions for each procedure follow this overview.
Set up an additional cloud account -- During initial installation, you set up one cloud account. To organize and compartmentalize your infrastructure, you can set up additional cloud accounts to include different providers or service accounts or datacenters.
Set capacity limit on requests -- Capacity limits place restrictions on the attributes of cloud resources such as the number of virtual machines, virtual CPUs, or aggregate storage. You can set limits on resources separately for each logical datacenter in a cloud account.
Use owner and assignment groups -- You must set up and use the user groups in Cloud Provisioning and Governance as a part of the day-2 task.
Cloud Provisioning and Governance administration guide -- After you set up the Cloud Provisioning and Governance application on your instance, there are many items that you must configure before your users can request and manage any cloud resources.
Domain separation and Cloud Provisioning and Governance -- Domain separation is supported in Cloud Provisioning and Governance. Domain separation enables you to separate data, processes, and administrative tasks into logical groupings called domains. You can control several aspects of this separation, including which users can see and access data.
On-board a Company -- Review the following considerations to on-board customers or companies in a domain separated instance, for Cloud Provisioning and Governance services.
Domain admin considerations -- Before configuring domain separation for customers, ensure that you review the following considerations ahead of provisioning cloud resources for each domain you are managing in the Cloud Provisioning and Governance application.
Cloud Provisioning and Governance Recipes -- Multi-cloud recipes provide ready content for typical cloud deployment and common operations scenarios across cloud platforms.
Cloud accounts -- A cloud account is the logical representation in Cloud Provisioning and Governance of all or part of your managed cloud infrastructure. A cloud account can include multiple service accounts — even service accounts from different providers. For each service account, you specify which datacenters to include in the cloud account.
Cloud Admin Portal -- The Cloud Admin Portal is a role-based portal. You can manage, design, govern, operate, and analyze all your cloud resources from a unified base.
Resource Profiles -- Resource profiles are cloud provider-agnostic definitions that specify the allowed attribute values for a resource. Resource profiles enable you to control the choices that the user sees when requesting a cloud resource. As a result, you do not need to define a unique blueprint for each variation of the resource.
Create an application profile -- An application profile specifies application software to install on newly-provisioned resources. Users can select applications when they request a stack. Use application profiles when you integrate with configuration management (continuous delivery) providers such as Ansible playbooks.
Create a compute profile -- A compute profile specifies the hardware to use for newly-provisioned virtual machines. A compute profile maps to a cloud account, a datacenter, and a hardware template.
Create a compute security group profile -- A compute security group profile applies specified security rules to newly-provisioned resources. You map a compute security group profile to a cloud account, a datacenter, a Compute Security Group template, and security rules for the template.
Create an OS profile -- An OS profile installs a specified image on a newly-provisioned virtual machine. You map an OS profile to a cloud account, a location (datacenter), an image template, and a cloud script. OS profiles are provider-agnostic and you can use the same profile for multiple cloud accounts.
Create a schedule profile -- You map a schedule profile to an instance schedule. The schedule profile applies to all newly-provisioned resources that use the profile. For example, a schedule profile can specify the days of the week and times of day when a stack should start and stop.
Add credentials to an image template -- When you add credentials to an image template, the credentials are inherited by all VMs that are provisioned using the template.
IPAM integration -- Use an IP address management (IPAM) tool like Infoblox to manage cloud IP addresses, networks, and subnets within your cloud catalog offerings. However, it's important to note that this functionality is not supported with our template-based cloud catalogs.
Register an Infoblox server -- To integrate with Infoblox, you must create an Infoblox record and associate it with the appropriate credentials to register your Infoblox server with the instance.
Create an IP pool -- Create an IP pool to associate a cloud subnet with an IPAM provider instance.
Create a cloud subnet -- If you have subnets in your VMware vSphere account, create a cloud subnet record in the instance.
Reserve IP address for VMware vSphere -- Create a policy to reserve IP addresses for VMware vSphere virtual machines in Infoblox, at the time of provisioning the virtual machines.
Register IP address for Azure and AWS -- Create a policy to register IP addresses for AWS and Azure virtual machines in Infoblox, once these virtual machines are provisioned.
Delete a host record in Infoblox -- When a virtual machine is de-provisioned, delete the host record from Infoblox. Deleting the host record enables that IP address to be available and be reused for other virtual machines.
Support for continuous delivery (configuration management) -- The Cloud Provisioning and Governance application supports integration with continuous delivery solutions (also known as configuration management). Ansible is supported as the default config management provider.
Create a workload provider type -- Create a workload provider type for each new configuration management provider. This information appears in the order catalog form as management attributes that your users can select when provisioning a virtual resource through a configuration management provider.
Cloud Services Catalog Terraform Connector -- Use the ServiceNow Cloud Services Catalog Terraform Connector to generate catalog items from the Terraform templates and use them to provision and manage resources in various clouds.
Exploring Cloud Services Catalog Terraform Connector -- Whether you're starting or expanding your implementation of Cloud Services Catalog Terraform Connector, learn more about the available features that help in provisioning and managing cloud resources across various public and private clouds.
Install Cloud Services Catalog Terraform Connector -- You can install the Cloud Services Catalog Terraform Connector application (com.sn_cmp_terraform) if you have the admin role.If the application does NOT include demo data or it does NOT install related applications and plugins, delete or revise the following sentence:
Create a Terraform Open Source config provider -- Create a Terraform Open Source config provider in Cloud Provisioning and Governance. The Terraform Open Source config provider enables Cloud Provisioning and Governance to discover the Terraform Open Source config installables (Terraform templates) and detect changes in them.
Create a Terraform Enterprise or Terraform Cloud config provider -- Create Terraform Enterprise or Terraform Cloud config provider in Cloud Provisioning and Governance. The config provider enables Cloud Provisioning and Governance to discover the workspaces and Version Control System (VCS) repositories attached to the Terraform organization.
Create API key for Terraform and VCS accounts -- Create API key credential for Terraform account and supported Version Control System (VCS) accounts that contain the Terraform template repositories.
Run the IaC Discovery -- Run the Infrastructure as Code (IaC) discovery to identify the resources of the Terraform environment.
Domain separation and Cloud Services Catalog Terraform Connector -- If any conrefs are broken, re-add them from the doc/source/reuse/domain-separation/domain-separation-overview.dita file. In the short description, edit the first sentence to state whether domain separation is supported or not and add the application name. Keep the conref at the end that describes domain separation.Domain separation is supported for Cloud Services Catalog Terraform Connector. Domain separation enables you to separate data, processes, and administrative tasks into logical groupings called domains. You can control several aspects of this separation, including which users can see and access data.
Populate the datacenter in Terraform-based catalog items -- In any request for a catalog item using Terraform templates, the required Location value specifies the datacenter or region where to provision the configuration items and stacks. You can use a variable named region in the Terraform template to map to the Location field on the request form.
Create a catalog item from the Terraform template -- Create a catalog item from the Terraform template to request cloud resource provisioning. Activated catalog items appear in the cloud user portal.
Manage the Terraform template-based catalog items -- Use an Infrastructure as Code (IaC) change task to create or update the Terraform template-based catalog items. The IaC change task helps ensure that the catalog items are aligned with the latest infrastructure specifications coded in the Terraform template.
Map credentials between Cloud Provisioning and Governance and Terraform -- Map credential types and service account fields Check for accuracy after IaC provider settings is updated to Credential mappings between Cloud Provisioning and Governance and Terraform using Credential Mapping.
Associate environment variable with CPG resource block -- Associate the Terraform environment variable with the Cloud Provisioning and Governance datacenter resource block. After associating the environment variable, you can use it to pass custom inputs parameters during resource deployment through Terraform Enterprise.
Day 2 operations using Workflow Studio subflow -- Take advantage of the flow designer to automate your Day 2 operations. Quickly write a subflow that communicates with a Cloud API or a particular resource.
Credential handling -- Extend the workflow engine to manage processes and automate things outside of an instance with Orchestration. Use the appropriate credentials required by Orchestration SSH and PowerShell activity elements: SSH requires SSH and PowerShell requires Windows.
Create a cloud catalog item -- Create a cloud catalog item for provisioning, based on a template or an existing blueprint, and publish the catalog item to provide a service.
Create a cloud template-based catalog item -- Create a cloud template and associate the template with a catalog item. Once you've created a template, you can reuse the template to create additional catalog items for the services you want to provision.
Create pre-provisioning operations -- Pre-provisioning operations streamline catalog item deployment by automating tasks like notifications, workflows, or scripts before provisioning. Configuring these operations eliminates manual steps, saving time and effort as the system automatically executes specified actions when a provisioning request is submitted, such as notifying users about the impending item provisioning process.
Create post-provision operations -- Create post-provision tasks for newly provisioned catalog items by defining subflows, scripts, CAPI calls, or resource operations. For efficiency, set up a post-provision operation, eliminating the need for manual invocation. This approach enhances time management, ensuring seamless execution of desired actions on the catalog item after resource provisioning.
Make catalog item visible -- You can use the catalog items created in cloud management, in standard service portal.
Create a variable set for Cloud Provisioning and Governance -- Reduce the number of steps required to create and manage multiple catalog items and order guides by creating variable sets. With variable sets, you don't have to create variables individually for each catalog item.
Manage operation attributes -- You can specify attribute values for catalog items help cloud users to correctly provision catalog items. You can configure and manage attributes for provision, pre-provision, and post-provision operations.
Cloud Provisioning Blueprints -- A blueprint is a specialized catalog item template for offering cloud services, or stacks, to cloud users. Blueprints work with any cloud service provider, such as Amazon AWS Cloud or Microsoft Azure Cloud. Blueprints are in restricted usage from the Orlando release.
Build a Cloud Provisioning blueprint -- Use the blueprint designer to create custom blueprints for the Cloud Provisioning and Governance application. Blueprints are deprecated in the Orlando release.
Blueprint attributes -- When you add a blueprint operation to a resource, the system adds the appropriate attributes. You can choose whether or not to make the attributes available as catalog properties on the form when the system performs the operation.
Configure a blueprint rule -- Configure a rule that contains actions the system can take on blueprint attributes.
Configure a blueprint action -- Configure a rule that contains actions the system can take on blueprint attributes.
Form configuration with blueprints -- Blueprints control what the user sees on the catalog order form. You can configure the form to show or hide fields, populate fields with default values, and otherwise create a unique form for the user based on criteria.
Add fields to a cloud catalog item order form -- You can add fields to a cloud catalog form if you want the user to enter additional information beyond what a default blueprint provides.
Control visibility default values for Cloud catalog items -- Through blueprints, you can control how form fields appear to users in the cloud catalog. For example, you can control where the fields appear to users on the catalog item form, and whether they are read only or mandatory.
Cloud catalog form configuration examples -- Several examples are provided to help you understand how to manipulate Cloud catalog order forms. These example cover blueprint rules, blueprint variables, and blueprint form UI groups.
Populate stack name with a script -- This example illustrates how to populate the name of the stack that a user requests from the Cloud Provisioning and Governance catalog by utilizing the user's ID. The example uses a script include that you can call from a blueprint rule action.
Set default values for a cloud catalog form fields -- You can set default values for all users or you can populate fields with default values based on conditions. This example shows you how to set a default schedule profile and business service.
Create a custom resource block -- If the blocks in the base system do not provide the cloud resources that you need to provision, you can create a custom resource block.
Specify a host resource for a resource block -- Hosts that support the Host interface of a resource block are potential hosts for the resource block. You use the Host interface setting to further limit the options that are presented to the stack requester while selecting a host type.
Specify the bindings for resource blocks -- Bindings represent endpoint relationships. For example, a storage volume might implement an endpoint type of Block EP (cmdb_ci_endpoint_block). A virtual server might consume an endpoint of that type. Bindings must support the Guest interface that is specified for the resource block.
Configure resource block input parameters -- You can configure operations for each interface of a resource block by specifying input parameters, steps, and output attributes. Input parameters hold values that the system requires to identify and manage a virtual resource, such as the datacenter and resource group that the resource is in.
Add operation steps to a resource block -- After you configure operations and input parameters for your resource block, add steps for each operation to tell the system which Cloud API (CAPI) to call. Each step is a separate call to CAPI.
Execute response processor for subflow -- Execute a response processor for a subflow to get the subflow data back into a configuration item (CI). The response processor picks up the data, sends the data to the CMDB, which in turn puts the data in a CI.
Virtual server response processor example -- The Create_Virtual_Server_Response_Processor script, which is available by default in Cloud Provisioning and Governance, is the response processor that handles the creation of AWS virtual machine CIs.
Add Terraform Orchestration interface on a resource block -- After you have activated the Terraform store app for Cloud Provisioning and Governance, to support cloud-based operations for cloud providers using Terraform Open Source Edition. Add the Terraform Orchestration interface on resource block, to execute cloud-based operations via terraform templates.
Create a resource block for Microsoft Azure Cloud -- Resource blocks are the building blocks of cloud catalog items. Create a resource block for the Microsoft Azure Cloud Platform provider, based on a CI type from the CMDB.
Cloud scripts and cloud script templates -- In the Cloud Provisioning and Governance application, script execution is divided into cloud scripts and cloud script templates. Use scripts in blueprints, resource blocks, OS profiles, and use policy scripts to set request form attributes. Policy scripts cannot override user data.
Map a script to an OS profile -- To execute scripted actions during VM provisioning, you can map a script to an OS profile. The script runs on VMs that are created based on the image template in the OS profile.
Cloud Governance -- Governance refers to the limitations that you can set on available cloud resources.
Permissions management for Cloud Governance roles -- Permissions are user group-level access rights to features in the Cloud Provisioning and Governance application and to specific records in the instance, such as blueprints or cloud accounts.
Assign a cloud permission -- Assign a permission to refine the actions that are allowed or prohibited for users based on the user group they belong to.
Policies for Cloud Provisioning -- A cloud policy can override a property value set by a user, create an approval task, reserve an IP address, pre-populate or hide form fields, execute custom scripts, call the Cloud API, or start or abort subflows. A cloud policy gives you system-wide control over approvals, resource operations, blueprint operations, or catalog item settings.
Cloud policy example -- A base system cloud policy, Lease End ServiceNow, uses the on Lease end trigger that fires when a virtual resource is near the lease end date. If the conditions in the policy rule are met, the policy engine sends a notification to the owner of the resource and performs operations on the resource.
Triggers for cloud policies -- Triggers are events that set the policy engine in motion. For example, the on Catalog item request end trigger fires after a user submits a request form. When the trigger for a policy fires, the policy engine tests the conditions specified in the policy rule and performs the actions specified in the rule, if the conditions are met.
Create a cloud policy -- A cloud policy can override a property value set by a user, create an approval task, reserve an IP address, pre-populate or hide form fields, execute custom scripts, call the Cloud API, or start or abort subflows. A cloud policy gives you system-wide control over approvals, resource operations, blueprint operations, or catalog item settings.
Configure a cloud policy rule -- A policy rule is a collection of conditions and actions. If all conditions evaluate to true, the policy engine performs the actions. If any condition evaluates to false, the policy engine does not perform the actions.
Using expressions in Cloud Provisioning and Governance -- Expressions in policy actions can set or override values. Expressions in blueprints can access attributes of resources and can map values to request form fields. Expressions are available in resource blocks, blueprints, policies, and anywhere that Cloud Provisioning and Governance allows scripts.
Create an action for an 'on Blueprint provision' policy -- The on Blueprint provision trigger fires after execution of on Catalog item request start policies. A policy that is triggered by the on Blueprint provision trigger can run a script, override a user-requested attribute value, or abort and send a message about the provision operation.
Create an action for an approval policy -- A policy that is triggered by one of the approval triggers can start approval subflows. The approval triggers are ( on Blueprint provision (approval), on Stack operation (approval), on Stack resource operation (approval), and on Task remediation .
Create an action for an 'on Catalog item launch' policy -- The on Catalog item launch trigger fires when an order form (stack request form) is launched for a catalog item. A policy that is triggered by the on Catalog item launch trigger can run a script or override a user-requested value (text values only).
Create action for 'on Catalog item request start/end' -- The on Catalog item request start trigger fires after the user opens a request form. The on Catalog item request end trigger fires after a user submits a request form. A policy that is triggered by the on Catalog item request start or on Catalog item request end trigger can run a script or execute a subflow.
Create an action for an 'on Lease end' policy -- A policy that is triggered by the on Lease end trigger can send a notification or perform a Start, Stop, or Deprovision life cycle operation.
Create an action for an 'on Resource operation' policy -- The on Resource operation trigger fires during the Orchestration process when a user performs a Start, Stop, or Deprovision life cycle operation on a specific resource. A policy that is triggered by the on Resource operation trigger can override a user-requested attribute value, run a script, call a Cloud API, or perform an IP address management operation.
Create action for 'on Resource operation launch' -- The on Resource operation launch trigger fires before the catalog for a resource operation is loaded from the Cloud User Portal. A policy that is triggered by the on Resource operation launch trigger can run a script or can override a user-requested value (text values only).
Create action for 'on Resource operation request start/end' -- A policy that is triggered by the on Resource operation request start or on Resource operation request end trigger can run a script or override a user-requested attribute value.
Create an action for an 'on Resource Limit exceeded' policy -- Set the on Resource limits exceeded policy to automatically run approval subflows or send notifications when an order form is submitted for a template-based catalog item that exceeds the defined resource limit or quota values.
Create an action for an 'on Task Remediation' policy -- The on Task remediation trigger fires when a user resubmits a failed request. A policy that is triggered by the on Task Remediation trigger can start approval subflows.
Example policy action script that tags resources -- Your instance tracks tagged resources for billing and reporting. Policy action scripts can add and modify resource tags. This example tags a storage volume resource.
Create a cloud approval policy -- A cloud approval policy specifies the users who must approve a specified cloud activity before the activity can proceed. Approvers can include the manager of the user making a request, a specified user or group, or users with a specified role. You can specify multiple approvers. Approvals occur in the order that you specify.
Create a cloud policy group -- A cloud policy group is a container for related policies. Consider grouping policies that are often used together or should be considered together. Grouping policies can help you to apply policies consistently across your organization.
Export or import a cloud policy -- To back up, move, or restore a policy, you can export and import the policy as an update set. The update set includes rules, conditions, actions, scripts, and script categories.
Pools and Filters for Cloud Provisioning -- A resource pool is a query or script that filters a table. You configure a resource pool to limit the values that are available to users when they request a catalog item.
Create a resource pool -- Based on blueprint settings, resource pools control the values that a user sees in a catalog item when they request a resource. Only values that pass the pool filter or script appear as options on the catalog item request form.
Bind a parameter to a resource pool -- To make catalog ordering less error-prone, you can bind a parameter to an resource pool (a pool provided in the base system). Parameters that are based on an resource pool list only specified values from existing tables on the catalog order form in the Cloud User Portal.
Quotas and resource order controls -- Quotas are limitations or requirements for groups and users on CIs or cloud resources. Use quotas to prevent wasteful resource usage in your cloud environment.
Create a cloud quota definition -- A cloud quota definition specifies the limitations on a resource block. You can use templates or manually create different types of configurations for each quota definition.
Resource order controls -- Use resource order controls to perform quota checks for template-based catalog items using quota definitions and policies. Quota limits enable you to control provisioning or ordering resources for users and groups. Configure policy actions to trigger notifications, an approval subflow, or both.
Set up resource order controls -- Create quota definitions and policies mapped to cloud-template based catalog items. Use policy rules and actions to trigger an approval subflow or notification when the quota limit defined for the group or user exceeds.
Use the Cloud Operations Dashboard -- The Cloud Operations Dashboard breaks down cloud service requests from your end users and cloud stacks that you offer in the Cloud User Portal.
Use Cloud Root Cause Analysis reports -- Root Cause Analysis reports help you troubleshoot issues with Cloud Provisioning and Governance. Use the reports to view details about the Cloud Orchestration Trail and the Cloud API Trail.
The Cloud API Trail -- The Cloud API Trail is an activity log for all activity that uses the Cloud API and goes through the MID Server.
Open the Cloud API Trail -- The Cloud API Trail is an activity log for all activity that uses the Cloud API and goes through the MID Server.
Perform life-cycle operations on cloud resources -- Configure life-cycle operations on cloud resources that are not provisioned using ServiceNow Cloud Provisioning and Governance. Provision resources and modify resource block operations to perform day-2 operations on cloud resources that are discovered using Cloud Discovery but not provisioned using Cloud Provisioning and Governance.
Pattern-based targeted discovery -- Automatically discover the newly provisioned cloud resources and store their information in the ServiceNow ServiceNow Configuration Management Database (CMDB) by using pattern-based targeted discovery.
Associate a resource type with a single-resource-discovery pattern -- Automatically discover the newly provisioned cloud resources and store their information in the ServiceNow ServiceNow Configuration Management Database (CMDB) by using pattern-based targeted discovery.
Troubleshooting tools for Cloud Provisioning and Governance -- The Cloud Provisioning and Governance application provides several tools to help you troubleshoot errors you might encounter during the Discovery of cloud accounts, the provisioning and managing of cloud resources, and the updating of the CMDB.
The Cloud Orchestration Trail -- The Cloud Orchestration Trail is an activity log for all cloud resource activity on the instance.
Open the Cloud Orchestration Trail -- Open the Cloud Orchestration Trail to debug and troubleshoot issues like a failed policy or failed Discovery of cloud resources.
Open cloud orchestrations -- Cloud orchestration records show you the orders that your instance processed for each attempted operation on a stack. They also show you the values of the fields that the user submitted through the Cloud User Portal. Use cloud orchestrations to troubleshoot issues that occur when a user provisions a cloud resource or runs another operation on an existing cloud resource.
Moving Cloud Provisioning and Governance content across environments -- You can move the content in the Cloud Provisioning and Governance application from one environment to the other. For example, develop an application in an environment and then move the application and all its dependencies to another environment for testing or production.
Move a blueprint from one environment to another -- Use update sets to move a blueprint and its dependencies from one environment to another. Update sets let you group a blueprint and its dependencies into a named set and then move them as a unit to other systems for testing or deployment. For example, you can move a blueprint from a development environment to a production environment.
Move a resource block from one environment to the other -- Use update sets to effortlessly transfer resource blocks and their dependencies between environments. Group them into a named set, facilitating seamless movement for testing or deployment. Simplify processes such as transferring a resource block from development to production, ensuring efficient and organized transitions across different systems.
Move a cloud API from one environment to the other -- Use update sets to move a cloud API from one environment to another. Update sets let you group a cloud API and its dependencies into a named set and then move them as a unit to other systems for testing or deployment. For example, you can move a cloud API from a development environment to a production environment.
Cloud API (CAPI) -- The Cloud API (CAPI) enables you to integrate Cloud Provisioning and Governance with cloud providers using REST APIs.
Default CAPI APIs -- Several CAPI APIs are provided by default with the Cloud Provisioning and Governance application.
CAPI classes in MID Server script includes -- Cloud Provisioning and Governance provides several JavaScript classes that make REST calls to cloud providers. These classes are called from MID Server script includes (for Azure by default) or from Java calls in the system (for AWS by default). If you create custom providers, interfaces, or CAPI APIs (for any cloud provider), you can use MID Server script includes to call the classes.
Azure VM provisioning walkthrough -- This example walks you through the components of Cloud Provisioning and Governance that function during the provisioning of a virtual machine in an Azure datacenter. Topics covered include blueprints, resource blocks, the Cloud API (CAPI), and MID Server script includes.
AWS VM provisioning walkthrough -- This example walks you through the components of Cloud Provisioning and Governance that function during the provisioning of a virtual machine in an AWS datacenter. Topics covered include blueprints, resource blocks, the Cloud API (CAPI), and MID Server script includes.
Add a product to an existing provider in CAPI -- The Cloud Provisioning and Governance Cloud API (CAPI) offers many providers, such as AWS and Azure, and products, such as EC2 instances. However, you can add products to existing providers for new types of cloud resources.
Create a CI class for a virtual cloud resource -- If the base system does not provide a CI type for cloud-based virtual resources, you can create a CI class based on the virtual machine object class.
Create a CAPI API -- If the existing CAPI APIs do not integrate with the CAPI interface for a provider, you can create an API. The steps in resource blocks can call your API methods when operations are executed.
Cloud User Portal -- The Cloud User Portal gives you immediate access to all day-to-day cloud activities.
Search the Cloud User Portal -- The Search page returns search results and provides filters that help you to zoom in on the results.
Launch a stack -- Launch a stack of cloud resources to submit a request for an item in the service catalog. You can launch a stack from the Cloud User Portal overview page.
Viewing resource quota limits -- View quota limits to see how many resources you have consumed and how many you can provision based on quota limits set for you and your user group.
Provisioning stacks based on quota limits -- The system calculates the quota allocated to you and the user groups to which you belong when you provision stacks. If quota limits are exceeded, the system either displays an error message or triggers a policy-based approval.
Track a stack request -- The system generates a request when you submit the form to launch a stack.
Resubmit a failed stack request -- The Cloud Provisioning and Governance application creates a remediation or a catalog task when a request for a stack fails to provision. You can resubmit the failed request or assign it to the Cloud Operator group to handle it for you.
Manage a stack -- Use the Stack Details page to view details and status for a stack and to perform life-cycle operations on a stack.
Manage a resource -- Use the Resource Details page to view details and status for a resource and to perform life cycle operations on a resource.
Perform a life-cycle operation on a stack or resource -- Operations like Start/Stop, Deprovision, and ExecuteScript are called life-cycle operations or day-2 operations. When you request a life-cycle operation on a stack or resource, the system generates a change request. An approval policy specifies either that the change is auto-approved or that a user on the approver list must approve the change.
Life-cycle operations in Cloud Provisioning and Governance -- Operations like Start/Stop, Deprovision, and ExecuteScript are called life-cycle operations or day-2 operations. When you request a life-cycle operation on a stack or resource, the system generates a change request. An approval policy specifies either that the change is auto-approved or that a user on the approver list must approve the change.
Submit an incident for a stack -- Submit an incident for a stack when it is not working as expected or you have questions. When the user responds or solves the issue, the incident is closed.
Using the Activities page -- Use the Activities page to view and manage details of your cloud actions.
Track a change request -- The system generates a change request when you perform a life cycle operation on a stack or resource.
Track an incident -- Before an incident is resolved and closed, you can view the state of the incident.
View cloud events -- You can view the events that are generated from your cloud resources if your administrator configured Cloud Provisioning and Governance to monitor them. All events are listed on the Cloud Events tab on the stack details page.
Create an SSH key -- A stack might include a virtual machine that requires an SSH key for access. To request such a stack, you can either use a key pair that is assigned to you or you can generate another key.
Download an SSH key -- If a resource on a stack requires login, then you must download the associated SSH key before you can access the resource.
Business hour scheduling -- You can set up business hour scheduling on all virtual machines in a stack. Business hour scheduling can be set up on stacks at the time of provisioning or on existing stacks.
Modify the lease for a stack -- When a stack reaches the end of its lease, the system notifies the stack owner and deprovisions the stack. You can modify the lease for a stack before it approaches its end date.
Manage personal and group resources -- You can view and manage your resources as well as the resources assigned to the group you belong to. If you belong to more than one group, you can view and manage all resources assigned to those groups.
Quick start tests for Cloud Provisioning and Governance -- Validate that Cloud Provisioning and Governance still works after you make any configuration change such as applying an upgrade or developing an application. Copy and customize these quick start tests to pass when using your instance-specific data.
Cloud Configuration Governance -- Use the ServiceNow Cloud Configuration Governance application to check the configuration settings of cloud resources in your organization against a set of policies to identify violations. After identifying the violation, use remediation workflows to mitigate them.
Install Cloud Configuration Governance -- You can install the Cloud Configuration Governance application (com.sn.itom.ccg) if you have the admin role. The application installs related ServiceNow Store applications and plugins if they aren’t already installed.
Install the CCG Content Pack -- You can install the CCG Content Pack application (sn_itom_ccg_cp) if you have the admin role.If the application does NOT include demo data or it does NOT install related applications and plugins, delete or revise the following sentence:
Set up Cloud Configuration Governance for AWS -- Set up access to the Amazon Web Services (AWS) cloud accounts in Cloud Configuration Governance to enable interaction between the application and the cloud. The application requires access to the cloud accounts to scan the cloud resources for non-compliant configurations and remediate them.
Create an assume role configuration -- Create a service account assume role configuration to facilitate cross-account access that is from a management account to a member account or from a trusted account to a trusting account. All the related member accounts or trusted accounts are automatically loaded avoiding the need to add them individually.
Set up Cloud Configuration Governance for Microsoft Azure -- Set up access to the Microsoft Azure cloud accounts in Cloud Configuration Governance to enable interaction between the application and the cloud. The application requires access to the cloud accounts of your organization to scan the cloud resources for non-compliant configurations and remediate them.
Domain separation and Cloud Configuration Governance -- If any conrefs are broken, re-add them from the doc/source/reuse/domain-separation/domain-separation-overview.dita file.Domain separation is not supported in Cloud Configuration Governance . Domain separation enables you to separate data, processes, and administrative tasks into logical groupings called domains. You can control several aspects of this separation, including which users can see and access data.
Using Cloud Configuration Governance -- Cloud Configuration Governance provides a set of ready-to-use policies. You can either use these policies to identify the non-compliant cloud resource configurations within your cloud organization, or create custom policies. After identifying the non-compliant cloud resource configurations, you can use the remediation feature of the application to fix the violations.
Scan configuration -- Scan configuration defines the various settings for the Cloud Configuration Governance scan.
Create a scan configuration -- Create a scan configuration in Cloud Configuration Governance to scan the cloud resources against one or more policy sets and identify the policy violations.
Run a scan configuration -- Run a scan configuration to evaluate the resource configuration of the given cloud against the specified policy sets and identify the policy violations. Cloud Configuration Governance reports the identified policy violations as audit results.
Scan run -- Each execution of a scan configuration is called a scan run. The Scan Runs module displays a list of all the scan runs.
Create a policy with the condition builder -- Use the condition builder to create a Cloud Configuration Governance policy without writing any code at all. Use it to specify the criteria for identifying and reporting the non-compliant cloud resource configurations.
Create a policy with the Integration Hub subflow -- Use the Integration Hub subflow to create a Cloud Configuration Governance policy. An Integration Hub subflow uses graphical coding mechanisms to specify the policy conditions. It offers greater flexibility in audit violation reporting than the condition builder. That is, you can use the same policy to report different types of issues.
Create a policy through script -- Use the ServiceNow platform native scripting mechanism to define the policy condition. You can externalize the decision making to script includes and reuse the code across different policies.
Test the policy -- Test the Cloud Configuration Governance policy against the configuration data imported for a previous scan run. Test the policy to make sure that it is working properly.
Create a configuration key -- Create a configuration key in Cloud Configuration Governance to use it in the policies. The configuration key specifies the resource collector and configuration collectors used to import the configuration data from the cloud. It also specifies the data type of the configuration value.
Create a resource collector -- Create a resource collector to set up how Cloud Configuration Governance imports all the resources of a given type.
Create a configuration collector -- Create a configuration collector to set up how Cloud Configuration Governance imports the configuration data from the cloud. The configuration collector uses Integration Hub subflows to import the configuration data from the cloud.
Create a CI finder mapping -- Use the CI finder mapping to link the resources fetched by the ServiceNow Cloud Configuration Governance scan runs with the appropriate Configuration Management Database (CMDB) Configuration Items (CIs), if available. After you create the mapping, you can associate the reported configuration violations with the CIs to which they belong.
Create a policy set -- Create a policy set in Cloud Configuration Governance to group policies that enforce a given security or organization standard. When the scan configuration runs the policy set, it identifies the cloud resources that don’t adhere to the set standards. A policy set can contain one or more policies.
Remediation -- Use the Cloud Configuration Governance remediation actions to fix the non-compliant cloud resource configurations identified during the scan runs.
Create a remediation catalog item -- Create a custom remediation catalog item in Cloud Configuration Governance for the remediations that require additional input parameters to execute.
Create a remediation action -- Create a remediation action in Cloud Configuration Governance for the remediations that doesn’t require any additional input parameters.
Run remediation -- Run the appropriate remediation action to fix the non-compliant cloud configuration identified during the Cloud Configuration Governance scan run.
Cloud Configuration Governance dashboard -- Cloud Configuration Governance is a tool used to manage the configuration of the cloud resources as per your organizational standards and established security standards. Use the dashboard to review the health score of the cloud, policy violation statistics, policy violation trend, remediations overview, and more.
Cloud Configuration Governance roles and system properties -- Cloud Configuration Governance users require the appropriate roles and system properties to perform various activities. These roles and system properties are installed with the activation of the application.
Cloud Configuration Governance Policy form -- The Cloud Configuration Governance Policy form displays detailed information about the policy such as cloud provider, resource type, policy type, and policy violation reporting settings.
Cloud Configuration Governance scripting reference -- Cloud Configuration Governance provides several objects and variables that you can use to create script-based policies and CI finder mapping scripts.
Cloud Configuration Governance actions reference -- Cloud Configuration Governance (CCG) uses Integration Hub subflows to interact with the cloud and update the configuration data in the Configuration Management Database (CMDB).
Cloud Action Library actions reference -- Cloud Action Library (CAL) offers various actions that you can use to build the Integration Hub subflows for Cloud Configuration Governance.
Obtain Cloud permission to collect base system CCG configuration keys -- The Cloud Configuration Governance requires appropriate cloud permissions to collect the base system configuration keys from the cloud. Therefore, you must set the appropriate permissions in the cloud to suit the needs of your organization.
AWS policies -- The Cloud Configuration Governance AWS policies are listed for your reference.
Azure policies -- The Cloud Configuration Governance AWS policies are listed for your reference.
Policy sets -- The Cloud Configuration Governance policy sets and its policies are listed for your reference.
Cloud Action Library -- Use the ready-to-use actions and subflows of the ServiceNow Cloud Action Library application to interact with the cloud resources of the organization. ServiceNow ITOM Cloud Accelerate features, such as Cloud Configuration Governance, use these actions to operate.
Install Cloud Action Library -- You can install the Cloud Action Library application (sn.itom.cal) if you have the admin role. The application installs related ServiceNow Store applications and plugins if they are not already installed.
Set up Cloud Action Library for AWS -- Set up access to the Amazon Web Services (AWS) cloud accounts in Cloud Action Library to enable interaction between the application and the cloud.
Domain separation and Cloud Action Library -- If any conrefs are broken, re-add them from the doc/source/reuse/domain-separation/domain-separation-overview.dita file. In the short description, edit the first sentence to state whether domain separation is supported or not and add the application name. Keep the conref at the end that describes domain separation.Domain separation is not supported in Cloud Action Library . Domain separation enables you to separate data, processes, and administrative tasks into logical groupings called domains. You can control several aspects of this separation, including which users can see and access data.
Cloud Action Library reference -- Reference topics provide additional information about the Cloud Action Library application.
AWS Get IAM Login Profile action -- Action that retrieves the user name for the specified Amazon Web Services (AWS) Identity Access Management (IAM) user.
AWS List Images action -- Action that describes the specified images (AMIs, AKIs, and ARIs) available to you or all of the images available to you.
AWS Put S3 Bucket Encryption action -- Action that configures the default encryption and Amazon Web Services (AWS) S3 Bucket Key for an existing bucket.
CAL - AWS List S3 Buckets action -- Action that returns a list of all the Amazon Web Services (AWS) buckets owned by the authenticated sender of the request.
CAL - AWS List VMs action -- Action that returns a list of all Amazon Web Services (AWS) Virtual Machines (VM) that belong to the specified logical datacenter.
CAL - Azure List VMs action -- Action that returns the list of Microsoft Azure Virtual Machines (VM) that belong to the specified logical datacenter.
CAL - Azure VM IP Metric action -- Action that returns the IP details of the specified Microsoft Azure Virtual Machine (VM).
Disable AWS IAM User action -- Action that deletes the password for the specified IAM user, which terminates the user's ability to access Amazon Web Services (AWS) services through the AWS Management Console.
CAL - AWS Generate Credential Report subflow -- Subflow that lists all users in your account and the status of their various credentials, including passwords, access keys, and MFA devices.
CAL - AWS S3 Get Encryption subflow -- Subflow that returns the default encryption configuration for an Amazon Web Services (AWS) S3 bucket.
CAL - Resolve MID subflow -- Subflow that returns a suitable MID Server based on the specified MID Server selection criteria.
CAL - AWS S3 Get ACL subflow -- Subflow that retrieves the Access Control List (ACL) details for the specified Amazon Web Services (AWS) S3 bucket.
Cloud profiles with minimal permissions for CAL -- You need appropriate cloud permissions to execute the Cloud Action Library actions and subflows. Edit the cloud permissions profile JSON to suit the needs of your organization.
ITOM Cloud Accelerate reference -- Reference topics provide additional information for configuring and using ITOM Cloud Accelerate.
Plugins or applications installed with ITOM Cloud Accelerate -- Tables that list the plugins or applications that are installed with ITOM Cloud Accelerate applications. When you update your application, any newly required application dependencies are installed.
ITOM Optimization -- The IT Operations Management (ITOM) Optimization application provides automation for the cloud workflows used to manage the cloud resources throughout their life cycle. It enables certified and enterprise-compliant cloud deployment, cost visibility, and other cloud management processes.
ITOM Optimization reference -- Reference topics provide additional information for configuring and using ITOM Optimization .
Plugins activated with ITOM Optimization -- Table that lists the plugins that are activated with the ITOM Optimization application Cloud Provisioning and Governance. When you update your application, any newly required application dependencies are installed.
MID Server configuration and exception handling -- You can configure a MID Server with additional configuration parameters or create a new Mid Server property to alter any default behavior.
ITOM Visibility -- The ServiceNow ITOM Visibility product consists of ServiceNow DiscoveryServiceNow Discovery is an automated process that continuously scans and identifies all the components within the IT infrastructure. It plays a crucial role in maintaining an accurate and up-to-date CMDB 360 with the information it finds., Firewall Audits and ReportingUse the Firewall Audits and Reporting application to explore and create an inventory of your firewall security policies, devices, device groups, and manager information. Additionally, you can initiate requests for new firewall rules through the Service Catalog application and conduct audits of firewall security policies within specified time frames., Certificate Inventory and ManagementWith Certificate Inventory and Management, you can discover, conduct an inventory, and proactively manage all TLS certificates. Certificate Inventory and Management supports IPv6, providing comprehensive coverage for your certificate management needs., Service MappingThe ServiceNow Service Mapping application discovers all application services in your organization and builds a comprehensive map of all devices, applications, and configuration profiles used in these application services., AI Agent Topology MappingWith AI Agent Topology Mapping, you can use patterns to identify AI infrastructure components across cloud platforms in your organization. Discover your AI agents, models, and prompts, and get centralized CMDB visibility to track security compliance and vulnerabilities across your AI deployments., ITOM Content ServiceServiceNow ITOM Content Service offers extensive visibility of products in your infrastructure. The classification of processes identified by Predictive Intelligence enables wider discovery and weekly updates of new configuration items in the CMDB. Use the Discovery Admin Workspace to review and manage ITOM Content Service suggestions., Tag GovernanceEffective tag management improves reporting and overall operations management efficiency. Use the ServiceNow Tag Governance app to identify and remediate on-premises or cloud resources that are inconsistent and don't comply with the tag policies of your organization., Cloud Discovery Workspace Cloud Discovery Workspace offers a comprehensive solution to manage the cloud operations of your organization., and Cloud License EstimatorCloud License Estimator enables you to get the estimated resource count for all the cloud resources that are eligible for licensing. applications. Discovery and Service Mapping give you a unified, connected view of your entire IT network and the services that it supports. The Service Graph Connectors and CMDB 360 applications provide data to ITOM Visibility.
Install ITOM Visibility -- Install all required ITOM Visibility applications and plugins from the IT Operations Management Product Hub.
Discovery -- ServiceNow Discovery is an automated process that continuously scans and identifies all the components within the IT infrastructure. It plays a crucial role in maintaining an accurate and up-to-date CMDB 360 with the information it finds.
Exploring Discovery -- Discovery finds computers, servers, printers, a variety of IP-enabled devices, and the applications that run on them. It can then update the configuration items (CIs) in your Configuration Management Database (CMDB) with the data it collects.
Horizontal discovery process flow with probes and sensors -- The horizontal discovery process passes through the four phases of discovery using probes, which gather information on the target machine, and then sensors, which help Discovery determine what to do with that information.
Horizontal discovery process flow with patterns -- Horizontal discovery with patterns has four phases, just as horizontal discovery with probes does. However, for the last two phases, Discovery triggers operations from a pattern, rather than additional sets of probes.
Discovery Admin Workspace -- The Discovery Admin Workspace serves as a central location for monitoring, tracking, and completing discovery-related tasks. Experience a streamlined discovery process and greater efficiency with the integration of schedules, diagnostics, tuning, anomaly detection, and more within this single workspace.
Discovery Admin Workspace Home -- The Discovery Admin Workspace Home page features tools to help you identify and address the most critical discovery errors.
Discovery Admin Workspace Schedules -- The Schedules page provides a single place to monitor Discovery performance, efficiently manage schedules and statuses, and set up new IP-based or Cloud Discovery schedules.
Discovery Admin Workspace schedule details -- The Schedules page provides a single place to monitor Discovery performance, efficiently manage schedules and statuses, and set up new IP-based or Cloud Discovery schedules.
Discovery Admin Workspace status details -- The Schedules page provides a single place to monitor Discovery performance, efficiently manage schedules and statuses, and set up new IP-based or Cloud Discovery schedules.
Discovery Admin Workspace Diagnostics -- The Diagnostics page helps you prioritize and address errors and anomalies in IP-based and Cloud Discovery schedules.
Discovery Admin Workspace Error Details -- The Error Details page displays the root cause and remediation steps for a specific Discovery error, along with the list of individual error instances associated with that error.
Error Framework in Discovery Admin Workspace -- Discovery Admin Workspace uses the Error Framework to surface actionable Discovery errors. You can review errors, understand their causes, and take steps to resolve them directly from the Diagnostics page.
Discovery Admin Workspace Content 360 -- The Content 360 page enables you to discover applications and evaluate application suggestions based on machine learning or crowd-sourced resources. Then, create configuration items with a single click.
Discovery Admin Workspace Insights -- The Insights page provides access to specialized widgets, dashboards, and reports to leverage your organization's IT operations management and infrastructure monitoring, taking advantage of Discovery's capabilities for improved operational visibility and infrastructure health.
Discovery Operations Monitor dashboard -- The Discovery Operations Monitor dashboard displays performance metrics for your Discovery environment. Use this dashboard to monitor discovery health and identify issues across your IT landscape.
Configure the time interval for a visualization -- Update the data collection time interval for individual visualizations on the Discovery Operations Monitor dashboard. By default, each visualization displays data in 15-minute intervals.
Configure the date range for a visualization -- Update the data time frame for individual visualizations on the Discovery Operations Monitor dashboard. By default, each visualization displays data from the last 7 days. You can extend the time frame up to 30 days, which is the maximum data retention period for this dashboard.
Shazzam Insights dashboard -- The Discovery Admin Workspace displays your port scanning information, IP address utilization, and Discovery schedules.
Tag Governance Insights dashboard -- View metrics like tag policy coverage, compliance status, and usage trends directly from the Discovery Admin Workspace.
Virtual Machine Explorer dashboard -- The Discovery Admin Workspace Virtual Machine Explorer dashboard displays information on the activity and capacity of your virtual machine (VM) instances as revealed by the discovery process.
Run historical data collection for Virtual Machine Explorer -- After installing Discovery Admin Workspace, run historical data collection jobs to populate the Virtual machines with server CI and Virtual machines with no deep dive discovery reports on the Virtual Machine Explorer dashboard.
URL Discovery insights dashboard -- The Discovery Admin Workspace URL Discovery insights dashboard displays captured data and analytics for web domains accessed on managed Windows and macOS devices.
Discovery Admin Workspace Tuning -- The Tuning page enables you to validate your existing configurations and resolve configuration issues.
Discovery Admin Workspace Settings -- The Settings page enables you to customize and manage high-level Discovery properties so they’re tailored to meet your specific needs.
Discovery for cloud environment -- ITOM Visibility cloud discovery solutions enable you to collect detailed information about your cloud-based infrastructure and your resources in major cloud service providers: Amazon Web Services (AWS), Microsoft Azure, Google Cloud Platform (GCP), IBM Cloud Platform, Oracle Cloud Infrastructure (OCI), and Alibaba Cloud.
Create a discovery schedule in Cloud Discovery Workspace -- Create schedules for discovering cloud resources based on the discovery method that you choose: service accounts or IP ranges. The discovery schedule defines the various settings for the cloud discovery.
Discovery for AWS -- Amazon Web Services (AWS) cloud discovery enables visibility to your AWS cloud resources, to populate and update the Configuration Management Database (CMDB). Visibility into AWS supports business outcomes such as cloud transformation and optimizing efficiency for operations (ITOM/ITSM/AIOps).
AWS events-driven discovery -- The Amazon Web Services (AWS) Config service can raise events for any changes in the life-cycle state or the configuration of a cloud resource. The ServiceNow event-driven discovery uses the events to auto-update the latest resource information in the Configuration Management Database (CMDB).
AWS config notifications -- Configure the Amazon Web Services (AWS) Config service to send event notifications to the ServiceNow instance for any changes in the lifecycle state of a resource.
Scale the AWS cloud event schedulers -- Scale the cloud event schedulers to improve the Amazon Web Services (AWS) event processing rate of the ServiceNow instance.
Create a database index for the Cloud Events table -- Create a database index from the specified columns of the Cloud Events [sn_cmp_cloud_event] table to improve the AWS cloud event processing performance.
AWS SSM discovery -- AWS Systems Manager (SSM) Agent discovery introduces a streamlined, agent-based approach to discovering Amazon Elastic Compute Cloud (EC2) using AWS SSM. This integration enhances Discovery by leveraging SSM agents to reduce dependency on traditional MID Server configurations, simplify credential management, and improve scalability across multi-region environments.
Configure MID Server for AWS S3 access -- Configure MID Server properties to enable Simple Storage Service (S3) access from the ServiceNow AI Platform when performing Systems Manager (SSM) Agent discovery.
Configure MID Server for AWS KMS access -- Configure MID Server properties to enable Key Management Service (KMS) key access from the ServiceNow AI Platform when performing Systems Manager (SSM) Agent discovery.
Enable root fallback -- Enable the fallback root user property to allow AWS SSM discovery to run commands as root on Linux systems when alternate user credentials aren’t configured.
Configure custom user credentials -- Define a non-root user for AWS SSM discovery by creating a credential record that specifies a user name with sufficient privileges to execute discovery commands on Linux targets.
Discovery for Microsoft Azure -- If your cloud resources are in an Azure cloud, you must create a user identity called a service principal that grants permissions to the MID Server to access selected resources.
Create Azure cloud credentials -- If your cloud resources are in an Azure cloud, create credentials that can access the Azure account. This procedure requires configuration in your Azure account.
Run discovery using Service Principal -- Discover Linux virtual machines on Azure using Service Principal (SP) with short-lived SSH certificates. Using these certificates circumvents the need for passwords or public and private key-pairs.
Microsoft Azure Alert driven discovery -- The Microsoft Azure Alert service can raise alerts for any changes in the life-cycle state or the configuration of a cloud resource. You can configure the service to auto-update the latest resource information in the Configuration Management Database (CMDB) without waiting for the next scheduled Cloud Discovery to run.
Configure the Microsoft Azure Alert service to auto-update the CMDB -- The Microsoft Azure Alert service can raise alerts for any changes in the life-cycle state or the configuration of a cloud resource. You can configure the service to auto-update the latest resource information in the Configuration Management Database (CMDB) without waiting for the next scheduled Cloud Discovery to run.
Add a Microsoft Azure alert rule -- The Microsoft Azure Alert service can raise alerts for any changes in the life-cycle state or the configuration of a cloud resource. You can configure the service to auto-update the latest resource information in the Configuration Management Database (CMDB) without waiting for the next scheduled Cloud Discovery to run.
Supported Microsoft Azure alert types -- The Microsoft Azure Alert service can raise alerts for any changes in the life-cycle state or the configuration of a cloud resource. You can configure the service to auto-update the latest resource information in the Configuration Management Database (CMDB) without waiting for the next scheduled Cloud Discovery to run.
Azure change processing -- The Azure change processing feature collects information about Microsoft Azure resources that have undergone a life-cycle state change or configuration change near real time. Then, it uses the collected information to update the Configuration Management Database (CMDB).
Enable Azure change processing -- Configure the Azure change processing to collect resource change information from the Microsoft Azure cloud and use it to update the Configuration Management Database (CMDB).
Migrate to Azure change processing -- Migrate to Azure change processing to improve the change processing performance of the ServiceNow AI Platform and take advantage of the simplified setup.
Discovery for Google Cloud Platform -- Discovery finds Google Cloud Platform and its components. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Configure the Google Cloud Logging service to auto-update the CMDB -- You can activate the Google Cloud Logging (formerly Stackdriver Logging) service to auto-update Configuration Management Database (CMDB) configuration items (CI) data whenever Google Cloud Connector or your Google account makes a life-cycle state or configuration change to a Google Cloud Platform (GCP) resource. As a result, the CI data in the CMDB is updated without having to wait for Discovery to run.
Discovery for VMware -- Applications that access VMware cloud resources need access to VMware credentials.
Configure the VMware Events service to auto-update the CMDB -- Configure events from the cloud environment to make the necessary updates to your CMDB without additional scanning. The VMware Events service can auto-update CI data in the CMDB whenever Cloud Provisioning and Governance makes a life-cycle state or configuration change to a VMware resource. As a result, the CI data in the CMDB is updated without having to wait for Discovery to run.
Discovery for Alibaba Cloud -- Alibaba Cloud discovery is one of the overall Cloud discovery offerings within the IT Operations Management (ITOM) Visibility framework. It’s an automated process used to scan and identify Alibaba Cloud resources within your organization's cloud infrastructure. This discovery process is critical for maintaining an accurate and trustworthy data foundation—the Configuration Management Database (CMDB).
Create Alibaba Cloud API Credentials -- Create Alibaba Cloud API credentials on the ServiceNow AI Platform to enable access to your Alibaba Cloud resources during Alibaba Cloud discovery.
Set up Alibaba Cloud service accounts -- Create Alibaba Cloud infrastructure service accounts on the ServiceNow AI Platform to access your Alibaba Cloud account during Alibaba Cloud discovery.
Cloud discovery reporting -- Cloud discovery reporting provides a user-friendly interface for navigating and analyzing your cloud resource inventory. It offers drill-down and slice-and-dice views to gain granular insights into your cloud resource inventories, with details obtained from the discovery. It provides an easier and faster way to locate and identify the state and location of cloud resources, streamlining your management tasks.
Analytics and Reporting for Cloud Resources -- Platform Analytics Solutions contain prepackaged Performance Analytics and Reporting content for use with other ServiceNow AI Platform products. Finish the following sentence with a short statement on the business use case for this Solution. For example: This Analytics and Reporting Solution helps you track trends in incidents and plan your incident management strategy going forward.
Cloud Resources dashboard -- The Cloud Resources dashboard shows the aggregated view of all your cloud resources, their combined analytical views, and a visual summary and detail of all your cloud resources.
Cloud Resources Explorer -- Use the ServiceNow Cloud Resources Explorer to filter and visualize the distribution of resources across your multi cloud estate. Gain insight into operational information such as stale resources and cloud event inflow rates.
Cloud discovery solutions comparison -- Comparing cloud discovery solutions provides insights on the relative strengths of each solution. The comparison showcases the number of resource types supported by the solutions across AWS, Microsoft Azure, and GCP. The comparison can help you understand the capabilities of each solution and better manage your CMDB when using one or multiple methods.
AWS discovery solutions comparison -- ITOM Visibility applications discover a variety of AWS resources and populate the relevant configuration item (CI) classes in the Configuration Management Database (CMDB) with their attributes.
Microsoft Azure discovery solutions comparison -- ITOM Visibility applications discover a variety of Microsoft Azure resources and populate the relevant configuration item (CI) classes in the Configuration Management Database (CMDB) with their attributes.
GCP discovery solutions comparison -- ITOM Visibility applications discover a variety of Google Cloud Platform (GCP) resources and populate the relevant configuration item (CI) classes in the Configuration Management Database (CMDB) with their attributes.
Discovery for containerized resources -- Container discovery enables IT departments of companies to collect detailed information about their container management tools in the infrastructure. Discovery finds resources in major container management services providers.
Kubernetes discovery using patterns -- The ServiceNow ITOM Visibility finds Kubernetes and OpenShift components using patterns and creates application services containing them. Discovery also finds Kubernetes events and frequently updates the CMDB to reflect the dynamic Kubernetes environment.
Container image scanning for software decomposition -- The ITOM Visibility apps, Discovery and Service Mapping Patterns and Kubernetes Visibility Agent integrate with Aqua Trivy to collect data on container images and OS packages. You can increase your control over container deployment by having visibility to the container components.
Map MID Server to container image repository -- If network access or datacenter location requires a specific MID Server, map MID Server to a private container image repository.
Configure the SBOM generation -- Enable the Software Bill of Materials (SBOM) creation and avoid duplicate SBOM files from being generated by setting the system properties.
Download a software bill of materials (SBOM) -- Download a software Bill of Materials (SBOM) to gain visibility to the components of the container image such as the operating system packages that are installed.
Container image discovery -- The Discovery and Service Mapping Patterns application uses the Scan Container Image pattern to discover Docker images and OS packages data. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Kubernetes discovery using Kubernetes Visibility Agent -- Kubernetes Visibility Agent detects changes on resources in a Kubernetes cluster. It performs continuous discovery, reports any changes back to your instance, and updates the Configuration Management Database (CMDB) with the latest data.
Exploring Kubernetes Visibility Agent -- Kubernetes Visibility Agent enables you to gain visibility into on-premises Kubernetes clusters as well as the various Cloud deployments.
Deactivate continuous discovery in Kubernetes Visibility Agent -- Switch off continuous discovery by Kubernetes Visibility Agent if all you need is periodic snapshots of your cluster resources. If you have multiple clusters with frequent changes, deactivating continuous discovery reduces the load on your instance.
Display the Kubernetes cluster version in the CMDB -- Make the Kubernetes Visibility Agent Informer populate the relevant field in the cmdb_ci_kubernetes_cluster CI to display the Kubernetes cluster version.
Retain inactive namespace CIs for audits -- If required by your corporate standards, retain inactive namespace configuration items (CIs) for reference and auditing purposes with the option to delete them manually later.
Define include and exclude lists of Labels and Annotations -- In Kubernetes Visibility Agent, define include and exclude lists of Labels and Annotations in Kubernetes resources that the Informer pulls into the Configuration Management Database (CMDB).
Upgrade Kubernetes Visibility Agent Informers remotely -- Upgrade Kubernetes Visibility Agent Informer pods in Kubernetes clusters remotely from the ServiceNow Instance to avoid dependence on your Kubernetes admin. You can upgrade a single Informer or multiple Informers together.
Override Informer parameters from the Instance -- Control Kubernetes Visibility Agent Informer execution parameters from the ServiceNow Instance to avoid dependence on your Kubernetes admin.
Enabling application service maps -- Application service maps give you visibility into how workloads communicate in a Kubernetes cluster, helping you detect dependencies and monitor traffic flows in real time.
Enable service maps using DaemonSet -- Enable application service maps based on the traffic between the workloads in Kubernetes by using a ServiceNow DaemonSet as part of Kubernetes Visibility Agent (KVA) installation.
Enable service maps using service meshes -- Enable application service maps based on the traffic between the workloads in Kubernetes by using Istio or Linkerd or service meshes as part of Kubernetes Visibility Agent (KVA) installation.
Enable service maps using Cilium -- Enable application service maps based on the traffic between the workloads in Kubernetes by connecting to a Cilium agent already running in the cluster.
Create application service maps -- Create a service map that maps application services based on traffic between the workloads in Kubernetes using Istio or Linkerd service meshes or a ServiceNow DaemonSet.
Create hybrid application service maps -- Create hybrid service maps that extend outside the Kubernetes cluster and map other related service resources.
Pulling additional resources from Kubernetes clusters into the CMDB -- You can configure the Kubernetes Visibility Agent Informer to pull extra resources from Kubernetes clusters into the Configuration Management Database (CMDB), in addition to the resources it sends to the database by default. By pulling in additional resources beyond the default set, you can enhance visibility into your Kubernetes clusters.
Kubernetes Visibility Agent Informer status fields -- The fields in the Kubernetes Visibility Agent Informers table sn_acc_visibility_kubernetes_informer describe the status of the Informer pods deployed in your Kubernetes clusters.
Kubernetes Visibility Agent support matrix -- The Kubernetes Visibility Agent component is supported on several versions of Kubernetes and OpenShift and in various Kubernetes environments.
Kubernetes Visibility Agent (KVA) Performance Benchmark -- Performance tests are available for Kubernetes Visibility Agent (KVA) (former CNO for Visibility) to help you estimate the load, memory, CPU, etc., on the Instance as well as on the Kubernetes cluster.
Discovering Kubevirt Virtual Machines -- KubeVirt provides a unified development platform where developers can build, modify, and deploy applications residing in both Application Containers as well as Virtual Machines in a common, shared environment.
Running Kubernetes Visibility Agent (KVA) at Scale -- When you run Kubernetes Visibility Agent (KVA) (formerly CNO for Visibility) on more than 100 clusters, configure your system properties to help prevent loss of data from the informers.
Configuring Discovery -- Configure the elements that Discovery requires to investigate your network, such as credentials, schedules, and IP addresses.
Request Discovery -- Request and activate the Discovery (com.snc.discovery) plugin to enable Discovery capabilities on your instance.
Discovery setup -- After you activate the Discovery application, you have several ways to get started.
ITOM Configuration Console -- The ITOM Configuration Console gives administrators a single place to complete all Event Management setup steps — from installing plugins to configuring alert automations.
Admin in ITOM Configuration Console -- Administrators can configure Discovery settings, assign roles, manage credentials, and review Discovery schedules, errors, and anomalies through the ITOM Configuration Console.
Assign Discovery admins -- Assign the discovery_admin role to users who will be in charge of Discovery configuration and operational control.
Create a MID Server user -- Create a user account with the mid_server role so MID Servers can authenticate and communicate with the ServiceNow instance.
Deploy a MID Server -- Deploying a MID Server allows ServiceNow to securely communicate with systems inside a private network by installing and validating a trusted runtime that performs discovery, integrations, and automation tasks without requiring inbound network access.
Validate a MID Server -- Validate a newly installed MID Server so it can communicate with the ServiceNow instance. During validation, you can optionally define which applications, capabilities, and IP ranges the MID Servers is allowed to use.
Create IP credentials -- Create IP credentials for Discovery to securely connect to devices in your environment. Discovery uses these credentials to log in to devices and retrieve configuration data during the discovery process.
Create cloud credentials -- Create cloud credentials to manage access to cloud-based applications, including Amazon Web Services, Microsoft Azure, and Google Cloud. Discovery uses these credentials to connect to your cloud provider accounts and discover cloud resources.
Run a Quick Discovery -- Scan one or more IP addresses to discover devices in your network without creating ongoing schedules.
Discovery Guided Setup -- ITOM Discovery Guided Setup provides a sequence of tasks that help you install and get started with Discovery. If you're setting up Discovery for the first time, this is a good way to get your environment up and running quickly.
Set up Discovery without Guided Setup -- If you aren’t using Guided Setup, you must perform several configuration steps manually to activate the application, set up the MID Server, and then set up Discovery.
Discovery Quick Start -- Discovery Quick Start is a wizard that helps you get up and running with Discovery quickly. Use Discovery Quick Start tasks to discover IP ranges, or subnets, in your environment and then to identify the configuration items (CI) in those subnets.
Configure and schedule subnet discovery -- Discovery Quick Start is a wizard that helps you get up and running with Discovery quickly. Use Discovery Quick Start tasks to discover IP ranges, or subnets, in your environment and then to identify the configuration items (CI) in those subnets.
Configure and schedule CI discovery -- Discovery Quick Start is a wizard that helps you get up and running with Discovery quickly. Use Discovery Quick Start tasks to discover IP ranges, or subnets, in your environment and then to identify the configuration items (CI) in those subnets.
Migrate from CAPI to Patterns -- Migrate from Cloud API (CAPI)-based Cloud Discovery to Patterns-based Cloud Discovery. The task requires supported instance and few plugins. Migration works for Amazon Web Services (AWS) and Microsoft Azure. Administrator can perform this task after the initial instance is set up.
Discovery properties -- Discovery properties allow you to control several aspects of the horizontal discovery process.
Discovery IP address configuration -- Use one or more of these methods in any combination to define the network or network segment for Discovery to query. You can include or exclude specific IP ranges from your query.
IP address selection properties -- Use one or more of these methods in any combination to define the network or network segment for Discovery to query. You can include or exclude specific IP ranges from your query.
Create a Quick IP range for a Discovery schedule -- Use one or more of these methods in any combination to define the network or network segment for Discovery to query. You can include or exclude specific IP ranges from your query.
Import IP ranges into Discovery schedules with import sets -- Use one or more of these methods in any combination to define the network or network segment for Discovery to query. You can include or exclude specific IP ranges from your query.
Exclude IP ranges from a Discovery range set -- Use one or more of these methods in any combination to define the network or network segment for Discovery to query. You can include or exclude specific IP ranges from your query.
Use Global Excludes List for IP addresses and ranges -- Use one or more of these methods in any combination to define the network or network segment for Discovery to query. You can include or exclude specific IP ranges from your query.
Discovery generic attributes -- Discovery generic attributes enable you to define custom attributes at the schedule, range, and range set level. These attributes attach metadata that can influence CMDB field population and Discovery runtime behavior, providing granular control based on the scope of the discovery.
Automatic CI field population -- Discovery generic attributes can automatically set configuration item (CI) field values during discovery. Attributes follow a scope hierarchy, where more specific scopes override broader ones, enabling you to define defaults at the schedule level and apply precise values at the range level.
Define CI field attributes -- Define attributes on a Discovery schedule, IP network, IP range set, or IP address range to automatically populate configuration item (CI) field values during discovery.
IPAM Discovery integration -- The IP Address Management (IPAM) to Discovery integration feature enables your organization to automatically create and manage Discovery schedules based on your IPv6 network infrastructure data stored in IPAM. This integration keeps your discovery processes synchronized with your IPv6 network changes, providing a complete and up-to-date view of your network environment.
Configure auto-created Discovery schedules -- Enable the system to automatically create Discovery schedules based on IP data from your IP Address Management (IPAM) connections.
Domain Separation and Discovery -- Domain separation is supported in Discovery. Domain separation enables you to separate data, processes, and administrative tasks into logical groupings called domains. You can control several aspects of this separation, including which users can see and access data.
Configure domain-separated Discovery schedules -- Configuring the "Run as" user in a Discovery schedule directs discovered Configuration Items (CIs) to the correct domain and maintains data isolation.
Microsoft Just Enough Administration (JEA) for Discovery -- Using Microsoft JEA with Discovery improves security by forcing the MID Server to run remote Windows commands through a constrained endpoint, which validates commands on the target before execution.
Prepare the instance for Discovery with JEA -- Using Microsoft JEA with Discovery improves security by forcing the MID Server to run remote Windows commands through a constrained endpoint, which validates commands on the target before execution.
SNMP support for Discovery -- Discovery supports SNMP versions 1, 2c, and 3. If you have an active SNMP v3 credential, valid options for SNMP version are v3 or All. If you have an active SNMP v1 or v2 credential (community string), valid options for SNMP version are v1, v2c, or All. Default is All.
Add an SNMPv3 user credential in Discovery -- Discovery supports SNMP versions 1, 2c, and 3. If you have an active SNMP v3 credential, valid options for SNMP version are v3 or All. If you have an active SNMP v1 or v2 credential (community string), valid options for SNMP version are v1, v2c, or All. Default is All.
Set SNMP version on the Discovery schedule -- Discovery supports SNMP versions 1, 2c, and 3. If you have an active SNMP v3 credential, valid options for SNMP version are v3 or All. If you have an active SNMP v1 or v2 credential (community string), valid options for SNMP version are v1, v2c, or All. Default is All.
Discovery and SCCM together -- Use these guidelines to avoid common issues when you use Discovery and System Center Configuration Manager (SCCM) together.
Configure ESXi resource pools -- The ESXi server has a default resource pool called Resources that defines normal resources for a virtual machine.
Discovery classifiers -- A classifier tells Discovery which probes to trigger for the identification and exploration phases of discovery. Classifiers can also trigger the Horizontal Pattern probe, which launches a pattern, rather than additional probes, for identification and exploration.
Create a Discovery CI classification -- A CI classification allows Discovery to discover most common operating systems, network devices, and processes.
Create a Discovery process classification -- A process classification allows Discovery to create a particular CI type from information gathered during the identification and exploration phases.
Create a Discovery process handler -- Process handlers prevent the creation of duplicate CIs by filtering out parameters known to have inconsistent values before process classification occurs. You can create new classifiers or edit existing ones.
Create an HTTP classification -- An HTTP classifier enables the horizontal discovery process to find devices via the HTTP protocol.
Classification for IP address discovery -- Discovery provides a way to classify devices it finds through IP address discovery, even when no credentials are available.
Modify classifiers for IP address discovery -- When you run an IP address type of discovery, port probes scan devices without the use of credentials, and then Discovery can determine which classifiers to use. You can add port probes and additional classifiers for IP address discovery.
Reclassify a Windows Workstation machine as a server -- By default, Discovery automatically classifies computers using certain Windows operating systems as workstations. However, you might want specific computers in your network that are acting as servers to be classified by their function and not their operating system.
Discovery identifiers -- After Discovery classifies a configuration item (CI), it uses identifiers to determine if the device already exists in the Configuration Management Database (CMDB).
How Discovery identifiers work -- When Discovery has determined the device's class, it launches an identity probe that is configured to run one or more commands with a single authentication.
Configure Discovery identity probes -- Identity probes are multi-probes, which contain one or more simple probes configured to extract specific information from manageable devices. You can create your own identity multi-probe to identify CIs that Discovery does not already identify.
Serial number types for identification -- As Discovery finds CIs, their serial numbers are listed in the Serial Number [cmdb_serial_number] table so they are easy to identify. Serial number types vary depending on the CI, as described in the following examples.
Discovery status -- The Discovery status provides a summary of a Discovery launched from a schedule. You can also cancel a Discovery that is in progress from the status form.
Discovery timelines -- A Discovery timeline generates a graphical display of a Discovery Status record, including information about each probe and sensor that was used in the discovery.
View the Discovery timeline -- A Discovery timeline generates a graphical display of a Discovery Status record, including information about each probe and sensor that was used in the discovery.
ECC queue for Discovery -- The External Communication Channel (ECC) Queue is a connection point between your ServiceNow instance and other systems that integrate with it, most commonly a MID Server.
Discovery device history -- The Devices Related list in the Discovery Status form provides a summary list of all the devices scanned.
Logs for horizontal discovery -- The system collects logs to reflect the activity that takes place during a horizontal discovery based on both patterns and probes. Use the logs to fine-tune or troubleshoot the discovery process.
Review the logs for horizontal discovery -- The system collects logs to reflect the activity that takes place during a horizontal discovery based on both patterns and probes. Use the logs to fine-tune or troubleshoot the discovery process.
Change retention time for probe-based discovery logs -- The system collects logs to reflect the activity that takes place during a horizontal discovery based on both patterns and probes. Use the logs to fine-tune or troubleshoot the discovery process.
Discovery commands for probes and patterns -- Discovery commands are used for both probe and pattern-based discovery to access configuration items (CIs) in your environment.
View Patterns commands through the Command List module -- View and filter infrastructure or application pattern commands by various criteria, including pattern, CI type, or command, to confirm you have all the required permissions.
Validate commands used in pattern-based discovery -- Validate pattern commands to verify that the MID Server can successfully run them. Typically, commands might fail if you haven't configured the credentials necessary to run these commands on your ServiceNow instance. Another common reason of command failure is that the IP addresses used for discovery aren’t reachable.
Discovery on Code Signing instances -- Discovery is supported on instances with Code Signing enabled. Code signing validates the integrity of Discovery components before execution to help prevent unauthorized scripts from running on MID Servers and target machines.
Advanced Discovery configuration -- You can configure several additional components of Discovery such as Application Dependency Mapping, the ECC queue, and extensions for the MID server.
gMSA configuration for Discovery -- Group managed service accounts (gMSAs) are managed domain accounts that you use to help secure services. gMSAs can be used for credential-less Discovery.
Configure gMSA for Discovery -- Group managed service accounts (gMSAs) are managed domain accounts that you use to help secure services. gMSAs can be used for credential-less Discovery.
Credential-less discovery with Nmap -- If the instance fails to identify a configuration item (CI) because of authentication failure, Discovery or Service Mapping can run selected Network Mapper (Nmap) commands with a MID Server to collect some basic information about the CI without using credentials.
Credential-less host Discovery -- Credential-less host discovery occurs when a scanned host is found to be alive, but not active, or when all configured credential-based classification probes have failed.
Credential-less Application Discovery -- Credential-less Application Discovery attempts to identify an application service actively listening on a specific port at a given IP address.
Nmap commands and data collected -- Nmap executes in phases when collecting data and runs a controlled set of safe commands with two patterns for exploring applications and devices.
PowerShell for Discovery and Service Mapping -- MID Servers use PowerShell and PowerShell Remoting for accessing configuration items (CIs) during horizontal and top-down discovery. Review MID Server parameters and script includes, probe parameters, and credentials for using PowerShell.
Set up MID Servers to use PowerShell -- Configure MID Servers in your organization to use PowerShell for horizontal and top-down discovery of Windows servers.
PowerShell remoting for Discovery -- Probe developers can use the PowerShell remote execution framework to automatically handle remote execution of scripts on target devices. The unified framework removes inconsistencies in remote execution, increases efficiency, and improves stability.
PowerShell commands run by Discovery -- These are the PowerShell cmdlets and their parameters that Discovery runs to control and automate the administration of Windows servers and applications. Included are the probe parameters and MID Server scripts that contain the commands.
MID Server parameters for PowerShell -- Parameters control the behavior of a particular MID Server and have lower precedence than MID Server properties.
Discovery behaviors -- Discovery behaviors determine the probes that Shazzam launches, and from which MID Servers these probes are launched.
Create a Discovery behavior -- Create a Discovery behavior to determine which probes Shazzam launches and which MID Server is used.
Set up a load balancing behavior -- When multiple MID Servers are configured to scan the same protocol, you can set up load balancing behavior to automatically balance the work between MID Servers.
CI deletion strategies for pattern discovery -- When you perform discovery with a pattern, you can choose what to do with configuration items (CIs) that are in the Configuration Management Database (CMDB) but Discovery can no longer find.
Set a deletion strategy -- Set a deletion strategy when you want to take action on a related configuration item (CI) that Discovery can no longer find through pattern discovery. You can delete the main CI only when it is an Application or Cloud Resource pattern type.
Configuration file tracking -- The horizontal discovery process can find configuration files that belong to certain applications and add those configuration files to the CMDB. You can track the changes to these files by comparing them to previous versions.
Modify tracking changes in configuration files -- Configure the system to collect information about changes in configuration files belonging to a configuration item (CI). Service Mapping uses this information to notify users that CI configuration files changed and to view actual changes to configuration files directly in the service instance maps.
Change the source name of Discovery results -- You have the option of changing the source name of discovery results. This might be desirable if Discovery is running on your network together with another discovery product, and you want to use customized identifiers.
Discovery API plugin -- The Discovery API plugin provides APIs for scoped applications and is loaded when the Discovery plugin is activated.
Running process filters -- Filter any processes, using combinations of name and key parameters, from coming back to the instance. Out-of-the box, you can filter OS processes. Filtering processes helps reduce the number of records created, updated, or deleted in the database which can improve overall database performance.
Out-of-the-box process filters -- There are a variety of Linux and Windows out-of-the-box running process filters that are turned on and used for filtering processes.
Configure Discovery to use Event Framework -- Configure Discovery to process jobs using the Event Framework method, which enables you to manage discovery throttling effectively and prioritize tasks based on their importance in the queue.
Configure background worker job priority -- Configure the job priority of background workers to help prevent noncritical tasks from preempting important work, which promotes system efficiency and stability.
Configure event processors to execute on specific nodes -- Configure the discovery.event.pin.jobs system property to enable event processors to execute on specific nodes and distribute the work evenly. The scale factor calculates the number of nodes but doesn't pin jobs to specific nodes.
Post-clone Discovery configuration -- When a clone occurs, Discovery schedules are copied from the source instance to the target instance. Additional configuration is necessary for these schedules to function correctly on the target instance, helping you properly configure Cloud-based and IP-based Discovery schedules and maintain optimal performance.
Sensitive data filters -- The Discovery Sensitive Data Filters [discovery_sensitive_data_filter] table provides a way to help prevent sensitive information from being exposed in the Configuration Management Database (CMDB) by applying redaction rules during data collection.
Using Discovery -- Run Discovery schedules and execute Discovery probes, sensors and patterns to find your IT resources and add them to the CMDB.
Running discoveries in your network -- You can run discoveries from schedules or scripts to create configuration items, define subnets, or to find resources in AWS and Azure clouds.
Discovery Configuration Console -- Use the Discovery Configuration Console to manage what kind of configuration items (CIs) and CI information you want to discover.
Exclude CIs from discovery -- Use the Discovery Configuration Console to manage what kind of configuration items (CIs) and CI information you want to discover.
Filter software to discover -- Use the Discovery Configuration Console to manage what kind of configuration items (CIs) and CI information you want to discover.
Configure File-based Discovery -- Use the Discovery Configuration Console to manage what kind of configuration items (CIs) and CI information you want to discover.
Create Basic Auth credentials -- Use the Discovery Configuration Console to manage what kind of configuration items (CIs) and CI information you want to discover.
Schedule a horizontal discovery -- A discovery schedule determines what horizontal discovery searches for, when it runs, and which MID Servers are used. Create a discovery schedule for your local environment or a schedule for discovering the resources in your cloud service account.
Run a Quick Discovery -- A discovery schedule determines what horizontal discovery searches for, when it runs, and which MID Servers are used. Create a discovery schedule for your local environment or a schedule for discovering the resources in your cloud service account.
Run DiscoverNow from a script -- A discovery schedule determines what horizontal discovery searches for, when it runs, and which MID Servers are used. Create a discovery schedule for your local environment or a schedule for discovering the resources in your cloud service account.
Validate discovery results -- A discovery schedule determines what horizontal discovery searches for, when it runs, and which MID Servers are used. Create a discovery schedule for your local environment or a schedule for discovering the resources in your cloud service account.
Selection sequence for discovery schedules -- A discovery schedule determines what horizontal discovery searches for, when it runs, and which MID Servers are used. Create a discovery schedule for your local environment or a schedule for discovering the resources in your cloud service account.
File-based Discovery -- File-based Discovery helps you identify what software is running on your Windows and UNIX servers and devices, even if there’s no registration information available. You can then manage and maintain records of your software licenses, check for unlicensed files, detect forbidden or damaged files, and help evaluate any threats from unwanted files.
Run File-based Discovery -- Run File-based Discovery to find all of your installed software whether it is registered or not. You can enable and configure File-based Discovery at any time using the Discovery Configuration Console.
File-based Discovery issue resolution -- If you have any issues while setting up or running File-based Discovery, follow the actions listed here to help resolve them.
Discover applications based on fingerprints -- Discover applications based on suggestions based on ServiceNow Predictive Intelligence. Predictive Intelligence automatically classifies and categorizes the discovered running processes, as application fingerprints, and provides suggestions. ITOM Visibility uses Predictive Intelligence to perform initial analysis of discovered processes and suggest applications that you might want to discover. When using this method, ITOM Visibility automatically creates a Configuration Management Database (CMDB) configuration item (CI) class, a classifier, or a pattern for the new application CI class.
Application Fingerprints dashboard -- ITOM Visibility uses Predictive Intelligence to perform initial analysis of discovered processes and suggest applications that you might want to discover. When using this method, ITOM Visibility automatically creates a Configuration Management Database (CMDB) configuration item (CI) class, a classifier, or a pattern for the new application CI class. Use the Application Fingerprints dashboard to review suggested applications.
Serverless Discovery -- Discovery can find applications on host machines without the need to discover the host first. This type of Discovery is referred to as serverless Discovery.
Create standard-discovery pattern and schedule -- To find application CIs that reside on an unknown host, create an infrastructure pattern for standard serverless discovery. After creating the pattern, create a Discovery schedule that triggers the pattern.
Create a schedule for standard serverless Discovery -- To find application CIs that reside on an unknown host, create an infrastructure pattern for standard serverless discovery. After creating the pattern, create a Discovery schedule that triggers the pattern.
Create host-based pattern and schedule -- To find application CIs that reside on a known host in your CMDB, create an infrastructure pattern for host-based serverless discovery. After creating the pattern, create a Discovery schedule that triggers the pattern.
Create a schedule for host-based serverless Discovery -- To find application CIs that reside on a known host in your CMDB, create an infrastructure pattern for host-based serverless discovery. After creating the pattern, create a Discovery schedule that triggers the pattern.
Discovery probes and sensors -- Discovery probes and sensors perform data collection and update the Configuration Management Database (CMDB).
List of Discovery probes -- A wide variety of probes exist for the Discovery application to detect elements on your network.
CIM probe -- The CIM probe uses WBEM protocols to query a particular CIM server, the CIM Object Manager, for a set of data objects and properties.
CimIQL syntax -- The CIM probe uses WBEM protocols to query a particular CIM server, the CIM Object Manager, for a set of data objects and properties.
CimIQL operation tokens -- The CIM probe uses WBEM protocols to query a particular CIM server, the CIM Object Manager, for a set of data objects and properties.
CimIQL component tokens -- The CIM probe uses WBEM protocols to query a particular CIM server, the CIM Object Manager, for a set of data objects and properties.
CimIQL tutorial -- The CIM probe uses WBEM protocols to query a particular CIM server, the CIM Object Manager, for a set of data objects and properties.
CimIQL results -- The CIM probe uses WBEM protocols to query a particular CIM server, the CIM Object Manager, for a set of data objects and properties.
DNS probe -- DNS probes determine the DNS names for configuration items (CI).
Horizontal Pattern probe -- Discovery uses the Horizontal Pattern probe to launch patterns for horizontal discovery.
PowerShell probe -- The PowerShell Probe executes PowerShell V2 scripts on the MID Server host.
SCPRelay probe -- The SCP Relay Probe copies a single file or the contents of a directory from one host to another, using the MID Server as a relay.
SNMP probes -- The SNMP probes use the SNMP protocol to query a particular device for a list of OIDs, which are then traversed and the results passed back to the sensors. MID Servers support all SNMP protocol versions by default. You can set a MID Server to only support specific versions of SNMP.
Load a MIB module -- You can load an additional Management Information Base (MIB) module by creating a new ecc_agent_mib record and attaching the actual MIB file to the record.
SNMP probe MIB modules -- A management information base module (MIB) is a database that is used to manage elements in a network.
SSHCommand probe -- A probe using the ECC queue topic name SSHCommand executes a shell command on the target host, and returns the resulting output to the sensor.
SSHCommand path -- The SSHCommand probe computes the default path from the following sources.
Shell script options -- The SSHCommand probe supports the following scripting options in the ECC queue name field.
Non-privileged SSH commands -- These tables display the SSH commands run by Discovery probes on target devices during horizontal discovery. These SSH commands don’t require elevated privileges to run.
Privileged SSH commands -- These tables display the SSH commands run by Discovery probes during horizontal discovery. These SSH commands require elevated privileges to run.
vCenter probes and probe parameters -- vCenter probes scan virtual machines using VMware's vSphere product suite. Each probe scans for different kinds of data, such as networks, NICs, and tags. The VMware - vCenter probe that discovered all vCenter objects in previous releases is deprecated in the Istanbul release and replaced by multiple probes.
Trigger custom probes with the vCenter Discovery extension -- vCenter probes scan virtual machines using VMware's vSphere product suite. Each probe scans for different kinds of data, such as networks, NICs, and tags. The VMware - vCenter probe that discovered all vCenter objects in previous releases is deprecated in the Istanbul release and replaced by multiple probes.
Windows probes and permissions -- Discovery accesses devices and software by executing commands as a specific user on Windows computers.
WMIRunner probe -- WMI Runner is a probe type that fetches data from Windows operating systems via the Windows Management Instrumentation (WMI) interface. IPv6 supports WMI Runner.
Port probes -- Port probes are used in Discovery by the Shazzam probe to detect protocol activity on open ports on devices it encounters.
Shazzam probe, port probes, and protocols -- Port scanning is the first step in the discovery process. The Shazzam probe performs port scanning, regardless of whether you use patterns for horizontal discovery. The following table lists the known ports and protocols used by Discovery.
Configure Shazzam probe -- When you run Discovery, the Shazzam probe finds your active network devices by scanning specified ports on specified IP address ranges. If the list of IP ranges being scanned is large, you can configure the Shazzam payload for JSON encoding to reduce its size.
Control Shazzam payload size -- When you run Discovery, the Shazzam probe finds your active network devices by scanning specified ports on specified IP address ranges. If the list of IP ranges being scanned is large, you can configure the Shazzam payload for JSON encoding to reduce its size.
Discovery sensors -- Every probe in Discovery must have a corresponding sensor to process the data returned.
Discovery probe management -- Several discovery probes and their associated sensors are included with Discovery. You rarely need to modify probes or sensors. But you might need to set parameters to control the behavior of a particular probe or align versions of customized probes.
Create or modify a probe -- Create a new probe to discover additional CIs or modify an existing probe to collect additional information. After you create or modify a probe, test it.
Set probe parameters -- Use probe parameters to control the behavior of a particular probe every time it is triggered.
Align versions of customized probes and sensors -- If you customized a probe or sensor and upgraded to a new version of an instance, you need to realign the versions of the customized probe and sensor to the most current version.
Discovery multiprobes and multisensors -- Multiprobes contain one or more simple probes configured to extract specific information from manageable devices by executing multiple queries with a single authentication.
Add a simple probe to a multiprobe -- Multiprobes contain one or more simple probes configured to extract specific information from manageable devices by executing multiple queries with a single authentication.
Create a Discovery multiprobe -- Multiprobes contain one or more simple probes configured to extract specific information from manageable devices by executing multiple queries with a single authentication.
Create a Discovery multisensor -- Multiprobes contain one or more simple probes configured to extract specific information from manageable devices by executing multiple queries with a single authentication.
Patterns and horizontal discovery -- A pattern is a series of operations that tell Discovery which CIs to find on your network, what credentials to use, and what tables to populate in the CMDB.
Pattern Orchestrator -- A pattern is a series of operations that tell Discovery which CIs to find on your network, what credentials to use, and what tables to populate in the CMDB.
Add the Horizontal Pattern probe to a classifier -- A pattern is a series of operations that tell Discovery which CIs to find on your network, what credentials to use, and what tables to populate in the CMDB.
Use a pattern for horizontal discovery -- A pattern is a series of operations that tell Discovery which CIs to find on your network, what credentials to use, and what tables to populate in the CMDB.
Discovery resource utilization -- Standard transactions on Windows and UNIX generate various amounts of network traffic, depending on what is being discovered.
Discovery monitoring and issue resolution -- Learn how to monitor the progress of your discoveries and how to configure the system to aggregate performance metrics that are important to you. Find descriptions of the error messages you see, as well as possible steps you can take to solve problems. The Now Support Knowledge Base on Hi contains several articles to help you troubleshoot discovery issues.
Discovery Home page -- The Discovery Home page provides a summary of discoveries that were triggered by cloud and non-cloud schedules. You can view any errors that occurred during a Discovery and find remediation suggestions. Use the Home page view to examine the cloud resources discovered for the service accounts you selected in a cloud schedule.
Resolve CI Discovery schedule errors -- The Discovery Home page provides a summary of discoveries that were triggered by cloud and non-cloud schedules. You can view any errors that occurred during a Discovery and find remediation suggestions. Use the Home page view to examine the cloud resources discovered for the service accounts you selected in a cloud schedule.
Cloud Discovery home page in Cloud Discovery Workspace -- The Cloud Discovery home page displays a summary of the discoveries triggered through a discovery schedule. You can view the count of CIs discovered and errors encountered over time. You can also select any dashboard report to view additional information.
Discovery performance metrics -- This Discovery enhancement collects performance metrics on probe/pattern and sensor processing times and then aggregates that data over time. You can use the roll-up data to monitor the performance of specific discoveries or to compare performance between versions after an upgrade.
View Discovery performance metrics for probes, sensors, and patterns -- This Discovery enhancement collects performance metrics on probe/pattern and sensor processing times and then aggregates that data over time. You can use the roll-up data to monitor the performance of specific discoveries or to compare performance between versions after an upgrade.
View Discovery performance metrics aggregated by build -- This Discovery enhancement collects performance metrics on probe/pattern and sensor processing times and then aggregates that data over time. You can use the roll-up data to monitor the performance of specific discoveries or to compare performance between versions after an upgrade.
View Discovery performance metrics aggregated by status -- This Discovery enhancement collects performance metrics on probe/pattern and sensor processing times and then aggregates that data over time. You can use the roll-up data to monitor the performance of specific discoveries or to compare performance between versions after an upgrade.
View Discovery performance metrics aggregated by IP address -- This Discovery enhancement collects performance metrics on probe/pattern and sensor processing times and then aggregates that data over time. You can use the roll-up data to monitor the performance of specific discoveries or to compare performance between versions after an upgrade.
Aggregated data for Discovery performance metrics -- This Discovery enhancement collects performance metrics on probe/pattern and sensor processing times and then aggregates that data over time. You can use the roll-up data to monitor the performance of specific discoveries or to compare performance between versions after an upgrade.
Discovery error messages -- Review common Discovery error messages and their causes to identify and resolve issues that occur during discovery runs.
Find the cause of a "No Sensor Defined" error message -- Every active probe looks for a corresponding sensor to process the data that is collected by the probe. The "No Sensors Defined" message indicates that the corresponding sensor for the probe is missing or inactive.
Fix the cause of a sensor error message -- To fix a Discovery sensor error message, you must fix the JavaScript file containing the code that generated the error.
Discover missing compute resources -- Use the Discovery Admin Workspace to identify compute resources that weren't discovered recently. Run a quick discovery to update the resource's data. If a resource isn't discoverable, ignore the resource and exclude it from the report. This procedure helps you maximize the use of your resources.
Run Tuning checks -- Tuning checks are scans aimed at optimizing configurations, grouped into suites with each specific check detailed below.
Edit an existing check -- By editing the definition check, you can change description and script.
Resolve Cloud Discovery errors in Cloud Discovery Workspace -- View the Cloud Discovery errors that occurred during the discovery and resolve them. You can view the errors for all the Cloud Discovery runs or a single Cloud Discovery run.
Discovery Platform Analytics Solutions -- Platform Analytics Solutions contain preconfigured dashboards. These dashboards contain actionable data visualizations that help you improve your business processes and practices.
Discovery for data-center virtualization -- Discovery and Service Mapping Patterns identify and classify information about virtual machines discovered in a data-center.
Discovery for VMware virtualization -- A Discovery schedule for VMware virtualization discovers vCenter and ESX hosts and individual ESXi hosts that manage VMs and related components without a vCenter.
VMware Workstation -- In the basic VMware system, the VMware Workstation runs on a Windows or Linux host machine, but not managed directly thorugh vCenter.
Discovery reference -- Reference topics provide additional information about Discovery lists and forms.
Cloud Discovery reference -- Reference topics provide additional information about the lists, forms, and cloud settings used in Cloud Discovery.
Cloud Discovery service account form reference -- The Cloud Discovery service account form displays detailed information about the selected cloud provider. The Cloud Discovery service account form is available in the Cloud Discovery Workspace.
Edit settings form reference -- The Edit settings form displays information about the Amazon Web Services (AWS) settings used to record and deliver the AWS events to the listening endpoint.
Discovery log details -- Discovery logs contain information on the horizontal discovery process based on probes and patterns.
Discovery Schedule form reference -- The Discovery Schedule form provides details about the configuration items (CIs) targeted for discovery, the associated MID Server, and the schedule settings for when and how the discovery runs.
Create a new discovery schedule form reference -- The Create a new discovery schedule form displays information related to the schedule and the target cloud provider. The Create a new discovery schedule form is available in the Cloud Discovery Workspace.
Discovery Admin Workspace reference -- Reference topics provide additional information about the lists, forms, and settings used in Discovery Admin Workspace.
Application fingerprint suggestion form -- When viewing suggestions based on application fingerprints, verify the information on the Application fingerprints suggestion form.
Discovery Admin Workspace data visualizations -- The Overview tab includes visualizations that provide detailed information about the Discovery schedule. These visualizations offer a comprehensive view of the schedule performance and status, showing key metrics like the number of discoveries completed, success rate, and any errors encountered.
Tracked Configuration file form -- The Tracked Configuration file form displays details about a specific configuration file.
Firewall Audits and Reporting -- Use the Firewall Audits and Reporting application to explore and create an inventory of your firewall security policies, devices, device groups, and manager information. Additionally, you can initiate requests for new firewall rules through the Service Catalog application and conduct audits of firewall security policies within specified time frames.
Exploring Firewall Audits and Reporting -- With Firewall Audits and Reporting, you have the capability to explore and conduct an inventory of your firewall security policies, devices, device groups, and manager information. Additionally, you can utilize it to submit requests for new firewall rules and audit security policies within a specified time frame.
Configuring Firewall Audits and Reporting -- Set up the process to gain insight into discovering and compiling an inventory of firewall security policies, devices, device groups, and manager information.
Get started with Firewall Audits and Reporting -- Prior to diving into Firewall Audits and Reporting functionality, meet the necessary requirements by installing and activating the plugin, upgrading your instance, and obtaining the application from the ServiceNow Store.
Visibility to Firewall inventory -- The Firewall Audits and Reporting application helps you to discover and take inventory of your firewall security policies, devices, device groups, and manager information.
Discover firewall policies -- As a member of a security team, you can discover firewall devices, policies, and owner groups, allowing a central view of the footprint. This data is updated in the ServiceNow CMDB. Set up a schedule to discover your firewall policies to help you keep track of your company's valuable information.
Archive firewall rule audit, rule requests, and audit tasks -- Archive firewall rule requests, audit requests, and audit tasks that are older than a specific time period to enhance system performance. At a later time, you can delete them from the archive table altogether to reduce the size of that table.
Firewall audits -- Firewall Audits and Reporting provides a flexible auditing framework to track your firewall policy ownership and the necessity of a firewall policy. You can trigger a random audit to measure your security hygiene on the firewall policy and ownership, as well as perform proactive audits on a regular basis.
Initiate audit request -- Initiate audits against a specified firewall manager or device to ensure proper configuration in alignment with the security policies of your organization.
Using Firewall Audits and Reporting -- Firewall Audits and Reporting is a powerful application for requesting new firewall rules, streamlining the management of IP addresses.
Firewall rule requests -- Use Service Catalog to request new firewall policies and rules.
Request firewall rule -- Use Service Catalog to request new firewall policies and rules.
Firewall rule requests using agentic workflows -- The Firewall Management Task Creation agentic workflow provides a path to request one or more firewall rules through natural language prompts in the Now Assist panel.
Request firewall rules using agentic workflow -- The Firewall Management Task Creation agentic workflow provides a path to request one or more firewall rules through natural language prompts in the Now Assist panel.
Approve firewall rule requests -- The Firewall Management Task Creation agentic workflow provides a path to request one or more firewall rules through natural language prompts in the Now Assist panel.
Implement firewall rules on Panorama -- The Firewall Management Task Creation agentic workflow provides a path to request one or more firewall rules through natural language prompts in the Now Assist panel.
Firewall Audits and Reporting reference -- Reference topics provide additional information about Firewall Audits and Reporting components, including dashboards and report calibration.
Firewall Admin Workspace dashboard -- The unified dashboard enables security and risk teams to oversee tasks, change requests, and the entire firewall inventory life cycle, with daily or manual updates for accurate and current information.
Certificate Inventory and Management -- With Certificate Inventory and Management, you can discover, conduct an inventory, and proactively manage all TLS certificates. Certificate Inventory and Management supports IPv6, providing comprehensive coverage for your certificate management needs.
Exploring Certificate Inventory and Management -- Certificate Inventory and Management serves as a centralized and automated solution for handling the complexities of certificate management. It enhances security, ensures compliance, and provides a streamlined approach to managing the life-cycle of digital certificates within an organization.
Certificate Inventory and Management process flow -- Certificate Inventory and Management allows Discovery to automatically scan for certificates on specific ports through your existing CI-based Discovery schedules. In addition, you can create new Discovery schedules to scan individual URLs.
Pre-discovery phase -- The pre-discovery phase involves preparatory steps, such as defining scanning parameters and configuring credential details, to ensure a smooth initiation of the certificate discovery process.
Post-discovery phase -- Following the discovery phase, the system manages TLS certificates, offering flexibility for both manual and automated request options, catering to various certificate-related tasks and processes.
Certificate Inventory and Management Workspace -- The Certificate Management workspace provides a unified solution for managing organizational . It strengthens security, ensures compliance, and streamlines the digital certificate life cycle.
Configuring Certificate Inventory and Management -- Establish a streamlined process for gaining insights into Certificate Inventory Management, covering key aspects like certificate discovery, bulk upload functionality, maintenance of certificate chain relationships, configuration of Credential Identifiers, customization of the system, creation of new/renewal requests, archiving tasks, automation of TLS certificate management, integration with Event Management, Slack notifications for alerts, and leveraging cert-Manager for efficient certificate generation.
Get started with Certificate Inventory and Management -- Prior to diving into the Certificate Inventory and Management application's functionality, meet the necessary requirements by installing and activating the plugin, upgrading your instance, and obtaining the Certificate Inventory and Management application from the ServiceNow Store.
Visibility to TLS certificates -- The Certificate Inventory and Management application allows Discovery to automatically scan for certificates on specific ports through your existing CI-based Discovery schedules. In addition, you can create Discovery schedules to scan for specific URLs.
Run Certificate Discovery via port scans -- When the TLS port probe [tls_ssl_certs] is enabled, Discovery automatically scans 14 pre-authorized ports as part of your existing CI Discovery schedules.
Run Certificate Discovery via individual URL scans -- To initiate certificate discovery through URL scans, you must manually include individual URLs and configure a new certificate Discovery schedule.
Run IP-Based Certificate Discovery -- Enable the Transfer Layer Security (TLS) port probe [tls_ssl_certs] and scan for certificates on an IP address or multiple IP addresses.
Use bulk certificate upload -- In Certificate Inventory and Management version 1.2.0 and later, you have the option to efficiently import SSL certificates in bulk, allowing you to upload up to 5000 certificates within a single .xlsx file for time and resource savings.
Configure IDs for Certificate Management credentials -- Maintaining certificate chain relationships via certificate import ensures the integrity and security of digital certificates, validating their authenticity in a system.
Run Certificate discovery via Certificate Authority query -- Running Certificate discovery via Certificate Authority query allows for systematic identification and import of TLS certificates from specific Certificate Authorities, ensuring comprehensive tracking, management, and security of the certificate inventory. Discover TLS certificates from Certificate Authorities (CA) with Certificate Inventory and Management, using Patterns for diverse certificate authority vendors.
Customize Certificate Inventory and Management -- Customize various aspects within Certificate Inventory and Management using Discovery properties, enabling you to tailor the solution to your specific needs and enhance the overall management of TLS certificates.
Manual flow for certificate requests -- Certificate renewal requests and incidents are automatically created when certificates are about to expire or have expired. For added flexibility and control, you can also manually create requests using the Service Catalog.
Create certificate requests -- Create certificate requests manually through Service Catalog for a personalized and efficient procurement of certificates, providing greater flexibility and control.
Create a renewal certificate request -- Manually initiate renewal requests for certificates using the Service Catalog for added flexibility and control.
Archive certificate tasks -- In Version 1.1.7 Certificate Inventory and Management, the Data Archiver [com.glide.auxdb] plug-in performs daily operations to transfer data that is no longer required from primary tables to a designated set of archive tables.
Use automated flow for certificate management -- Certificate and Management streamlines your TLS certificate processes, offering benefits such as improved efficiency and enhanced security. Automating certificate management ensures timely renewal of certificates, which minimizes the risk of expired certificates.
Set up routing policy -- Set up a routing policy to automate your Certificate Inventory and Management. Creating a policy based on Certificate Authority (CA), environment, and other features ensures efficient TLS certificate management.
Routing policy details -- Routing policies are essential for automated certificate management in TLS certificates as they define specific criteria, such as CA and environment, enabling efficient handling of different scenarios during the certificate lifecycle.
Request certificates -- Request a new certificate and automatically retrieve the certificates for an application using automated certificate management. Certificate Inventory and Management Version 2.1.0 supports requesting certificates from DigiCert and Entrust CA Gateway. Version 2.3.2 also supports Microsoft CA.
Approve certificate tasks -- Sometimes you need to manually approve a certificate task to ensure the validity and security of TLS certificates.
Renew a certificate using automated certificate management -- Request renewal for a certificate and automatically retrieve the certificate for an application. This maintains secure and uninterrupted services as you extend the validity period of the certificate, preventing potential service disruptions due to expired certificates.
Revoke a certificate using automated certificate management -- Revoke certificate for an application. Revocation doesn't require approval if order Id and certificate Id are present in the Certificate Extension table. If order Id and certificate Id aren't present in the Certificate Extension table, then you need approval.
Certificate generation through Cert-Manager Integration -- Request a certificate through Kubernetes cert-manager using the ServiceNow External Issuer (sn-external-issuer) and save the certificate and its related information securely within the Kubernetes cluster as a secret. In Kubernetes, a secret is an object that allows you to store and manage sensitive information, such as passwords, API keys, and certificates.
Certificate alerts and notifications -- From version 1.2.0 onward, Certificate Inventory and Management integrates with Event Management, providing a unified solution for streamlined operations. This integration enables the generation of events and notifications, with the added capability of sending alerts to Slack. Certificate Inventory and Management also supports sending certificate notifications via email and Microsoft Teams.
Integrate Event Management with Certificate Inventory and Management -- In Certificate Inventory and Management version 1.2.0 and later, Event Management can create events and alerts for both expiring and expired certificates, enhancing the system's monitoring capabilities.
Receive certificate notifications on Slack -- In Version 1.2.0 of Certificate Inventory and Management, set up Slack notifications to stay informed about expiring and expired certificates. Receive detailed alerts with convenient URL links for additional information.
Receive certificate notifications via Microsoft Teams -- Configure certificate notifications to be delivered to a Microsoft Teams channel so that you can receive alerts and initiate certificate renewal workflows directly from Microsoft Teams.
Certificate attestation for certificate owners -- Attestation jobs run in regular intervals, sending emails to certificate owners, giving them a chance to review certificate ownership.
Configure a certificate attestation review -- Send out emails to all certificate owners confirming their ownership or confirming they're no longer certificate owners at set intervals.
Exploring ACME -- The Automated Certificate Management Environment (ACME) is a communication protocol that automates the interaction between a certificate authority (CA) and a server. It streamlines the processes of requesting, renewing, and revoking SSL/TLS certificates.
Configuring ACME -- Configuring Automated Certificate Management Environment (ACME) helps to configure the SSL/TLS certificates automatically for web servers, enhancing security and simplifying administration.
Create the credential for the ACME Certificate Authority -- Create an ACME credential on the ACME Certificate Authority's website or API. The credential is used by your ACME client software to interact with the ACME Certificate Authority (CA) to request, renew, or revoke certificates.
Set up the routing policy for ACME -- Set up a routing policy to establish an Automated Certificate Management Environment (ACME). It involves creating a policy based on factors such as Certificate Authority (CA), environment, and other features, ensuring efficient SSL/TLS certificate management.
Using ACME -- Use the Automated Certificate Management Environment (ACME) to request, renew, or revoke SSL/TLS certificates.
Request certificates using ACME manual flow -- Request a new certificate and automatically retrieve the certificates for an application using ACME manual flow of DNS challenge.
Request certificates using ACME automated flow -- Request a new certificate and automatically retrieve the certificates for an application using an Automated Certificate Management Environment (ACME) automated flow of DNS challenge.
Renew certificate using ACME automated flow of DNS challenge -- Request to renew the certificate and automatically retrieve the certificates for an application using an Automated Certificate Management Environment (ACME) automated flow of DNS challenge.
ACME integration with KeyFactor EJBCA -- Automate the flow of requesting, renewing, and revoking your certificates by integrating Keyfactor EJBCA with the Automated Certificate Management Environment (ACME).
Create a routing policy for EJBCA ACME certificates -- Automate your EJBCA ACME workflows by creating a routing policy that aligns with your Certificate Signing Requests (CSRs) to request, renew, and revoke certificates.
ACME reference -- Reference topics provide additional information about the Automated Certificate Management Environment (ACME), including tables, patterns, and terms.
Certificate routing policy form table -- To automate the processes of your certificate life cycle, you must fill out a routing policy form that populates your Certificate Signing Requests. This table shows you the required fields and values.
Automated certificate renewal -- Detect certificates that are about to expire and renew them automatically before expiration to keep your digital systems secure and continuously available.
Configure automatic certificate renewal -- Enable the auto-renewal options in your System Properties to configure your system to renew automatically Transport Layer Security (TLS) certificates before they expire.
Set a certificate to renew automatically -- Configure automatic certificate renewal to avoid service interruptions from expired certificates. Set the number of days before expiration when the system should automatically renew certificates.
Certificate management with CyberArk Certificate Manager SaaS -- The ServiceNow Certificate Inventory and Management application has been integrated with CyberArk Certificate Manager SaaS for automated certificate life-cycle management, providing centralized certificate provisioning, renewal, and revocation capabilities.
Configure credentials -- Configure authentication credentials so Certificate Inventory and Management can communicate with CyberArk Certificate Manager SaaS for automated certificate life-cycle management.
Create routing policies -- Create routing policies to direct certificate requests to CyberArk Certificate Manager SaaS by matching attributes such as organization, domain, and certificate type to the Routing Policy [sn_disco_certmgmt_routing_policy] table.
Request certificates -- Submit a certificate request managed through CyberArk Certificate Manager SaaS using configured routing policies.
Renew certificates -- Renew an existing certificate through the CyberArk Certificate Manager SaaS to extend its validity period before expiration.
Revoke certificates -- Revoke a certificate through the CyberArk Certificate Manager SaaS to invalidate it before its scheduled expiration date.
Certificate Inventory and Management reference -- Reference topics provide additional information about Certificate Inventory and Management dashboard and components, including tables, patterns, and terms.
Certificate Inventory and Management tables -- This framework supports security, compliance, and streamlined operations. Certificate Inventory and Management tables provide a centralized system to track and manage digital certificates. They capture key details, including discovered certificates, installation locations, historical data, and associated tasks such as renewals and requests.
Certificate Routing Policy form -- The Certificate Routing Policy form enables you to configure routing policies for CyberArk Certificate Manager SaaS.
Certificate Inventory and Management patterns -- Efficiently manage your Certificate Inventory with patterns to streamline the management of digital certificates. Patterns reduce the risk of vulnerabilities by bolstering security, compliance, and efficient lifecycle control.
AWS Certificate Manager discovery -- Cloud Discovery uses Patterns to discover certificate data that the Amazon AWS Cloud Certificate Manager (ACM) manages. Discovering this data requires installing and updating Discovery and Service Mapping Patterns and Certificate Inventory and Management.
GCP Certificate Manager discovery -- Cloud Discovery uses Patterns to discover certificate data that the GCP Certificate Manager manages. Discovering this data requires installing and updating Discovery and Service Mapping Patterns and Certificate Inventory and Management.
Azure Key Vault certificate discovery -- Cloud Discovery uses Patterns to discover Azure Key Vault certificates. Discovering this data requires installing and updating Discovery and Service Mapping Patterns and Certificate Inventory and Management.
Java KeyStore and Windows Certificate Store discovery -- Discovery uses the Collect Certificates extension section of the Linux Server and Windows OS – Servers patterns to discover certificates stored in the Java KeyStore or Windows Certificate Store. Discovering the certificate information requires installing and updating Discovery and Service Mapping Patterns and Certificate Inventory and Management.
Certificate Inventory and Management terms -- The Certificate Inventory Management glossary comprises a set of concise definitions and explanations for terms related to the tracking, storage, and management of digital certificates within an IT environment.
Discovery schedule form table -- To perform Discovery on root certificates stored outside your server, you must set a special Discovery schedule that locates these certificates. This table guides you through the form required for this task.
Certificate request form -- The Request New Certificate (Automated) and Renew Certificate (Automated) forms enable you to submit or update a Certificate Signing Request (CSR) to be submitted to a certificate authority.
Service Mapping -- The ServiceNow Service Mapping application discovers all application services in your organization and builds a comprehensive map of all devices, applications, and configuration profiles used in these application services.
Exploring Service Mapping -- Service Mapping discovers all service instances in your organization and builds a comprehensive map of all devices, applications, and configuration profiles used in these service instances.
Choose the right method for discovering and mapping services -- Service Mapping deploys different methods for collecting information about configuration items (CIs) and organizing them into application services. The available mapping methods are: pattern-based, tag-based, traffic-based, and discovery based on Predictive Intelligence. Learn about the mapping methods to use the ones that best suit the needs of your organization.
Multi-source service mapping -- Multi-source service mapping combines data from multiple discovery methods to create a single, comprehensive service map that provides complete visibility into your organization's hybrid IT infrastructure.
Service Mapping with Agent Client Collector -- Agent Client Collector enables the discovery and mapping of application services without requiring you to set up credentials for the MID Server.
CMDB-based mapping -- Using data stored in the Configuration Management Database (CMDB), you can run top-down discovery and map your organization's application services without having to access a MID Server.
Automated Service Suggestions -- Automated Service Suggestions simplifies the processing of mapping application services or adding to an existing service by providing application service candidates using machine learning. Mapped services provide key information to help you make data-driven decisions, prioritize services, and respond to situations.
Pattern-based discovery in Service Mapping -- Pattern-based discovery is the main method of Service Mapping collecting data about devices and applications used in application services. After Service Mapping collects data, it then creates a map of application services and stores the collected data in the CMDB.
Tag-based discovery in Service Mapping -- If your organization uses tags, or establishes them in a local ServiceNow instance, you can use these tags to map application services.
Tag discovery for the workspace -- If your organization uses tags for asset management, you can use the Service Mapping workspace to manage these tags and create tag-based application services.
Traffic-based discovery in Service Mapping -- Service Mapping can discover and map configuration items (CIs) following their traffic-based connections. This method is referred to as traffic-based mapping and complements pattern-based mapping.
Service Mapping for containerized environments using KVA -- Kubernetes Visibility Agent (KVA) and Service Mapping discover and visualize application dependencies across Kubernetes clusters and related resources, providing complete visibility into containerized environments.
Discovery of application services on cloud -- Service Mapping in cloud environments provides critical visibility into application dependencies and connections. By identifying how different application components interact within IaaS and PaaS environments, your organization can gain better insight into its application services and improve overall service management.
Service Mapping flow -- Learn about high-level tasks users having different roles perform in Service Mapping.
Tag mapping in the workspace -- The Tag-based service mapping dashboard offers an intuitive way to manage tag-based services. Use the widgets, data visualizations, and list navigation to review and update your services, or create new tag-based services in a few steps. The dashboard enhances the Service Mapping Workspace, offering an efficient and user-friendly interface for organizing and optimizing your service mappings.
About the tag-based application service form -- The tag-based application service form provides a centralized location for viewing detailed information about a selected tag-based service, including its configuration and its associated configuration items.
Traversal Rules -- Traversal rules identify and map relationships between configuration items to create comprehensive application service maps. They connect relevant configuration items based on predefined relationships, promoting accurate service mapping and visualization.
Configuring Service Mapping -- You get started with Service Mapping by configuring roles, credentials, and MID Server connections.
Request Service Mapping -- Service Mapping is available under the ITOM Visibility subscription and requires activation by ServiceNow personnel.
Install Service Mapping Plus -- You can install the Service Mapping Plus application (sn_sm_scoped_app) if you have the admin role. The application installs related ServiceNow Store applications and plugins if they are not already installed.
Choose MID Server selection algorithm -- Service Mapping supports the new and the legacy algorithms for selecting a MID Server for a discovery request. Depending on your organization needs, you can choose which algorithm to enable.
Commands requiring a privileged user -- Service Mapping uses commands requiring elevated rights to discover and map Unix-based hosts in your organization. In addition to configuring necessary credentials, configure servers in your organization to allow Service Mapping to run these commands with elevated rights.
SNMP-based queries -- Service Mapping accesses network infrastructure devices like load balancers and routers using Simple Network Management Protocol (SNMP) v1/v2c/v3. Configure SNMP community credentials to enable this type of access.
Verify that Service Mapping is set up properly -- Before you start mapping application services, verify that you configured MID Servers to discover application services and provided all the necessary host and application credentials.
Quick start tests for Service Mapping -- After upgrades and deployments of new applications or integrations, run quick start tests to verify that Service Mapping still works. If you have customized Service Mapping, copy the quick start tests and configure them for your customizations.
Advanced Service Mapping configuration -- Fine-tune Service Mapping collaboration with other components and modules as well as customize data display in service instance maps.
Enable traffic-based discovery for CI types or specific CIs -- Service Mapping can discover and map CIs by detecting the inbound and outbound traffic that the CIs generate. Create a traffic-based discovery rule to determine which configuration items are available for traffic-based mapping.
Tag-based discovery configuration -- You can refine the default configuration to control which CIs Service Mapping includes in application services during the tag-based discovery process.
Include CIs based on classes in tag-based discovery -- Use CI classes to identify which CIs Service Mapping includes in application services during tag-based discovery. By default, this list appears empty and includes all CIs belonging to all CI classes. Define CI classes and allow only CIs belonging to these classes or their extensions to participate in tag-based discovery.
Exclude CIs by installation status in tag-based discovery -- Use the CI installation status to create CI classes and exclude CIs from application services during tag-based discovery. By default, application services based on tags exclude CIs with the Retired or Absent install status. You can expand this list of excluded CIs to include additional installation statuses such as Pending install or Stolen.
Exclude CI relationships from tag-based discovery -- Exclude preconfigured CI relationships from the tag-based discovery process to refine the application services created. Service Mapping consists of preconfigured CI relationships and includes CIs in these relationships even if they do not have assigned tags. Choose which preconfigured CI relationships to exclude and the remaining CI relationships participate in tag-based discovery.
Add or edit CI relationships in tag-based discovery -- Activate pre-configured CI relationships that Service Mapping does not include by default or add additional relationships to use in the tag-based discovery process. For example, you can add a CI relationship between Linux servers and storage devices to discover servers hosting storage devices based on tags.
Fine-tune tracking changes for the change history -- Define CI fields for which the system reflects changes in the change history for application services. The change history view shows changes to CIs making up application services as well as changes to application services themselves.
Data collection and discovery using Netflow -- Service Mapping can perform discovery based on data collected using the Netflow protocol. Netflow is a protocol that Service Mapping can use to collect data about CIs and their connections along with Netstat and lsof commands.
Configure data collection using Netflow -- Enable Service Mapping to perform discovery based on data collected using the Netflow protocol. This setup results in fully automated data collection flow, where all involved components send, collect, and analyze data automatically.
Data collection and discovery using VPC Flow Logs -- Service Mapping can perform discovery based on data collected using VPC Flow Logs. Amazon VPC hosts Amazon Elastic Compute Cloud (EC2) instances that provide Amazon Web Services. VPC Flow Logs collect data on IP traffic going to and from network interfaces in the VPC.
Configure data collection using VPC Flow Logs -- Enable Service Mapping to perform discovery based on data collected using Virtual Private Cloud (VPC) logs. This method is relevant for organizations using Amazon Web Services (AWS).
Configure Search Assistant for Windows -- The Search Assistant feature of Pattern Designer allows you to search within files or registries. Upload grep files on to your instance to enable this feature to search on Windows servers.
Modify display for CI attributes -- You can control what configuration item (CI) attributes the system displays in the Properties pane of service instance maps.
Upload the rctrlx.exe file to MID Servers -- Upload the rctrlx.exe file to MID Servers to enable running discovery commands on Microsoft Exchange 2007 and 2010, and Citrix XenApp.
Fine-tune Service Mapping with MID affinity and IP reuse -- The MID Server needed to map an application service might be misidentified in subnetworks with overlapping IP ranges and reused IP addresses. To enable the successful discovery of resources associated with a subnetwork, Service Mapping provides several properties for MID Server identification.
Using Service Mapping -- As the Service Mapping administrator, you support companies in their efforts to map and maintain critical application services so that they remain service-aware.
AI capabilities in Service Mapping -- Service Mapping AI capabilities helps Service Mapping Administrators speed-up mapping processes and manage team flows more efficiently.
AI Agents for Service Mapping -- The Service Mapping AI agents automate the creation and maintenance of service maps in the Configuration Management Database (CMDB), reducing manual effort for Service Mapping administrators.
Activate AI Agents for Service Mapping -- Activate the Service Mapping AI Agent and the Business App Mapping AI Agent from the Service Mapping home page to start automated service map creation.
Business App Mapping AI Agent confidence thresholds -- Use this reference to understand how the Business App Mapping AI Agent handles matches based on their AI confidence score, and what action is taken for each score range.
Service Mapping MCP tools -- The Service Mapping tools, delivered as part of the CMDB MCP Server, expose live application service data and enable AI clients such as Claude to query service topology, identify mapping gaps, and create new application services in natural language.
Configure roles for the Service Mapping MCP tools -- Configure the role containment chain and assign the required roles to users so they can connect to the CMDB MCP Server and call the Service Mapping MCP tools.
Activate the CMDB MCP Server for Service Mapping tools -- Activate the CMDB MCP Server and configure the OAuth inbound integration so that external AI clients can connect to your ServiceNow instance and query application service data.
Connect Claude Desktop to the Service Mapping MCP Server -- Add the Service Mapping MCP Server as a custom connector in Claude Desktop so you can query application service data from your ServiceNow instance in natural language.
Service Mapping MCP tools reference -- Reference information for the six Service Mapping MCP tools provided by the CMDB MCP Server, including their inputs, outputs, and example natural-language queries for use with Claude, and service creation workflows.
Create an application service for unmapped servers -- Maximize the use of your organization's resources by mapping application service candidates that include unmapped servers. Use the Service Mapping workspace's unmapped servers widget to create an application service and ensure that your servers are used efficiently.
Use Automated Service Suggestions -- Map a new application service based on automatically generated suggestions. Use the Automated Service Suggestions or Service Fingerprints features to create a new application service or add to an existing service in a few clicks.
Map tag services in workspace -- Categorize and organize organization's configuration items and map them into application services using the Tag-based dashboard in the Service Mapping workspace.
Access the Unified Map from the Workspace -- View a hierarchical map of CIs and the relationships between them by adding access to the Unified Map feature to the Service Mapping Workspace.
Map multiple application services suggested by classic Service Mapping -- You can map multiple application services identified and suggested by Service Mapping in a single operation. This method suits your organization if you do not have much information about application services.
Manage CI connections for multiple services using suggestions -- If the discovery based on Predictive Intelligence is enabled, the newly mapped application services include only CIs and CI connections added by discovery patterns. Use connection suggestions to decide which configuration items (CIs) to include or exclude globally. Service Mapping then updates all relevant discovered application services to reflect your decisions.
Add CIs to application services using connection rules -- Create rules for automatically adding traffic-based connections and the CIs they lead to in discovered service instances. Create rules that add CIs to multiple application services.
Map application services using tags with classic Service Mapping -- Use tags that help categorize and organize configuration items (CIs) in your organization to map application services. Tag-based mapping doesn't require configuring credentials or providing users with elevated rights.
Map multiple application services from a CSV file using classic Service Mapping -- This method suits you if your organization has performed cross-organization mapping and analysis and collected some information about planned service instances. If so, you can organize the collected information in a specific order and save it as a CSV file. Service Mapping extracts information from this file and creates potential service instances referred to as service candidates.
Map a single application service using classic Service Mapping -- In addition to mapping application services in bulk, you can map individual, single application services by defining attributes for each application service. Use this mapping method if you already know or are planning to find out application service details. You must have Service Mapping enabled to map or review application services.
Request entry point information for service mapping -- The most important attribute you must know and configure to discover an service instance is an entry point. If you do not know the entry points for the service instance, request this information from the service instance owner.
Provide entry points for mapping an application service -- As an application service owner you may receive a request for information about entry points in an email notification. Provide information about entry points to enable administrators to start discovery of an application service.
Manage CI connections for a single service using suggestions -- If discovery based on Predictive Intelligence is enabled, newly mapped application services include only configuration items (CIs) and CI connections added using discovery patterns. Use the suggestions for CI connections, generated by Service Mapping, to complete the application service.
Tibco BusinessWorks and EMS discovery -- Discovery can find Tibco ActiveMatrix BusinessWorks and Enterprise Message Service (EMS). Service Mapping can discover application services containing Tibco BusinessWorks, Enterprise Message Service (EMS), and their components.
Map application services containing Tibco BusinessWorks and EMS -- Discovery can find Tibco ActiveMatrix BusinessWorks and Enterprise Message Service (EMS). Service Mapping can discover application services containing Tibco BusinessWorks, Enterprise Message Service (EMS), and their components.
Modify or update tag definitions for tag-based mapping -- You can change tag definitions that Service Mapping uses for tag-based mapping. Service Mapping uses updated tag definitions to create new tag-based services without applying tag-related changes to services you mapped earlier.
Fix application service errors in bulk -- Service Mapping classifies errors by their root cause, for example, missing credentials or task timeout. For a fast and efficient process, fix errors belonging to the same category in bulk.
Fix service mapping errors using discovery messages -- Service Mapping does not offer semi-automated resolution options for errors that require advanced resolution. Fix such errors using symptoms and discovery messages.
Skip errors to continue discovering an application service -- If you know what configuration items (CIs) and connections make up your service instance, you can enable Service Mapping to continue discovery of the service instance even if there are some errors. You can skip errors to troubleshoot later so you can complete mapping most of the service instance, even if some CIs are missing.
Review and approval of application service maps -- After the Service Mapping administrator maps IT services and fixes errors in them, the administrator and the owner collaborate to review and approve the service maps. The review and approval process is available only for discovered and manually created service instances.
Send application service maps for review -- After you map an application service, send it to the application service owner for review to make sure that the map is accurate.
Review application service maps -- As the application service owner for the application service map, you receive an email notification that the application service map is assigned to you for review. Review mapping results for correctness and either provide your feedback or approve the application service map. The review and approval process is available only for discovered and manually created service instances.
Manually add CIs -- Add configuration items to manually created application services or to services discovered by Service Mapping.
Remove CIs not belonging to application services -- Remove CIs erroneously mapped as part of an application service by Service Mapping. Unnecessary CIs included in the map can generate irrelevant alerts in Event Management. For example, when creating an application service for a web portal, Service Mapping might automatically discover a connection to unaffiliated external services, such as PayPal.
Transfer a map segment into another application service -- You can remove a branch of a service and place it into another application service, either new or existing. Transfer map segments to split large services or when you want to organize services differently from the initial mapping result.
Link application services -- You can manually link two application services by adding a reference to one application service into another application service. The service that contains the reference, becomes a dependent service. The service that you include as a reference is a contained service. You can link application services to create dependencies for impact monitoring in Event Management.
Discover CIs identified as generic applications -- Service Mapping identifies application configuration items (CIs) that it failed to properly discover as generic applications. Correctly identify generic applications by creating a simplified discovery pattern from an application service map, rather than creating a fully functional pattern from scratch using the Pattern Designer.
Application service completion -- After an application service is reviewed and approved, you can define attributes that enhance its discovery, reflect its importance, and control access to it.
Group application services -- Organize application services by groups to perform actions simultaneously on multiple services, and to control user access to services. You can use Event Management to track service health by service groups.
Control user access to application services -- Assign user roles to service groups to grant users access to application services in your organization. Your organization may restrict access to some services for security or secrecy reasons.
Schedule a top-down discovery by Service Mapping -- After Service Mapping discovers configuration items (CIs) belonging to your service instance for the first time, it then rediscovers CIs to find changes and updates. Create or modify discovery schedules to control how often Service Mapping rediscovers services or CIs. For example, you may create custom discovery schedules to avoid redundant stress on the infrastructure.
Service definition transfer from one instance to another -- Save time and effort by exporting definitions of service instances from the source instance and importing these definitions into the target instance. You can use this method to copy definitions of service instances only of the discovered type.
Export service definitions -- Save time and effort by exporting definitions of service instances from the source instance and importing these definitions into the target instance. You can use this method to copy definitions of service instances only of the discovered type.
Import service definitions from one instance to another -- Save time and effort by exporting definitions of service instances from the source instance and importing these definitions into the target instance. You can use this method to copy definitions of service instances only of the discovered type.
Application service analysis and maintenance using classic Service Mapping -- Service Mapping creates maps to help you see the architecture and organization of application services. These maps are useful for planning change or migration, as well as analyzing the continuity and availability of services.
Application service maps in classic Service Mapping -- Maps offer you a visualization of data on configuration items (CIs) comprising application services, and relations and connections between these CIs.
View the change history of application services in classic Service Mapping -- You can view the changes made to an application service as a whole and to the individual configuration items (CIs) comprising the service. Change history is useful for maintenance, planning, or troubleshooting procedures.
Compare two versions of an application service in classic Service Mapping -- You can see a summary of application service changes at a glance by comparing two versions of an application service. This feature is useful for checking the application service status before and after a certain change or problem.
View contained application services in classic Service Mapping -- A contained application service is a reference included into another, dependent application service. You can open the contained service map directly from within the dependent service map.
Check CI dependencies -- You can see if a particular configuration item (CI) is part of other application services and check if it depends on other CIs.
View the network or storage path in classic Service Mapping -- You can drill down to see objects behind a connection on a map for troubleshooting service performance or maintaining your network. This feature is not available for manually created services or for services on instances using Edge Encryption.
View the list of CIs belonging to an application service -- View a complete list of CIs that make up an application service, including CIs not shown on the application service map: tracked configuration files, endpoints, processes, and network devices.
Convert application service maps into PDFs -- You may want to create a PDF for a map to share information about the service content with other people. PDFs are especially useful during the review and approve process for application services discovered by Service Mapping.
Application service analysis and maintenance using legacy Agent Workspace -- Service Mapping creates maps to help you see the architecture and organization of application services. These maps are useful for planning change or migration, as well as analyzing the continuity and availability of services.
Application service maps in legacy Agent Workspace -- Maps offer you a visualization of data on configuration items (CIs) comprising application services, and relations and connections between these CIs.
View maps for application services in legacy Agent Workspace -- Use maps to see the details of application services. Maps show configuration items (CIs) making up application services, connections between these CIs and other service-related details.
View the change history of application services in legacy Agent Workspace -- View changes made to a service instance and to the individual configuration items (CIs) comprising the service in Agent Workspace. You can also compare the service status before and after a certain change or problem. The change history is useful for maintenance, planning, or troubleshooting procedures.
Service Mapping reference -- Reference topics provide additional information about mapping and fine-tuning application services using Service Mapping lists and forms.
Service Mapping Workspace -- The Service Mapping workspace provides a central location to streamline the process of mapping your application services. Use the visualizations and reports to analyze, monitor, and update your resources, create application services, and manage your service mapping tasks efficiently.
Predefined traversal rules -- Service Mapping uses traversal rules to bring in related configuration items and expand the application service map. Several predefined rules are provided by default to help find and correctly map these relationships.
Traversal rules form completion -- To edit an existing CI relationship or add a new CI relationship during the tag-based discovery process, complete the Traversal Rules for Application Services form.
Name suggestions for application service candidates -- Automated Service Suggestions provides meaningful name suggestions for service identification, which you can access on the Application Service Suggestions tab in the Service Mapping workspace.
Application service readiness dashboard in configurable workspace -- Review the information on the dashboard to confirm that you’re ready to discover and map application services based on machine learning (ML). Service Mapping uses data processed by Predictive Intelligence to generate suggestions for traffic-based connections.
Components installed with Service Mapping -- Several types of components are installed with activation of the Service Mapping plugin, including tables, user roles, properties, and scheduled jobs.
Domain separation and Service Mapping -- Domain separation is supported in Service Mapping. Domain separation enables you to separate data, processes, and administrative tasks into logical groupings called domains. You can control several aspects of this separation, including which users can see and access data.
Service Mapping Recomputation -- Keep application services up to date and track changes to services through the recomputation capability of the Application Service feature of Service Mapping. Recomputation jobs recalculate mapped application services when changes occur to an associated configuration item (CI) within the Configuration Management Database (CMDB).
Connection Suggestions list -- Review details of connection suggestions to decide which connections are relevant for application services.
Entry point attributes -- Service Mapping comes with a wide range of preconfigured entry point types that cover many commonly used applications. Check attribute definitions to correctly add entry points to your application services.
MID Server properties used by Service Mapping -- Service Mapping uses the MID Server parameters during discovery and mapping. Do not change default values for these parameters unless you are troubleshooting the discovery process.
Preconfigured CI relationships in tag-based discovery -- Several preconfigured CI relationships participate in tag-based discovery, by default. The Traversal Rules for Application Services [svc_traversal_rules] table stores these relationships.
Tag-based mapping criteria examples for service families -- When preparing to map application services based on tags, create tag categories that contain tags with similar use. Define a tag-based service family and the tags you want to use for mapping. In addition to tag categories, you can also define tag values to narrow the criteria for the service candidates created by Service Mapping. Use these examples for guidance.
Traffic-based connections list -- Refer to this chart for information about traffic-based connections when you remove CIs from an application service.
Discovery patterns used by ITOM Visibility -- Service Mapping and Discovery use patterns in their discovery process that cover most industry standard network devices and applications. You can customize these patterns and create new ones.
Apache Cassandra database -- ServiceNow Discovery finds the Apache and the DataStax Cassandra database on UNIX using the Cassandra Distributed DB pattern. Discovering some of these resources requires installing the Discovery and Service Mapping Patterns from the ServiceNow Store.
Apache Kafka and Apache Zookeeper -- ServiceNow Discovery uses the Kafka and Zookeeper discovery pattern to find Kafka data built on the Zookeeper synchronization service.
Apigee Edge Enterprise edition -- The ServiceNow Discovery application uses the APIGee pattern to find Apigee Edge Enterprise edition versions 4.x.x. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Avi Vantage load balancer -- The ServiceNow Discovery and Service Mapping applications use the Avi load balancer discovery patterns to find Avi Vantage load balancer components. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Cisco Firewall -- The ServiceNow Discovery application uses the Next Generation Cisco Firewall pattern to find Cisco firewalls. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Cisco Switch WAP -- The ServiceNow Discovery application uses the Cisco WAPs extension to find Wireless Access Points (WAPs) that are controlled by a Cisco network switch. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Citrix NetScaler SDX -- The ServiceNow Discovery application can discover Citrix NetScaler SDX devices using the Citrix NetScaler SDX pattern. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Citrix Xen Hyper-V -- ServiceNow Discovery uses the Citrix Xen Hyper-V pattern to find and map instances. Discover these resources by installing the pattern applications from the ServiceNow Store and add Citrix Xen Hyper-V to the Linux Server Pattern’s Extension Section.
Cloudian Storage -- ServiceNow Discovery uses the Cloudian Storage discovery pattern to find Cloudian servers and related disks. Discovering these resources requires installing the Patterns application from the ServiceNow Store.
Cohesity storage system -- The Discovery and Service Mapping Patterns application uses the Cohesity Storage System pattern to find clusters, nodes, and chassis for the Cohesity DataPlatform. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
ColdFusion -- The ServiceNow Discovery application finds Adobe ColdFusion servers and the instances of ColdFusion applications running on them. Only the 2016 version of ColdFusion is supported. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Couchbase Database -- The ServiceNow Discovery application uses the Couchbase Instance discovery pattern to find and map Couchbase Database instances and their clusters. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Dell EMC XtremIO storage array -- ServiceNow Discovery uses the Dell EMC XtremIO storage array pattern to find Dell EMC XtremIO storage array components. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Dell EMC Isilon -- The ServiceNow Discovery application uses the Dell EMC Isilon pattern to find components of Dell EMC Isilon. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Dell PowerMax storage -- ServiceNow Discovery uses the EMC PMAX phase1 and EMC PMAX phase2 patterns to find Dell PowerMax storage components. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Dell Data Domain storage -- Discovery and Service Mapping use the Dell EMC Data Domain serverless pattern to find the Data Domain storage systems registered in the Data Domain Management Center (DDMC). Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
F5 certificate -- The ServiceNow Discovery application uses The F5-SSH-SSL Certification pattern extension to find all associated certificates on F5 load balancers that use IPv4 addresses, IPv6 addresses, or both.
Fortinet firewall and FortiGate VDOM REST-based -- The Discovery and Service Mapping Patterns application uses the Next Generation Fortinet Network Firewall - REST pattern to find Fortinet firewalls through REST API calls. Additionally, the pattern extension VDOM Discovery finds FortiGate Virtual Domains (VDOMs). Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Disable SNMP-based discovery -- Disable the default SNMP-based Fortinet firewall discovery and use REST-based discovery instead to discover FortiGate Virtual Domains (VDOMs).
Create an alias for the API key credential -- Create an alias and add it to an API key credential to discover Fortinet firewalls and FortiGate Virtual Domains (VDOMs) through REST-based discovery.
Create a serverless discovery schedule -- Create a serverless discovery schedule to discover Fortinet firewalls and FortiGate Virtual Domains (VDOMs) through REST-based discovery.
Fortinet Firewall SNMP-based -- The Discovery and Service Mapping Patterns application uses the Next Generation Fortinet Network Firewall pattern to find Fortinet firewalls through a series of SNMP calls. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Gunicorn -- Discovery and Service Mapping Patterns finds Gunicorn WSGI HTTP server instances running on Linux servers. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
HAProxy load balancer -- The Discovery and Service Mapping Patterns application uses the HA Proxy pattern to find HAProxy Community load balancers running on a Linux server. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
HPE BladeSystem Enclosure -- ServiceNow Discovery uses the HPE BladeSystem Enclosure discovery pattern to discover BladeSystem, which is a line of Hewlett Packard Enterprise blade server machines. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
IBM Db2 on Linux database -- ServiceNow Discovery uses the Db2 on Linux discovery pattern to find IBM Db2 instances on Linux servers.
IBM Db2 on Windows database -- ServiceNow Discovery uses the Db2 on Windows discovery pattern to find IBM Db2 instances on Windows servers.
IBM Informix Dynamic Server -- The ServiceNow Discovery and Service Mapping applications can find and map the Informix Dynamic Server. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
IBM PowerHA SystemMirror for AIX -- The ServiceNow Discovery application uses the IBM PowerHA Cluster (HACMP) pattern to find IBM PowerHA SystemMirror for AIX (formerly HACMP) high-availability clusters on AIX UNIX and Linux systems running on IBM platforms. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
IBM Virtualization and HMC -- The Discovery and Service Mapping Patterns application uses the IBM HMC Server pattern to find information about Hardware Management Console (HMC), frame, and logical partition (LPAR) servers. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
IBM WebSEAL -- The Discovery application uses the IBM WebSEAL patterns to find WebSEAL applications, web application servers, and junctions on your infrastructure. Discovering some of these resources requires installing the Discovery and Service Mapping Patterns application from the Store.
IBM WebSphere Application Server -- The Discovery and Service Mapping Patterns application uses the Websphere On Windows and Websphere On Unix patterns to find IBM WebSphere Application Servers. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
InfiniBox -- ServiceNow Discovery uses the InfiniBox pattern to find and map instances. Discovering these resources requires installing the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Juniper Network Firewall -- The ServiceNow Discovery application uses the Next-Generation Juniper Network Firewall discovery pattern to find Juniper network firewalls. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Linux Pacemaker Cluster -- The ServiceNow Discovery application uses the Linux Pacemaker Cluster discovery pattern to find high-availability cluster data and populate the CMDB with the discovered information. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Microsoft CA certificates -- The ServiceNow Discovery application can discover Microsoft Certificate Authority (CA) certificates using the Microsoft CA - Certificate Management pattern. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
NetApp SolidFire storage system -- ServiceNow Discovery uses the NetApp SolidFire storage system discovery pattern to find clusters and nodes on the SolidFire storage system. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Network router -- The Discovery and Service Mapping Patterns application uses the Network Router pattern to find network routers in your environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Network switch -- The Discovery and Service Mapping Patterns application uses the Network Switch pattern to find network switches in your environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Nutanix Acropolis -- The ServiceNow Discovery application uses the Nutanix Components pattern to find components of the Nutanix Acropolis solution containing Nutanix Prism Central version 2024.3.1.8 or Nutanix Prism Element 7.0.1.6. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Enable event discovery -- Activate the Nutanix events scheduled job to trigger rediscovery of Nutanix components when a state change is detected.
NVIDIA GPU -- The Discovery and Service Mapping Patterns application uses the Linux Server pattern extension Discover Nvidia GPU to find NVIDIA graphics processing units (GPUs). Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Oracle Analytics Server -- Discovery and Service Mapping Patterns finds Oracle Analytics Server (formerly Oracle Business Intelligence Enterprise Edition) components on Windows and Linux servers in your environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Oracle Catalog -- The Discovery and Service Mapping Patterns application uses the Get Catalog info pattern extension of the Oracle DB on Unix and Oracle DB on Windows patterns to find Oracle Catalog objects. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Oracle PDBs and CDBs -- The ServiceNow Discovery application can discover Oracle pluggable databases (PDBs) and container databases (CDBs). Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Oracle GLAS data collection -- The ServiceNow Discovery application uses the Oracle GLAS Data Collection pattern extensions to discover Oracle GLAS data. This data includes discovered Oracle Database, Middleware, and Java configuration items.
Download Oracle GLAS data -- Download Oracle GLAS data in CSV format to get detailed information on patterns and configuration items. You can also download reports for Oracle Database, Middleware, Oracle Java, VM, and vCenter hardware information.
Enable Oracle GLAS V2 data collection -- Enable the Oracle GLAS V2 data collection method to improve data collection performance in large-scale or high volume Oracle database environments.
Oracle GoldenGate -- The ServiceNow Discovery and Service Mapping applications find Oracle GoldenGate version 12c components using the Oracle Golden Gate pattern. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
OLVM and RHV -- The ServiceNow Discovery application uses patterns to find Oracle Linux Virtualization Manager (OLVM) and Red Hat Virtualization (RHV) components. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Oracle Listener HD -- ServiceNow Discovery uses the Oracle Listener HD pattern to find and map Oracle real application cluster components. To discover these resources, install the CMDB CI Class Models and the Discovery and Service Mapping Patterns from the ServiceNow Store.
Oracle Solaris LDOM -- Discovery uses the Solaris Logical Domain (LDOM) infrastructure pattern and Solaris LDOM shared library pattern to find all LDOM data. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Palo Alto Networks firewall -- The ServiceNow Discovery application uses the Next-Generation Palo Alto Firewall pattern to find Palo Alto Networks firewalls. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Pivotal Cloud Foundry -- The ServiceNow Discovery application finds Pivotal Cloud Foundry (PCF) version 3 components using the Pivotal Cloud Foundry pattern. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Pure Storage FlashArray -- The Discovery and Service Mapping Patterns application uses the Pure Storage Flash Array pattern to find Pure Storage FlashArray on your infrastructure. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Pure Storage FlashBlade -- The ServiceNow Discovery application uses the FlashBlade Pure Storage pattern to find FlashBlade components. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Red Hat JBoss Fuse -- The ServiceNow Discovery and Service Mapping applications can find and map the Fuse application server using the JBoss Fuse pattern. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Rubrik Cluster -- Discovery uses multiple patterns to find all Rubrik cluster data. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Create a serverless discovery schedule -- Set up a dedicated discovery schedule for each Rubrik cluster (Brik) to identify cluster resources using a serverless pattern and credential alias.
Veritas Cluster Server -- The ServiceNow Discovery application uses the Unix Cluster – VERITAS Cluster pattern to find Veritas Cluster Server components. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
VMware NSX load balancer -- The ServiceNow Discovery application uses the VMware NSX Advanced load balancer discovery pattern to find VMware NSX load balancers. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
VMware NSX-T cluster -- Discovery and Service Mapping Patterns uses the NSX Cluster pattern to find VMware NSX-T infrastructure. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Create a serverless discovery schedule -- Create a serverless discovery schedule to run the NSX Cluster pattern against a VMware NSX-T management cluster.
Available cloud discovery patterns -- ITOM Visibility comes with an extensive library of patterns that can discover your cloud environment: AWS, Azure, GCP, IBM, and OCI.
Alibaba Cloud discovery -- Discovery and Service Mapping Patterns uses patterns to discover components of the Alibaba Cloud deployment during horizontal discovery. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Alibaba Cloud availability zones -- Discovery and Service Mapping Patterns uses the Alibaba - Availability Zone (LP) pattern to discover availability zones during horizontal discovery. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Alibaba Cloud cloud hardware type -- Discovery and Service Mapping Patterns uses the Alibaba - Cloud Hardware Type (LP) pattern to discover cloud hardware types during horizontal discovery. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Alibaba Cloud cloud OS images -- Discovery and Service Mapping Patterns uses the Alibaba - Cloud OS Image (LP) pattern to discover cloud OS images during horizontal discovery. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Alibaba Cloud datacenters -- Discovery and Service Mapping Patterns uses the Alibaba - Datacenter (LP) pattern to discover datacenters during horizontal discovery. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Alibaba Cloud service accounts -- Discovery and Service Mapping Patterns uses the Alibaba - Service Account Validation pattern to discover service accounts during horizontal discovery. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Alibaba Cloud storage volume -- Discovery and Service Mapping Patterns uses the Alibaba - Storage Volume (LP) pattern to discover storage volumes during horizontal discovery. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Alibaba Cloud virtual machines -- Discovery and Service Mapping Patterns uses the Alibaba - Virtual Machine (LP) pattern to discover VMs during horizontal discovery. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
AWS discovery -- Discovery and Service Mapping Patterns uses patterns to discover components of the Amazon AWS Cloud deployment during horizontal discovery. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Amazon API Gateways -- The ServiceNow Discovery and Service Mapping applications use the Amazon AWS API Gateway pattern to find Amazon API Gateways and connections to other entities. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Test AWS API Gateway and AWS Lambda patterns -- Run the horizontal and top-down discovery using Amazon AWS API Gateway [cmdb_ci_cloud_gateway] and Amazon AWS Lambda [cmdb_ci_cloud_function] patterns. Verify that the result is as expected.
Amazon API Gateway Domain Name -- Discovery and Service Mapping Patterns finds AWS services on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Amazon Athena Workgroup -- Discovery and Service Mapping Patterns finds Amazon Athena Workgroups on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Amazon CloudFront Distribution -- Discovery and Service Mapping Patterns finds Amazon CloudFront Distributions on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Amazon CloudWatch Log Group -- Discovery and Service Mapping Patterns finds Amazon CloudWatch Log Groups on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Amazon Cognito -- The ServiceNow Discovery and Service Mapping applications use the Amazon AWS Cognito pattern to provide authentication, authorization, and user management functions for AWS customers. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Amazon DB cluster -- ServiceNow Discovery uses the AWS DB cluster discovery pattern to find and map Aurora DB clusters, Aurora Serverless resources, Amazon Neptune DB instances, and Amazon DocumentDB instances. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Amazon DynamoDB -- The ServiceNow Discovery and Service Mapping applications use the Amazon AWS DynamoDB pattern to find components of DynamoDB. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Define a Cloud REST Query -- As part of creating or modifying a discovery pattern, you can use the Cloud REST Query operation to extract information from configuration items (CIs) of the PaaS (Platform as a Service) type, such as Microsoft Azure or Amazon Web Services.
Amazon DynamoDB Cluster -- Discovery and Service Mapping Patterns finds AWS services on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Amazon EC2 Amazon EBS Snapshot -- Discovery and Service Mapping Patterns finds AWS services on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Amazon EC2 Reserved Instance -- Discovery and Service Mapping Patterns finds AWS services on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Amazon EC2 VPC Endpoint Service -- Discovery and Service Mapping Patterns finds AWS services on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Amazon EC2 VPC Peering Connection -- Discovery and Service Mapping Patterns finds AWS services on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Amazon ECS resource -- The ServiceNow Discovery application uses the Amazon AWS - ECS pattern to find resources managed by the Amazon Elastic Container Service (Amazon ECS). This includes resources that are run on the Fargate launch type. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Create a serverless discovery schedule -- Create a serverless schedule to discover Amazon Elastic Container Service (Amazon ECS) and Amazon Elastic Container Registry (ECR) resources in a standalone discovery.
Amazon EFS -- Discovery and Service Mapping Patterns finds AWS services on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Amazon ElastiCache -- The ServiceNow Discovery application uses the Amazon ElastiCache discovery pattern to find Redis clusters deployed as part of the ElastiCache service. ElastiCache is compatible with both Redis and Memcached, but the pattern collects information only for Redis.
Amazon ElastiCache Snapshot -- Discovery and Service Mapping Patterns finds AWS services on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Amazon EMR Cluster -- Discovery and Service Mapping Patterns finds Amazon EMR Clusters on your cloud environment running on EC2. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Amazon EventBridge Event Bus -- Discovery and Service Mapping Patterns finds Amazon EventBridge Event Buses on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Amazon FSx Backup -- Discovery and Service Mapping Patterns finds Amazon FSx Backups on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Amazon FSx File System -- Discovery and Service Mapping Patterns finds Amazon FSx File Systems on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Amazon MQ Broker -- Discovery and Service Mapping Patterns finds Amazon MQ Brokers on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Amazon MQ Configuration -- Discovery and Service Mapping Patterns finds Amazon MQ Configurations on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Amazon MWAA Environment -- Discovery and Service Mapping Patterns finds AWS services on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Amazon RDS -- Discovery and Service Mapping Patterns uses the Amazon AWS Relational Database Service pattern to find Amazon RDS components in your environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Amazon RDS DB Snapshot -- Discovery and Service Mapping Patterns finds AWS services on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Amazon Redshift -- The ServiceNow Discovery application uses the Amazon AWS Redshift pattern to find Redshift data warehouse services available on Amazon Web Services (AWS). Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Amazon Redshift Serverless Namespace -- Discovery and Service Mapping Patterns finds AWS services on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Amazon Redshift Serverless Snapshot -- Discovery and Service Mapping Patterns finds AWS services on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Amazon Redshift Serverless Workgroup -- Discovery and Service Mapping Patterns finds AWS services on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Amazon Route 53 -- Discovery and Service Mapping Patterns finds Amazon Route 53 domain name systems (DNS) and aliases on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Amazon S3 -- The ServiceNow Discovery application uses the Amazon AWS S3 pattern to find public and non-public storage buckets of Amazon Simple Storage Service. The pattern uses a set of REST API calls to find these resources. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Amazon S3 Glacier Vault -- Discovery and Service Mapping Patterns finds Amazon S3 Glacier Vaults on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Amazon SageMaker Notebook Instance -- Discovery and Service Mapping Patterns finds Amazon SageMaker Notebook Instances on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Amazon SageMaker Training Job -- Discovery and Service Mapping Patterns finds AWS services on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Amazon SES Identity -- Discovery and Service Mapping Patterns finds Amazon Simple Email Service (SES) Identities on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Amazon SQS Queue -- Discovery and Service Mapping Patterns finds Amazon SQS Queues on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Amazon Timestream for InfluxDB Database Instance -- Discovery and Service Mapping Patterns finds AWS services on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Amazon VPC Flow Log -- Discovery and Service Mapping Patterns finds Amazon Virtual Private Cloud (Amazon VPC) Flow Logs on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Amazon VPC Managed Prefix List -- Discovery and Service Mapping Patterns finds Amazon Virtual Private Cloud (Amazon VPC) Managed Prefix Lists on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
AWS application ELB Service -- Discovery uses the Amazon AWS application ELB Service discovery pattern to show all load balancers in your environment in a map.
AWS AppSync API -- Discovery and Service Mapping Patterns finds AWS AppSync APIs on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
AWS Auto Scaling groups -- The Discovery application uses the Amazon AWS - AutoScaling Groups (LP) pattern and Auto Scaling extensions to find AWS Auto Scaling groups. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
AWS Backup Plan -- Discovery and Service Mapping Patterns finds AWS Backup Plans on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
AWS Backup Vault -- Discovery and Service Mapping Patterns finds AWS Backup Vaults on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
AWS Batch Compute Environment -- Discovery and Service Mapping Patterns finds AWS services on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
AWS classic ELB Service -- Discovery uses the Amazon AWS classic ELB Service discovery pattern to find all load balancers that use HTTP and HTTPS traffic.
AWS CloudHSM HSM -- Discovery and Service Mapping Patterns finds AWS services on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
AWS CloudTrail Trail -- Discovery and Service Mapping Patterns finds AWS services on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
AWS CodeDeploy Deployment -- Discovery and Service Mapping Patterns finds AWS CodeDeploy Deployments on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
AWS CodePipeline Pipeline -- Discovery and Service Mapping Patterns finds AWS CodePipeline Pipelines on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
AWS datacenters -- Discovery and Service Mapping Patterns finds AWS Regions for your AWS account on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
AWS DataSync Task -- Discovery and Service Mapping Patterns finds AWS services on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
AWS DMS Endpoints -- Discovery and Service Mapping Patterns finds AWS DMS endpoints on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
AWS Elastic Beanstalk Application -- Discovery and Service Mapping Patterns finds AWS Elastic Beanstalk Applications on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
AWS Global Accelerator -- Discovery and Service Mapping Patterns finds AWS services on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
AWS Glue Database -- Discovery and Service Mapping Patterns finds AWS Glue Databases on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
AWS hardware type -- Discovery and Service Mapping Patterns finds Amazon EC2 instance types on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
AWS IAM Policy -- Discovery and Service Mapping Patterns finds AWS IAM Policies on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
AWS IAM Role -- Discovery and Service Mapping Patterns finds AWS IAM Roles on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
AWS IAM User -- Discovery and Service Mapping Patterns finds AWS IAM Users on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
AWS Keyspaces -- The ServiceNow Discovery application uses the Amazon Keyspaces discovery pattern to find Amazon Keyspaces managed Apache Cassandra–compatible database service.
AWS Kinesis -- The ServiceNow Discovery application uses the Amazon Kinesis discovery pattern to find Kinesis services available on Amazon Web Services (AWS).
AWS KMS Key -- Discovery and Service Mapping Patterns finds AWS KMS Keys on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
AWS Lambada -- The ServiceNow Discovery and Service Mapping applications can find and map Lambda functions that run in your AWS cloud. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
AWS MemoryDB for Redis -- The Discovery application uses the Amazon AWS MemoryDB pattern and extensions to find AWS MemoryDB for Redis. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
AWS Network Firewall -- Discovery and Service Mapping Patterns finds AWS services on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
AWS OpenSearch -- The ServiceNow Discovery application uses the Amazon OpenSearch discovery pattern to find Amazon OpenSearch service domains.
AWS Organizations -- Discovery and Service Mapping Patterns finds AWS Organizations accounts on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
AWS OS image -- Discovery and Service Mapping Patterns finds AWS OS images (both owned and executable) on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
AWS Resource Inventory -- The ServiceNow Discovery and Service Mapping applications can find and map the AWS resources available by AWS Config Service. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
AWS Secrets Manager Secret -- Discovery and Service Mapping Patterns finds AWS Secrets Manager Secrets on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
AWS Serverless Database -- Discovery and Service Mapping Patterns finds Amazon Aurora Serverless databases on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
AWS Step Functions State Machine -- Discovery and Service Mapping Patterns finds AWS Step Functions State Machines on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
AWS Storage Gateway File Share -- Discovery and Service Mapping Patterns finds AWS services on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
AWS Storage Gateway Gateway -- Discovery and Service Mapping Patterns finds AWS Storage Gateway Gateways on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
AWS sub account -- Discovery and Service Mapping Patterns finds member accounts and the primary account within an AWS Organization. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
AWS Systems Manager Document -- Discovery and Service Mapping Patterns finds AWS Systems Manager Documents on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
AWS Systems Manager Parameter Store -- Discovery and Service Mapping Patterns finds AWS Systems Manager Parameter Store parameters on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
AWS tags -- The ServiceNow Discovery and Service Mapping applications can use patterns to discover the tags for AWS resources and configuration item (CI) types, and then populate the CMDB with these discoveries. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
AWS Transfer Family Server -- Discovery and Service Mapping Patterns finds AWS Transfer Family Servers on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
AWS virtual server -- Discovery and Service Mapping Patterns finds AWS EC2 virtual machine instances on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
AWS X-Ray Sampling Rule -- Discovery and Service Mapping Patterns finds AWS X-Ray Sampling Rules on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Enable AWS ALB target discovery -- Enable the sn_itom_pattern.discover_aws_app_pool_members MID Server property to discover AWS Application Load Balancer targets.
GCP discovery -- Discovery and Service Mapping Patterns uses patterns to discover components of the Google Cloud Platform (GCP) deployment during horizontal discovery. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
GCP AlloyDB for PostgreSQL -- Discovery and Service Mapping Patterns uses the Google Cloud Platform (GCP) - AlloyDB for PostgreSQL pattern to discover AlloyDB for PostgreSQL during horizontal discovery. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
GCP BigQuery -- Discovery and Service Mapping Patterns finds GCP BigQuery datasets and tables on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
GCP Bigtable -- Discovery and Service Mapping Patterns finds GCP Bigtable instances on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
GCP Cloud Firestore -- Discovery and Service Mapping Patterns finds GCP Cloud Firestore database instances on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
GCP Cloud Functions -- Discovery and Service Mapping Patterns uses the Google Cloud Platform (GCP) - Cloud Functions pattern to discover Cloud Functions in a Google Cloud Platform (GCP) deployment during horizontal discovery. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
GCP Cloud SQL -- Discovery and Service Mapping Patterns finds GCP Cloud SQL instances and their databases on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
GCP Disk Types -- Discovery and Service Mapping Patterns finds GCP Disk Types on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
GCP Events -- Discovery uses event patterns to update GCP component data in near real-time. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
GCP External IP Addresses -- Discovery and Service Mapping Patterns finds GCP external IP addresses on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
GCP Firebase Realtime DB -- Discovery and Service Mapping Patterns finds GCP Firebase Realtime Database instances on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
GCP Load Balancer -- Discovery and Service Mapping Patterns finds GCP Load Balancers on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
GCP Memorystore -- Discovery and Service Mapping Patterns uses the Google Cloud Platform (GCP) - Memorystore DB pattern to discover Memorystore for Memcached and Memorystore for Redis during horizontal discovery. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
GCP Networking -- Discovery and Service Mapping Patterns finds GCP networking resources on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
GCP Organization -- The ServiceNow Discovery application uses the Discover Google Organization discovery pattern to find GCP Organization projects and resources. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
GCP resource inventory -- The ServiceNow Discovery application uses the Google Cloud Platform (GCP) Resource Inventory pattern to find GCP resources and policies. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
GCP Spanner -- Discovery and Service Mapping Patterns finds GCP Spanner instances and databases on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
GCP SSH Keys -- Discovery and Service Mapping Patterns finds GCP SSH keys stored in project metadata on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
GCP Storage -- Discovery and Service Mapping Patterns finds GCP persistent disks and snapshots on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
GCP virtual server -- Discovery and Service Mapping Patterns finds GCP Virtual Machine (VM) instances and related resources on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
IBM Cloud Platform discovery -- The ServiceNow Discovery application finds IBM Cloud Platform components (Softlayer API v3 and v3.1 and Bluemix API v2) using the IBM Cloud Platform patterns. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Microsoft Azure discovery -- Discovery uses multiple patterns to discover components of the Microsoft Azure Cloud deployment during horizontal discovery. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Azure App Configuration Store -- Discovery and Service Mapping Patterns finds Azure services on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Azure App Service App Service Plan -- Discovery and Service Mapping Patterns finds Azure services on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Azure Application Gateway -- The ServiceNow Discovery application uses the Azure Application Gateway (LP) pattern for discovering this product, while the Service Mapping application discovers Application Gateway using the Azure Application Gateway TD (LBS) pattern. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Azure Application Insight Component -- Discovery and Service Mapping Patterns finds Azure services on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Azure Application Insight Data Collection Rule -- Discovery and Service Mapping Patterns finds Azure services on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Azure Application Security Group -- Discovery and Service Mapping Patterns finds Azure services on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Azure Automation Account -- Discovery and Service Mapping Patterns finds Azure services on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Azure availability sets -- Discovery and Service Mapping Patterns uses the Azure - Availability Set (LP) pattern to discover Azure availability sets during horizontal discovery. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Azure availability zones -- Discovery and Service Mapping Patterns uses the Azure - Availability Zones (LP) pattern to discover Azure availability zones during horizontal discovery. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Azure Blob Storage -- Discovery and Service Mapping Patterns finds blob resources within Azure Blob Storage on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Azure Classic Load Balancer -- Discovery and Service Mapping Patterns finds Azure Classic Load Balancers on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Azure Compute Gallery Image Definition -- Discovery and Service Mapping Patterns finds Azure services on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Azure Compute Snapshot -- Discovery and Service Mapping Patterns finds Azure services on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Azure Container Registry -- Discovery and Service Mapping Patterns finds Azure services on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Azure Cosmos DB for PostgreSQL Cluster -- Discovery and Service Mapping Patterns finds Azure services on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Azure Data Explorer Cluster -- Discovery and Service Mapping Patterns finds Azure services on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Azure Data Factory -- Discovery and Service Mapping Patterns finds Azure services on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Azure Data Protection Backup Vault -- Discovery and Service Mapping Patterns finds Azure services on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Azure Databricks Workspace -- Discovery and Service Mapping Patterns finds Azure services on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Azure Datacenter discovery -- Discovery and Service Mapping Patterns finds Azure Datacenter resources on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Azure Dev Center -- Discovery and Service Mapping Patterns finds Azure services on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Azure Disk Encryption Set -- Discovery and Service Mapping Patterns finds Azure services on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Azure DNS zones and record sets -- The Discovery and Service Mapping Patterns application uses the Azure - DNS Zones (LP) and Azure - DNS Zone Recordsets (LP) Patterns to discover Azure Domain Name System (DNS) definitions (zones and their respective record sets). Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Azure Event Grid -- Discovery and Service Mapping Patterns finds Azure services on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Azure Event Hub Namespace -- Discovery and Service Mapping Patterns finds Azure services on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Azure Express Route Circuit -- Discovery and Service Mapping Patterns finds Azure Express Route Circuit resources on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Azure File Share -- Discovery and Service Mapping Patterns finds Azure File Share resources within Storage Accounts on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Azure Firewall Network Security -- Discovery and Service Mapping Patterns finds Azure services on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Azure Functions -- The Discovery and Service Mapping Patterns application uses the Azure - Functions (LP) and Azure - Functions TD Patterns to discover Azure Functions apps and map them in the context of application services. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Azure hardware type -- Discovery and Service Mapping Patterns finds Azure hardware type configurations on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Azure Host -- Discovery and Service Mapping Patterns finds Azure Hosts on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Azure Key Vault -- Discovery and Service Mapping Patterns finds Azure services on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Azure Key Vault Key -- Discovery and Service Mapping Patterns finds Azure Key Vault Keys on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Azure Local Network Gateway -- Discovery and Service Mapping Patterns finds Azure Local Network Gateway resources on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Azure Log Analytics Workspace -- Discovery and Service Mapping Patterns finds Azure services on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Azure Logic App -- Discovery and Service Mapping Patterns finds Azure services on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Azure Managed Identity User Assigned Identity -- Discovery and Service Mapping Patterns finds Azure services on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Azure NAT Gateway -- Discovery and Service Mapping Patterns finds Azure NAT Gateway resources on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Azure Networks IP Group -- Discovery and Service Mapping Patterns finds Azure services on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Azure OS image -- Discovery and Service Mapping Patterns finds Azure OS images on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Azure Private DNS Zone -- Discovery and Service Mapping Patterns finds Azure Private DNS Zone resources on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Azure Private Link Private Endpoint -- Discovery and Service Mapping Patterns finds Azure services on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Azure Recovery Services Vault -- Discovery and Service Mapping Patterns finds Azure services on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Azure Recovery Services Vault Backup Item -- Discovery and Service Mapping Patterns finds Azure services on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Azure resource inventory -- The ServiceNow Discovery application uses the Azure Resource Inventory (LP) pattern to find resources available through Azure that don’t have a dedicated pattern. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Azure Service Bus Namespace -- Discovery and Service Mapping Patterns finds Azure services on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Azure Service Bus Queue -- Discovery and Service Mapping Patterns finds Azure services on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Azure Service Bus Topic -- Discovery and Service Mapping Patterns finds Azure services on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Azure Service Endpoint Policy -- Discovery and Service Mapping Patterns finds Azure services on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Azure Subscriptions Discovery For Management Group -- Discovery and Service Mapping Patterns finds Azure Subscription entities under Management Groups on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Azure virtual machine -- Discovery and Service Mapping Patterns finds Azure virtual machines (VMs) on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Azure Virtual Machine Scale Sets (VMSS) Instance -- The Discovery and Service Mapping Patterns application uses the Azure - VM Scale Set (LP) and the Azure VM Instance - Uniform Scale Set patterns to find Azure Virtual Machine Scale Sets (VMSS). Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Azure Virtual Network Gateway Connection -- Discovery and Service Mapping Patterns finds Azure Virtual Network Gateway Connection resources on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Azure Web Application Firewall Policy -- Discovery and Service Mapping Patterns finds Azure services on your cloud environment. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
OCI discovery -- ServiceNow Discovery uses the Oracle Cloud Infrastructure (OCI) discovery patterns to provide real-time elasticity for enterprise applications by combining Oracle autonomous services, integrated security, and cloud compute. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
OpenStack resource discovery -- The ServiceNow Discovery application uses OpenStack resource discovery patterns to find OpenStack resources through REST API calls. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Install Visibility Content -- You can install the Visibility Content application (sn_pattern_design) if you have the admin role.
Password2 encryption for patterns -- The Password (two-way encrypted) field type is used to encrypt and decrypt data. The field type works in accordance with NIST 800-57 guidelines and provides FIPS 140-2-L3 protection.
Create entry point types for Service Mapping -- An entry point is a point where clients access a service instance. Service Mapping starts the mapping process for every application service from the entry point you define for it. Service Mapping includes a wide range of preconfigured entry point types that cover most commonly used applications. If your organization uses a less known or proprietary application that does not have a corresponding entry point type in Service Mapping, you must create it.
Discover related items together with the main CI -- Add related items to the patterns to perform horizontal discovery of configuration items with all their related items: CIs or non-CIs, like ports or serial numbers.
Enhance patterns without modifying identification sections -- Enable patterns to search for additional attributes and modify pattern discovery logic defined in identification sections by using extension sections. Each extension section contains a preconfigured set of discovery steps referred to as a shared library.
Fine-tune patterns using traffic-based discovery -- As an alternative to customizing the pattern from the Pattern Designer side, improve existing patterns so that Service Mapping can use them to find configuration item (CI) connections previously found using traffic-based discovery.
Finalize a pattern -- After you finish defining your pattern, make it ready for use by Service Mapping and Discovery.
Copy patterns from one instance to another -- To copy patterns from one instance to another, create an update set containing new or modified patterns with their related items in your development instance. Then, import the update set into your production instance.
Choose the pattern version -- Every time you modify and save a pattern, you create a version of this pattern. Choose which pattern version Service Mapping and Discovery use for discovery.
Compare pattern versions -- If you have multiple versions of the same pattern, you can compare them to decide which pattern version to use for discovery.
Activate a disabled pattern -- If you want to use a pattern for discovery that's disabled by default, activate it manually.
Enable Cloud Hardware table -- Enable the Cloud Hardware Type [cmdb_ci_cloud_hardware_type] table to store the predefined virtual machine (VM) hardware type records for Amazon AWS Cloud Microsoft Azure Cloud and Google Cloud Platform (GCP). This class extension helps prevent duplication of the VM hardware type records in the Hardware Type [cmdb_ci_compute_template] table, which improves performance for Discovery and related flows.
Enable Cloud OS Image table -- Enable the Cloud OS Image [cmdb_ci_cloud_os_image] table to store the cloud OS image records for Amazon AWS Cloud, Microsoft Azure Cloud, Google Cloud Platform (GCP), Oracle Cloud Infrastructure (OCI), and IBM Cloud.
Discover datacenters only for new cloud accounts -- If you have multiple cloud accounts and datacenters in AWS and Azure, you can discover datacenters for new cloud accounts only, instead of refreshing the entire list.
Improved query performance with direct field population in CI tables -- The Populate Service Account and LDC IN CMDB scheduled job populates the Service Account and Logical Datacenter fields in cloud configuration item (CI) tables, and the Virtual Machine Object field in the Hardware [cmdb_ci_hardware] table. This direct population reduces query complexity and improves query performance.
Configure Server CI creation -- Create Server CIs during cloud discovery without running IP-based discovery, reducing discovery time in large environments.
Enable Oracle Wallet authentication -- Enable Oracle Wallet authentication to use credentials stored on the target server during Oracle database discovery on UNIX systems.
AI Agent Topology Mapping -- With AI Agent Topology Mapping, you can use patterns to identify AI infrastructure components across cloud platforms in your organization. Discover your AI agents, models, and prompts, and get centralized CMDB visibility to track security compliance and vulnerabilities across your AI deployments.
Explore -- Learn how AI Agent Topology Mapping discovers AI infrastructure components across cloud platforms using patterns.
Configure -- Install AI Agent Topology Mapping from the ServiceNow Store and configure discovery schedules to identify AI infrastructure components.
Install AI Agent Topology Mapping -- You can install the AI Agent Topology Mapping application (sn_itom_agnt_ptrn) if you have the admin role.
Reference -- Reference topics provide pattern information for AI Agent Topology Mapping, including prerequisites, tables, fields, and relationships.
Amazon Bedrock -- AI Agent Topology Mapping discovers Amazon Bedrock AI services, agents, and models during horizontal discovery.
Microsoft Foundry (Classic) -- AI Agent Topology Mapping discovers Microsoft Foundry (Classic) services, agents, and models during horizontal discovery.
ITOM Content Service -- ServiceNow ITOM Content Service offers extensive visibility of products in your infrastructure. The classification of processes identified by Predictive Intelligence enables wider discovery and weekly updates of new configuration items in the CMDB. Use the Discovery Admin Workspace to review and manage ITOM Content Service suggestions.
ITOM Content Service use case -- This ITOM Content Service use case demonstrates how organizations can achieve enhanced visibility into their environment.
Install ITOM Content Service -- Install the ITOM Content Service application (sn_smart_content) to manage and monitor the creation of configuration items based on application fingerprints.
Share data on ITOM Content Service -- Control data sharing by opting in or out of ITOM Content Service sharing options using the Discovery Admin Workspace.
Enable discovery with ITOM Content Service -- Review the ITOM Content Service suggestions for application discovery and activate the discovery classifiers to enable the creation of configuration items.
Discover installed software data with ITOM Content Service -- Use ITOM Content Service and ITSM Software Asset Management to discover version-less installed software that isn't discovered automatically with Software Asset Management Core or Software Asset Management Professional or file-based Discovery.
ITOM Content Service reference -- Using ITOM Content Service enables you to have the CMDB populated with new data every week. Use the knowledge base articles to learn about the Configuration Item candidates that were released.
Tag Governance -- Effective tag management improves reporting and overall operations management efficiency. Use the ServiceNow Tag Governance app to identify and remediate on-premises or cloud resources that are inconsistent and don't comply with the tag policies of your organization.
Discovery's contribution to Tag Governance -- The Discovery and Cloud Discovery features discover all resources in the CMDB as well as cloud resources from cloud providers such as Amazon AWS Cloud, Microsoft Azure Cloud, and Google Cloud Platform (GCP).
View Tag Governance metrics -- View metrics like tag policy coverage, compliance status, and usage trends on the Tag Governance Insights dashboard.
Tag Categorization in Tag Governance -- By automatically grouping similar tag keys into predefined categories, Tag Categorization streamlines the management of configuration items (CIs) and cloud resources while promoting clear and consistent tagging practices.
Configuring Tag Governance -- Install the Tag Governance app to execute tag audits, view the Tag Data Governance dashboard, and perform tag remediation.
Install Tag Governance -- Install the Tag Governance app to execute tag audits, view the Tag Data Governance dashboard, and perform tag remediation.
Using Tag Governance -- Use the ServiceNow Tag Governance app to identify and remediate on-premises or cloud resources that are inconsistent and don't comply with the tag policies of your organization.
Establishing Tag Governance policies -- Configure tag policies that define the criteria for tag audits on discovered cloud resources or CIs. View audit results on tag quality and compliance on the Tag Health dashboard. You establish tag policies that support the scale and needs of the various groups in your organization so all users can benefit.
Configure a tag policy for Tag Governance -- Configure tag policies that define the criteria for tag audits on discovered cloud resources or CIs. View audit results on tag quality and compliance on the Tag Health dashboard.
Configure remediation policies on tag audit findings -- Configure and preview remediation options, generate keys, and perform actions to remediate non-compliance or failures that are based on tag audit reports.
Preview and remediate tag audit failures -- Preview audit reports for resources that tag policies identify as non-compliant. Remediate failures by adding or updating tags.
Modify tag category information -- Modify tag category definitions to support Tag Categorization and ensure that tag categories align with your requirements for data management and classification.
Add or delete tag categories -- Add or delete a tag category for improved tagging of your organization's configuration items (CIs) and cloud assets.
Add or delete tag keys -- Tag keys define the values available within a tag category. Add or delete tag keys to keep your tag categorization structure current as data management and classification requirements change.
Tag Governance reference -- Reference topics provide additional information on Tag Governance forms and other resources.
Domain separation and Tag Governance -- Domain separation is supported in Tag Governance. Domain separation enables you to separate data, processes, and administrative tasks into logical groupings called domains. You can control several aspects of this separation, including which users can see and access data.
Tag policies and remediation for AWS -- Tag audits apply policies to discovered CIs to determine tag compliance; existence of tags, appropriate count of tags, and the presence of specified key-value pairs.
Tag Policies form -- You use the Tag Policy form to configure tag compliance and health policies that are used in tag audits runs on discovered cloud resources or CIs.
Tag Remediation Key form -- You use the Tag Remediation Key form to create a tag remediation key.
Components in Tag Governance -- Several key components are installed with, or linked to, the Tag Governance plugin to help standardize and manage your organization's tags.
Cloud Discovery Workspace -- Cloud Discovery Workspace offers a comprehensive solution to manage the cloud operations of your organization.
Install Cloud Discovery Workspace -- You can install the Cloud Discovery Workspace application (com.cloud_operations_workspace) if you have the admin role.If the application does NOT include demo data or it does NOT install related applications and plugins, delete or revise the following sentence:
Cloud Discovery Workspace dashboard -- The ServiceNow Cloud Discovery Workspace dashboard provides a summary of the cloud operations of your organization and shows the ServiceNow applications that you can use to manage them.
Kubernetes Explorer -- Use the ServiceNow Kubernetes Explorer to drill-down and view the Kubernetes environments and resources of your organization.
Dependency Views map -- ServiceNow The Dependency Views map shows an overall top-down Kubernetes perspective, starting from a top-level cluster to the container and within the container.
Cloud License Estimator -- Cloud License Estimator enables you to get the estimated resource count for all the cloud resources that are eligible for licensing.
Configure Azure Credentials for Cloud License Estimator -- To use this tool, configure the Azure Service Principal Account credentials. If you already have credentials configured in the ServiceNow instance, those credentials can be used.
Create Azure Account Configuration and generate CLE reports -- To use this tool, configure the Azure Service Principal Account credentials. If you already have credentials configured in the ServiceNow instance, those credentials can be used.
ITOM Infra Services Workspace -- The dashboard integrates several tables so that issues can be monitored and resolved. The workspace provides real-time monitoring, proactive alerts, automation of common tasks, and centralized diagnostics to reduce downtime and support tickets.
Explore ITOM Infra Services Workspace -- The workspace provides real-time monitoring, proactive alerts, automation of common tasks, and centralized diagnostics to reduce downtime and support tickets.
Configure ITOM Infra Services Workspace -- The dashboard provides real-time monitoring, proactive alerts, automation of common tasks, and centralized diagnostics to reduce downtime and support tickets.
Use ITOM Infra Services Workspace -- The dashboard integrates different applications to provide real-time monitoring, proactive alerts, automation of common tasks, and centralized diagnostics to reduce downtime and support tickets.
MID Server Workspace -- See a concise overview of MID Server activity. The workspace provides real-time monitoring and enables corrective actions across multiple MID Servers.
Generate an ACC installation plan -- Configure and deploy new agents in your environment, using the Agent Onboarding guide. The Agent Onboarding guide generates a customized installation plan for deploying the Agent Client Collector on your endpoints or servers.
Run agent diagnostics -- Run automated self-tests on an Agent Client Collector (ACC) agent from the ITOM Infra Services Workspace to identify and address agent issues. View agent errors and invoke the relevant remediation steps.
ITOM Visibility reference -- Reference topics provide additional information about mapping and fine-tuning application services using ITOM Visibility lists and forms.
Data collected by ITOM Visibility -- ITOM Visibility collects unique data for each type of device and stores it in dedicated tables, fields, and relationships.
Data collected for AWS -- Discovery collects information about cloud resources in AWS datacenters. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Data collected for Azure -- Discovery collects information about cloud resources in Microsoft Azure datacenters. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Data collected for GCP -- Discovery collects information about cloud resources in Google Cloud Platform (GCP). Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Data collected for IBM -- Discovery collects information about cloud resources in the IBM Cloud Platform and creates relationships between the CIs it finds. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Data collected for VMware -- Discovery collects information about VMware resources in your cloud service accounts.
Operating systems discovery -- Discovery identifies the following computers, clusters, and virtual machines.
AIX server -- Discovery identifies and classifies information about AIX servers.
Apache HBase instance -- Discovery creates or updates a CMDB record when it detects a running instance of HBase on a UNIX server.
HP-UX -- Discovery identifies and classifies information about HP-UX computers.
Hyper-V -- The ServiceNow Discovery application finds Microsoft Hyper-V hypervisors in your environment.
Clone Hyper-V virtual machines -- The ServiceNow Discovery application finds Microsoft Hyper-V hypervisors in your environment.
Red Hat JBoss server -- Discovery can detect JBoss application servers running on Linux and Windows systems.
Linux -- Discovery and Service Mapping applications use probes and patterns to discover and map information about Linux computers and servers. The information is populated in the CMDB. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Linux Red Hat cluster -- Discovery can find Linux Red Hat clusters that offer high availability and load balancing.
Omit network adapter secondary IP addresses -- Limit Linux discovery to specific network adapters and their primary IP addresses to improve performance by ignoring secondary IP addresses.
Netware -- Discovery identifies and classifies information about Netware.
Mac (OS/X) -- Discovery identifies and classifies information about Mac (OS/X) computers.
Solaris -- Discovery identifies and classifies information about Solaris computers.
Discovery for VMware vCenter -- Discovery can explore the VMware vCenter process running on a Windows or Linux host. IPv6 is supported for discovery in VMware vCenter.
Windows -- Discovery identifies and classifies information about Windows computers that use IPv4 addresses, IPv6 addresses, or both.
Windows server cluster -- Discovery establishes the relationships between a Windows server cluster and its nodes.
z/OS -- Discovery and Service Mapping Patterns finds computers running the z/OS operating system using the IBM zOS Server pattern. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
OS-level virtualization discovery -- Discovery can collect image and container information from Operating system-level virtualization (OS-level virtualization) engines.
Docker virtualization -- Discovery uses the Docker Pattern to collect data about specific objects in a Docker engine, running on a Linux host.
Active Directory Domain Controller -- The Discovery and Service Mapping Patterns application uses the Active Directory Domain Controller On Windows pattern to find Active Directory domain controllers running on a Windows server. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Adobe JRun -- Discovery creates or updates a CMDB record when it detects a running instance of Adobe JRun.
Apache web server -- Discovery identifies and classifies information about Apache web servers on both Windows and Linux computers.
Apache mod_jk and mod_proxy -- Discovery identifies and classifies information about Apache web servers on both Windows and Linux computers.
Clustered applications on Windows -- A process and its corresponding resource information can be used to determine whether the process is a clustered process.
Discovery with Software Asset Management -- The table structure for managing software installations behaves differently when the Software Asset Management (SAM) application is activated.
Microsoft Exchange CAS -- Discovery creates or updates a CMDB record when it detects a running instance of Microsoft Exchange Client Access Server (Microsoft Exchange CAS).
Exchange Hub Transport Servers -- Discovery creates or updates a CMDB record when it detects a running instance of Exchange Hub.
Exchange MailBox -- Discovery creates or updates a CMDB record when it detects a running instance of Exchange Mailbox.
General software package -- General software packages are collections of programs that work together, often with similar user interfaces. Examples include Microsoft Office 365 (Word, Excel, PowerPoint), and Apple's iWork (Pages, Numbers, Keynote). Discovery identifies and classifies information about general software packages. Data it collects include, Name, Version, Install Count, License Count, Installation Date, Software, and more.
GlassFish Server -- Discovery creates or updates a CMDB record when it detects a running instance of GlassFish Server.
HP Operations Manager -- Discovery creates or updates a CMDB record when it detects a running instance of HP Operations Manager.
HP Service Manager -- Discovery creates or updates a CMDB record when it detects a running instance of HP Service Manager.
IBM App Connect Enterprise and HTTP listener -- Discovery and Service Mapping Patterns application uses the WMB patterns to discover Integration Bus (formerly WebSphere Message Broker and IBM Integration Bus) and HTTP listeners running on both Linux and Windows. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
IBM MQ -- The ServiceNow Discovery application uses the WMQ On Unix and WMQ On Windows patterns to find IBM MQ (formerly IBM WebSphere MQ) resources. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Microsoft IIS server -- Discovery identifies and classifies information about Microsoft IIS servers.
Microsoft SharePoint -- Discovery creates or updates a CMDB record when it detects a running instance of Microsoft SharePoint.
NGINX web server -- NGINX is an open source web server with a load balancer. Discovery identifies the web server and information related to the load balancer.
Oracle Tuxedo -- The ServiceNow Discovery application uses the Tuxedo pattern to find Oracle Tuxedo resources. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
SAP products -- ITOM Visibility can discover SAP applications, SAP HANA Database, and SAP HANA DB Catalog. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Map application services containing SAP applications -- ITOM Visibility can discover SAP applications, SAP HANA Database, and SAP HANA DB Catalog. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Troubleshoot application services containing SAP applications -- ITOM Visibility can discover SAP applications, SAP HANA Database, and SAP HANA DB Catalog. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
SQL Server Analysis Services -- The Discovery and Service Mapping application uses the SSAS pattern to find SQL Server Analysis Services (SSAS) on your infrastructure. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store..
Microsoft SQL Server Integration Services -- The Discovery and Service Mapping application uses the SSIS pattern to find SQL Server Integration Services (SSIS) on your infrastructure. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Sun Java Enterprise System -- Discovery creates or updates a CMDB record when it detects a running instance of Sun Java Enterprise System (JES).
Tomcat server -- Discovery identifies and classifies information about Tomcat server Web applications running on UNIX machines.
WebLogic application server -- Discovery creates or updates a CMDB record when it detects an instance of an Oracle or BEA Weblogic application server running on a Windows or Linux system.
Identifying Windows WebLogic application servers -- If you are not using the Weblogic pattern, Discovery follows this process when it uses the Windows - Active Processes or Linux - Active Processes probes.
IBM WebSphere server using probes -- The IBM WebSphere application server is a software framework with middleware that hosts Java-based web applications. Discovery creates or updates a CMDB record when it detects an instance of a WebSphere application server running on a Windows or Linux system.
Database discovery -- Discovery can find database applications, such as MySQL, Oracle, and MongoDB. Discovery can also find database management system software, such as MSSQL Server.
Database catalog -- The database catalog lists all the catalog objects, or databases, discovered for an instance of a database.
DBA report -- Discovery and Service Mapping uses the Patterns extension sections to provide a Database Administrator report (DBA report) for the Apache Cassandra, Microsoft SQL, MySQL, MongoDB, and Oracle databases. The extension sections for each DB pattern populate the related entries tables. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Microsoft SQL Server and Cluster -- The Discovery and Service Mapping Patterns application uses the MSSql DB On Windows pattern to find Microsoft SQL DB servers and clusters on your infrastructure. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Microsoft SQL Server and Cluster -- The Discovery and Service Mapping Patterns application uses the MSSql DB On Windows pattern to find Microsoft SQL DB servers and clusters on your infrastructure. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
MySQL -- Discovery can identify an instance of MySQL that is running on UNIX or Windows operating systems.
MongoDB -- Discovery creates or updates a CMDB record when it detects a running instance of MongoDB.
PostgreSQL -- Discovery can find running instances of PostgreSQL on Windows and Linux systems.
Oracle database -- Discovery can identify an Oracle database instance that is running on UNIX or Windows operating systems. It can also find Oracle clusterware, which runs Real Application Clusters (RAC).
SAP Sybase ASE -- Discovery and Service Mapping uses the Sybase pattern to find SAP Sybase Adaptive Server Enterprise (ASE) databases and catalogs in your infrastructure. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Network device discovery -- Discovery identifies several network devices, including load balancers, routers, TCP connections, IP networks, and so on. It can find devices through traditional port probes, and then through identifications and exploration probes, or through patterns. It also supports discovery by identifying HTTP and TCP connections.
Load balancers -- Discovery can collect data about network routers, switches, and applications.
A10 -- Discovery and Service Mapping uses patterns to collect information about A10 load balancers.
Cisco ACE -- Discovery identifies and classifies information about ACE load balancers.
Cisco GSS -- Discovery of Cisco GSS load balancers is performed by both SNMP and SSH.
Cisco CSS -- Discovery of Cisco CSS load balancers is performed by SNMP.
Citrix NetScaler -- Discovery and Service Mapping find Citrix NetScaler load balancers including Server Load Balancing (GSLB).
F5 BIG-IP -- Discovery and Service Mapping can find F5 BIG-IP load balancers via SNMP, SSH, and through the REST API.
HAProxy using probes -- Discovery of HAProxy Community edition load balancers is performed by SSH.
Enable HAProxy with probes -- If you prefer not to start using the default HAProxy pattern-based discovery, enable probe-based HAProxy discovery to continue using it instead.
NGINX -- Discovery of NGINX load balancers is performed by SSH.
Radware Alteon -- Discovery identifies and classifies information about Alteon load balancers.
Radware-appDirector -- Discovery of Radware load balancers is performed by SNMP.
IP service and daemon -- Discovery identifies and classifies information about services and daemons.
Uninterruptible power supply -- Discovery identifies and classifies information about an uninterruptible power supply (UPS).
IBM WebSphere DataPower -- ITOM Visibility discovers IBM WebSphere DataPower. The Discovery feature uses the DataPower Server pattern for horizontal discovery. The Service Mapping feature uses the DataPower pattern for top-down discovery.
Cisco UCS -- Discovery and Service Mapping Patterns application uses the to find Cisco UCS equipment, including chassis and blades. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Dell Remote Assistant Card -- The Dell Remote Assistant Card (DRAC) and Integrated Remote Assistance Card (iDRAC) provide users with tools and functionality to monitor, troubleshoot, and repair servers. You can generate DNS URLs to access out-of-band devices when security prevents access from IP addresses.
HTTP device -- Discovery can find devices that use the HTTP protocol.
Run discovery through HTTP/HTTPS REST calls -- Discovery can classify devices using the HTTP(S) protocol. You can create your own HTTP classifier to find devices and access them with Basic Auth credentials, rather than using SNMP or SSH credentials.
Storage discovery -- Discovery collects information on Direct Attached Storage (DAS), Storage Area Networks (SAN), and Network Attached Storage (NAS).
Storage discovery via a host -- Discovery gathers information about storage units that connect to Linux, Solaris, and Windows hosts via a local I/O port or Host Bus Adapter (HBA).
Storage Discovery via SMI-S and CIM -- Discovery can explore storage devices that contain a Storage Management Initiative Specification (SMI-S) provider that is a specialized Common Information Model (CIM) server.
Storage area network -- Discovery collects information about storage area networks from specialized devices, such as storage arrays and Fibre Channel (FC) switches, and creates specific references between the tables in the SAN schema.
How CIM Discovery works -- This is the processing flow for classifying Common Information Model (CIM) storage systems.
Configure SMI-S Provider -- Use this procedure for configuring a standalone storage device with the required SMI-S Provider for Discovery.
Veritas Volume Manager on Linux -- Discovery collects disk and volume information for Veritas Volume Manager (VxVM) on Linux hosts and maps file systems mounted on Veritas volumes to the upstream storage provider.
NetApp Server and Cluster -- Discovery and Service Mapping find NetApp servers and clusters using patterns. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
Disable SNMP-based discovery -- Disable the default SNMP-based NetApp storage cluster discovery and use REST-based discovery instead for enhanced security.
Manage large storage payloads in Linux and Solaris -- Large payloads for Linux and Solaris direct attached storage can cause out of memory errors if not configured to serialize the processing of the payload.
Storage discovery examples -- Discovery creates configuration items (CI) and CI relationships for physical and logical storage components attached directly to application and database servers or by fibre channel switched fabric in a multi-path configuration.
ITOM Visibility and CSDM reference -- ITOM Visibility consists of two ServiceNow products: Discovery and Service Mapping. These products are responsible for creating Configuration Items (CIs) in the CMDB and relating them. The goal of this product view is to help you to understand how ITOM Visibility works with the core CSDM framework.
ITOM Visibility and CMDB tables -- ITOM Visibility manages and uses CMDB tables. Several ServiceNow products benefit from and add value to ITOM Visibility.
Plugins or applications installed with ITOM Visibility -- Tables that list the plugins or applications that are installed with ITOM Visibility applications. When you update your application, any newly required application dependencies are installed.
ACC admin workspace agent actions -- When working in the Agent Client Collector (ACC) admin workspace, you can select actions to perform on the agent by selecting the Agent actions button.
ACC admin workspace information -- When selecting an agent in the ACC admin workspace, select from the displayed options to view information relating to the agent.
ITOM AIOps -- ITOM AIOps enables IT operations teams, site reliability engineers, and DevOps professionals to proactively monitor, analyze, and optimize the health and performance of their IT infrastructure and services.
Explore -- Overview of ITOM AIOps applications and capabilities that enable proactive IT operations management through AI-powered monitoring, analytics, and automation.
Admin configuration use case for AIOps -- Learn how IT administrators configure and optimize ITOM AIOps for enterprise environments. This use case demonstrates the setup journey for a multi-cloud financial services organization.
NOC operator use case for AIOps -- Follow a typical NOC operator through their daily workflow using ITOM AIOps capabilities to transform reactive operations into proactive, intelligent IT management.
Service Operations Workspace for ITOM -- ServiceNow Service Operations Workspace (SOW) is a configurable workspace designed to streamline IT Operations Management (ITOM) workflows, offering a unified experience for multiple IT operational processes. Configurable and user-friendly, it consolidates various tasks into a single interface, allowing seamless navigation and easy access to tools and information.
Exploring SOW for ITOM -- Discover how Service Operations Workspace for ITOM streamlines the entire life cycle of alerts, including alert generation, notification, grouping, analysis, investigation, resolution, and closure.
Overseeing AIOps AI Specialist in Service Operations Workspace -- The AIOps Supervisor home page helps supervisors review operational workload, monitor AIOps AI Specialist activity, and review alerts closed by AIOps AI Specialist in Service Operations Workspace.
Configuring SOW for ITOM -- Configure Service Operations Workspace for ITOM so that you can manage IT alert volumes efficiently and customize the workspace to enhance service delivery and operational visibility.
Install SOW for ITOM application -- You can install the AIOps Experience [sn_sow_aiops] application to get Service Operations Workspace for ITOM if you have the admin role.If the application does NOT include demo data or it does NOT install related applications and plugins, delete or revise the following sentence:The application includes demo data and installs related ServiceNow Store applications if they are not already installed.
ITOM AIOps configuration center -- The ITOM AIOps configuration center is a centralized hub to manage AIOps settings. It helps you integrate monitoring tools, optimize alerts, metrics, and logs, manage services, dashboards, teams, and authorization—streamlining event-to-response workflows for better visibility, noise reduction, and operational efficiency.
Customize the SOW for ITOM home page -- You can customize the data displayed in sub pages of the home page that is available in the base system. For any visual styling changes, you need to create a copy of that landing page and edit it.
Modify the greeting text on the landing page -- Customize the header message that is a part of the greeting text on the home page. This will create a more personalized user experience, making visitors feel welcomed and valued, and can also help in setting the right tone and context for the information presented.
Create a copy of the Service Operations Workspace for ITOM landing page -- Make visual styling changes to the sub-pages in the home page. This will enhance the overall user experience by providing a consistent and visually appealing interface, improving navigation, and ensuring that key information is easily accessible and engaging.
Redirect to the Service Operations Workspace home page -- Enable quick task prioritization by directing agents to the homepage immediately upon logging into the ServiceNow instance. This improves workflow efficiency by granting agents immediate access to essential tools and information, facilitating the timely resolution of critical tasks and issues.
Service Operations Workspace -- The Service Operations Workspace monitors services within your Event Management environment, enabling you to review their status and identify those at risk of suboptimal performance. This empowers you to promptly address any issues.
Delete a user view in Service Operations Workspace -- Delete a Service Operations Workspace user view you no longer need. You perform this action from the Event Management menu, outside of Service Operations Workspace.
View application service details in Service Operations Workspace -- View comprehensive information about an application service, including its name, business criticality, ownership, process and operational status, traffic-based discovery details, discovery status, and relevant comments. This enables thorough analysis of the application service's current state and usage, provides clarity on ownership and criticality, and facilitates effective prioritization of resources and actions.
Create a list in Service Operations Workspace for ITOM -- Customize lists in Service Operations Workspace by creating new lists, changing their order, modifying their content, or deleting lists as needed. This flexibility allows operators to organize information according to their specific requirements, facilitating easier navigation, quicker access to relevant data, and streamlined workflow management.
Rename a list in Service Operations Workspace for ITOM -- Rename a list to better reflect its content or purpose. This customization allows operators to align list names with their workflow terminology, improving clarity and usability.
View unified service map and the impact paths in Service Operations Workspace -- Visualize relationships between Configuration Items (CIs) and alerts with real-time updates and detailed impact paths. Enhance troubleshooting and proactive management by quickly identifying root causes and dependencies for both discovered services and application services.
Configure live updates for alert lists -- Choose live updates for alert lists to receive real-time updates, or disable live updates and refresh the alert list manually.
Configure alert metrics -- Configure the metrics you want to be visible for Service Operations Workspace alerts or use the metrics configured with the base system to focus on relevant data for faster troubleshooting.
View CI health in Metric Explorer -- View the health and performance of an alert's CI using Metric Explorer, to help troubleshoot problematic areas in the CI.
View alert metric trends in Service Operations Workspace -- View the metrics for an alert and adjust the time range to see the trends for either the alert or its associated Configuration Item (CI), enabling more accurate analysis and timely decision-making.
On-call scheduling in SOW for ITOM -- ITOM Service Operations Workspace supports creating and managing your on-call shifts and schedules. On-call schedule determines who is on-call at a given time. Learn how to configure on-call calendars and escalation policies to ensure timely responses to critical issues, reducing downtime and maintaining service continuity. Streamlining these processes enhances team readiness, minimizes disruptions, and improves service reliability.
Add alert table to enable on-call scheduling for Service Operations Workspace for ITOM -- Enable on-call scheduling by incorporating the Alert table [em_alert] into the Trigger Rule Table Config list. This allows for creating shifts and implementing escalation triggers and policies, ensuring teams can promptly respond to alerts and maintain operational continuity.
Using SOW for ITOM -- Service Operations Workspace for ITOM delivers a unified platform integrating various applications, specializing in streamlined alert management. Seamlessly manage IT Operations workflows while efficiently handling alerts, ensuring optimal performance and productivity.
Integrations Launchpad in SOW for ITOM -- The Integrations Launchpad showcases all Event Management connector integrations, allowing users to pull or push events from external or internal devices. This centralized hub simplifies Event Management by consolidating integration options in one place.
Configure an event pull connector -- Configure event pull connectors that require a script, connector definition, and connector instance to pull events from external devices. These connectors automate the data retrieval process, ensuring the seamless integration of external events into your system for efficient monitoring and management.
Configure an event push connector -- Integrate with an event push connector to connect to an external event source and push event information to your ServiceNow instance.
Configure an event custom connector -- Authenticate your event custom connector as a data source to enable the pushing of event information to your ServiceNow instance. Define the custom connector by providing its details and mapping fields. This allows the extracted information from your custom connector's event messages to populate the required event fields. Finally, create and supply a URL for the custom connector webhook.
Configure Solarwinds metric pull connector -- Configure a metric pull connectors that require a script, connector definition, and connector instance to pull metrics from external sources. These connectors automate the data retrieval process, ensuring the seamless integration of external metrics into your system for efficient monitoring and performance analysis.
Configure Dynatrace metric pull connector -- Configure metric pull connectors that require a script, connector definition, and connector instance to pull metrics from external sources. These connectors automate the data retrieval process, ensuring the seamless integration of external metrics into your system for efficient monitoring and performance analysis.
Configure Datadog metric pull connector -- Configure OAuth-based integration between your Datadog instance and ServiceNow Event Management to securely ingest metric from the Datadog Instance. This setup enables authenticated metric delivery using client credentials, maps discovered server CIs, and allows anomaly alerts to create actionable events in ServiceNow through standard webhooks.
Review integration and configuration health -- Review your events to ensure alerts are created as intended. Start this process by checking the health status of your integration. This provides useful statistics to highlight where you can make improvements to enrich alerts with relevant business context, group them for better noise reduction, escalate critical alerts promptly, and notify your team for swift response and resolution.
Activate integration -- Activate integration allows you to enable a previously deactivated connector integration, restoring its functionality. This feature helps you seamlessly resume data flow and integration activities, ensuring continuity and efficient event management without the need to reconfigure the integration.
Deactivate integration -- Deactivate integration allows you to temporarily disable an active connector integration without deleting it. This feature helps you manage integrations more effectively by pausing data flow when needed, reducing unnecessary event processing and improving system performance.
Delete integration -- Delete integration allows you to permanently remove a connector integration from your system. This feature helps you maintain a clean and organized system by eliminating unused or obsolete integrations, freeing up resources and reducing potential clutter.
Express List in SOW for ITOM -- The ServiceNow Event Management Express List feature helps you identify health issues across the datacenter on the Service Operations Workspace. It provides a list of quick information on alerts so you can more efficiently monitor systems and services, resolve alerts, evaluate the alert impact, track issues, and report incidents.
Assign alerts in Express List -- Assign alerts in Express List to yourself, to someone else, or to an assignment group to balance your organization's work load.
Identify an assigned Express List view -- Identify Express List views assigned to you by your Event Management admin to make sure that you focus on specific services, priorities, or alerts.
Add or modify Express List columns -- Add columns to the Event Management Express List display to focus the list of alerts that is displayed or modify the existing columns that are displayed.
Monitor incoming alerts -- You can monitor incoming alerts in Service Operations Workspace. You can also monitor and manage alerts in the Event Management interface.
Close an alert in Express List -- Manually close alerts directly from the Express List pane or from the preview panel without waiting for them to be automatically closed if you already know the root cause or have fixed the problem.
Mute a CI's alerts in Express List -- Mute a CI's alerts in Express List to avoid alerts being issued when replacing or upgrading the CI.
Place an alert in the Maintenance state -- Placing an alert into the Maintenance state indicates that there are issues with the alert's CIs that are being addressed.
Run response actions on multiple alerts -- Run response actions to efficiently remediate and respond to issues on multiple alerts directly from the Express List pane.
View metrics for an alert -- Viewing metrics enables you to understand historical data related to an alert's CI.
View anomaly alert metric data -- View visualizations for anomaly alerts to investigate anomalies using metric data. You can view visualizations from the Express List preview panel or the alert record.
View Log Analytics anomaly alert charts -- View visualizations for Health Log Analytics anomaly alerts to identify periods of behavior that deviate from expected ranges. You can view visualizations from the Express List preview panel or the alert record.
Hide closed alerts in Express List -- Choose whether to display the closed alerts in an alert group as well as the open alerts on the preview panel and in Link View.
View an alert analysis by Now Assist in Express List -- View an alert analysis created by Now Assist using generative AI. Alert analyses include a human-readable brief of the alert and technical information to help you investigate the alert more effectively.
Generating case from an alert -- Enable swift resolution by generating cases from alerts, either manually or automatically.
Viewing links between alerts in alert groups in Express List -- Gain a better understanding of the relationships between alerts in alert groups in the Express List by using Link View. Link View offers a visual representation of the relationships between the alerts in a group.
Viewing alert links in tag-based groups -- View the connections between alerts in a tag-based alert group in Express List by using Link View. Link View shows how the attributes of the alerts in the group are linked with each other.
Viewing alert links in rules-based groups -- View the connections between alerts in a rules-based alert group in Express List by using Link View. Link View shows how the attributes of the alerts in the group are linked with each other.
Viewing alert links in CMDB-based groups -- View the connections between alerts in alert groups in Express List that were created based on the proximity of Configuration Items (CIs) in the Configuration Management Database (CMDB). Link View shows how the attributes of the alerts in the group are linked with each other.
Viewing alert links in network traffic-based groups -- View the connections between alerts in network traffic-based alert groups in Express List by using Link View. Network traffic-based alert groups are created by analyzing network traffic connections between processes across hosts.
Viewing alert links in log analytics-based groups -- Use Link View in Express List to see why alerts in a log analytics-based alert group are correlated together through the visualization of shared attributes.
Viewing alert links in mixed alert groups -- Link View displays the connections between alerts in mixed alert groups in Express List, including how alert attributes relate to each other within the group.
Explore chronological alert data for an alert group -- Visualize the chronological sequence of events within an alert group in Express List using the Timeline view. This feature provides a comprehensive overview of when the alerts occurred, their severity changes, and other pertinent data for efficient triage and Mean Time to Resolution (MTTR).
View a timeline of the alerts in an alert group -- Gain insight into the sequence of events relating to an issue by viewing chronological information of the alerts in an alert group in Express List.
View alert insights and remediation in Preview panel -- Resolve alerts more quickly by reviewing AI-generated insights and recommended remediation in the Preview panel and acting on them without navigating to the alert record.
Filtering the alert display in the Express List pane -- Filters help you create different views of categorized alerts, creating a targeted list of alerts to prioritize and focus on, saving time and minimizing distractions.
Filter the Express List display using attributes -- Filter the Express List display by text, number, and date attributes using the interactive Express List filter panel. Create a targeted list of alerts to prioritize and focus on.
Categorize alerts displayed in Express List -- Create different views of alerts by adding tags in Express List to enable you to easily identify and group alerts without the need for discovery or accessing the CMDB.
Filter out or show matching alerts -- Create different views of categorized alerts in Express List by either displaying or filtering out alerts that match a selected alert.
Save a custom filter in Express List -- Save your custom view of categorized alerts in Express List to use again, share, or set as your default view. Saving your custom view saves all filters, tags, and conditions.
Viewing an alert group analysis by Now Assist in Express List -- View an analysis of alert groups in Express List, generated by Now Assist using AI. The analysis helps you better understand the nature of the alert group, why the alerts in the group were correlated, and how to proceed in the remediation process.
View an alert group analysis by Now Assist in Express List -- View an alert group analysis created by Now Assist using generative AI. The analysis offers a simplified, human-readable description of the alert group and technical information to help you investigate it more efficiently.
Alert automation in SOW for ITOM -- Alert automation is crucial as organizations deal with increasing number of alerts and complex IT infrastructures. Manual alert handling is slow, error-prone and inefficient, underscoring the need for automated systems. Automation can improve the mean time to resolve alerts, improve service reliability and better scale staff resources.
Create Ignore automation -- Ignore automation streamlines the process of disregarding irrelevant or false-positive alerts from monitoring systems, efficiently managing alert fatigue by filtering out unnecessary notifications. As a result, teams can prioritize and resolve critical issues more effectively.
Create Enrich automation -- Alert enrichment involves transforming raw events from monitoring tools into a standard format, aiding automated grouping and response. This includes extracting fields from lengthy alert payloads or composing them into a standardized format. Additionally, you can create tags, which are metadata added to alerts for easier filtering and grouping.
Extracting and composing alert fields -- Extracting and composing are ways to manage what you see in the alert output, making it simpler to filter, group, and read. Alert automation enables you to extract values from event payload's alert field and place it in an alert output field. Composing allows you to merge multiple alert fields into a single output field.
Regex preprocessing behavior in Enrich alert automation -- Explains how Event Management alert automation preprocesses values before applying regex patterns, why matching behavior differs between pre-populated Additional Info JSON fields and free-text sample values, and how to design regex patterns that work reliably.
Set additional info fields to match CI attribute format -- Set additional info fields in alerts to match the field and value format of CI attributes in CI records. This ensures accurate alert-to-CI binding, improving alert tracking and reducing manual effort.
Create Group automation -- Grouping automation helps you manage alerts more effectively by collecting similar alerts together. This makes it easier to see patterns, quickly identify issues, and respond efficiently. By organizing alerts in this way, you can reduce alert noise, identify root causes, and assign them to the appropriate teams.
Create Respond automation -- Respond to alerts automatically by notifying appropriate stakeholders, escalating them as needed based on severity and type, or other executing response actions. This process ensures that alerts are managed promptly and effectively.
Delete an automation -- Delete an automation to permanently remove an automated alert handling rule from your system.
AIOps Dashboards in SOW for ITOM -- The AIOps dashboards offer comprehensive visualizations of critical operational data. You can monitor key performance indicators (KPIs), track service health, and gain valuable context on the overall IT environment. These dashboards provide actionable insights that facilitate proactive responses to potential issues.
AIOps 360 overview dashboard -- The AIOps 360 Overview dashboard offers a unified view of value and performance across IT operations, helping teams track efficiency, monitor alert handling, and assess automation outcomes. It enhances visibility into AIOps impact, supports informed decisions, and drives faster, smarter operations.
AIOps Value Realization dashboard -- The AIOps Value Realization dashboard uses Performance Analytics to offer comprehensive visibility into the business outcomes of alerts, events, and incidents. It features metrics such as noise reduction (events to alerts compression), average MTTR for incidents created by Event Management[var.event-mgmt], and the most critical services impacted by hours.
Event and Alert dashboard -- The Event and Alert dashboard uses Performance Analytics to provide real-time visibility into events and alerts in Event Management, showcasing key trends, outcomes, and the most impacted configuration items. It highlights metrics such as noise reduction, alert grouping coverage, and top alert sources.
Agent Health dashboard -- The Agent Health dashboard provides visibility into the status and distribution of agents installed in your system. It allows you to quickly assess the number of deployed agents and their distribution, helping you prioritize your work more efficiently.
HLA Operational dashboard -- The Health Log Analytics Operational dashboard uses Performance Analytics to enable you to monitor log data, alerts, and error rate information in Service Operations Workspace and address issues as they occur in the system.
Data visualization in ITOM -- Gain insights faster with data visualization in IT Operations Management (ITOM). Visualize metrics, logs, events, and alerts through intuitive dashboards and charts to identify trends, monitor performance, and resolve issues proactively.
Create a funnel visualization -- A funnel visualization shows how data progresses through sequential stages, helping you identify drop-offs or bottlenecks at each step. Use it to track conversions, workflows, or process completion rates. You can add a funnel visualization to an existing dashboard or to a new dashboard.
Components installed with AIOps Experience -- Several types of components are installed with activation of the AIOps Experience [sn_sow_aiops] application, including user role and plugins.
Alert field mapping on the Respond page -- The fields to be configured on the Respond page, when selecting an action to be triggered by an alert automation.
Outbound webhook parameters -- The parameters to be configured when sending data to other systems using an outbound webhook.
Application service details page -- Provides comprehensive information about an application service, including its name, business criticality, ownership, process and operational status, traffic-based discovery details, discovery status, and relevant comments. This enables thorough analysis of the application service's current state and usage, provides clarity on ownership and criticality, and aids in prioritizing resources and actions effectively.
Create list fields -- Create customized lists with fields tailored to your needs.
Integration and configuration health event fields -- Populate the event fields to capture details such as the event time, description, alert number, state, severity, metric name, node, message key, and error message, enabling precise tracking, effective incident management, and improved error analysis.
Datadog advanced settings fields -- Populate the Datadog advanced settings fields to define API paths, batching limits, host filters, sync duration, connection details, and debugging options. These values control how the pull connector retrieves and processes metrics and host data from Datadog, ensuring the connector runs with the desired scope and behavior.
Dynatrace advanced settings fields -- Populate the pull connector advanced settings fields to optimize event retrieval and synchronization based on specific requirements such as connection preferences, event frequency, and time zone settings.
Pull connector fields -- Populate the pull connector advanced settings fields to optimize event retrieval and synchronization based on specific requirements such as connection preferences, event frequency, and time zone settings.
Event Management -- ServiceNow Event Management is a robust application that helps keep your IT systems healthy by spotting problems quickly and fixing them. It collects events from different sources, figures out what's causing the issues, and converts them into alerts. These alerts are then analyzed, grouped, and acted upon to resolve issues and maintain system health.
Exploring Event Management -- Explore Event Management to understand its overview, process flow, user roles, and benefits for comprehensive IT issue monitoring and resolution.
Event Management process flow -- Event Management collects, analyzes, and converts events into alerts, enabling efficient tracking and remediation.
Event Management architecture -- Event Management architecture integrates data collection, processing, and alerting into a unified system for streamlined IT issue detection and resolution.
Configuring Event Management -- Event Management administrators administer events, manage and monitor alerts, aggregate alerts, and work review and monitor services' status with the Operator Workspace service monitor.
Configure Event Management using Setup Hub -- The ITOM Configuration console gives administrators a single place to complete all Event Management setup steps — from installing plugins to configuring alert automations.
Create integration account -- Create a dedicated account with the evt_mgmt_integration role for third-party monitoring systems to push events to ServiceNow.
Install Discovery -- Configure Discovery to lay the groundwork for AIOps success by establishing a key foundation for your team.
Learn the basics -- ServiceNow Event Management and AIOps help IT operations teams manage high alert volumes by reducing noise and turning raw events into prioritized, actionable alerts. This section covers core concepts, implementation stages, CMDB considerations, prerequisites for setup, and resources to help you get started quickly and confidently.
Install integrations -- Access Integrations Launchpad to configure and install integrations for Event Management monitoring tools.
Review alerts -- Access the Express List interface to review and manage alerts in your Event Management system.
Alert enrichment automations -- Configure alert enrichment rules to automatically add context and metadata to incoming alerts for better analysis and response.
Create incidents -- Configure automation rules to automatically create incidents from alerts that require immediate attention and resolution.
Alert ignore automations -- Configure ignore rules to automatically suppress alerts that are not actionable or relevant to your operations team.
Alert group automations -- Configure grouping rules to automatically consolidate related alerts into single actionable items for more efficient incident management.
Delay incidents -- Configure delay rules to postpone incident creation for alerts that may resolve automatically or represent transient conditions.
Training operations team -- Get your L1/L2 operators up to speed with ServiceNow Event Management. This section walks through the key concepts, tools, and workflows they need to confidently triage alerts, understand service impact, and take action from day one.
Dashboards -- Access Event Management dashboards to monitor system performance, alert trends, and operational metrics for your IT operations.
Learn how to deploy Event Management to production -- Understand the process and considerations for deploying Event Management configurations from development to production environments using update sets.
Request Event Management -- AIOps Experience plugin (sn_sow_aiops) requires a separate subscription and must be activated by ServiceNow personnel. This plugin includes the required Event Management components.
Install Event Management -- Retrieve the most updated apps for the Event Management application (com.glideapp.itom.snac) in the ServiceNow Store. Periodically check the ServiceNow Store for new app versions.
Enhance Event Management performance -- The Event Management Accelerator plugin ensures that Event Management maintains performance at a high level. This plugin is optional.
Event Management setup -- After activating Event Management, set it up to receive and process events, and generate and analyze alerts.
MID Web Server -- The MID Web Server is part of the common infrastructure of the MID Server.
Configure the MID Web Server extension -- The MID Web Server is a MID Server extension that enables developing REST APIs to send events and metrics to the MID Server. The extension is leveraged by other MID Server extensions, such as Metric Intelligence, MID WebService Event Listener, and the Agent Client Collector websocket endpoint extension.
Configure a secure MID Web Server extension -- Configure a TLS listener for extra security and encryption of data transferred to and from the MID Web Server extension. Access both a private key and a certificate (or certificate chain) from a Java keystore to use during the TLS handshake where the MID Web Server and the client acknowledge each other.
Configure key-based MID Web Server authentication -- Provide added security to your MID Web Server extension by using key-based authentication. Generate an authentication token to be sent in the Authorization header of incoming client requests.
Configure MID Web Server API key authentication -- Authenticate incoming requests from clients to the MID Web Server extension using API key authentication. API authentication is a secure and simple way to authenticate your request. You can create or modify a MID Web Server API key.
MID Web Server and agent mTLS Authentication -- Mutual authentication using the Transport Layer Security protocol (mTLS) is a secure, certificate-based authentication scheme. With mTLS, the server (the MID Web Server extension) and the client (the agent) authenticate each other.
Create keys and certificates -- Create keys and certificates in your root directory to enable Transport Layer Security (TLS) setup. TLS setup is necessary before you can configure mTLS on the MID Web Server and agent.
Set up the MID Web Server -- Install the .pem file into the MID unified keystore and set up the MID Web Server to enable configuring mTLS on your MID Web Server and agent.
Connect the agent to the MID Server using mTLS -- Before configuring mTLS authentication on the agent, you must run a series of commands that enable configuring Transport Layer Security (TLS) authentication.
Domain separation and Event Management -- Domain separation is supported in Event Management. Domain separation enables you to separate data, processes, and administrative tasks into logical groupings called domains. You can control several aspects of this separation, including which users can see and access data.
Configure domain separation -- You can configure Event Management for domain separation to create logically defined domains that limit unauthorized access to data. When domains are separated in Event Management, users can only see and manage alerts and events in their own (tenant) domain.
Event Management Integrations -- An event is a notification from one or more monitoring tools that indicate something of interest has occurred, such as a log message, warning, or error.
Connector domain personalization -- Create events in different domains for all Event Management connectors using just a single connector instance by personalizing domain separation of Event Management connectors.
Domain mapping for pull connectors -- Configure pull connectors to personalize domain separation of events so you can use them to create events in domains other than the user's currently logged-in or MID Server domain.
Domain mapping for push connectors -- Configure push connectors to personalize domain separation of events so you can use them to create events in different domains other than the user's currently logged-in or MID Server domain.
Configure Event Management connectors -- Event Management provides many connectors to pull or push events from external devices. Connectors are available from the ServiceNow store as well as from third parties. You can also create custom connectors.
Create a custom pull connector -- You can create a customized pull connector that requires a script, connector definition, and connector instance, to retrieve events on behalf of an event source.
Configure event collection from IBM Netcool -- Configure the IBM Netcool_V2 connector to receive events from IBM Netcool/OMNIbus Object Servers and Impact Servers. The IBM Netcool_V2 connector uses REST API calls and is bidirectional.
Configure event collection from Logicmonitor -- The Logicmonitor pull connector sends information from Event Management to Logicmonitor. It sends responses received from a Push connector in a bi-directional environment to Logicmonitor.
Configure event collection from NNMi -- Configure the HP Network Node Manager i (NNMi) connector instance to receive events while monitoring your network resources.
Configure event collection from OBM -- Configure the Operation Bridge Manager (OBM), also known as OMi v2, connector instance to receive alerts from the OBM server. The OBM connector script OBM v2 will be available after installing the Event Management Connectors app.
Configure OP5 or OP5_v2 connector -- Configure the OP5 or OP5_v2 Monitor connector instance to receive alerts from an OP5 Monitor source.
Configure Opsview_v2 connector -- Configure the Opsview_V2 connector instance to receive alerts from an Opsview Monitor source.
Configure PRTG connector -- Configure the PRTG connector instance to receive alerts from a Paessler PRTG Network Monitor source.
Apache Kafka Consumer Connector -- The Apache Kafka Consumer connector instance enables you to create events from messages collected from the Apache Kafka topic as a JSON payload that contains essential information in a data block.
Configure the Apache Kafka Consumer connector -- Configure the Apache Kafka Consumer connector instance to create events from streaming messages collected by the Apache Kafka connector.
Map Kafka message payload attributes to alert fields -- Map Kafka message attributes to alert fields to make alerts based on the messages more meaningful. Use event field mapping to map Kafka severity values to appropriate ServiceNow values.
Configure SAP Solution Manager connector -- Configure the SAP Solution Manager (Solman) connector instance to enable communication between the SAP Solution Manager and Event Management.
Enable SAP connector configurations -- Configure your SAP environment to work with the ServiceNow Event Management platform so you can use the SAP Solution Manager connector.
Use the SAP Solution Manager Pull connector -- The SAP Solution Manager Pull connector sends information from Event Management to the SAP Solution Manager. The Pull connector sends responses received from a Push connector in a bi-directional environment.
Use the SAP Solution Manager Push connector -- The MID Server web service Event Collector enables you to collect alerts sent from the SAP Solution Manager through event stream notification capabilities. The interface runs both a Push and a Pull interface to interact directly with the SAP Solution Manager.
SAP Solution Manager setup configurations -- As part of the SAP Solution Manager setup, you must perform several configurations to enable SAP Solution Manager to interact with Event Management.
Configure RFC in SAP Solution Manager -- As part of enabling communication with Event Management, you must create a Remote Function Call (RFC) in the SAP Solution Manager and install a transport.
Configure SAP to forward alerts to your BADI -- After setting up SAP Solution Manager monitoring, you must configure SAP to forward alerts to the BADI (Business Add-in) you create as the first step in the SAP integration setup.
View alerts in the SAP Solution Manager inbox -- You can view alerts generated in SAP Solution Manager to see any pressing issues. All alerts also forward to Event Management automatically.
SAP Solution Manager transaction codes -- The transaction code abbreviations that you can use in the SAP interface when working with the SAP Solution Manager connector.
Configure alert collection from SCOM -- Alerts from the Microsoft System Center Operations Manager (SCOM) are collected using the SCOM connector instance.
Configure the SCOM connector instance -- Configure the Microsoft System Center Operations Manager (SCOM) connector to receive alerts and Metric Intelligence raw data from the SCOM server. SCOM event collection and metric collection are handled by two separate connector definitions: SCOM (for alerts and bi-directional exchange) and SCOM Metrics (for Metric Intelligence raw data).
SCOM metric event rules -- The base system comes with Microsoft System Center Operations Manager (SCOM) metric event rules. SCOM metric event rules bind event metrics to configuration items (CIs).
Create SolarWinds monitor credentials -- Create a Basic Auth credential in ServiceNow to store the SolarWinds user name and password that the SolarWinds monitor connector uses to access the SolarWinds API.
Configure event collection from vCenter -- Configure the VMware vCenter Server (vCenter or vCenter_V2) connector instance to receive events from your VMware vSphere environment.
Configure event collection from vRealize -- Configure the VMware vRealize Operations (vRealize or vRealize_V2) connector instance to receive events from the vRealize Operations Log and Event Management servers. vRealize uses basic authentication. vRealize_V2 uses token-based authentication.
Configure a push connector -- You can configure listeners and connectors to push event information to the instance or MID Server.
Configure ServiceNow Cloud Observability event collection -- Integrate ServiceNow Cloud Observability with Event Management by adding a standard webhook in the ServiceNow Cloud Observability platform. Download the Event Management Connector plugin from the ServiceNow Store so you can integrate with ServiceNow Cloud Observability.
Configure MID Server push listener -- The MID Server supports the collection of event messages, using the MID Web Server to collect data from external sources and transforming (parsing) them to the format required for event fields in the event [em_event] table. The transformed events are then transmitted to the instance.
Event collection from custom payloads -- The MID WebService Event Collector enables you to collect event information from custom payloads in JSON, XML, or plain text format.
Integrate with push connectors -- Integrate with a push connector to connect to an external event source. Push connectors process the collected event messages and transform them to the required event format.
Use legacy listener transform scripts -- Use legacy listener transform scripts when upgrading a ServiceNow AI Platform instance from Paris or earlier. These scripts can be run as part of existing integrated systems, or in unison with Event Management push connectors.
Integrate AWS platform as a data source -- Integrate Amazon Web Services (AWS) with Event Management. To add AWS platform as a data source, configuration is required in the AWS platform.
Integrate AWS with REST API key token -- Integrate using an API key to establish secure communication and automate data exchange via REST API. This simplifies integration, enabling seamless access to services and enhancing operational efficiency.
Integrate Azure with REST API key token -- Integrate using an API key to establish secure communication and automate data exchange via REST API. This simplifies integration, enabling seamless access to services and enhancing operational efficiency.
Configure Azure Monitor Bi-directional connector -- The Azure Monitor Pull connector sends information from ServiceNow Event Management to the Azure Portal. The pull connector sends the alert state changes from the ServiceNow environment to the Azure Portal.
Event collection from BMC TrueSight and BMC TrueSight_v2 -- The MID WebService Event Collector enables you to collect JSON formatted event messages sent from BMC TrueSight Operations Management (TrueSight), previously known as BMC ProactiveNet Performance Management (BPPM), utilizing event stream notification capabilities.
Integrate New Relic platform events -- Integrate New Relic with Event Management by adding a standard webhook in the New Relic old and new consoles.
Integrate New Relic with REST API key token -- Integrate using an API key to establish secure communication and automate data exchange via REST API. This simplifies integration, enabling seamless access to services and enhancing operational efficiency.
Integrate Catchpoint events -- Integrate Catchpoint with Event Management by adding an alert webhook in the Catchpoint platform.
Integrate Grafana with REST API key token -- Integrate using an API key to establish secure communication and automate data exchange via REST API. This simplifies integration, enabling seamless access to services and enhancing operational efficiency.
Integrate Honeycomb events -- Integrate Honeycomb with Event Management by creating a webhook and configuring it as a trigger in the Honeycomb platform.
Integrate Instana events -- Integrate Instana with Event Management by adding Instana as an authenticated data source.
Integrate Instana events -- Integrate Instana with Event Management by adding a standard webhook in the Instana console.
Integrate ServiceNow Cloud Observability Events -- Integrate ServiceNow Cloud Observability with Event Management by adding a standard webhook in the ServiceNow Cloud Observability platform. Download the Event Management Connector plugin from the ServiceNow Store so you can integrate with ServiceNow Cloud Observability.
Integrate Logicmonitor events -- Integrate Logicmonitor with Event Management to send events into ServiceNow by adding a webhook using Basic Authentication, it will also be available with bi-directional functionality.
Event collection from Logicmonitor -- The MID WebService Event Collector enables you to collect JSON formatted event messages from the Logicmonitor.
Integrate Oracle Cloud Infrastructure alarms -- Integrate Oracle Cloud Infrastructure (OCI) alarms with Event Management to send events into ServiceNow by adding a https subscription using Basic Authentication.
Integrate Prometheus events -- Integrate Prometheus with Event Management by adding a standard webhook in Prometheus's Alert Manager.
Integrate Sentry events -- Integrate Sentry with Event Management by adding a standard webhook in the Sentry platform.
Integrate Scout APM events -- Enable the collection of events from Scout APM by authenticating Scout APM as a data source to integrate it with Event Management.
Integrate Sumo Logic events -- Use the Sumo Logic push connector to integrate Sumo Logic with Event Management by adding a standard webhook in the Sumo Logic platform.
Integrate Sumo Logic with REST API key token -- Integrate using an API key to establish secure communication and automate data exchange via REST API. This simplifies integration, enabling seamless access to services and enhancing operational efficiency.
Integrate ThousandEyes with REST API key token -- Integrate using an API key to establish secure communication and automate data exchange via REST API. This simplifies integration, enabling seamless access to services and enhancing operational efficiency.
Integrate Panopta as a data source -- Integrate the Panopta cloud-based monitoring solution with Event Management. To add Panopta as a data source, configuration is required in Panopta.
EIF events warning severity -- If the EIF event payload has a warning severity, it will be mapped differently in the ServiceNow instance.
Create a push connector configuration parameter -- Some connectors have no parameters that are shipped out of the box. Therefore, it’s necessary to create and add the parameter to the push connector configurations list in the form layout before adding the new parameter.
Configure event collection for SNMP traps -- The SNMP listener runs on the MID Server, which acts as a collection endpoint for SNMP traps. The MID Server sends the traps to the ServiceNow instance for further processing as an event by Event Management.
Configure message keys to spread SNMP object identifiers -- By default, most SNMP trap events are processed by a single Event Management processing job. This can negatively effect event processing. Configure message keys on the MID Server to ensure that more than one processing job is invoked, ensuring optimal SNMP trap performance.
Event forwarding -- Accelerate the event processing testing life cycle by forwarding a stream of events from your ServiceNow production environment to your non-production environment.
Set up event forwarding -- Create an event forwarding configuration record to enable events to flow from one ServiceNow instance to another instance. Forwarding events to multiple target instances requires creating separate configuration records for each target instance.
Periodically run an event forwarding job -- Activate the event forwarding job to periodically send events to all target instances with active event forwarding configurations.
Processing Events -- Event processing is the process of taking events or streams of events, analyzing them and taking automatic action. The process includes viewing events, event binding, event rules and event field mapping.
View events -- Event Management tracks individual events to manage external systems. These events are notifications from monitoring tools indicating occurrences of interest, like log messages, warnings, or errors. Event Management gathers events from external sources and stores them in the Event [em_event] table, offering a list of raw incoming events.
Team-based integrations -- Team-based integrations empower teams to optimize event processing within Event Management to enhance efficiency and operational effectiveness.
Event rules -- Use event rules to generate alerts for tracking and remediation. Event rules are stored in the Event Rule [em_match_rule] table. Configure and customize event rules to manage events and alert generation.
Create or edit an event rule -- You can create event rules to generate alerts for tracking and remediation. Use team-based integrations in event rules to make sure that connector ownership and execution of rules give precedence to general rules. Teams can maintain consistency and hierarchy while offering flexibility and customization options.
Use event input information -- The Event Input pane that is included in the steps to create an event rule provides a reference to the information that you can use when configuring an event rule.
Filter the events that an event rule applies to -- Define a filter to restrict to which events the event rule must apply. Configure the filter by providing a set of conditions that each event must match to be either excluded or included from applying to the event rule.
Events without matching rules -- Find events that are not matched to any rules, and determine if it is necessary to create event rules to manage them.
View event rules -- You can view all event rules on the Event Rules list.
Define event rules to modify alerts -- You can configure an event rule to customize alert content. You can customize the order of the fields and select which fields display. The fields in the left-hand work area of the Transform and Compose Alert Output section of an event rule are the fields that appear in the generated alert.
Set suppression threshold -- The event threshold is the rate upon which Event Management generates an alert. Receiving multiple events for a device over a short interval may warrant creating an alert, as the condition may be serious. However, receiving events over a longer interval may indicate a less serious situation which would not warrant creating an alert.
Binding alerts to CIs -- CI binding or linking is the process of finding and connecting a Configuration Item (CI) from the Configuration Management Database (CMDB) to an alert, using the logic defined in event rules. This helps ensure alerts are tied to the right IT components for better visibility and faster issue resolution.
Binding process flow -- Learn the process of binding Configuration Items (CIs) to alerts. This includes handling event arrival, binding alerts using available fields when no node is present, and searching the CMDB for matching hosts. It also explains linking alerts to CIs based on host and CI type detection.
Binding alerts to a specific host CI (default binding) -- Binding alerts to Configuration Items (CIs) using the Node field or the CI Identifier field ensures accurate event association. By comparing an event record’s Node or CI Identifier value, alerts are linked to the right system. This improves response, root cause analysis, and impact assessment by providing clear visibility into affected assets.
Overriding default binding -- Overriding default binding allows flexibility in linking alerts to CIs beyond the default Node-based matching. This helps customize alert binding based on business needs, ensuring accurate associations and preventing mislinked alerts, improving incident management and root cause analysis.
Bind host CIs using CI field matching -- When CI Field Matching is used and the CI is a host, the Node value from the alert is used for binding. The system compares the Node with attributes like Name, FQDN, IP, or MAC Address in the CMDB to find a match. This ensures that alerts are correctly linked to the corresponding host CI.
Bind alerts to a specific device -- Bind each alert directly to the originating device to establish a clear source of impact. This ensures accurate troubleshooting, reduces noise from unrelated alerts, and helps teams focus on resolving the right issue faster.
Bind alerts to a specific process -- Bind specific server processes to their corresponding Configuration Items (CIs) in the CMDB to ensure accurate mapping and visibility. This binding is crucial for identifying service dependencies, reducing ambiguity from generic process names, and enabling effective monitoring. It supports faster alert resolution, impact analysis, and better alignment between infrastructure and application components in dynamic environments.
Bind non-host CIs using CI field matching -- If no match is found using the Node field, the system uses the CI identifier field to match alerts with non-host CIs based on attributes like Name, FQDN, IP, or MAC. This ensures accurate alert association, improving visibility, troubleshooting, and root cause analysis for diverse infrastructure components.
Bind CIs using CI field and column matching -- Bind CIs by matching event Additional information fields with CI attributes. If column names differ, manually create an additional key-value pair to align with the CI table, ensuring accurate CI association.
Bind alerts to CIs using CI identification -- Bind alerts to specific applications on hosts using event rules to ensure accurate tracking and to improve issue resolution speed—leading to efficient remediation and better alignment of alerts with the right resources.
Example: Binding alerts to non-host CIs -- Bind alerts to an application service (a non-host CI) using event rules and event field mapping. This example demonstrates how to achieve this by leveraging the IP address associated with the service.
Example: Bind alerts to CIs using dynamic CI types -- Use event field mapping to dynamically bind alerts to the appropriate CIs based on event attributes, eliminating the need for separate event rules for each CI type (also known as CI class). This approach simplifies configuration, improves accuracy, and enhances alert to CI binding.
Event grouping patterns -- Event groups are sets of events that do not have a matching event rule. You can view the patterns in a group of events to learn the impact of creating a rule based on the event source and description patterns.
Refresh event rules -- Manually update event rules to reflect current event information because once an event rule is created, the Event Additional info and Event Raw info fields are not automatically updated.
View rules for an event -- View the rules that will be applied on an event to determine how this event will be processed.
Simulate event processing -- You can simulate event processing logic on events and display the resulting alert to better understand which rules are executed on a given event and how the event fields change after the rule is executed.
Create event field mappings -- Use event field mappings to map values from specific event fields to values in other fields to provide more comprehensive information in an alert. Use team-based integrations in event rules to make sure that connector ownership and execution of rules give precedence to global rules. Teams can maintain consistency and hierarchy while offering flexibility and customization options.
Event identifiers -- Event identifiers uniquely distinguish one event from another. Event Management uses these identifiers to determine whether to create a new alert or update an existing one.
Alert tags -- Alert tags allow consolidation for all normalized fields and improve the admin experience to transform and normalize alert fields (key/value) enabling reuse of normalized fields across different sources. This improves alert quality for correlation and provides more out-of-the-box TBAC (Tag Based Automatic Correlation) definitions.
Custom alert fields -- You can populate custom alert fields with data contained in Additional information field of the event.
Testing and sending events -- You can manually test and send events to confirm that Event Management properly manages events and generates alerts.
View event processing statistics -- Extract statistics from your instance to ensure that performance is not affected and extract metrics related to event processes to monitor event processing status.
Enable event stats processing -- Enable the system property that switches on statistics processing for events to let the platform collect and analyze metrics such as event volume, processing flow, and handling time. This helps you monitor system performance, identify bottlenecks, and optimize event handling for faster and more efficient operations.
Configure statistics processing period -- Set the time period, in seconds, for collecting event processing statistics. For example, you can set a time period twice as long as the default 60 seconds to collect more statistics.
Manage and monitor alerts -- An alert is a notification for selected events that are considered to be important and require attention. Event Management generates alerts based on event rules.
Alert management rules for resolving alerts -- You can configure Event Management to respond to alerts automatically. An alert management rule determines the required alert response, such as to open an incident, knowledge base article, open a task, launch remediation action.
Create an alert management rule -- Create an alert management rule to track alerts and resolve them by determining the required response, for example, to open an incident or launch remediation action.
Subflows in the base system -- The subflows provided with the base system appear in the Remediation Subflows area of alert management rules.
Create a custom subflow for alerts -- You can create a subflow according to your requirements. For example, you can resolve alerts, notify teams, or run remediation actions.
Alert executions information -- Alert executions information provides a reference to the alert management rule actions that are performed. This information appears in the Alert Management Rule record only if an alert matches the filter in the rule and an action was performed. You can click any link in the Alert Executions list to open the referenced item.
View alert execution information -- You can click any link in the Alert Executions list to view the alert execution information of the referenced item. This information appears in the Alert Management Rule record only after an alert matched the filter in the rule and an action was performed.
Migrate alert action rule -- Existing alert action rules from an earlier release can be executed, but cannot be modified. Alert action rules that have been migrated become alert management rules and all the definitions of the alert action rules are migrated to the alert management rule format. Migrated rules can be modified.
Alert grouping and response sync -- Synchronize alert response with grouping by ensuring alert management jobs runs after alert grouping jobs—this prevents duplicate actions like incident creation on secondary alerts.
CI Remediation -- Alert and configuration item (CI) remediations help troubleshoot and resolve underlying problems that generate alerts. Remediation is based on Orchestration workflows that can be scripted to perform remediation tasks such as gathering system information or rebooting a server.
Create or edit CI remediation -- Create a CI remediation rule that lets users manually apply an Orchestration workflow for resolving issues with specific CIs associated with alerts. Define these CIs in the CI filter conditions of the rule.
View remediation tasks -- Event Management automatically creates a remediation task to capture every remediation that was applied to a CI or to an alert. It gives you an overall view of remediation activities in the organization.
How alerts work with CIs in maintenance -- When a CI is in maintenance, the impact tree, the service map, and Alerts tab are updated based on various factors.
Create an SLA configuration for CIs -- Create an SLA configuration from the Event Management application to determine which CIs are available for SLAs.
Alert lifecycle configuration -- Event Management provides various modules, templates, and properties for configuring alerts and the actions that execute for these alerts.
Configure the alert active interval -- The active interval property (evt_mgmt.active_interval) determines how Event Management handles a new event that is similar to events that appear on an existing closed alert. Based on the active interval, event, and existing closed alert information, the alert is reopened and the event information is added to the existing alert or a new alert is created.
Configure alert flapping -- Set flapping properties to determine when an alert enters and exits the flapping state. Flapping can indicate configuration problems (that is, thresholds set too low), troublesome services, or real network problems.
Alert priority -- Determine the order in which to handle alerts according to the alert priority score. Multiple factors determine the alert priority score and this value changes with changes to the underlying factors.
Alert assignment groups for teams -- Alert assignment groups assign alerts to the right teams promptly and automatically, improving overall incident management capabilities.
Alert group precedence setup -- Assign alert assignment group precedence to make sure that alerts are routed to the appropriate team members.
Create a predefined Express List view for users -- Configure an Express List view for users to make sure that they focus on specific services, priorities, or alerts. You can set the filters, column order, and filter attributes for this view and assign it to individual users or user groups.
Assign users and groups -- Assign individual users and user groups to preconfigured Express List views to make sure that they focus on specific services, priorities, or alerts.
Alert impact calculation -- Impact calculation shows the magnitude of an outage on CIs, services, alerts, and alert groups. The system uses factors such as impact rules and CI relationships to calculate the severity of a generated alert. The severity appears on the impact tree, application services maps, and dashboards.
Understand Service Maps -- Service maps show active alerts for CIs and the relationships between CIs. By viewing this information, you can better understand the source of alerts and take remediation steps. The service map is available for all application services.
View the impact tree -- The impact tree shows the relationships between CIs and the relative percentage impact for each child CI. This information is available for both discovered services and application services.
Adjust impact rules for a CI -- Configure impact rules to customize the impact calculation for discovery services and manual services. The impact rules update the overall alert and show the impact on related CIs. When you change impact rules, the updates apply to alert severity in places such as the Event Management dashboard and Operator Workspace.
View an alert impact on CIs in a service map -- You can view service maps to see active alerts for CIs and the relationship between CIs. By viewing this information, you can better understand the source of alerts and take remediation steps. The service map is available for all application services.
Create an infrastructure relationship for related CIs -- Infrastructure relationships show CIs that are connected to a application service but are not necessary parts of the service. Infrastructure relationships are only available for application services.
Add CMDB tables or classes for impact calculation -- Add the CMDB tables that contain application services to be considered during impact calculation, helping ensure accurate and relevant impact results.
Alert similarity -- Finding alerts that are similar to the alert that you are currently investigating can help save troubleshooting time by seeing how similar alerts were resolved.
Find similar alerts -- You can find alerts similar to the alert currently being investigated. Save troubleshooting time by reviewing similar alerts to see how they were resolved.
Similarity solutions -- Similarity solutions enable you to use Machine Learning (ML) to compare the text in a resolved alert record to an open alert record to reuse its resolution approach.
Create similarity solution -- Create and train a solution that applies machine learning to a collection of words to target and suggest similar alerts in your instance dataset. For example, you can compare the text in a resolved alert record to an open alert record to reuse its resolution approach.
View solution training progress -- View solution training progress or statistics to determine whether a solution is available or how long the next training cycle might take to complete.
Review similarity examples -- Review the similarity examples and scores that the system provides during solution training to see how the selected alert record compares to existing alert records. For example, you can modify the similarity score threshold to increase the accuracy of your similarity recommendations.
Activate solution version -- The system activates the most recent version of the solution, but you can activate any previously trained Event Management solution version if it is more appropriate.
Start or stop self-health monitoring -- You can control the starting or stopping of the self-health monitor feature by configuring the self-health monitoring property. The first time that the self-health monitoring property is enabled, it automatically creates the ServiceNow Event Management application services.
Monitor self-health with domain separation -- Use domain separation to enable self-health to display Event Management health issues that are based on data, rules, and settings from the logged in user domain. The selected domain must not contain any child domains.
Configure a self-health monitor -- You can configure a self-health monitor to track Event Management components and see that they do not exceed the specified threshold.
Create custom health monitor -- You can create a self-health monitor to use custom health monitor script to monitor specified Event Management components.
View self-health app services map -- You can view Event Management application services maps to have a visualization of the data on configuration items (CIs) that comprise this service, and the relations and connections between these CIs.
Create maintenance rules -- Use maintenance rules to mark CIs in maintenance status. When in maintenance status, these CIs are excluded from impact calculation.
Resolve an incident related to an alert -- When you resolve an incident that is associated with an alert, the alert can also close according to the evt_mgmt.incident_closes_alert property.
Close an alert -- Close an alert by an event or a user action. Closing an alert also closes any related incident that is not already resolved or closed.
Reopen an alert -- Additional events can cause reopening of alerts, or you can reopen an alert by changing its state. When an alert reopens, any associated incidents can also be updated or reopened according to the incident state and the evt_mgmt.alert_reopens_incident property.
Rotate event and alert table for cleanup -- The growth of data tables impedes performance. Preserve instance performance by event table rotation and alert table cleanup for status and alert history retention.
Modify event table rotation -- Table rotation is used by Event Management, by default, to contain the growth of event [em_event] tables within the rotation table group.
Purge impact status and alert history -- Automatically cleans up outdated impact statuses and alert history from the database to free up space, improve system performance, and ensure only relevant data is retained.
Clean alert history and impact status tables -- Schedule jobs to mark and remove old alert records in the Alert History [em_alert_history] and Impact Status [em_impact_status] tables, to prevent the tables from becoming overloaded with data.
Alert table clean up -- The Scheduled Jobs feature runs a script to automatically close alerts in the Alerts [em_alert] table that meet specific conditions, helping reduce alert noise and keep the system clean and efficient.
Alert grouping -- Alert grouping is the process of organizing and consolidating related alerts into sets based on common characteristics or criteria. This helps in simplifying alert management by reducing noise, making it easier to prioritize, track, and address issues efficiently. Grouped alerts provide a clearer overview of related incidents, facilitating quicker root cause analysis and remediation.
Alert grouping and use cases -- Alert grouping methods range from user-defined approaches, like Manual and Rule-based to advanced, fine-tunable algorithms, including Automatic, Mixed, Text-based, Log Analytics, and Network Traffic-based grouping.
Configure alert correlation logic order -- Improve alert management by enabling users to customize correlation logic order. This feature empowers you to fine-tune correlation methods to their specific needs, enhancing alert prioritization and response efficiency.
Configure filters for automatic alert groups -- Filter alerts and alert groups to reduce alert noise. Only alerts that match the filter are included in the group of the selected group type (Automated, CMDB, or Text).
Apply alert group filters to aggregated groups -- Reduce noise by locating only aggregated alert groups that match a configured filter. Aggregated groups are groups created for alerts with identical CIs and pattern identifiers.
Alert grouping types and creation methods -- Explore different alert grouping types, understand their descriptions, and learn about their creation methods to enhance problem identification and streamline alert management.
Mixed alert grouping -- Mixed alert grouping combines multiple strategies—currently CMDB-based, tag-based, related log entities-based, and shared impacted services-based grouping—to form a single, cohesive alert group. It reduces noise, bridges gaps when one method isn't enough, and delivers a clearer, end-to-end view of incidents. This approach helps operators identify root causes faster and take informed action, even in complex or incomplete data environments.
CMDB based alert grouping -- CMDB based alert grouping helps organizations manage alerts by organizing them according to their related configuration items (CIs) within the Configuration Management Database (CMDB). This method group alerts based on CI relations in applications or infrastructure components, allowing teams to better understand the impact of issues, respond more effectively to alerts, and maintain service availability.
Use cases for CMDB based alert grouping -- Use cases for CMDB grouping enhance alert management by correlating alerts based on Configuration Item relationships, improving visibility, and facilitating more efficient troubleshooting.
CMDB alert grouping — properties and functionality -- Learn about the key properties and functionality of CMDB alert grouping, which facilitate efficient alert organization based on relationships and enhance the overall effectiveness of alert management.
View the Dependency map for CMDB alerts -- The Dependency map illustrates how and why alerts are grouped, simplifying troubleshooting and issue management. It reveals connections between CIs within a CMDB alert group, enhancing visibility into their relationships. Additionally, if a CI is not part of the group but connects to other alert CIs, it remains visible on the map, aiding alert resolution and proactive management.
Tag cluster alert grouping -- Tag cluster alert grouping enables you to easily create groups of alerts. It is a non-code method of alert grouping that correlates alerts without having to use CMDB or model training. This simpler way of grouping similar alerts reduces the overall noise of a large quantity of alerts.
Create alert clustering tags -- Create streamlined alert correlations with alert clustering tags by grouping alerts that share identical or similar tags based on your configured match method. This reduces noise, enhances incident prioritization, and improves operational efficiency, enabling faster issue resolution and response times.
Create an alert clustering definition -- Define alert clustering conditions to trigger one or more alert clustering tags, which help create alert groups from fewer alerts. Creating alert groups from fewer alerts reduces noise, making it easier to identify critical incidents, prioritize responses, and manage issues effectively.
Activate a predefined alert clustering definition -- Activate the predefined alert clustering definitions provided with the Tag-Based Alert Clustering Engine application before use. Utilizing these preconfigured definitions minimizes setup time and ensures a more efficient configuration process, allowing for quicker implementation and streamlined alert management.
Assign tag to alert grouping -- Get started faster with alert clustering by attaching a predefined alert clustering tag to a tag-based alert clustering definition in Event Management. By associating a predefined tag, you ensure that alerts meeting the specified criteria are grouped effectively, facilitating quicker identification and response to related incidents.
Related log entities alert grouping -- The Related log entities (formerly known as Health Log Analytics alert grouping automatically gathers HLA alerts that originate from the same log query job into a single, organized group. Instead of a scattered collection of individual log-based alerts, your team gets one consolidated view of everything tied to the same underlying log event — speeding up issue response.
Shared impacted services alert grouping -- The Shared impacted services alert grouping automatically gathers related alerts under the business service they affect. When your IT environment generates multiple alerts at once, instead of facing a flood of disconnected notifications, your team gets one focused, organized view — making it faster to spot what is broken and act.
Rule-based alert grouping -- Rule-based alert grouping is created by alert correlation rules. These rules allow you to manually classify alerts as primary or secondary and establish a relationship between them. Use alert correlation rules to group related alerts. The rule runs only for new alerts or alerts whose status changed from close/flapping to open/reopen.
Create an alert correlation rule -- Create an alert correlation rule to designate primary and secondary alerts. The primary alert is identified as the root cause of the alert group and the secondary alerts are grouped under the primary alert.
Automated alert grouping -- Automated alert grouping is a process that uses historical data to automatically organize similar alerts into groups. These alerts could be system issues, like server errors or network outages. By grouping related alerts together, it helps teams quickly identify patterns, manage recurring problems, and reduce the noise from too many individual alerts.
Understanding pattern identifiers -- A pattern identifier is a set of criteria or attributes (such as alert type, affected system, etc.) used to group similar alerts. It helps to identify recurring issues, making it easier for teams to respond and address ongoing problems.
Configure pattern based alert grouping -- Configure the Alert Aggregation Learner (Service Analytics Alert Aggregation Learner - Daily), an offline job that runs daily to process past alerts. It identifies patterns of related alerts using a combination of pattern-based and probabilistic techniques, enabling quicker detection and resolution of recurring issues.
Manage grouping pattern attributes -- The Alert Aggregation Learner analyzes alerts and identifies patterns using a defined set of alert and configuration item (CI) attributes. By configuring these attributes as pattern identifiers, you can control which characteristics are used to group alerts. This customization creates meaningful alert groups, improving alert management and response times by reducing noise and enabling focus on critical issues.
Learned patterns report -- The Learned Patterns report helps assess the efficiency of alert aggregation and identify recurring alert patterns. It enables proactive issue resolution, enhancing overall system performance by providing insights into frequent alerts.
Exclude CI-based patterns -- Exclude CI-based or CI class-based alerts and patterns when you encounter alerts incorrectly added to a learned pattern by the Learned Patterns job. For example, a pattern might include an alert that occurred at the same time as other alerts but is not actually related to them. This maintains accuracy, ensuring better alert groupings and improved management efficiency.
Restore excluded patterns -- Restoring excluded patterns to the learned patterns report lets you reintegrate valuable insights lost due to incorrect alerts. This flexibility maintains accurate alert aggregation and enhances monitoring. For example, if you excluded a pattern due to an incorrect alert, you can restore it without that alert, ensuring relevant data remains accessible for analysis and decision-making.
Network traffic based alert grouping -- The Network traffic based alert grouping method groups alerts by analyzing network traffic connections between processes across hosts. It leverages service candidates identified by ML Service Mapping to group alerts related to network traffic issues. This ensures alerts from directly connected processes within the same service candidate are grouped together, offering a more contextual view of network incidents.
Enable network traffic-based alert grouping -- Activate network traffic-based alert grouping to automatically correlate and reduce alert noise by grouping related events based on network traffic patterns. This helps improve efficiency in alert response and streamlines alert management.
Disable network traffic-based alert grouping -- Disable network traffic-based alert grouping to prevent alerts from being grouped solely by network activity, reducing noise during traffic spikes and ensuring critical issues stand out for quicker resolution.
Follow up on work notes and review service candidate -- Track and follow up on work notes while reviewing the service candidate to ensure all actions and updates are captured. This helps maintain clarity and continuity in the review process, reducing the chances of missed details.
Text-based alert grouping -- In text-based alert grouping, alerts are organized and correlated based on specific text patterns or keywords within the alert content. This approach dynamically groups alerts that share similar textual characteristics, such as error messages or event descriptions, allowing for more flexible and adaptive management of alerts.
Verify text-based clustering solution -- Event Management uses Natural Language Processing (NLP) algorithms to identify common text patterns in alerts and create alert groups through clustering. This approach not only organizes similar alerts efficiently but also reduces noise and helps focus on significant issues, enhancing overall alert management.
Manual alert grouping -- Manual alert grouping involves organizing and categorizing alerts based on user-defined criteria and direct intervention.
Create alert group manually -- Manually create an alert group to organize and manage related alerts when not using scheduled jobs. This provides flexibility to group alerts on-demand for effective resolution.
Add secondary alert manually to an existing alert group -- Add any relevant alert discovered during the review of an automated alert group as a secondary alert to improve the group's completeness and utility for incident troubleshooting.
Remove an alert from an alert group -- Remove an alert if you want to improve the group's accuracy and usefulness in troubleshooting an incident. If this action leaves the group with one or no alerts, the group is deleted and no longer displays as an alert group.
Configure grouping worknotes types -- As alerts are added to a group, a message is recorded in the alert’s Work notes field to explain why the alert was included in the group. Define alert types for creating these worknotes related to alert group reasoning.
Application services in Event Management -- An application service is a set of interconnected applications and hosts which are configured to offer a service to the organization.
Create application service manually -- You can manually create an application services. Event Management can use application services to monitor service performance and identify health issues.
Convert manual services to application services -- You can convert existing manual services to application services. Event Management can use application services to monitor service performance and identify health issues.
Convert manual services to application services using API -- You can use a JavaScript API to convert existing manual services to application services. Event Management can use application services to monitor service performance and identify health issues.
Configure CIs as manual cluster -- Configure or modify a CI as a specific CI or a generic CI class in a manual service (that was not discovered automatically) as a manually defined cluster. A manual cluster delivers redundancy capabilities in the cluster and provides continued operations or services of the entire cluster in case of failure of one or more CIs in that cluster.
Configure a manual cluster -- Provide redundancy capabilities of an entire cluster in case of failure of one or more CIs in that cluster. By viewing the relative impact of a cluster member on the cluster information, you can better understand the source of alerts and take remediation steps.
Modify a manual cluster -- Modify an existing manual cluster by changing the service, the specific CI, the generic CI class, or the description in case of an incorrect initial configuration, changes in the network, or other issues.
Create an alert query -- An alert query is a set of alerts that meet specific criteria for a particular service.
Create an application service group -- Create service groups to combine similar services. Organize services by groups to perform actions simultaneously on multiple services and to control user access to services.
Assign a role to a service group -- Assign an Event Management role to the application service group to ensure that group members can manage and act on alerts.
Activate and configure Service Mapping for top-down discovery -- A top-down discovery provides a list of CIs and their interrelationships. This information is useful for managing software services and hardware issues that are associated with alerts.
Configure contextual colors and icons -- Use the Contextual colors and icons form to configure color, text, and icons to have different default or custom contexts, identified by a context ID.
View Event Management license usage -- Event Management is licensed based on the number of CIs bound to alerts during the last year. For alerts that are not bound to CIs, the system calculates the number of nodes (servers) that can send events to the instance directly or through a third-party monitoring tool during the last year.
Using Event Management -- As an Event Management operator, your role is to find alerts, analyze them, and take action to help resolve the underlying issue.
View alert information -- View a list of all alerts for application services s, and then manage individual alerts as necessary.
Priority group -- For better triage and focus, alerts that have a higher priority are brought to the top of the alert list. This placement brings to your attention those alerts that require you to handle them at a higher priority than other alerts.
Alert execution information -- Alert execution information provides a reference to the actions that have been performed concerning the alert. Among the information presented is which alert management rules ran on the alert, incidents that were opened, and which remediation workflows ran.
View all alerts by the maintenance status -- The Maintenance status indicates that the CI is under maintenance. For example, there is a software upgrade, and the issues can result from that activity, therefore all maintenance alerts are discarded.
In-alert collaboration -- You can collaborate with colleagues and write work notes while working in an alert.
Place an alert into maintenance -- You can manually place any alert into maintenance to hide it from the Alerts list and Agent Workspace.
Alert insight information -- Alert insight aids faster alert triage, enabling a quicker way to find a solution and expose the probable root cause of the selected alert.
Apply a quick response in an alert -- In an alert, use the Quick Response feature to apply remediation to the alert or to launch a web application.
Monitor service health -- On the Operator Workspace, you can view alerts by application services, technical service, and alert group. For services, you can also open a service map to view relationships between CIs in the service.
View discovered service history -- The discovered service history shows the frequency of discovered services for a particular time period.
Monitor alerts for an application services -- To view information for application services only, navigate to the application services list. From this list, you can open service maps to view and manage alerts for the CIs in each service.
View monitored services -- View all services that Event Management supports, such as, alert groups, discovered services, application services, and technical services. According to the type of service, you can view service definition details or drill down into the service.
Use the Overview dashboard -- The Event Management overview module uses Performance Analytics to present data from your instance for you to better visualize and understand your processes and drive continual improvement.
Launch web application from alert -- You can launch a web application from an alert that matches the conditions set in an alert action rule.
Event Management Operator Tutorial -- As an Event Management operator, your role is to find alerts, analyze them, and take action to help resolve the underlying issue.
Alert overview -- As an Event Management operator, you need to understand how an alert is generated from an event, what to look for in an alert, and how alerts can be grouped together.
Application services -- As an Event Management operator, you need to understand what application services are.
Operator environment -- As an Event Management operator, your primary work environment is the Service Operations Workspace dashboard.
Operator responsibilities -- As an Event Management operator, your typical workflow involves three phases: analyzing an alert and its effect on application services, taking some type of action, and making sure the alert is finally closed.
Operator phase 1: Analyze and acknowledge an alert -- As an Event Management operator, the first thing you should do is access alerts and then find the ones you want to focus on. You can open the Alert form to analyze the details, and then acknowledge it to let other operators know that the issue causing the alert should be addressed in some way.
Operator phase 2: Triage an alert -- After you analyze and acknowledge an alert, you must triage it. The triage phase involves verifying alert correlation and taking an action to help resolve the issue that caused the alert. This topic covers the most common triage task: creating an incident from an alert.
Run a remediation workflow on an alert -- As an Event Management operator, you can also run a workflow on your ServiceNow instance that helps remediate the alert. For example, you might run a workflow that automatically restarts a server on your network, which might resolve an alert about CPU usage.
Launch a web application from an alert -- As an Event Management operator, you can also launch a web application from an alert. The web application might be a console for the event monitoring tool that your organization uses, or any external website that provides additional information you might need about the alert.
Associate a knowledge base article with an alert -- As an Event Management operator, you can associate a knowledge base (KB) article with the alert to capture additional information about the alert. This might include a procedure that someone has to follow to resolve the underlying issue on your network, or a best practice to prevent the issue from reoccurring.
Put an alert into maintenance -- As an Event Management operator, you can put an alert into maintenance if the alert does not require any further action, but you still want to keep the alert active. Putting the alert into maintenance hides it from the Service Operations Workspace dashboard so that other operators do not need to access it, but it does not close the alert.
Operator phase 3: Close an alert -- After you take action on an alert, you can verify several items on the alert and then close it.
Advanced operator responsibilities -- As an Event Management operator, you might need to perform additional tasks that are outside of your typical workflow, or tasks that you need to perform only once.
Customize your alert list view -- You can create one or more customized alert list views that show only the information pertinent to you. For example, you might want to focus only on the alerts for application services in a specific location, or only the alerts for application services of high criticality.
Work with flapping alerts -- If an alert is in the flapping state, you might need to triage the alert again.
Handle alerts while CIs are in maintenance -- When an alert occurs on a CI that is in the maintenance state, the alert state is also changed to maintenance. You should find and monitor the states of these alerts. Later, when changes on the CI are complete, finish triaging the alert and close it.
Adjust alert impact while triaging an alert -- As an Event Management operator, you might need to modify the impact that an alert has on an application service and on the CIs in a service. Do this when you think that the impact does not accurately represent what you see in your network environment so other operators and administrators see the correct impact information.
Event Management reference -- Reference topics provide additional information about mapping and fine-tuning application services using Event Management lists and forms.
Roles -- Activating the Event Management (com.glideapp.itom.snac) plugin adds several roles, scheduled jobs, and tables.
Scheduled jobs -- Activating the Event Management (com.glideapp.itom.snac) plugin adds several roles, scheduled jobs, and tables.
Properties for domain separation -- Activating the Event Management (com.glideapp.itom.snac) plugin adds several roles, scheduled jobs, and tables.
Tables -- Activating the Event Management (com.glideapp.itom.snac) plugin adds several roles, scheduled jobs, and tables.
Event Management Platform Analytics Solutions -- Platform Analytics Solutions contain preconfigured dashboards. These dashboards contain actionable data visualizations that help you improve your business processes and practices.
Tag-based alert grouping form -- The form for creating or modifying a tag based alert clustering tag displays detailed information about the tag.
List of predefined alert grouping tags -- A list of the predefined alert clustering tags provided with the Tag Based Alert Clustering Engine application.
Tag-based alert grouping definition form -- The form for creating or modifying a tag based alert clustering definition displays detailed information about the definition.
Domain metadata properties -- Use the domain properties installed with Event Management to provide the metadata that points to the appropriate table to identify the domain so that you know which domain to create the event in.
Connector domain metadata -- Override push connector default domain metadata values installed with Event Management with the values in the event HTTP request, including the URL, headers, request body (payload), and connector parameters. Override pull connector domain metadata values with connector parameters only.
Dynatrace connector instance form -- The Dynatrace connector instance form displays the fields you must fill in when creating a Dynatrace connector instance.
Dynatrace connector instance value parameters -- The following table displays the Dynatrace connector instance value parameters that you can fill in, as needed, when creating a Dynatrace connector instance.
Push connector instance form -- Push Connector Instance form displays the fields that you must fill when you create or modify a connector.
Nagios connector instance value parameters -- The following table displays the Nagios connector instance value parameters that you can fill in, as needed, when creating a Nagios connector instance.
Nagios connector instance form -- The Nagios connector instance form displays the fields you must fill in when creating a Nagios connector instance.
Zabbix connector instance form -- The Zabbix connector instance form displays the fields you must fill in when creating a Zabbix connector instance.
Zabbix connector instance value parameters -- The following table displays the Zabbix connector instance value parameters that you can fill in, as needed, when creating a Zabbix connector instance.
SCOM connector instance form -- The SCOM connector instance form displays the fields you must fill in when creating a SCOM connector instance.
Solarwinds connector instance form -- The Solarwinds connector instance form displays the fields you must fill in when creating a Solarwinds connector instance.
Solarwinds connector instance value parameters -- The following table displays the Solarwinds connector instance value parameters that you can fill in, as needed, when creating a Solarwinds connector instance.
Team-based integration properties -- Team-based integration system properties enable you to customize the assignment group functionality for existing and new customers for event rules and event field mapping.
Alert Query form -- You can combine similar alerts that meet specific criteria for a particular service by creating an alert query.
Health Log Analytics -- The ServiceNow Health Log Analytics application helps prevent IT issues before your users are affected. It helps you identify the root cause of an issue by enabling you to triage related logs and analyze the raw data.
Exploring -- ServiceNow Health Log Analytics (HLA) predicts IT issues before they affect your users by collecting, analyzing, and correlating machine-generated log data in real time. It discovers anomalies and alerts you to potential issues.
Architecture -- Health Log Analytics collects logs streaming into your ServiceNow instance from endpoints or data lakes, such as Splunk and Elasticsearch.
Terminology -- Before getting started with Health Log Analytics, it's important to familiarize yourself with some key concepts used in the application.
How Health Log Analytics generates alerts -- Health Log Analytics identifies patterns in your log data and learns pattern behavior. When HLA's AI engine detects anomalous behavior, it sends an event to the ServiceNow Event Management application. As an operator, you can use these predictive alerts to handle emerging IT issues before they impact users.
Types of anomalous behavior -- Anomalous behavior in a CI or a service can indicate an important issue. For example, a spike in the frequency or number of messages of a particular type can indicate a problem.
Configuring -- As an administrator, set up and configure Health Log Analytics for operators to use, and carry out administration tasks to confirm that the system runs efficiently.
Install HLA -- Install Health Log Analytics by requesting ServiceNow HLA installation from ServiceNow Customer Support.
MID-less integrations -- Health Log Analytics (HLA) supports integrations that stream log data directly to your ServiceNow instance without a MID Server. Use these integrations to simplify your deployment and reduce infrastructure overhead.
MID-less log streaming -- Health Log Analytics (HLA) can receive log data from external sources directly through the ITOM Gateway, without routing data through a MID Server. This architecture supports cloud-native log sources such as Amazon Data Firehose, Cribl, and OpenTelemetry, and is required for high-volume HLA deployments.
Configure a JWT provider and token -- Configure a JWT provider and token to authenticate log streaming integrations sending data to Health Log Analytics (HLA) via ITOM Gateway. This configuration is required before you can activate any ITOM Gateway integration in Integrations Launchpad.
Set up log streaming via ITOM Gateway -- Set up log streaming via ITOM Gateway to enable Health Log Analytics (HLA) to receive log data directly from external sources without a MID Server.
Amazon Data Firehose -- Set up an integration to stream log data from Amazon Data Firehose directly to the ServiceNow datacenter, where it’s queued for Health Log Analytics processing. There’s no need to store AWS keys on your ServiceNow instance.
Cribl Stream -- Set up a Cribl Stream integration to stream Cribl log data directly to your ServiceNow instance, without a MID Server.
Microsoft Azure Event Hubs (MID-less) -- Set up an integration for streaming events from Microsoft Azure Event Hubs to your ServiceNow instance without a MID Server.
OpenTelemetry Collector -- Set up an OpenTelemetry Collector integration to stream log data directly to your ServiceNow instance using the OpenTelemetry (OTLP) protocol, without a MID Server.
Splunk OpenTelemetry Collector -- Set up a Splunk OpenTelemetry Collector integration to stream Splunk log data directly to your ServiceNow instance using the OpenTelemetry (OTLP) protocol, without a MID Server.
ACC Log Analytics (ACC-L) -- Set up an ACC Log Analytics (ACC-L) integration for streaming log messages to your ServiceNow instance. This integration can be used when agent-less log collection is impractical, for example because of security requirements or host accessibility.
Amazon CloudWatch -- Set up an integration for streaming log data from Amazon CloudWatch to your ServiceNow instance.
Amazon S3 -- Set up an integration for streaming log data from Amazon S3 (Simple Storage Service) buckets to your ServiceNow instance.
Apache Kafka -- Set up an integration for streaming log data from Apache Kafka to your ServiceNow instance for processing by Health Log Analytics.
Cribl -- Set up an integration to enable Health Log Analytics to process Cribl log messages streaming into your ServiceNow instance.
Edge Delta REST -- Set up an Edge Delta REST integration to enable Health Log Analytics to process logs it receives from Edge Delta in a distinct format. These logs stream into your ServiceNow instance via REST.
Edge Delta TCP -- Set up an Edge Delta TCP integration to enable Health Log Analytics to process logs it receives from Edge Delta in a distinct format. These logs stream into your ServiceNow instance over the TCP transport protocol.
Elasticsearch -- Set up an integration to stream log data seamlessly from Elasticsearch indices to your instance for Health Log Analytics processing.
GCP PubSub -- Set up an integration for receiving log messages that were published to a Google Cloud Platform (GCP) Pub/Sub topic and streaming them to your ServiceNow instance.
Microsoft Azure Event Hubs -- Set up an integration for streaming events from Microsoft Azure Event Hubs to your ServiceNow instance.
Microsoft Azure Log Analytics -- Set up an integration for streaming log data from Microsoft Azure Log Analytics to your ServiceNow instance. The integration points the Health Log Analytics AI engine to a data source in your Microsoft Azure Log Analytics account.
MID Server -- Set up an integration for collecting and streaming MID Server log messages to your ServiceNow instance for processing by Health Log Analytics.
REST API -- Set up an integration for streaming log data to your ServiceNow instance for processing by Health Log Analytics.
ServiceNow System Logs Retriever -- Set up an integration for streaming log data from your ServiceNow platform's System Log table to the HLA engine.
Splunk Poller -- Set up an integration that periodically pulls log data from Splunk to your ServiceNow instance for processing by Health Log Analytics.
Splunk TCP -- Set up an integration to stream log messages to your ServiceNow instance over the TCP transport protocol using a Splunk heavy forwarder. Health Log Analytics processes the ingested log data.
Splunk UDP -- Set up an integration to stream log messages to your ServiceNow instance over the UDP transport protocol using a Splunk heavy forwarder. Health Log Analytics processes the ingested log data.
TCP -- Set up an integration for sending log data to your ServiceNow instance directly over a TCP/SSL socket.
UDP -- Set up an integration for sending log data to your ServiceNow instance directly over a UDP socket.
Vector Agent -- Set up a Vector Agent integration to enable Health Log Analytics to process log messages that are streaming into your ServiceNow instance via a Vector Agent.
Monitor log data flow and optimize integration settings -- The Overview screen in Health Log Analytics provides a comprehensive view of the components in the log-processing pipeline of a specific active integration. From this screen, you can troubleshoot any streaming issues for this integration and adjust its settings if needed.
Review streaming data and adjust integration settings -- Review the log data streaming status and streaming sources of an active integration for Health Log Analytics on the integration's Overview screen. From this tab, you can investigate streaming issues and refine the integration settings. Leverage the displayed data to refine how HLA reads the log data by adjusting the integration's configuration.
Mapping logs for contextual alerts -- Map your logs to service instances, components, and source types so that Health Log Analytics can generate alerts in context.
Map logs for context -- Map your logs to service instances, components, and source types so that Health Log Analytics (HLA) can generate contextual alerts.
Activate a draft integration -- Activate an integration that was configured and saved as a draft in Health Log Analytics (HLA).
Edit an installed integration -- Edit an installed integration for streaming log data to Health Log Analytics on the Integrations Launchpad. For example, you can switch to a different service instance.
Deactivate an integration -- Deactivate an integration for streaming log data to Health Log Analytics on the Integrations Launchpad. A deactivated integration stops streaming logs to your ServiceNow instance, but is still available.
Set up data inputs using guided setup -- The Health Log Analytics guided setup provides a sequence of tasks to help you create data inputs on your ServiceNow instance. Data input configuration is an essential step in setting up the Health Log Analytics application. Using guided setup ensures that you have the minimum required setup for the data input process.
Set up data inputs manually -- Set up your Health Log Analytics data inputs for Health Log Analytics manually. Data input configuration is an essential step in setting up the Health Log Analytics application.
Manual data input configuration -- Configure the data input process manually in Health Log Analytics. Data input configuration is an essential step in setting up the Health Log Analytics application.
Amazon CloudWatch -- Set up a data input for streaming log data from Amazon CloudWatch to your ServiceNow instance.
Amazon S3 -- Set up a data input for streaming log data from Amazon S3 (Simple Storage Service) buckets to your ServiceNow instance.
Apache Kafka -- Set up a data input for streaming log data from Apache Kafka to your ServiceNow instance.
Cribl -- Configure a dedicated Cribl data input to enable Health Log Analytics to process Cribl log messages streaming into your ServiceNow instance.
Edge Delta -- Set up an Edge Delta data input to enable Health Log Analytics to process Edge Delta log messages streaming into your ServiceNow instance.
Elasticsearch -- Set up a data input for streaming log data from Elasticsearch indices to your ServiceNow instance.
GCP PubSub -- Set up a data input for receiving log messages that were published to a Google Cloud Platform (GCP) Pub/Sub topic and streaming them to your ServiceNow instance.
Microsoft Azure Event Hubs -- Set up a data input for streaming events from Microsoft Azure Event Hubs to your ServiceNow instance.
Microsoft Azure Log Analytics -- Set up a data input for streaming log data from Microsoft Azure Log Analytics to your ServiceNow instance. The data input points the Health Log Analytics AI engine to a data source in your Microsoft Azure Log Analytics account.
MID Server -- Set up a data input for collecting and streaming MID Server log messages to your ServiceNow instance.
REST API -- Set up a REST API data input for streaming log data to your ServiceNow instance.
Rsyslog, Filebeat, or Winlogbeat -- Set up a data input for streaming log messages to your ServiceNow instance using an Rsyslog, Filebeat, or Winlogbeat agent.
ServiceNow Log Export -- Set up a data input for monitoring ServiceNow instance node logs from both Java code and JavaScript in Health Log Analytics (HLA). This data input provides a complete view of your instance status, including server context.
ServiceNow System Logs Retriever -- Set up a data input for streaming log data from the ServiceNow System Log table to the HLA engine (aka Occultus).
Splunk -- Set up a data input for streaming log messages to your ServiceNow instance using a Splunk heavy forwarder.
Splunk Polling -- Set up a data input that periodically pulls log data from Splunk by using a query.
TCP -- Set up a data input for sending raw log messages to your ServiceNow instance directly over a TCP/SSL socket.
UDP -- Set up a data input for sending raw log messages to your ServiceNow instance directly over a UDP socket.
Vector Agent -- Set up a Vector Agent data input to enable Health Log Analytics to process log messages that are streaming into your ServiceNow instance via a Vector Agent.
Additional data input setup tasks -- After performing the initial data input setup and configuration in Health Log Analytics, continue with the remaining data input setup tasks.
Add a timestamp format -- Define any timestamp format that does not appear in the list of defined formats. Health Log Analytics must be able to read timestamps of any format contained in your log files.
Add a source type manually -- Create a source type manually before you configure a data input if you want to stream log data to a specific source type rather than to the source type automatically extracted by Health Log Analytics during the mapping process.
Configure source type capabilities -- Health Log Analytics extracts source types automatically in the mapping process. You can add timestamp formats and specify, delete, or exclude keywords for individual source types.
Verify your log sources -- Verify that all your log sources are present and active after Health Log Analytics tagging has assigned a log to a service instance and components, and has automatically mapped the log to a source.
Delete a log source -- Delete a log source with or without its associated log data in Health Log Analytics.
Review properties extracted from a source type -- Inspect the properties that were extracted from all the source types in a source type structure in a single table to identify any setup issues.
Review patterns extracted from a source type -- Inspect all learned patterns extracted from a source type in a source type structure, together with the log sources in which these patterns appeared. Reviewing these patterns can provide valuable insights into the log message patterns that Health Log Analytics tracks for each source type and log source.
Modify a data input configuration -- Change the configuration of a data input for Health Log Analytics by adding a new path to an existing data input configuration or modifying the data input's MID Server destination and port.
Advanced manual data input configuration -- When you have configured a data input successfully, Health Log Analytics adds a record to the Data Inputs table and attaches the configuration file to it. You can configure advanced settings for your data input. Configuring advanced settings is optional.
Amazon CloudWatch -- Configure advanced settings for data inputs used for streaming log data from Amazon CloudWatch to your instance.
Amazon S3 -- Configure advanced settings for data inputs used for streaming log data from Amazon S3 buckets to your instance.
Apache Kafka -- Configure advanced settings for data inputs used for streaming log data from Apache Kafka to your instance.
Beats -- Configure advanced settings for data inputs that use Beats agents.
Elasticsearch -- Configure advanced settings for data inputs used for streaming log data from Elasticsearch indices to your instance.
Microsoft Azure Event Hubs -- Configure advanced settings for data inputs used for streaming log data from Microsoft Azure Event Hubs to your instance.
Microsoft Azure Log Analytics -- Configure advanced settings for data inputs used for streaming log data from Microsoft Azure Log Analytics to your instance.
MID Server -- Configure advanced settings for data inputs that are used for collecting and streaming MID Server log messages.
Rsyslog, Splunk, or TCP -- Manually configure advanced settings for data inputs that use Rsyslog, Splunk, or TCP agents in Health Log Analytics.
Stop or restart a data input -- You can stop using a data input for streaming log messages to your ServiceNow instance. Restart the data input if you want it to resume streaming data.
Edit raw log data before processing -- Use the Data Input Preprocessor to filter, split, or sanitize raw log data before it is treated in the MID Server and mapped and structured by Health Log Analytics.
Log data auto-mapping and mapping -- By default, the HLA Engine tries to auto-map every incoming log line to the correct tags. You can change automatic mapping results manually by defining a JavaScript function.
Map raw log data manually -- Mapping raw log data that streams into your ServiceNow instance determines how Health Log Analytics processes the data. If HLA doesn't discover properties automatically, you can map data input sources manually.
Source type and log source relationships -- Explore the many-to-many relationships between source types and log sources to help you optimize data input mapping in Health Log Analytics.
Header properties detection -- In Health Log Analytics, automatic header properties detection separates the transport header from the inner log message and forwards only the inner log message to the source type structure. The inner message contains the actual log data without including shipping information.
Extract specific log data -- Set Health Log Analytics to extract specified terms from logs and map them to specific components.
Stop extraction of unneeded log data -- If an extracted string of data is not descriptive enough or contains redundant text or information, you can set Health Log Analytics to stop extracting such data from your logs.
Source type structure adjustment -- Health Log Analytics (HLA) enables you to reclassify auto-classified log properties and change auto-mapped labels. These adjustments help HLA machine learning analyze your data accurately.
Refine the source type structure -- Fine-tune how Health Log Analytics reads your inner log messages and detects anomalies by customizing the extracted properties in the source type structure.
Content packs for quicker time to value -- Shorten onboarding time for the Health Log Analytics application by installing content packs. The packs contain default source types and mapping script templates that save you the time it takes to create them from scratch.
Migrating a data input configuration -- Export a Health Log Analytics data input and source types configuration as an update set and import it to a different ServiceNow instance. In the target environment, you can use the migrated data input for streaming and processing log data. This functionality saves time and reduces possible errors by avoiding the need to configure the settings again on the target instance.
Export a data input configuration -- Export the configuration of a Health Log Analytics data input with or without the related source types to an update set. You can then import the update set to the target environment.
Export source types to an update set -- Export source types to an update set separate from the Health Log Analytics data input configuration. You can then import the update set to the target environment.
Export source types by log source -- Export all source types related to one or more selected log sources to an update set together in Health Log Analytics. You can then import the update set to the target environment.
Administer HLA -- This section covers tasks involved in Health Log Analytics administration. It provides you with information needed to keep Health Log Analytics running efficiently.
Configure global system properties -- Configure global Health Log Analytics system properties if you need to alter the default values, which typically should not be necessary.
Enable or disable system features -- Customize the basic configuration of Health Log Analytics by enabling or disabling system features.
View log anomaly metrics -- View and query all metrics that Health Log Analytics tracks from a single location.
Receive alert notification in Slack or Microsoft Teams channels -- Health Log Analytics sends notifications for new anomaly alerts in real time to Slack or Microsoft Teams channels. This built-in functionality frees you from having to continuously monitor logs to prevent incidents.
Set up alert notifications in channels -- Set up notifications for new Health Log Analytics anomaly alerts in either a Slack or Microsoft Teams channel.
Storage space for log retention -- The Health Log Analytics base system typically provides 1,000 GB storage space for log source retention, although the storage capacity may vary depending on your license. The default retention time for logs is three days, but you can modify that period.
Modify the log source retention period -- Modify the period that Health Log Analytics retains logs from a specific source. You can calculate the impact of your intended change on storage to help you make an informed decision.
Enrich the CMDB with host data from logs -- When Health Log Analytics streams logs, it extracts host data from the log events. If host data is discovered that doesn't match the information in the Configuration Management Database (CMDB), the system creates a configuration item (CI) candidate for you to review based on the data it found in the logs.
Add log-based CIs to the CMDB -- Keep the Configuration Management Database (CMDB) updated with host data Health Log Analytics discovered in your logs by adding log-based configuration items (CIs) to the database.
Analyzing and resolving alerts -- Analyze and resolve Log Analytics alerts by investigating log data and taking action to resolve the underlying issue.
Start remediation of a Log Analytics alert -- Begin the remediation process of a Log Analytics alert from the alert Overview tab. This tab provides information on the alert, the log data associated with the anomalous behavior, CIs associated with the alert, and services impacted by it.
Review logs that surround the anomaly -- When Health Log Analytics identifies an anomaly, viewing the logs that surround the anomaly provides clues about the state of faulting systems. This information can help you narrow down the root cause of an alert.
Find correlations between alerts -- In Health Log Analytics, log correlators are keys or values in log data that detect correlations between alerts to help you determine whether an alert is part of a larger issue. For example, a log correlator could detect when the interface ID of a particular network device occurs simultaneously in multiple warnings across different service instances.
Add a log correlator to find related alerts -- In Health Log Analytics, detect related alerts in log data by adding log correlators. The base system includes several log correlators and you can define custom log correlators.
Exclude a source from a log correlator -- Prevent Health Log Analytics from analyzing log lines from a specific source by excluding that source from the log correlator.
Review alert-related logs on the Log Viewer -- The Log Viewer tab lets you browse the logs for an alert by timestamp or time range, and visualize anomaly frequency within a specific time period. Customizing the displayed data and adjusting time filters enables you to better understand the framework in which the anomaly occurred, helping you find the root cause faster.
View log data for an alert -- View a chart of the frequency of anomalous log lines and the associated log data on the Log Viewer.
Use or modify a saved log data search -- Use a saved search of log data to better understand the causes of an alert. As the owner of a saved search, you can modify the search values and save your changes.
Filter search results -- Apply filters on the Log Viewer to show only your desired data.
Add a KB article to an alert -- Add your own knowledge base (KB) article to an alert that was generated by Health Log Analytics. For example, you can provide additional information that might help to resolve the underlying issue. Health Log Analytics also uses your knowledge to enhance similar alerts.
Use custom alert rules -- Alert rules enable you to set conditions that determine when Health Log Analytics (HLA) triggers an alert.
Log Analytics alert rules -- Health Log Analytics (HLA) detects anomalies automatically by learning from your log data. However, some log types require a custom alert rule to generate alerts reliably.
Define a custom Log Analytics alert rule -- Define a custom Log Analytics alert rule for log data that might not generate alerts automatically. A custom rule enables you to specify the metric, threshold, and alert properties directly.
Assign higher or lower significance to an alert -- Label an alert in Health Log Analytics as meaningful or insignificant, or restore normal importance to the metric involved in generating it.
Mark an alert as significant -- Make an alert more likely to be included in a Log Analytics group when the associated metric behaves anomalously by labeling the alert as meaningful.
Mute an unimportant alert -- Eliminate distracting new alerts for insignificant issues by muting them.
Restore normal importance to an alert metric -- Return normal significance to the metric involved in generating a Log Analytics alert. Use this option if you no longer want an alert to be treated specially that was muted, marked as significant, or made less sensitive to similar anomalies.
Influence anomaly detection with lexical keywords -- Influence how Health Log Analytics finds anomalies by managing keywords it looks for in your log data. When text in log data for a source matches a lexical keyword that exceeds a specified count threshold, the system identifies an anomaly and generates an alert.
Reduce noise with advanced log alert filters -- Use advanced log alert filters to determine whether to allow an alert or to drop it. These filters reduce noise by dropping alerts that don't indicate a significant issue.
Create advanced log alert filters -- Add advanced log alert filters to scan alerts for conditions that you specify. The filters reduce noise by dropping alerts that do not indicate a significant issue. While developing a filter, you can test, update, publish, or activate the filter at any time.
Dashboards for real-time visualization of log data -- Health Log Analytics enables you to create log data dashboards and visualizations in real time for enhanced data monitoring and faster identification of deviations.
Create log data dashboards and visualizations -- Build Health Log Analytics log data dashboards and visualizations in real time for easier identification and understanding of issues.
Monitor visualized log data on a predefined dashboard -- Use visualizations to monitor log data on the built-in Operational Dashboard in Service Operations Workspace Log Analytics and address issues as they occur in the system.
Viewing system features and health alerts -- View all Health Log Analytics system features that your admin can activate or deactivate for you. In addition, you can view a model of the Health Log Analytics core components and the system health alerts that affect them.
View system features settings -- View the settings for all Health Log Analytics system features. These features configure many operations that affect your work. The admin can enable or disable features for you.
View system health alerts on the service map -- The ServiceNow Event Management service map includes a model of the Health Log Analytics core components and the system health alerts that affect them.
Analytics and Reporting in Health Log Analytics -- Gain valuable insights into the number of IT issues predicted before your users were affected and the money it saved your organization by using Analytics and Reporting in Health Log Analytics.
Platform Analytics Solutions for Health Log Analytics -- Platform Analytics Solutions contain prepackaged Performance Analytics and Reporting content for use with other ServiceNow AI Platform products. This Platform Analytics Solution provides valuable insights into the number of IT issues Health Log Analytics predicted before your users were affected, and the money it saved your organization by preventing critical outages.
Health Log Analytics Operational dashboard -- The Health Log Analytics Operational dashboard uses Performance Analytics to enable you to monitor log data, alerts, and error rate information in Service Operations Workspace and address issues as they occur in the system.
Health Log Analytics reference -- Reference topics provide additional information about the Health Log Analytics application.
Components installed with HLA -- Activating the Health Log Analytics, Health Log Analytics Viewer and Health Log Analytics Core plugins adds several components.
Supported data inputs for HLA -- Health Log Analytics (HLA) enables you to connect your ServiceNow instance to several types of data input.
General guidelines for streaming data to HLA -- This section helps you identify the appropriate data input for streaming your specific data type to the Health Log Analytics (HLA) application.
Configuration preferences -- Commonly used settings for Health Log Analytics properties and general configuration.
System health notifications -- Health Log Analytics system health notifications help to ensure that you're aware of potentially dangerous conditions. You can manually adjust the status of a notification as the issue is being addressed.
Language and character support -- Health Log Analytics provides international language support. The default language is US English.
Domain separation and HLA -- Domain separation is supported for Health Log Analytics. Domain separation enables you to separate data, processes, and administrative tasks into logical groupings called domains. You can control several aspects of this separation, including which users can see and access data.
Severity mapping -- Health Log Analytics (HLA) uses common severity values to identify severity labels in the Source Type Structure.
Information on the alert Overview tab -- The Overview tab helps you understand Log Analytics alerts, Log Analytics alert groups, and component-based alerts.
Log Analytics alerts -- The Overview tab in Health Log Analytics helps you understand Log Analytics alerts.
Log Analytics groups -- The alert Overview tab in Health Log Analytics helps you understand Log Analytics groups.
Component-based alerts -- The alert Overview tab in Health Log Analytics helps you understand Component-based alerts.
Integration configuration fields -- This section provides descriptions of the fields on the integration configuration forms for Health Log Analytics.
ACC Log Analytics (ACC-L) -- Description of the fields on the ACC Log Analytics (ACC-L) integration configuration forms for Health Log Analytics.
Amazon CloudWatch -- Description of the fields on the Amazon CloudWatch integration configuration forms for Health Log Analytics.
Amazon S3 -- Description of the fields on the Amazon S3 integration configuration forms for Health Log Analytics.
Apache Kafka -- Description of the fields on the Apache Kafka integration configuration forms for Health Log Analytics.
Amazon Data Firehose -- Description of the fields on the Amazon Data Firehose integration configuration forms for Health Log Analytics.
Cribl -- Description of the fields on the Cribl integration configuration forms for Health Log Analytics.
Edge Delta REST -- Description of the fields on the Edge Delta REST integration configuration form for Health Log Analytics.
Edge Delta TCP -- Description of the fields on the Edge Delta TCP integration configuration forms for Health Log Analytics.
Elasticsearch -- Description of the fields on the Elasticsearch integration configuration forms for Health Log Analytics.
GCP PubSub -- Description of the fields on the GCP PubSub integration configuration forms for Health Log Analytics.
Microsoft Azure Event Hubs -- Description of the fields on the Microsoft Azure Event Hubs integration configuration forms for Health Log Analytics.
Microsoft Azure Log Analytics -- Description of the fields on the Microsoft Azure Log Analytics integration configuration forms for Health Log Analytics.
MID Server -- Description of the fields on the MID Server integration configuration forms for Health Log Analytics.
REST API -- Description of the fields on the REST API integration configuration forms for Health Log Analytics.
ServiceNow System Logs Retriever -- Description of the fields on the ServiceNow System Logs Retriever integration configuration form for Health Log Analytics.
Splunk Poller -- Description of the fields on the Splunk Poller integration configuration forms for Health Log Analytics.
Splunk TCP -- Description of the fields on the Splunk TCP integration configuration forms for Health Log Analytics.
Splunk UDP -- Description of the fields on the Splunk UDP integration configuration forms for Health Log Analytics.
TCP -- Description of the fields on the TCP integration configuration forms for Health Log Analytics.
UDP -- Description of the fields on the UDP integration configuration forms for Health Log Analytics.
Vector Agent -- Description of the fields on the Vector Agent integration configuration forms for Health Log Analytics.
Data input configuration fields -- This section provides descriptions of the fields on the Health Log Analytics data input configuration forms.
Log-based CI candidates fields -- Field descriptions for the Log-based CI candidates table, the Log-based CI candidate form, and the Add CI candidate to CMDB form.
Metric Data table columns -- The Metric Data table lists all metrics that Health Log Analytics collects. Use the table to query metrics by log source, integration, source type, and metric type, review anomaly detection statistics, and view metric baselines.
Service Reliability Management -- Service Reliability Management (SRM) helps your organization respond, collaborate, track, and self-remediate when working on alerts and incidents. SRM is available when you have both ITSM Standard and ITOM Operator Professional subscriptions.
Exploring Service Reliability Management -- Service Reliability Management (SRM) provides a self-serve, guided experience for teams to manage service health. The experience is built using the Service Operations Workspace application and combines ITOM and ITSM capabilities into a single workflow.
Get started with Service Reliability Management -- Service Reliability Management (SRM) accelerates your path to viewing service health in the context of service level objectives and incident resolution. Helps IT Operations and DevOps teams deliver on the promise of agility, performance, and uptime.
SRM Home page -- The Service Reliability Management (SRM) Home page provides relevant information about your work, services, schedules, maintenance reminders, and teams. View the Home page by navigating to Service Reliability Management .
SRM interface -- The different components on the Service Reliability Management (SRM) interface provide easy access to different functions. The features and functions that appear depend on your role and permissions.
Search, filters, lists, forms, and guides -- An overview of the additional elements in the Service Reliability Management (SRM) interface that help you find items, view available forms and lists, and follow setup processes.
Export list information to a file -- You can export live information to a file in Service Reliability Management (SRM).This is the file referenced by all lists that can export. No need for services, alerts, incident or calendar specific files. They are kept in repo until certain about this.
Manually create SRM tags -- Add tags to classify, categorize, and add context to data. Service Reliability Management (SRM) imports tags and attaches them to services, alerts, and incidents. You can also manually create tags.
SRM incidents -- Track and collaborate on incidents in the Incidents tab, helping you and your teams resolve issues efficiently.
Service Operations Workspace setup -- Install and configure Service Reliability Management (SRM) within the Service Operations Workspace Admin Center so that SRM admins, managers and responders can provide service reliability efficiently.
Configuring Service Reliability Management -- Configuring Service Reliability Management (SRM) involves installing it from the ServiceNow Store or Service Operations Workspace Admin Center. You can also assign administrators and import services and teams.
Install SRM -- Install the Service Reliability Management (SRM) application from the Admin Center or ServiceNow Store.
Assign an administrator to SRM -- Add people from your ServiceNow instance to administer Service Reliability Management (SRM) and your service operations.
Activate teams and services -- Activate teams and services to be managed in the Service Reliability Management (SRM) application.
Customize team approval settings -- Customize how team approvals work when non-admin users create or add a team in Service Reliability Management (SRM). This feature, also known as team governance, helps you control access and align with internal policies.
Configure error budget actions -- Configure the actions that the team can select when the error budget of a service level objective (SLO) is breached.
Approve a change request -- Approve a service change request in Service Reliability Management (SRM) to allow the requested action to proceed.REVISE FOR SRM
Using Service Reliability Management -- Service Reliability Management (SRM) enables you to register services, monitor service health, respond to service degradations with on-call shifts and escalation policies and triggers, and onboard distributed teams with minimal governance from central IT.
Working with SRM services -- A service represents a functional outcome like networking, payments, or HR services, that is owned by a team. To deliver that outcome, a service can contain one or more technical components like a user authentication service, or a piece of shared infrastructure like a database.
Add a service -- Add services to Service Reliability Management (SRM) to help your teams manage service health.
Edit service details -- Edit an existing service owned by your team. For each service that you support in SRM provide general information about the service and the SRM team that supports it.
Remove a service -- Remove a service from Service Reliability Management (SRM) when you no longer need to track or monitor its reliability.
Working with integrations -- Connect your services to monitoring tools using the Integrations Launchpad . Integrations send information to Service Reliability Management (SRM), helping you track alerts, manage incidents, and maintain service health.
Working with SRM teams -- Manage schedules and define escalation policies for your team. That way, your team sees who is on call and accountable and can have the confidence that critical alerts or incidents are acknowledged in a timely manner.
Add an SRM team -- Request to create a team to start monitoring your services. Teams are responsible for the issues that occur in the associated services.
Add team members to SRM -- Add new team members to your team as required to plan, manage, resolve issues, and increase the efficiency of your business operations.
Set up escalation policies for your team in SRM -- Set up an escalation policy for your team to ensure that alerts or incidents are resolved in a timely manner by the appropriate team member.
Create an escalation trigger -- To address issues promptly, define the conditions that trigger a team's escalation policy in Service Reliability Management (SRM).
Working with SRM reliability tasks -- Alerts, incidents, and change requests are reliability tasks. From creation to resolution, SRM helps you manage your alerts throughout the response life cycle.
Working with incidents in SRM -- Plan ahead of service disruptions and have SRM send notifications and create status when incidents occur. Distractions are minimized and teams stay focused on remediation.
Manually create an SRM incident -- Create an incident if you think an issue poses a serious risk and should be taken care of as soon as possible.
Reassign an SRM incident -- Reassign an incident to a responder when the incident tasks should be addressed by a particular team member.
Update the priority of an SRM incident -- If the priority of an incident should be changed, you can manually update it to reflect its new criticality.REVISE FOR SRM
SRM roles and responsibilities -- Roles grant users access to different parts of the SRM console. Roles determine the actions that users can or can't perform in Service Reliability Management.
Create team form -- Request to create a team to start monitoring your services.
Add service form -- Create or add an existing service to your instance so that alerts and incidents on that service are available to your teams within SRM.
Domain separation and SRM -- Domain separation is supported for Service Reliability Management (SRM).This needs to be updated with correct version.
Create change request forms -- Fill out the fields in the forms to create a change task to implement a controlled process for modifying approved and supported actions for SRM.
SRM incident states -- Incidents can be in a few different states depending on how they are acted on.
SRM alert states -- Alert can be in a few different states depending on how they are acted on.If changing states starts to do something then use this topic. Otherwise it's not necessary.
SRM change request states -- Incidents can be in a few different states depending on how they are acted on.
CMDB service classes -- Service Reliability Management (SRM) typically supports several Configuration Management Database (CMDB) service classes.
Troubleshoot SRM -- Find answers to issues that you may encounter when using Service Reliability Management (SRM).
ITOM Mobile Agent -- Stay connected and keep services reliable with ITOM Mobile Agent, which lets you access Service Reliability Management (SRM) features on iOS and Android devices. Use it to track alerts, manage incidents, work on change and catalog tasks, and manage on-call shifts on the go.
Explore -- Learn how you can use ITOM Mobile Agent to manage service reliability on the go, including its capabilities, benefits, and a sample workflow.
Configure -- Set up and configure ITOM Mobile Agent.
Log in to ITOM Mobile Agent -- Log in to your ITOM Mobile Agent instance on the ServiceNow Agent app to manage alerts, incidents, and on-call schedules on the go.
Customize alert email recipients -- Customize who receives emails about alerts to help reduce notification overload and efficiently delegate responsibilities.
Customizing other mobile settings -- Learn how to customize your mobile experience further. Configure actionable notifications, set custom notification tones, and override the Do Not Disturb setting for critical issues to help your teams stay informed.
Use -- Work with alerts, incidents, on-call schedules, and tasks on the go.
Work with alerts in ITOM mobile -- Manage alerts on the go. Learn how to assign, reassign, and close alerts in ITOM Mobile Agent. You can also add work notes to alerts and create incidents from alerts.
Managing incidents on mobile -- Manage and resolve incidents on the go using ITOM Mobile Agent. Learn how to create, process, and collaborate on incidents on your mobile device. You can also track and collaborate on major incidents.
Working with On-Call Scheduling on mobile -- Manage on-call schedules on the go using ITOM Mobile Agent. As a manager, learn how to manage shifts, time-off requests, and scheduling gaps. As a responder, learn how to request time off, view who is on call, and see upcoming shifts.
Working with tasks on mobile -- Manage change and catalog tasks on your mobile device using ITOM Mobile Agent. Learn how to respond to issues quickly by viewing, closing, and adding comments to tasks on the go.
Reference -- Learn about ITOM Mobile Agent settings. You can view the app version, give feedback, and adjust your preferences.
Service Level Objective Management -- Service Level Objective Management (SLO Management) helps your organization define, track, and meet agreed-upon service quality standards. It works alongside Service Level Agreements (SLAs) to help make sure that services meet customer expectations.
Exploring SLO Management -- Service Level Objective Management (SLO Management) helps IT services meet customer expectations.
Exploring AI in SLO Management -- Learn about the AI capabilities that can help teams adopt service level objectives (SLOs) faster and monitor service performance.
SLO creator agent -- Use the service level objective (SLO) creator agent to auto-generate SLOs for services and configuration items (CIs). The agent can help teams adopt SLOs faster and monitor service performance.
Reliability metrics in SLO Management -- Learn about the reliability metrics and features that can help you track service health, respond to issues, and support business goals.
Configuring SLO Management -- Configure SLO Management to help teams monitor and improve service reliability.
Manage SLO creator agent settings -- Activate or deactivate the service level objective (SLO) creator agent and configure the notification settings.
Using SLO Management -- Using SLO Management ensures IT services meet customer expectations, improves service quality and transparency, and enables data-driven decision making.
View AI-generated SLOs -- View service level objectives (SLOs) generated by the SLO creator agent and review information about how they were created.
Create SLOs, SLIs, and error budget policies -- Define service level objectives (SLOs), service level indicators (SLIs), and error budget policies to monitor service health. These tools help you and your teams track performance and respond when needed.
Service Observability -- The ServiceNow Service Observability application enables operators to triage and manage incidents in a complex and distributed system. Application and platform telemetry insights from multiple observability tools are combined into a centralized workflow.
Exploring Service Observability -- Service Observability helps operations teams triage and manage incidents in a complex and distributed production system. It combines external observability monitoring systems' telemetry with related data from the Configuration Management Database (CMDB) and displays both in a single workflow in the Service Operations Workspace (SOW).
Configuring Service Observability -- After you install Service Observability, you must connect external observability systems and map that data to services. You can also customize the out-of-the-box dashboards to show different information, including data from other ServiceNow products.
Install Service Observability -- If you have the system admin role, you can install the Service Observability application (sn_sow_svcobs). The application installs related ServiceNow Store applications and plug-ins if they aren't already installed.
Connect a data source -- Connect Service Observability to an external observability system. Service Observability displays metrics in the Service Operations Workspace (SOW) from that observability instance.
Create and manage mappings -- Map your services to the data from a connected external observability vendor instance, and view it in charts for the service.
Customize dashboard templates -- You can customize the Service Observability dashboards on both the Overview and Observability tabs of the Service Details page. You can change or add metrics and related data to fit your business needs.
Edit observability chart data -- Edit Service Observability dashboard templates to view different observability metrics on the Overview or Observability tabs' charts. Metrics are scoped to the selected service.
Edit ServiceNow chart data -- Edit Service Observability dashboard templates to view data from problem and business app records on the Overview or Observability dashboards.
Add MetricBase chart data -- Add MetricBase data to charts on Service Observability dashboard templates when you want to view those metrics in context of Service Observability.
Add Health Log Analytics data -- Add a graph showing logs from Health Log Analytics (HLA) in a Service Observability dashboard.
Add Splunk Enterprise chart data -- Add Splunk Enterprise data to charts on Service Observability dashboard templates when you want to view those metrics in context of Service Observability.
Monitoring and investigating -- Operators use Service Observability to monitor the health of their services and to triage and manage incidents. They can view performance metrics from external observability monitoring systems in the context of an application service and its related CIs (Configuration Item).
View overall service health -- View overall service health and related events, like alerts and changes, with the Overview tab on the Service Details page in the SOW.
View service health metrics -- View detailed metrics for a service, as well as metrics from related entities, such as databases and hosts, on the Observability tab in SOW.
Service Observability reference -- Reference topics provide additional information about administering and using Service Observability.
Domain separation and Service Observability -- If any conkeyrefs are broken, re-add them from the doc/source/reuse/domain-separation/domain-separation-overview.dita file.In the short description, edit the first sentence to state whether domain separation is supported or not and add the application name. Keep the conkeyref at the end that describes domain separation.Domain separation is supported for Service Observability. Domain separation enables you to separate data, processes, and administrative tasks into logical groupings called domains. You can control several aspects of this separation, including which users can see and access data.
Observability vendor entity mappings -- Understand how Service Observability maps service, host, and database entities to your observability vendor resources.
Template variables -- Understand the template variables that you can use in your queries when editing Service Observability dashboards and charts.
Service Observability templates -- View the templates for your observability vendor to understand the default dashboards provided by Service Observability.
Amazon CloudWatch templates -- Templates used to create Amazon CloudWatch dashboards in Service Observability. You can edit these templates as needed.
Overview tab -- Information that is displayed on the Amazon CloudWatch Overview tab of the Service Details page in the SOW.
Observability tab -- Dashboard and charts on the Amazon CloudWatch tab of the Service Details page in the SOW.
AppDynamics templates -- Templates used to create AppDynamics dashboards in Service Observability. You can edit these templates as needed.
Overview tab -- Information that is displayed on the AppDynamics Overview tab of the Service Details page in the SOW.
Observability tab -- Dashboard and charts on the AppDynamics Observability tab of the Service Details page in the SOW.
Azure Monitor templates -- Templates used to create Azure Monitor dashboards in Service Observability. You can edit these templates as needed.
Overview tab -- Information that is displayed on the Azure Monitor Overview tab of the Service Details page in the SOW.
Observability tab -- Dashboard and charts on the Azure Monitor Observability tab of the Service Details page in the SOW.
Cisco Thousand Eyes templates -- Templates used to create Cisco ThousandEyes synthetics dashboard in Service Observability. You can edit this template as needed.
Observability tab -- Dashboard and charts on the Cisco ThousandEyes Observability tab of the Service Details page in the SOW.
Datadog templates -- Templates used to create Datadog dashboards in Service Observability. You can edit these templates as needed.
Overview tab -- Information that is displayed on the DatadogOverview tab of the Service Details page in the SOW.
Observability tab -- Dashboard and charts on the Datadog Observability tab of the Service Details page in the SOW.
Dynatrace templates -- Templates used to create Dynatrace dashboards in Service Observability. You can edit these templates as needed.
Overview tab -- Information that is displayed on the Dynatrace Overview tab of the Service Details page in the SOW.
Observability tab -- Dashboard and charts on the Dynatrace Observability tab of the Service Details page in the SOW.
LogicMonitor templates -- Templates used to create LogicMonitor dashboards in Service Observability. You can edit these templates as needed.
Overview tab -- Information that is displayed on the LogicMonitor Overview tab of the Service Details page in the SOW.
Observability tab -- Dashboard and charts on the LogicMonitor Observability tab of the Service Details page in the SOW.
MetricBase templates -- Templates used to create MetricBase dashboards in Service Observability. You can edit these templates as needed.
Overview tab -- Information that is displayed on the MetricBase Overview tab of the Service Details page in the SOW.
Observability tab -- Dashboard and charts on the MetricBase Observability tab of the Service Details page in the SOW.
New Relic templates -- Templates used to create New Relic dashboards in Service Observability. You can edit these templates as needed.
Overview tab -- Information that is displayed on the New Relic Overview tab of the Service Details page in the SOW.
Observability tab -- Dashboard and charts on the New Relic Observability tab of the Service Details page in the SOW.
Prometheus templates -- Templates used to create Prometheus dashboards in Service Observability. You can edit these templates as needed.
Overview tab -- Information that is displayed on the Prometheus Overview tab of the Service Details page in the SOW.
Observability tab -- Dashboard and charts on the Prometheus Observability tab of the Service Details page in the SOW.
SolarWinds templates -- Templates used to create SolarWinds dashboards in Service Observability. You can edit these templates as needed.
Overview tab -- Information that is displayed on the SolarWinds Overview tab of the Service Details page in the SOW.
Observability tab -- Dashboard and charts on the SolarWinds Observability tab of the Service Details page in the SOW.
Splunk Observability templates -- Templates used to create Splunk Observability dashboards in Service Observability. You can edit these templates as needed.
Overview tab -- Information that is displayed on the Splunk Overview tab of the Service Details page in the SOW.
Observability tab -- Dashboard and charts on the Splunk Observability tab of the Service Details page in the SOW.
Zabbix templates -- Templates used to create Zabbix dashboards in Service Observability. You can edit these templates as needed.
Overview tab -- Information that is displayed on the Zabbix Overview tab of the Service Details page in the SOW.
Observability tab -- Dashboard and charts on the Zabbix Observability tab of the Service Details page in the SOW.
Data mapping form -- Field descriptions for the Observability data mapping form. Use this form to map activated services in Service Observability to metrics from your observability instance. Each service can be mapped only once, but can contain exceptions to include all related entities.
Chart error states -- Understand the different error states that the charts in Service Observability might display and how to fix them.
Synthetic monitoring -- The ServiceNowsynthetic monitoring application empowers organizations to proactively manage and enhance the performance and availability of critical services. By simulating user transactions on API endpoints, this solution identifies performance bottlenecks, helps ensure up-time, and optimizes user experiences.
Exploring synthetic monitoring -- Learn how synthetic monitoring provides proactive, automated testing of service endpoints. By simulating user interactions, it can identify bugs, performance issues, and outages before they impact real users.
Install synthetic monitoring -- You can install the synthetic monitoring application (com.snc.uib.sow_synthetics) with the admin role.
Create synthetic monitoring locations -- Create a synthetic monitoring location to run a synthetic monitor. If you plan to run monitors from a ServiceNow hosted location, you can skip this procedure.
Create and edit a synthetic monitor -- Create or edit a synthetic monitor to test the availability and performance of your HTTP endpoints before your users discover issues.
Synthetic monitoring reference -- Reference topics provide additional information about the synthetic monitoring application, such as components installed and page details.
Domain separation and synthetic monitoring -- Domain separation is supported for synthetic monitoring. Domain separation enables you to separate data, processes, and administrative tasks into logical groupings called domains. You can control several aspects of this separation, including which users can see and access data.
Upgrade issues -- What to do when monitors don't work after upgrading synthetic monitoring.
OAuth issues -- Learn how to fix OAuth token refresh issues.
Impacted Service not appearing in alerts -- When a test fails for a monitor and you have configured an alert to trigger, the alert record should show the impacted service. There are a few reasons why this field might not be populated.
Synthetic monitoring Landing Page -- Read the following to understand what is displayed on the Synthetic monitoring landing page where you can view aggregate information about your synthetic monitors.
Details page of a synthetic monitor -- Use the details page of a synthetic monitor to view test results, monitor status, and configuration settings.
Applying the CSDM guidelines to ITOM AIOps -- ITOM AIOps helps you track and maintain the health of services in your organization. ITOM AIOps CSDM reference serves as a foundational blueprint for maintaining optimal IT operations by standardizing data models and processes. The main goal is to help you understand the two main capabilities that work together within the CSDM framework.
CMDB tables managed by ITOM -- ITOM AIOps leverages and maintains CSDM tables, while various ServiceNow products enhance and contribute value to its operations.
Plugins or applications installed with ITOM AIOps -- Tables that list the plugins or applications that are installed with ITOM AIOps applications. When you update your application, any newly required application dependencies are installed.
Agent Client Collector -- The Agent Client Collector is an agent that is installed on infrastructure components. The Agent Client Collector is built on a Sensu framework which enables you to adopt and extend monitoring checks from the community. It executes commands on the machines it is installed on and sends output data to the ServiceNow instance via the MID Server, storing events and metrics in the relevant database.
Exploring Agent Client Collector -- The Agent Client Collector Framework (ACC-F) is a powerful solution for monitoring the performance and health of infrastructure components by using agents installed on servers and devices. It collects and sends critical system data to ServiceNow for analysis, enabling proactive management and troubleshooting of Configuration Items (CIs).
ACC-F use case -- The Agent Client Collector Framework (ACC-F) use case demonstrates how a financial organization can use Agent Client Collector Framework to assist in IT asset discovery.
ACC architecture -- The Agent Client Collector is a ServiceNow agent installed on your Windows, Linux, and macOS devices to monitor your company’s infrastructure and installed applications.
Domain separation and ACC -- If any conkeyrefs are broken, re-add them from the doc/source/reuse/domain-separation/domain-separation-overview.dita file.In the short description, edit the first sentence to state whether domain separation is supported or not and add the application name. Keep the conkeyref at the end that describes domain separation.Domain separation is supported for Agent Client Collector (ACC). Domain separation enables you to separate data, processes, and administrative tasks into logical groupings called domains. You can control several aspects of this separation, including which users can see and access data.
Optimization use case -- Optimizing data isolation and monitoring with domain separation ensures financial institutions protect sensitive information, improve operational efficiency, and maintain compliance by securely segregating departmental data.
Compliance use case -- A financial institution needs to ensure that its data is accessible only to the departments that have authorization for the indicated data.
ACC plugins -- An Agent Client Collector (ACC) plugin is a script or group of scripts that extend the Agent Client Collector's capabilities. Plugins enhance monitoring by collecting metrics, performing specialized checks, and triggering events based on conditions, like monitoring an application's queue size when it reaches 60% or 80%. Plugins ensure scalable, customizable monitoring to adapt to evolving infrastructure or application needs.
Secure parameters in ACC -- Secure parameters in Agent Client Collector (ACC) refers to securely passing sensitive data, such as user names, passwords, and API keys, during check execution, without exposing the sensitive data in the command line. Parameters are passed to the script through standard input (STDIN), hiding them from logs or any process that might capture command-line arguments.
ACC logs -- Agent Client Collector (ACC) logs play a critical role in monitoring the activity and performance of the agent. Logs offer valuable feedback that helps identify potential issues, especially when the agent's performance is suboptimal. By providing insights into areas of concern, these logs are essential for troubleshooting and resolving issues, ultimately improving the overall effectiveness of the agent.
Operating system and application monitoring using ACC -- IT Operations Management (ITOM) monitoring for the Agent Client Collector is installed on the ServiceNow instance. It monitors the specific operating system and applications that are installed on the host machine.
Configure ACC Apache HTTP server monitoring -- To configure the Agent Client Collector to perform Apache HTTP server monitoring, set the following configurations in the Apache HTTP server application.
Configure ACC Apache Tomcat monitoring -- To configure the Agent Client Collector to perform Apache Tomcat monitoring, set the following configurations in the Apache Tomcat application.
Monitor HTTP points -- Use the Monitoring HTTP Entry Points and Monitoring HTTP Entry Points Metrics policies that come with the ITOM Monitoring scoped app to monitor http and https entry points and entry points metrics. You can customize these policies as needed, or you can configure a new policy to monitor service entry points.
Agent-based data flow -- The Agent Client Collector gathers information on the health of the CI that the Agent is installed on, and the applications that run on the hosts. The Agent runs several checks and pushes the checks' results to the MID Server, where they are converted into events or metrics.
ACC-M use case -- The Agent Client Collector Monitoring (ACC-M) use case demonstrates how organizations can achieve unified monitoring across hybrid IT environments.
Windows event log monitoring -- Windows event log monitoring tracks, analyzes, and manages event logs generated by various Windows OS components.
How ACC-VC works -- Agent Client Collector for Visibility Content (ACC-VC) requires installation of ServiceNow Agent Client Collector (ACC) on the target host. ACC is a derivative of Sensu-Go, an open-source software.
Agent Client Collector for Visibility Content use case -- The Agent Client Collector for Visibility Content (ACC-VC) use case demonstrates how a financial organization can perform effective discovery across on-premise and remote environments.
Preparing for Agent Client Collector implementation -- Successful Agent Client Collector (ACC) implementations, especially involving large numbers of endpoints or servers, require careful deployment. When proceeding with a large-scale ACC deployment, follow the steps described in the planning and deployment checklists.
Agent Client Collector planning checklist -- Successful Agent Client Collector (ACC) implementations, especially involving large numbers of endpoints or servers, require careful planning. Before proceeding with a large-scale ACC deployment, follow the steps described in the planning checklist.
Agent Client Collector deployment checklist -- Successful Agent Client Collector (ACC) implementations, especially involving large numbers of endpoints or servers, require careful deployment. When proceeding with a large-scale ACC deployment, follow the steps described in the deployment checklist.
ACC deployment - servers -- When deploying the Agent Client Collector, perform deployment and management tasks on your environment's servers.
Configuring ACC with a MID Server -- Configure the Agent Client Collector with a MID Server to enable communication between network servers and the ServiceNow instance.
Configure an ACC with a MID Server -- Use a single-line command to set up an Agent Client Collector with a MID Server. You can also use the single-line command to migrate agents with MID-less configuration to be used with a MID Server.
Configure the websocket server on the MID Server -- Configure the websocket server on MID Servers to enable connections from agents to the MID Server. You can configure only one websocket server per MID Server.
Configure a websocket endpoint -- Configure a websocket to enable the endpoint to provide web access from the MID Server to the Agent Client Collector (ACC).
Configure the frequency of updating the agent MID Server list -- By default, the list of MID servers connected to agents is updated once daily. If you have a dynamic environment that adds MID servers frequently, you may want to schedule updates more often, or execute the job on demand.
Enable ACC monitoring on the MID Server -- Enable Agent Client Collector monitoring on the MID Server by configuring the Agent Client Collector framework (ACC-F) and Metric Intelligence extensions in a single action. Enabling Agent Client Collector monitoring also enables monitoring on agents connected to the MID Server.
Automatic MID Server selection -- Automatic selection of MID Servers ensures that each agent uses the most efficient available MID Server.
Enable automatic MID Server selection -- Enabling automatic MID Server selection lets the agent perform a connectivity test against the list of available MID Servers and determine the best connection based on latency and number of currently connected agents. Automatic MID Server selection is disabled by default.
Configure the Agent Client Collector capabilities for MID Servers -- Configure the MID Servers with Agent Client Collector capabilities to enable the MID Servers to work with agents. Agents that have identical MID Server capabilities are eligible for automatic MID Server selection.
Configure automatic MID selection based on ACC capabilities -- Configure the MID Servers that are ineligible for automatic MID Server selection with the agent. For example, you may want to block a MID Server from connecting to your agent due to firewall constraints.
ACC installation -- You can install the Agent Client Collector on any supported host machine. The Agent Client Collector connects to a MID Server using the HTTP/S protocol, and the connection remains active after being established. One MID Server may handle several agents simultaneously, while a single agent works with one MID Server at a time and switches to a different MID Server when necessary to provide failover protection.
ACC system requirements -- System requirements are the fundamental specifications and configuration needed to install and run Agent Client Collector (ACC) effectively.
Configuring ACC for mass deployment -- Deploy the Agent Client Collector on a virtual machine during mass deployment using the machine's base image. Mass deployment uses silent installation, which hides installation status.
Enable the ACC load balancer -- Enable a load balancer to ensure that you have functional MID Servers. A load balancer distributes resources over multiple MID Servers to ensure that no single MID Server is overloaded.
Perform high-volume ACC upgrade -- Perform high-volume upgrade of your Agent Client Collector agents when you want to upgrade all of your agents at one time.
Restart an agent manually -- Perform manual restart of an agent when the agent configuration file has been refreshed, or if the agent is unstable. You can perform manual restart only on agents installed in a Windows environment and for Linux-based agents that use systemd.
ACC installation on a Linux OS system -- Install Agent Client Collector on a system that uses a Linux OS, either using a single-line command script, or following the installation procedure to embed in your own package distribution mechanism. The installation procedure provides consistency when using package distribution solutions.
Install ACC on a Linux system -- Install Agent Client Collector using a package distribution tool. Before installing, you can manually install the Agent Client Collector on a few machines to ensure that your agents contain the correct policies and checks before installing a large number of agents.
Validate Linux installation -- After installing the Agent Client Collector on a Linux system, validate the installation by ensuring it was completed properly.
Upgrade ACC on a Linux system -- Upgrade your existing Agent Client Collector version on a system running a Linux OS if the single-line command script is not connected to the instance or you want to use enhanced customization options.
Uninstall ACC from a Linux system manually -- Uninstall the Agent Client Collector from a Linux machine manually if the command script is unavailable due to the specific agent not being connected to the instance.
Perform a single-line ACC installation on Linux -- Use an efficient single-line command script to install Agent Client Collector on a machine that uses a Linux operating system. If a script is not connected to the instance or you want to use enhanced customization options, you might have to install Agent Client Collector manually.
Upgrade the ACC manually on a Linux system -- Perform a manual upgrade of your existing Agent Client Collector version on a system running a Linux OS if the single-line command script is not connected to the instance or you want to use enhanced customization options.
Uninstall ACC from a Linux system using a single-line command -- Uninstall the Agent Client Collector from a Linux machine by running an efficient single-line command. If the script is not connected to the instance, you might have to uninstall Agent Client Collector manually.
ACC installation on a Windows machine -- When installing the Agent Client Collector on a Windows machine, either download an installation file and use a wizard to install the agent manually, or use silent installation to automate agent installation and configuration. Manual installation enables you to test the agent on a single system, while silent installation enables you to deploy the agent at scale.
Uninstall the ACC manually from a Windows machine -- Uninstall the Agent Client Collector from a Windows machine manually instead of using the single-line procedure. Use the manual procedure if the command script is unavailable due to the specific agent not being connected to the instance.
Uninstall ACC using a single-line command -- Uninstall the Agent Client Collector from a Windows machine by running an efficient single-line command. If the script is not connected to the instance, you might have to uninstall Agent Client Collector manually.
Agent Client Collector upgrade overview -- The Agent Client Collector Framework manages agent upgrades directly from the instance, with no manual action required on individual agent hosts.
Upgrade an agent in an instance -- Perform selective self-upgrade instead of bulk upgrade for enhanced efficiency when working with agents that are difficult to access, such as agents deployed in the cloud. You can perform selective upgrade on up to 50 agents at a time.
Upgrade multiple agents in an instance -- When performing selective upgrade of an agent in an instance, you can select multiple instances to upgrade at once.
Repeat high-volume upgrade for failed agents -- If high-volume upgrade fails for specific agents, you must clear the problematic agents' history to re-enable upgrade. If the target upgrade version changes, you don't need to clear the agents' history, as the agents upgrade with the next scheduled high-volume upgrade.
Configure a download proxy for upgrades -- Add a proxy server entry so that agents behind a corporate proxy can download upgrade packages from the ServiceNow Content Delivery Network (CDN).
Create and edit ACC plugins -- You can edit the default plugins, or you can add new plugins, as needed. Creating and editing plugins customizes the Agent Client Collector monitoring capabilities.
Secure a custom plugin with a certificate -- When you customize or create an Agent Client Collector plugin, you can secure the plugin with either a third-party certificate or an internal secure certificate in the plugin's script. Official plugins are signed by an external certificate authority.
Optimize distribution of agents to MID Servers -- Optimize the distribution of agents by allowing redistribution from one MID Server to another. Agents will always be connected to the MID Server with the fastest response time.
View the ACC configuration file for an agent -- View the acc.yml Agent Client Collector configuration file without having to access the host server by retrieving the file from an agent.
Create an ACC configuration data file -- Create an Agent Client Collector configuration data file and associate it with check definitions so that you can view the information about your instance. You can also add or delete an attachment to the configuration data files, which are used by check definitions during check executions.
Validate plugins on the MID Server -- Validate plugins on your MID Server to ensure that they match the plugins on your ServiceNow instance. Validating plugins ensures that the instance provides accurate data on all of your MID Server plugins.
Validate plugins on agents -- Validate plugins on your agents to ensure that they match the plugins on your ServiceNow instance. Validating plugins ensures that the instance provides accurate data on all of your agents' plugins.
Using proxy agents in ACC -- You can use a proxy agent to monitor the health and performance of your configuration items (CIs) even if the agent is in the cloud or any place that is external to your host server.
Configure an agent on a proxy server -- Configure an Agent Client Collector on a proxy server when monitoring services external to the host server, such as URLs or external databases in the cloud.
Create a proxy agent cluster -- Create a cluster of agents on multiple proxy servers to monitor services external to the host server. Creating a cluster of agents enables you to assign that cluster to multiple policies instead of having to assign the agents individually to every policy.
Assign a proxy agent cluster to a policy -- Assign a proxy agent cluster to a policy when monitoring services external to the host server, such as URLs or external databases in the cloud. The agents in the cluster monitor all of the policy's CIs.
Load balancing in a proxy agent cluster -- Enable load balancing between proxy agents in a cluster so that if an agent is not functioning properly, monitored CIs are redistributed to another agent. After enabling load balancing, you can view the CIs monitored by each proxy agent in a policy.
Enable log monitoring in a Linux environment -- To enable monitoring logs in a Linux environment, select the relevant policy and assign specific check parameters to the policy. When log monitoring is enabled and a specified string is discovered in the log being monitored, the system creates an event.
Enable log monitoring in a Windows environment -- To enable monitoring logs in a Windows environment, select the relevant policy and assign specific check parameters to the policy. When log monitoring is enabled and a specified string is discovered in the log being monitored, the system creates an event.
Select the Azure policies to activate for metric collection -- Activate the Azure policies that come with the Agent Client Collector base system so that Azure virtual machines can collect metrics. These metrics help you monitor the configuration items (CIs) in the CMDB.
View the ACC Health Dashboard -- The Agent Client Collector Health Dashboard enables you to monitor the status of the agents in your system.
ACC Discovery -- Discover CIs in your environment by using Agent Client Collector for Visibility Content (ACC-VC) Discovery. ACC-VC works with both horizontal IP-based Discovery, and you can also use push-based Discovery.
Using push and horizontal IP-based Discovery together -- Discovery performed by Agent Client Collector for Visibility Content (ACC-VC) is compatible and can coexist with horizontal IP-based Discovery. You may have ACC installed on a given target host and still have that host as part of a horizontal IP-based Discovery schedule as well.
Using push-based Discovery and EMA together -- Agent Client Collector for Visibility Content (ACC-VC) can collect data for uses cases with the Intel vPro platform when the Intel EMA application is installed on Windows endpoints. You can install the Intel EMA application from the ServiceNow store. Attributes are stored in the CMDB when enabled. Currently, data for Intel EMA can only be fetched for Windows endpoints.
Using push-based Discovery and SAM together -- Agent Client Collector for Visibility Content (ACC-VC) collects installed software data for use cases for Software Asset Management (SAM), when the SAM plugin is installed. Using push-based Discovery and SAM together can help optimize software data collection with SAM basic metering and SAM total usage metrics.
Configure Osqueryd schedule for SAM total usage metrics -- SAM total usage metrics works by relying on the Osqueryd service running on the target host. Configure the Osqueryd service to run the required schedule Osquery on the host.
Configure Osqueryd logs for SAM total usage metrics -- By default, Osquery supports log rotation based on size. To enable it for SAM total usage metrics and to configure the log size and rotation, you need to add specific flags for Osqueryd service.
Application patterns for the Agent Client Collector -- Application patterns gather details on the applications that run on the Agent Client Collector (ACC) host. Application patterns are supported only for servers, and are triggered after the Agent Client Collector host Discovery is complete.
Discovering DNS names using push-based discovery -- CMDB owners need CIs to contain all domain system names (DNS) associated with their system. Starting in Agent Client Collector for Visibility Content (ACC-VC) version 2.3.0, ACC-VC can discover DNS name lists for Windows and Linux CIs.
License key discovery -- License key discovery in Agent Client Collector for Visibility Content automatically collects software license keys from the Windows registry on managed endpoints.
Configure license key discovery -- Enable license key discovery and define the registry paths and values you want the Agent Client Collector for Visibility Content Windows agent to collect from managed endpoints.
ACC data input streaming sources -- In the ACC data input record, the Streaming Sources related list shows the streaming data of that data input's sources.
View log shipper alerts -- View all log shipper check alerts for Agent Client Collector Log Analytics (ACC-L) agents.
View log shipper events -- View all log shipper events with all severity levels for Agent Client Collector Log Analytics (ACC-L) agents.
Collect web usage data using ACC-VC -- Track website visits across your organization and gain visibility into web applications your users access using Agent Client Collector for Visibility Content (ACC-VC).
ACC deployment - endpoints -- When deploying the Agent Client Collector, perform deployment and management tasks on your endpoints.
Configuring MID-less ACC -- Configure MID-less Agent Client Collector to enable sending information through the cloud. Sending information through the cloud allows the MID Server to be used for more persistent resources.
Configure MID-less ACC using a single-line command -- Use a single-line command to set up a MID-less Agent Client Collector. You can also use the single-line command to migrate agents configured with a MID Server to have a MID-less configuration.
Installing MID-less ACC -- Installing MID-less Agent Client Collector enables you to send data from the agent to the instance through the cloud. Sending information through the cloud allows the MID Server to be used for more persistent resources.
Install MID-less ACC using a single-line command in a Windows environment -- Install MID-less Agent Client Collector on a Windows machine to enable sending data from the agent to the instance through the cloud. Sending information through the cloud allows the MID Server to be used for more persistent resources.
Install MID-less ACC manually in a Linux environment -- Install MID-less Agent Client Collector manually on a Linux machine to enable sending data from the agent to the instance through the cloud. Sending information through the cloud allows the MID Server to be used for more persistent resources.
Install MID-less ACC using a single-line command in a Linux environment -- Install MID-less Agent Client Collector on a Linux machine to enable sending data from the agent to the instance through the cloud. Sending information through the cloud allows the MID Server to be used for more persistent resources.
Install MID-less ACC manually in a macOS environment -- Install MID-less Agent Client Collector manually on a macOS machine to enable sending data from the agent to the instance through the cloud. Sending information through the cloud allows the MID Server to be used for more persistent resources.
Install MID-less ACC using a single-line command in a macOS environment -- Install MID-less Agent Client Collector on a macOS machine to enable sending data from the agent to the instance through the cloud. Sending information through the cloud allows the MID Server to be used for more persistent resources.
Configure an agent registration key -- Configure an agent registration key so that you can deploy MID-less Agent Client Collector. Deploying MID-less Agent Client Collector enables you to use the MID Server for more persistent resources.
ACC installation on a macOS system -- Install Agent Client Collector on a system that uses macOS. You can either use a single-line command script or follow a manual installation procedure if the agent is not connected to the instance or you want enhanced customization options.
Perform a single-line ACC installation on macOS when using a MID Server -- Use an efficient single-line command script to install Agent Client Collector on a machine that uses macOS operating system. Use the manual installation procedure if the agent is not connected to the instance or you want enhanced customization options.
Manually install ACC on macOS -- Install Agent Client Collector manually on a machine that uses macOS when the agent is not connected to the instance or you want enhanced customization options.
Upgrade ACC manually on a macOS system -- Perform a manual upgrade of your existing Agent Client Collector version on a system running a macOS. Manual upgrade is useful if the single-line command script isn’t connected to the instance or you want to use enhanced customization options.
Uninstall the ACC from macOS using a single-line command -- Uninstall the Agent Client Collector from macOS machine by running an efficient single-line command. If the agent is connected to the instance, uninstall Agent Client Collector manually.
Uninstall ACC from a macOS machine manually -- Uninstall the Agent Client Collector from a macOS machine manually instead of using the single-line procedure when the specific agent is not connected to the instance.
Agent Client Collector File-Based Discovery -- Agent Client Collector File-Based Discovery (FBD) scans file systems on managed endpoints to discover installed software and track file inventories.
Running process-based discovery -- Running process-based discovery extends File-Based Discovery (FBD) with process-based path detection, enabling the Agent Client Collector for Visibility Content agent to detect software running outside of standard configured scan directories.
Enable running process-based discovery -- Enable running process-based discovery so that the Agent Client Collector for Visibility Content agent detects software running from directories outside your configured File-Based Discovery scan paths.
Exclude directories from running process-based discovery -- Exclude specific directories from running process-based discovery so that processes running from those locations aren't recorded or included in File-Based Discovery scans.
Perform Zscaler remediation -- If the Zscaler application installed on your Windows or macOS agent is not running efficiently, you can stop and start the app. This process is called remediation. Running remediation automatically creates an incident on the agent. You can also view Zscaler statuses on the Zscaler dashboard as a graph.
Check Zscaler monitoring -- Check the monitoring status of your Zscaler app, to verify that it is running properly.
Customize the Zscaler remediation wait time -- Configure the amount of time (in seconds) by which the Zscaler remediation check verifies the Zscaler status. This amount of time indicates how often the system checks the Zscaler status after the remediation check runs.
Customize the Zscaler monitoring check -- Customize the frequency by which the Zscaler monitoring check runs. By default, the Zscaler monitoring check runs every 30 minutes. If your Zscaler app is not working efficiently, you can set the check to run more frequently.
Check Zscaler remediation -- Verify that Zscaler remediation stops and starts the Zscaler app after the remediation monitoring check fails.
Use the Zscaler dashboard -- Use the Zscaler dashboard to view Zscaler monitoring and remediation statuses in graph format.
Choose and configure metrics to monitor -- Metric Intelligence uses data sources that can be monitoring hundreds of metrics for all CIs. Choose for each data source type which details are important for which CIs, and then activate or deactivate the respective monitor type to control the amount of data that is being processed.
Create a configuration settings rule -- Configuration settings affect how metric data is processed. Configuration settings rules override the default metric processing behavior to determine the system actions when an anomaly is detected.
Synchronize configuration settings rules -- Metric Intelligence configuration settings rules contain user specified values that override default values that currently exist on Metric Intelligence MID Servers. To take effect, the Metric Intelligence MID Servers must be synchronized with the updated set of configuration settings rules.
Understanding the Monitoring Technology Dashboard -- The Monitoring Technology Dashboard enables you to monitor server resources for the platform you select. The dashboard enables you to identify the CIs and servers in your system with the highest resource consumption, and the most recent active alerts.
Monitoring Technology Dashboard for Linux -- With the Linux Monitoring Technology Dashboard, you can monitor the health and performance of your Linux infrastructure. The dashboard enables you to identify the CIs and servers in your system with the highest resource consumption, and also the most recent active alerts.
Monitoring Technology Dashboard for Windows -- With the Windows Monitoring Technology Dashboard, you can monitor the health and performance of your Windows infrastructure. The dashboard enables you to identify the CIs and servers in your system with the highest resource consumption, and also the most recent active alerts.
Monitoring Technology Dashboard for HTTP -- With the HTTP Monitoring Technology Dashboard you can monitor the response time of your http and https URLs. By using the dashboard, you can identify the URLs with the highest metric readouts in your system's infrastructure, and view the most recent active alerts on those URLs.
Monitoring Technology Dashboard for Azure -- With the Azure Monitoring Technology Dashboard, you can monitor the health and performance of your Azure infrastructure. By using the dashboard, you can identify the configuration items (CIs) and servers with the highest metric readouts, and view the most recent active alerts on those CIs.
Monitoring Technology Dashboard for AWS -- With the AWS Monitoring Technology Dashboard, you can monitor the health and performance of your AWS infrastructure. By using the dashboard, you can identify the configuration items (CIs) and servers with the highest metric readouts, and view the most recent active alerts on those CIs and servers.
Monitoring Technology Dashboard for GCP -- With the GCP Monitoring Technology Dashboard, you can monitor the health and performance of your GCP infrastructure. By using the dashboard, you can identify the configuration items (CIs) and servers with the highest metric readouts, and view the most recent active alerts on those CIs and servers.
Monitoring Technology Dashboard for VMware vSphere -- With the VMware vSphere Monitoring Technology Dashboard, you can monitor the health and performance of your VMware vSphere infrastructure. By using the dashboard, you can identify the configuration items (CIs) and servers with the highest metric readouts, and view the most recent active alerts on those CIs and servers.
Customize the Monitoring Technology Dashboard -- Customize the Monitoring Technology Dashboard widgets in the Data Visualizations library so your dashboard displays information exactly as you want to see it.
Setting exclusion lists for IPs and NICs -- Agent Client Collector for Visibility Content (ACC-VC) version 1.3.0 supports exclusion list for IPs and Network Interface Controllers (NICs) with a flexible mechanism for filtering out values for IPs and or NICs when creating or updating the host CI and related items.
Identify software editions on Windows devices -- Determine which edition of software is in use on Windows devices in your environment, to maintain an accurate software inventory. Software products commonly support multiple editions, making it difficult to identify which edition is in use.
Generate a Pattern allowlist -- Generate an allowlist for a selection of patterns, to configure the patterns permitted to run on an agent.
Define temporary variables for a pattern allowlist -- Define temporary variables by assigning values such as executable paths, config file paths, and so forth. Defining temporary variables ensures that runtime commands are successful.
Checks and policies -- A check is a combination of a command and its configuration. The check is executed on the Agent Client Collector's devices to gather data from those devices.
ACC configuration data files -- Configuration data files store dynamic instance data, such as virtual machine details, that check definitions use during execution. This ensures that checks are executed with up-to-date and accurate information about the instance being monitored.
Agent Client Collector API -- Use the Agent Client Collector (ACC) API to create a flow that executes an osquery command on agents and processes the results. By leveraging the ACC API, you can automate the querying of agent data and streamline the processing of results, making it easier to monitor and manage system performance.
ACC health instance scan suite -- The Agent Client Collector (ACC) health instance scan suite consists of checks that detect anomalies and other issues that might occur on your instance. These checks ensure the overall health and performance of the ACC, proactively identifying potential problems before they impact system operations.
ACC certificates -- Agent Client Collector certificates verify the authenticity of your agents, servers, and users. Using Agent Client Collector certificates ensures the safety of your environment.
Manually refresh ACC certificates -- Refresh Agent Client Collector self-signed certificates manually to validate Agent Client Collector plugins, instead of waiting for the scheduled synchronization. For example, you can use this feature when the agent can't validate a plugin and you don't want to wait for the scheduled synchronization.
Enable OpenSSL secure signing for plugins -- Create a self-signed certificate for an Agent Client Collector plugin. The following procedure gives an example of how to create an x509 certificate using OpenSSL. For other certificate types, consult OpenSSL documentation.
Add a certificate to your OS truststore -- Add a self-signed certificate to the truststore of your operating system (OS). By adding a certificate to the truststore, you can verify that the certificate is authentic and that your connections are secure.
Import a self-signed certificate -- Import a self-signed certificate in a Windows system by using the Certificate Import Wizard. The Certificate Import Wizard is required to complete the self-signed certificate import process on a Windows Operating System (OS).
Revoke ACC certificates -- Stop communication between the agent and ITOM cloud services by removing an Agent Client Collector certificate. For example, there might be a security breach due to which you want to stop communication by revoking the agent's certificate.
Agent certificate rotation -- The Agent Client Collector certificate is valid for two years and must be rotated before it expires to avoid issues with agent connectivity. When expiration is approaching, the agent initiates a certificate rotation request.
Run Certificate Discovery via ACC-VC -- Discover TLS/SSL certificates used by ports running on the agent's server. The Certificate Inventory and Management application uses this information to manage TLS/SSL certificates.
Collect data from your system devices -- Run a check command on your server or database to gather data from those devices. Depending on the check that is invoked, collected data may be monitoring data, visibility data, log data, or user metrics.
Verify data collection in ACC -- Collect data by gathering essential information from an agent's host system before executing any checks or policies. This process ensures that the Agent Client Collector has accurate and up-to-date data on the infrastructure, processes, and applications running on the host.
Create an ACC policy -- Policies consist of the CIs monitored by the Agent Client Collector and the checks that run on those CIs. When creating a policy, you configure a filter which determines the CIs on which the checks are to run. For example, a policy to run checks on all Apache web servers. You can create new policies or edit the default policies.
Create a policy hierarchy -- Policies are attached to groups of related CIs. If you have a subgroup of related CIs, you can attach a new policy to the subgroup using a policy hierarchy, without creating the new policy from scratch.
Edit a published policy -- A policy with a status of published has been passed through the MID Server and sent to the agent. To edit a published policy, you must enable editing.
Export and import an Agent Client Collector policy -- You can move a single or multiple Agent Client Collector policies from one ServiceNow instance to another by exporting the policy and then importing it into the target instance. Only published policies can be exported.
Create and edit checks -- You can select a check based on the type of entity (such as a server or an application) you want to monitor. You can view and edit the default checks or create new checks, as needed.
Test a check definition or check instance -- When working with a check definition or check instance, you can test the check against its assigned agent to ensure that the check is configured properly.
Create secure parameters for a check -- When creating a check definition or check instance, you can configure the parameters you want to be secured when the agent executes the check. During check execution, the secured parameters are obfuscated, securing their information. Only credential information is obfuscated.
Create a check type -- Create a check type to execute the osquery command on the Agent.
Enable checks from the community for ACC -- You can take checks from the github community and customize them for use in the Agent Client Collector (ACC), or you can compose your own scripts. Create a plugin with the customized Sensu check and install it on a ServiceNow instance.
Verify agent functionality -- Verify that an agent is running properly by performing a self-test on the agent. If one or more of the tests fail, you can diagnose the agent problem and view a potential resolution.
View the Agent feature matrix -- The Agent Client Collector Agent feature matrix displays the availability of Agent Client Collector features. The matrix displays data in a graph and a table.
View agent errors -- Agent Client Collector (ACC) errors are visible in logs related to the agent and the ServiceNow instance. This feature provides improved visibility of agent errors, enabling faster error resolution.
Using ACC logs -- Use Agent Client Collector logs to track events in your system. Log levels indicate the severity of each event.
Configure ACC log levels -- You configure the log levels that you want the Agent Client Collector logs to contain. All events that match or exceed the specified log level display in the Agent Client Collector logs.
View the ACC logs -- You can view the activity logs for an Agent Client Collector.
Set the agent log level -- Configure the agent log level directly from your ServiceNow instance, without needing to access the acc.yml configuration file.
Enable metrics collection and evaluation -- To enable a ServiceNow instance to collect and evaluate metrics, you must create a distributed MID Server cluster, associate MID Servers with the cluster, and enable Metric Intelligence for your MID Server.
Limit metrics collection and evaluation -- You can limit the metrics you send from the MID Server to the instance, either by de-activating a specific CI or an entire CI type.
Configure the action level for anomaly detection -- Create a configuration setting rule that refines the level of anomaly detection processing and analysis that is applied to specific CIs and metrics. Set a processing level that reflects the importance of metrics at different stages of implementation, to reduce data load if needed.
Create Azure policies for metric collection -- Create your own policies to enable Azure to collect the metrics for the resources that have policies that don’t come with the base system. The Azure Metrics Collector check brings the metrics to the agent through the Azure Metrics Batch API.
Block event creation for non-existent entities -- Invoke the skip_events_for_nonexistent parameter to block event creation when specific process, service, or log does not exist. Invoke this parameter if you do not want to be notified about these non-existent entities.
Enable viewing HAProxy metrics -- Configure the HAProxy metrics stats page to enable monitoring your system devices by viewing HAProxy metrics.
Enable Apache Kafka health monitoring -- Set configurations in the Apache HTTP server application to enable the Agent Client Collector to perform Apache Kafka HTTP server monitoring.
Detecting portable applications using push-based discovery -- Portable applications are those applications that don’t need to be installed on the target system. Starting in ACC-VC version 2.3.0, push-based Discovery can detect portable applications, such as Firefox, VLC, Notepad++ etc, for Windows only.
CNO for Visibility -- Cloud Native Operations for Visibility (CNO for Visibility) has been renamed Agent Client Collector for Kubernetes – Visibility. The term Cloud Native Operations for Visibility has been deprecated.
Enabling ACC data collection -- You can perform actions which enhance data collection from the hosts on which Agent Client Collector is running.
Create a call API to send an osquery request -- Create a background script to send an osquery request. The osquery request enables data collection from your host's operating system.
Generate an ACC allow list -- Specify the checks to be included in the list of checks that are enabled to run on the agent.
Run host data collection for an agent -- Collect data on the host being monitored by an agent. Manually collecting host data ensures that the host's files are up to date.
Run host data collection on demand -- You can perform host data collection on demand, if you need to perform data collection before the job is scheduled to run.
Pause ACC data collection -- If CPU consumption on your server is getting too high, you can manually turn off the Agent Client Collector data collection to pause all checks performed by the agent, except for the agent's keep alive messages.
Clear ACC plugins -- Clear the plugin and configuration file cache folder and control plugin downloads. Clearing the cache folder removes unwanted plugins that have synced to the agent.
Agent Client Collector Monitoring -- Agent Client Collector Monitoring enables you to monitor your service availability, examine the health and performance of your environment, and ensure that your infrastructure and its applications are running properly.
Exploring Agent Client Collector Monitoring -- Agent Client Collector Monitoring is built on a Sensu framework which enables you to adopt and extend monitoring checks from the community. Agent Client Collector Monitoring collects data on your company’s infrastructure and installed applications.
Agent Client Collector Log Analytics -- Agent Client Collector Log Analytics (ACC-L) enables you to stream log data from Linux and Windows hosts to a ServiceNow instance, using the Agent Client Collector.
Set up additional ACC data inputs -- Data inputs for streaming log messages to your ServiceNow instance using the Agent Client Collector are created automatically as part of the Agent Client Collector setup. Set up additional ACC data inputs manually as needed using the Health Log Analytics data input setup flow.
Configure ACC data inputs manually -- Agent Client Collector setup automatically creates an ACC data input for streaming log messages to your ServiceNow instance. You can set up additional ACC data inputs manually as needed.
Agent Client Collector log policies -- Agent Client Collector data inputs stream log messages to your ServiceNow instance using the ServiceNow Agent Client Collector. The Agent Client Collector Log Analytics (ACC-L) application provides predefined log policies for collecting log data from the CIs monitored by the ACC.
Create a child log policy -- Refine an existing log policy to focus on a subset of CIs or services by creating a child policy.
Edit a log policy -- You can edit published Agent Client Collector log policies. For example, modify a default log policy if your organization always uses a specific non-default log path.
View live CI data logs -- View CI logs to receive additional details on an incident when viewing live CI data. For example, viewing log information for a process with high CPU usage can help you pinpoint when the usage went up, helping you determine the root cause of the issue.
Assign a CI to an incident to view live CI data -- Retrieve live CI data to help troubleshoot the issues that caused an incident by assigning the problematic CI to its incident. An incident typically is associated with the CI that caused the incident, but if this was omitted during the incident creation, you can assign the CI manually.
ACC-F reference -- Reference topics provide additional information about mapping and fine-tuning application services using Agent Client Collector Framework lists and forms.
Agent Client Collector user roles -- Administrators can assign user roles to grant access to the Agent Client Collector. The following standard roles for the Agent Client Collector Framework (ACC-F) are included in the ServiceNow system with the Agent Client Collector installed on it.
Agent Client Collector certificate revocation reasons -- The following table lists and describes the possible reasons for revoking an Agent Client Collector certificate to stop communication between the agent and ITOM cloud services.
Agent Client Collector data collection tables -- Agent Client Collector performs data collection based on the scoped apps that you've installed. Agent Client Collector Framework performs basic data collection, and Agent Client Collector for Visibility Content performs enhanced data collection.
Account commands for Windows installation -- When installing an agent on a Windows host using a LocalService, LocalSystem, or gMSA account, you must run msi commands to enable the accounts.
Verify API is associated with a live agent -- Call the AgentNowHandler.hasAgent API to determine if the CI is associated with a live agent. The API gets a sys_id of the CI and returns a true/false result.
Agent Client Collector log levels -- The following table displays the available log levels which indicate the severity of Agent Client Collector events.
Agent Client Collector log rotation parameters -- If Agent Client Collector logs get too large, they can drain system resources. To ensure system efficiency, configure parameters in the acc.yml file by which to rotate logs out of the system's storage (Windows default location = C:\ProgramData\ServiceNow\agent-client-collector\config\acc.yml. Linux default location = /etc/servicenow/agent-client-collector/acc.yml).
ACC CPU protection thresholds -- When an agent meets the configured thresholds specified in the agent's acc.yml file, it enters CPU protection mode, either for an individual check or for all checks. Agents in CPU protection mode appear in the agent logs with the syntax Agent Protection.
Golden image structure and modularity -- The following table outlines the structure and modularity of the golden image mode for cloning agents, based on the operating system (OS) in use.
Agent Client Collector health instance scan checks -- The Agent Client Collector (ACC) health instance scan suite includes checks that detect anomalies and issues on your instance. Use this reference to identify what each check does and when it applies.
Agent onboarding configuration settings -- The settings you can customize when generating an Agent Onboarding installation plan. Toggle settings to activate and enable customization.
Agent installation plan steps -- After you complete agent onboarding, the system generates an installation plan. The following table describes each step in the plan and the commands or actions required.
ACC upgrade properties -- System properties that control Agent Client Collector upgrade behavior, including the target version, rate limits, retry logic, and timeouts.
ACC upgrade error codes -- Error codes generated during Agent Client Collector upgrades, with descriptions and resolution steps.
Supported platforms for auto-upgrade -- Operating systems and package types supported for Agent Client Collector auto-upgrade, and the minimum agent version required.
ACC-M reference -- Reference topics provide additional information about Agent Client Collector Monitoring checks and policies.
Agent Client Collector Monitoring Footprint -- The following table describes Agent Client Collector resource consumption. We supply performance testing values to specific customers upon request.
Active Directory metrics -- The following table lists the metrics that are gathered as output from Active Directory checks. Entries indicated as Featured metrics are high-visibility metrics that are displayed in the Operator Workspace Metric tab after an alert is generated. These metrics provide the operator with additional information to help them further explore the specified issue.
Apache Kafka default checks and policies -- Agent Client Collector provides the following policies for Apache Kafka health monitoring. Policies come with the checks specified in the indicated table. Policies and checks are available for both Windows and Linux.
Apache Kafka metrics -- The following table lists the metrics that are gathered as output from Kafka checks. Entries indicated as Featured metrics are high-visibility metrics that are displayed in the Operator Workspace Metric tab after an alert is generated. These metrics provide the operator with additional information to help them further explore the specified issue.
AWS metrics -- The following tables list and describe the metrics that are gathered as output from the specified AWS checks. Entries indicated as Featured metrics are high-visibility metrics that are displayed in the Operator Workspace Metric tab after an alert is generated. These metrics provide the operator with additional information to help them further explore the specified issue.
Azure metrics -- The following tables list and describe the metrics that are gathered as output from Azure checks. Entries indicated as Featured metrics are high-visibility metrics that are displayed in the Operator Workspace Metric tab after an alert is generated. These metrics provide the operator with additional information to help them further explore the specified issue.
Azure cloud metrics -- Azure cloud metrics are gathered from Azure virtual machines (VMs) and Azure storage account policies. Collecting the cloud metrics enables you to monitor the performance of your Azure resources.
Cassandra default checks and policies -- Agent Client Collector provides the following policies for Cassandra health monitoring. Policies come with the checks specified in the indicated table. Policies and checks are available for Linux only.
Cassandra metrics -- The following table lists the metrics that are gathered as output from Cassandra checks. Entries indicated as Featured metrics are high-visibility metrics that are displayed in the Operator Workspace Metric tab after an alert is generated. These metrics provide the operator with additional information to help them further explore the specified issue.
Google Cloud Platform (GCP) metrics -- The following table lists and describes the metrics that are gathered by the acc_grp_metrics_list.json configuration data file. The file is uploaded to a check definition or check instance, and the metrics in the file are monitored by the check for its agent.
GlassFish metrics -- The following table lists the metrics that are gathered as output from GlassFish checks. Entries indicated as Featured metrics are high-visibility metrics that are displayed in the Operator Workspace Metric tab after an alert is generated. These metrics provide the operator with additional information to help them further explore the specified issue.
HAProxy metrics -- The following table lists the metrics that are gathered as output from HAProxy checks. Entries indicated as Featured metrics are high-visibility metrics that are displayed in the Operator Workspace Metric tab after an alert is generated. These metrics provide the operator with additional information to help them further explore the specified issue.
HTTP default checks and policies -- Agent Client Collector provides the following policies for HTTP health monitoring. Policies come with the checks specified in the tables below.
HTTP entry point metrics -- The following table lists the metrics that are gathered as output from HTTP entry point checks. Entries indicated as Featured metrics are high-visibility metrics that are displayed in the Operator Workspace Metric tab after an alert is generated. These metrics provide the operator with additional information to help them further explore the specified issue.
HTTP response code check -- Agent Client Collector provides the following additional check for HTTP response code. This check is not associated with any policy.
Internet Information Services (IIS) metrics -- The following table lists the metrics that are gathered as output from IIS checks. Entries indicated as Featured metrics are high-visibility metrics that are displayed in the Operator Workspace Metric tab after an alert is generated. These metrics provide the operator with additional information to help them further explore the specified issue.
Linux default checks and policies -- Agent Client Collector provides the following default checks and policies for Linux Metrics monitoring.
Linux metrics -- The following table lists the metrics that are gathered as output from Linux checks. Entries indicated as Featured metrics are high-visibility metrics that are displayed in the Operator Workspace Metric tab after an alert is generated. These metrics provide the operator with additional information to help them further explore the specified issue.
MongoDB default checks and policies -- Agent Client Collector provides the following policies for MongoDB health monitoring. Policies come with the checks specified in the indicated table. Policies and checks are available for both Windows and Linux.
MongoDB metrics -- The following table lists the metrics that are gathered as output from MongoDB checks. Entries indicated as Featured metrics are high-visibility metrics that are displayed in the Operator Workspace Metric tab after an alert is generated. These metrics provide the operator with additional information to help them further explore the specified issue.
MSSQL default checks and policies -- The Agent Client Collector provides the following default checks and policies for MSSQL Metrics monitoring.
MySQL default checks and policies -- The Agent Client Collector provides the following default checks and policies for MySQL Metrics monitoring.
Network ping default checks and policies -- Agent Client Collector provides the following default checks and policies for Network ping monitoring. Policies and checks are available for both Windows and Linux.
Network ping metrics -- The following table lists the metrics that are gathered as output from Network ping checks. Entries indicated as Featured metrics are high-visibility metrics that are displayed in the Operator Workspace Metric tab after an alert is generated. These metrics provide the operator with additional information to help them further explore the specified issue.
Network host availability check -- Agent Client Collector provides the following default check for network ping monitoring. The check is available for both Windows and Linux.
Nginx default checks and policies -- Agent Client Collector provides the following policies for Nginx health monitoring. Policies come with the checks specified in the indicated table. Policies and checks are available for both Windows and Linux.
Nginx metrics -- The following table lists the metrics that are gathered as output from Nginx checks. Entries indicated as Featured metrics are high-visibility metrics that are displayed in the Operator Workspace Metric tab after an alert is generated. These metrics provide the operator with additional information to help them further explore the specified issue.
PostgreSQL metrics -- The following tables list and describe the metrics that are gathered as output from the specified PostgreSQL checks. Entries indicated as Featured metrics are high-visibility metrics that are displayed in the Operator Workspace Metric tab after an alert is generated. These metrics provide the operator with additional information to help them further explore the specified issue.
RabbitMQ default checks and policies -- Agent Client Collector provides the following default checks and policies for RabbitMQ health monitoring. You must perform RabbitMQ discovery before executing the checks. RabbitMQ checks are available only in a Windows environment.
RabbitMQ metrics -- The following table lists the metrics that are gathered as output from RabbitMQ checks. Entries indicated as Featured metrics are high-visibility metrics that are displayed in the Operator Workspace Metric tab after an alert is generated. These metrics provide the operator with additional information to help them further explore the specified issue.
Varnish metrics -- The following table lists the metrics that are gathered as output from Varnish checks. Entries indicated as Featured metrics are high-visibility metrics that are displayed in the Operator Workspace Metric tab after an alert is generated. These metrics provide the operator with additional information to help them further explore the specified issue.
vSphere metrics -- The following table lists the metrics that are gathered as output from vSphere checks. Entries indicated as Featured metrics are high-visibility metrics that are displayed in the Operator Workspace Metric tab after an alert is generated. These metrics provide the operator with additional information to help them further explore the specified issue.
Windows default checks and policies -- Agent Client Collector provides the following default checks and policies for Windows health monitoring.
Windows metrics -- The following table lists the metrics that are gathered as output from Windows checks. Entries indicated as Featured metrics are high-visibility metrics that are displayed in the Operator Workspace Metric tab after an alert is generated. These metrics provide the operator with additional information to help them further explore the specified issue.
Azure metrics script -- When creating a new policy for Azure cloud metrics, create a .json script to determine the metrics to be monitored. The format for the script appears below, followed by a table explaining the script contents.
Components installed with Metric Intelligence -- Several types of components are installed with activation of the Metric Intelligence (com.snc.sa.metric) plugin, including tables, scheduled jobs, and properties.
Quick start tests for Metric Intelligence -- Validate that Metric Intelligence still works after you make any configuration change such as apply an upgrade or develop an application. Copy and configure these quick start tests to pass when using your instance-specific data.
Event severities -- The event severity numbers correspond to actual severities on the Metric Anomaly Score to Event Severity Maps page.
ACC-VC reference -- Review this information for details on OS query scripts, data collected, and definition of terms.
ACC-VC default checks and policies -- Agent Client Collector for Visibility Content (ACC-VC) provides various checks and policies as well as a business rule.
Software edition configuration fields -- Description of the software edition configuration fields in use when identifying the edition of Windows software.
ACC File-Based Discovery properties -- Configure File-Based Discovery behavior using system properties that control scanning paths, performance throttling, and file filtering options.
Archive file scanning rules and limits -- Reference information for the filtering rules and performance safeguards that apply when Agent Client Collector for Visibility Content scans ZIP and JAR archive files during File-Based Discovery.
License key discovery and access control tables -- Reference information for the tables, fields, access control, and scheduled job used by license key discovery in Agent Client Collector for Visibility Content.
Running process-based discovery platform coverage and properties -- Platform coverage identifies which operating systems are supported and what privileges the agent needs for full coverage. The system property controls whether the feature is enabled or disabled.
Metric Intelligence -- ServiceNow Metric Intelligence provides the ability to capture, and then explore and analyze operational metrics data, identifying and indicating anomalies. Metric Intelligence generates anomaly alerts that can be promoted to IT alerts and appear on the Service Operations Workspace and service health dashboard. You can leverage this analysis to prevent potential service outages.
Exploring Metric Intelligence -- Learn more about using Metric Intelligence to analyze metric data and identify anomalies.
Understanding Metric Intelligence -- Use Metric Intelligence to identify and prevent potential service outages. Metric Intelligence, based on historical metric data, indicates anomalous behavior of CIs which events might not capture. Anomaly alerts can be promoted to regular IT alerts and appear on the Service Operations Workspace and service health dashboard for preventive actions.
MID setup for Metric Intelligence -- Using Metric Intelligence requires at least one MID Server distributed cluster which contains a single MID Server that is configured for Metric Intelligence.
Metric Configuration Rules -- Metric configuration rules enable you to determine how incoming metrics from the Agent Client Collector are to be processed.
Metric bounds sensitivity -- When monitoring metrics in Insights Explorer, the system might detect too many anomalies if the sensitivity settings are too narrow. When detecting a large number of anomalies, the system automatically adjusts to reduce false alerts.
Metric collection sources -- When setting up Metric Intelligence, you must configure a source for metric collection. Metric collection can be performed either by the Agent Client Collector, or by metric connectors.
Metric binding -- After metric data is collected, Metric Intelligence identifies the CIs and the resources to bind the data to.
Metric binding to resources -- Bind metrics to resources to simplify metric events binding by enabling binding to resources such as specific disks or web pages, in addition to binding to CIs.
Creating an event rule to map metrics to specific CIs -- Create event rules to map incoming raw metric data to specific CIs, to optionally modify metric names, and to populate the resource_path attribute for resource binding.
CIs in maintenance mode -- Configure anomaly detection to exclude metrics for CIs that are in maintenance mode from model learning.
Anomaly model testing -- Use anomaly model testing to apply and evaluate anomaly detection for a small set of CIs and metrics, using actual metric data. Compare test results to expected results, then fine-tune the anomaly detection model before enabling anomaly detection for the tested CIs and metrics in the production environment.
Advanced Promotion Engine -- You can create a definition for the Advanced Promotion Engine so that you can define the conditions for promoting the anomaly alerts to the All Alerts table. By promoting the alerts that meet the conditions, only the most relevant anomaly alerts move to the table.
Metric Explorer -- Metric Explorer provides an easy-to-navigate interface where service agents can view the health of a CI associated with an alert. Health details for a CI include various metric charts with control bounds, and aggregations in a time period.
Self-health monitoring for Metric Intelligence -- Use Event Management self-health monitors to monitor the health of Metric Intelligence infrastructure components and processes, and to alert about potential issues. Self-health monitoring allows you to proactively remediate issues and minimize data loss.
Domain separation and Metric Intelligence -- Domain separation is supported in Metric Intelligence. Domain separation enables you to separate data, processes, and administrative tasks into logical groupings called domains. You can control several aspects of this separation, including which users can see and access data.
Activating Metric Intelligence -- Metric Intelligence enables you to capture, explore and analyze operational metrics data, identifying and indicating anomalies. This analysis can prevent potential service outages.
Automated Metric Intelligence setup -- When you initially set up Metric Intelligence, you can automate many of the setup steps. For example, the automated setup configures a MID Server for Metric Intelligence and creates a MID Server distributed cluster which contains that MID Server.
Manually configure a MID Server for Metric Intelligence -- To use Metric Intelligence, configure at least one MID Server with Metric Intelligence as a supported application, with the Metrics capability, and which runs the Metric Intelligence Metrics extension. Then, add that Metric Intelligence MID Server as a member to a MID Server distributed cluster.
Manually configure the Metric Intelligence extension -- Configure the MID Server Metric Intelligence extension to enable the MID Server to pull raw metrics from external systems, to detect anomalies and report anomalies to the instance along with raw data. This MID Server Metric Intelligence extension is required and must be running in order for your system to be able to collect Metric Intelligence data.
Create an anomaly test rule -- To use the anomaly model testing, create an anomaly test rule in which you specify up to 20 metric series to test anomaly detection for. Run the anomaly test, and after it completes, use the provided URL to open the Insights Explorer which is pre-loaded with the model testing results.
View metric to CI and resource binding -- View the metric to CI and resource binding results, including details for failed bindings which you can use to mitigate the failure. If Metric Intelligence cannot map and bind a metric to a CI or to a resource, then that CI or resource is not included in anomaly detection until it is properly mapped.
Disable a metric for a CI -- Metric Intelligence can be configured to collect significant amounts of data, some of which might not be necessary. To improve performance, you can disable a specific metric for a specific CI to stop processing data related to the specified metric and CI.
Disable event collection -- For performance reasons, you might want to disable the collection of events from a data source from which metric data is also collected. You can disable event collection for data sources such as Nagios XI server, SolarWinds monitoring system, and Zabbix server.
Configure anomaly score thresholds -- Metric Intelligence scores anomalies on a range 0-10. This range is broken down to the five levels of event severities, each represented by a different color in the Insights Explorer and in the Anomaly Map. You can configure the anomaly score threshold for each level of severity.
View anomaly alerts -- Anomaly alerts indicate deviation from projected metric values for monitored CIs. Anomaly alerts are separate from regular IT alerts. They appear in the Service Operations Workspace but not in Express List. You can define an anomaly alert promotion rule to generate an IT alert that is based on anomaly alerts.
View metric values in the Insights Explorer -- Metric Intelligence calculates statistics for CI metric data. Insights Explorer displays these metric values as metric charts for the CIs in the CMDB. Insights Explorer lets you overlap any metrics for any CIs in a single chart to create a multi-layered view of metric values across a time range.
Create an Insights Explorer view -- You can create a custom view in the Insights Explorer that saves any metric charts that were added to the canvas, and any added configuration items. After you create a view, you can share a link to the view.
View metric charts in Agent Workspace -- Agent Workspace for Metric Intelligence provides easy access to metric charts for a CI. On an alert form, you can drill down to important metric charts for the CI that is associated with the alert.
Configure metric charts for Agent Workspace -- Configure the set of Metric Intelligence metric charts, chart types, and other chart characteristics, that appear in Agent Workspace.
MI self-health monitoring stats -- Monitor the status of components and processes of Metric Intelligence. Use the XMLStats page to view statistics and diagnostic details that can help with troubleshooting issues with Metric Intelligence.
Create a definition for the Advanced Promotion Engine -- Create a definition for the Advanced Promotion Engine so that you can define the conditions for promoting the anomaly alerts to IT alerts. By promoting the alerts that meet the conditions, only the most relevant alerts move to the table.
View the promoted events -- View the anomaly alerts that the Advanced Promotion Engine promoted to IT events. Viewing IT events enables you to track the source of the event.
View the promoted anomaly alerts -- View the anomaly alerts that the Advanced Promotion Engine promoted to events, which are then processed as alerts in the All Alerts table. Viewing alerts in the All Alerts table enables you to track the source of the alert.
Create metric rules -- Create a metric rule to determine the metric, the threshold values and ranges, and the severity level of generated events. You can add a filter that determines the Configuration Items (CI) types or resources for which you receive alerts. For example, you can configure a filter to receive alerts only for Windows servers.
Metric Intelligence reference -- Reference topics provide additional information about Metric Intelligence settings and properties.
Insights Explorer settings -- You can configure Insights Explorer settings to control for example, the refresh frequency or the display of related records.
Sensitivity bounds properties for Insights Explorer metrics -- The following properties can be configured to customize system behavior when detecting sensitive bounds for Insights Explorer metrics. To invoke changes to the default values, navigate to System Properties All Properties and add the indicated properties (they are not visible by default).
Now Assist for ITOM -- Use the ServiceNow Now Assist for ITOM application to analyze alerts in Event Management. Alert analyses include a human-readable brief of the alert and technical information to help you investigate the alert more effectively.
Explore -- The Now Assist for IT Operations Management (ITOM) application uses generative AI to provide alert analyses. Alert analyses include a human-readable brief of the alert and technical information to help you investigate the alert more effectively.
Configure -- Enable Event Management users to view alert analyses that Now Assist for ITOM creates using generative AI.
Activate the analyze service health skill -- The analyze service health skill uses generative AI to provide an analysis of all Service Observability dashboards for the selected service. You need to activate this skill before using it.
Activate the analyze Service Observability dashboard skill -- The analyze Service Observability dashboard skill uses generative AI to provide an analysis of a Service Observability dashboard. You need to activate this skill before using it.
Activate the Service Mapping Candidate skill -- The Service Mapping Candidate skill provides Now Assist the ability to classify app service candidates and generate a description for them. The skill is active by default. If needed, administrators can activate or deactivate the skill.
Activate the Service Mapping Candidates Impact skill -- The Service Mapping Candidates Impact skill analyzes connections and effects on servers. It enables generating an impact summary, using Now Assist. The skill is active by default. If needed, administrators can activate or deactivate the skill.
Configure the Dynatrace analysis AI agent -- Configure the Dynatrace analysis AI agent for the analyze alert impact agentic workflow. This configuration also supports the Dynatrace observability skill in the manage alerts autonomously agentic workflow. After you configure the agent, the workflows can surface information from Dynatrace to help you investigate alerts.
Configure the Google Gemini Cloud Assist agent -- Configure the Google Gemini Cloud Assist agent to use the Gemini Cloud Assistant observability skill in the manage alerts autonomously agentic workflow. Once configured, the skill gathers information to help you investigate alerts.
Configure observability agents for Now Assist -- Configure observability agents for third-party application performance monitoring (APM) or network performance monitoring (NPM) vendors. These agents are invoked by the analyze alert impact agentic workflow. You must configure connections to those vendors before they can be invoked.
Use generative AI -- Use the ServiceNow Now Assist for ITOM application to view alert or incident analyses that Now Assist creates using generative AI.
View an alert analysis by Now Assist in Service Operations Workspace -- View an alert analysis by Now Assist for an alert on the alert's Overview tab in the Service Operations Workspace. Alert analyses include a human-readable brief of the alert and technical information to help you investigate the alert more effectively.
View an alert analysis by Now Assist in Express List -- View an alert analysis created by Now Assist using generative AI. Alert analyses include a human-readable brief of the alert and technical information to help you investigate the alert more effectively.
View an alert group analysis by Now Assist in Express List -- View an alert group analysis created by ServiceNow Now Assist using generative AI. The analysis offers a simplified, human-readable description of the alert group and technical information to help you investigate it more efficiently.
Generate an alert group description in Express List using Now Assist -- Use Now Assist to generate a meaningful description of an alert group in Express List that encompasses all the alerts within the group. The generated description replaces the original description of the group.
Use agentic AI -- Use the IT Operations Management (ITOM) agentic workflows to complete tasks autonomously.
Analyze alert impact agentic workflow -- Use the analyze alert impact agentic workflow to investigate an alert and get the context that you need to respond efficiently.
Analyze alert impact in the Now Assist panel -- Learn how to use the analyze alert impact agentic workflow in the Now Assist panel. The agentic workflow helps you investigate an alert and get the context that you need to respond efficiently.
Analyze potential impact agentic workflow -- The Analyze potential impact agentic workflow analyzes how a change request might impact servers and services. This analysis helps you make informed decisions about the next steps regarding the change request.
Assess change request with analysis of potential impact -- Use the Analyze potential impact agentic workflow to assess the effects of a change request. This workflow highlights the potential impacted servers and suggested services to help you identify risks, benefits, and make any necessary adjustments.
Now Assist certificate renewal AI agent -- Using the Now Assist certificate renewal AI agent, see which certificates are about to expire and renew them. Choose a specific certificate and renew it on the spot.
Discover and renew certificates about to expire using Now Assist -- Use Now Assist to find out which certificates expire on a certain date or within a certain date range. Now Assist produces a Unique Certificates list of these certificates and prompts you to renew them in a single click.
Review AI-generated alert insights in Express List -- Access alert information in Express List that is consolidated autonomously by AI skills and agents. Use the AI insights badge, column, and filter to monitor alert statuses and review of AI-generated insights.
Reference -- Reference topics provide additional information for configuring and using the Now Assist for ITOM application.
Applications installed with Now Assist for ITOM -- Table that lists applications installed with the Now Assist for IT Operations Management (ITOM) application. When you update your application, any newly required application dependencies are installed.
Exploring LEAP -- LEAP categorizes similar incidents into groups and uses AI to generate resolution steps, problem records, AI-enhanced knowledge base articles, and playbooks.
LEAP features -- LEAP includes features such as grouping incidents, creating problem records, and generating playbooks.
LEAP savings metrics -- LEAP displays two distinct types of savings metrics: projected savings and actual savings. The difference between these metrics helps you correctly interpret the values shown across the platform and make informed decisions about automation opportunities.
Prioritization logic for automation of LEAP -- LEAP uses built-in prioritization logic to identify the highest-impact automation opportunities. This logic helps you focus on the most valuable automation tasks. The calculations provide an estimate of potential cost and time savings. It's best to validate these values in a non-production environment before implementing them in production.
LEAP AI agent -- Enhance IT operations with AI-driven, autonomous artifact creation such as problem records, knowledge base articles, and playbooks using LEAP AI agent.
Automation opportunities -- LEAP groups similar incidents into automation opportunities and uses AI to generate resolution artifacts that help reduce manual effort and repeat incidents.
Automation opportunity sub-groups -- Large automation opportunities in LEAP can be broken into smaller, more manageable sub-groups to achieve more granular and accurate incident resolution.
Missed automation opportunities -- Track instances where users could have benefited from generated resolution steps, knowledge base articles, or playbooks but didn't have access to them.
Ansible automation integration -- The Ansible automation integration connects LEAP with Ansible Automation Platform to enable AI-driven discovery of relevant job templates and automated incident remediation from the Service Operations Workspace.
Ansible discovery agent -- The Ansible discovery agent analyzes automation opportunities and identifies relevant Ansible job templates using AI-powered semantic matching and historical execution patterns.
Configuring LEAP -- You can download and install LEAP application from the ServiceNow Store to manage your IT operations efficiently.
Install LEAP -- You can install the LEAP application using Now Assist for IT Operations Management (ITOM) (sn_itom_gen_ai) if you have the admin role. If the application does NOT include demo data or it does NOT install related applications and plugins, delete or revise the following sentence:The application installs related ServiceNow Store applications and plug-ins if they aren’t already installed.
Setup LEAP properties -- Configure LEAP properties to estimate cost and time savings calculations for your organization.
Activate LEAP -- Activate the LEAP skill after installing the application to assemble and categorize incidents.
Change LEAP LLM models -- LEAP allows you to change the default LLM provider from the Now LLM to your required LLM.
Configure Ansible automation integration -- Connect LEAP to Ansible Automation Platform so the Ansible Discovery and Execution Agents can automatically identify job templates and launch them during incident remediation.
Using LEAP -- Use LEAP to analyze automation opportunities (AOs), generate resolution steps and playbooks, create problem records, build knowledge base articles, and execute Ansible automations during incident remediation.
Create sub-groups for automation opportunities -- Large automation opportunities in LEAP are broken into smaller, more manageable sub-groups to support focused and contextual incident resolution steps.
Create LEAP problem records -- Create problem records for LEAP from available incident clusters, also known as automation opportunities, for further analysis.
Generate LEAP knowledge base articles -- Generate AI-enhanced knowledge base articles from automation opportunity resolution steps to share structured, publication-ready knowledge across your organization.
View resolution step recommendations in SOW -- Use LEAP to view AI-generated resolution step recommendations that match the incident description in SOW to resolve incidents more efficiently.
Create LEAP playbooks -- Create standard, dynamic, and automated playbooks using LEAP to promote fast incident resolution and response time.
Map Ansible jobs to resolution steps -- Create mappings between automation opportunity resolution steps and Ansible job templates to enable automated incident remediation.
Execute Ansible automations for incidents -- Use the Ansible Execution Agent to automatically launch mapped Ansible job templates during incident remediation in the Service Operations Workspace, reducing manual effort and accelerating mean time to resolution..
LEAP reference -- These topics provide detailed field description information required during LEAP installation.
LEAP Installer fields -- Field values that you configure when installing LEAP using the LEAP Installer.
Components installed with LEAP -- Several types of components are installed with activation of the plugin, including tables, user roles, and scheduled jobs.
LEAP settings fields -- LEAP settings page field values help estimate cost and time savings when automation is used. These settings support cost predictability.
LEAP AI indicators -- AI indicators mark the artifacts that the LEAP AI agent creates. They appear on the home page list and on the automation opportunity details page.
Access to cloud environments for ITOM products -- If your organization deploys IT assets on the cloud, ITOM products must access your cloud environment to collect information about the IT infrastructure.
Cloud Request Retry Configuration -- If a request is throttled by a cloud provider during Discovery, Cloud Request Retry Configuration provides a customizable method to retry requests. Discovery and Service Mapping Patterns includes a retry configuration for AWS and Azure. You can customize the included configuration or create your own.
Set up a cloud service account -- Create and configure ServiceNow cloud accounts at ServiceNow AI Platform for the corresponding Cloud vendor service accounts.
OCI access and permission using policies -- Oracle Cloud Infrastructure (OCI) access and permission using policies provide privileges for secure cloud resource utilization and management in OCI.
Create Oracle API credentials -- Create Oracle API credentials on the ServiceNow AI Platform to enable access to your Oracle resources during Oracle discovery.
Create OCI service accounts -- Create Oracle Cloud Infrastructure (OCI) service accounts on the ServiceNow AI Platform to access your Oracle account during Oracle discovery.
Setting up AWS service accounts -- Create and configure cloud service accounts at ServiceNow AI Platform for the corresponding Amazon Web Services (AWS) service accounts.
Access setup for AWS service accounts -- Cloud Discovery and Cloud Provisioning and Governance need access to resources in the Amazon Web Services (AWS) service accounts. Learn about different methods of configuring such access.
Configure access using permanent credentials -- To securely access data on your provider account, the Discovery process must present appropriate credentials. To make the credentials available to Discovery and Cloud Provisioning and Governance, you first create a user with programmatic access in the AWS Management Console. You then securely store the credentials in a service account at ServiceNow AI Platform.
Create AWS service accounts -- Create AWS service accounts on the ServiceNow AI Platform to access your AWS account during AWS discovery.
Configure MID Server for IAM roles -- Configure the MID Server to retrieve the temporary security credentials associated with an IAM role.
Control AWS access and permissions using policies -- I have reworked this topic to fit the new accessibility configuration structure. Per our discussion, please remove this topic from the CPG map and add a reference to the new access configuration anchor (./../discovery/concept/access-aws-accounts.dita) to the AWS Day 1 landing page. Configure policies with the necessary level of permissions to provide access to the AWS resources for Cloud Discovery and Cloud Provisioning and Governance.
Set up Azure service accounts -- Create and configure cloud service accounts at ServiceNow AI Platform for the corresponding Microsoft Azure accounts.
Set up Google Cloud Platform service accounts -- Create and configure cloud service accounts at ServiceNow AI Platform for the corresponding Google Cloud Platform (GCP) service accounts.
Create GCP service accounts -- Create Google Cloud Platform (GCP) service accounts on the ServiceNow AI Platform to access your GCP account during GCP discovery.
GCP access and permission using policies -- Google Cloud Platform (GCP) access and permission using policies provide privileges for secure cloud resource utilization and management in GCP.
Exploring Service Mapping -- Service Mapping discovers all service instances in your organization and builds a comprehensive map of all devices, applications, and configuration profiles used in these service instances.
Application service maps in classic Service Mapping -- Maps offer you a visualization of data on configuration items (CIs) comprising application services, and relations and connections between these CIs.
Check CI dependencies -- You can see if a particular configuration item (CI) is part of other application services and check if it depends on other CIs.
Pattern-based discovery in Service Mapping -- Pattern-based discovery is the main method of Service Mapping collecting data about devices and applications used in application services. After Service Mapping collects data, it then creates a map of application services and stores the collected data in the CMDB.
Pattern-based discovery in Service Mapping -- Pattern-based discovery is the main method of Service Mapping collecting data about devices and applications used in application services. After Service Mapping collects data, it then creates a map of application services and stores the collected data in the CMDB.
View the change history of application services in classic Service Mapping -- You can view the changes made to an application service as a whole and to the individual configuration items (CIs) comprising the service. Change history is useful for maintenance, planning, or troubleshooting procedures.
Modify tracking changes in configuration files -- Configure the system to collect information about changes in configuration files belonging to a configuration item (CI). Service Mapping uses this information to notify users that CI configuration files changed and to view actual changes to configuration files directly in the service instance maps.
Compare two versions of an application service in classic Service Mapping -- You can see a summary of application service changes at a glance by comparing two versions of an application service. This feature is useful for checking the application service status before and after a certain change or problem.
PowerShell for Discovery and Service Mapping -- MID Servers use PowerShell and PowerShell Remoting for accessing configuration items (CIs) during horizontal and top-down discovery. Review MID Server parameters and script includes, probe parameters, and credentials for using PowerShell.
PowerShell for Discovery and Service Mapping -- MID Servers use PowerShell and PowerShell Remoting for accessing configuration items (CIs) during horizontal and top-down discovery. Review MID Server parameters and script includes, probe parameters, and credentials for using PowerShell.