MID Server Audit Logs in ServiceNow Quebec
markup here from glidefast consulting and i just want to walk you through one of the new features that became available in the quebec release that's going to help us out significantly in the item space the servicenow discovery is one of the market leaders of a discovery tool to populate our cmdb but as with any discovery tool that operates in an agentless fashion we require a series of service accounts to enable us to perform our discovery and collection of the payload successfully and this typically involves a number of interactions with the security team to be able to generate these service accounts with adequate and required privileges and in the past being able to articulate exactly what we need hasn't been the most transparent we can share servicenow documentation that outlines the series of commands that's going to be used in effect but they are quite high level they don't go quite to the level of granularity that a lot of security teams is going to be looking for we can sit down in a workshop and go through the discovery patterns themselves outlining each of the patterns and steps that's involved and the commands that are executed but as you can see there isn't a series of patterns and steps that's involved that could take a significant period of time to go through with all the various different technologies so in the quebec release we're actually fortunate enough now that we have what we consider mid server audit log so this mid server audit log allows us to run discovery with this parameter set to true and the result of it allows us to see all of the different commands that are executed against that target device so we can work closely with the security team up front run some initial scans to begin with and we can start building out our privileges associated with our service account i can simply look at this success rate of the previous run and i can see the various different commands that we're trying to execute that are currently not being we don't have the privilege to run and it's resulting in a failure of execution once we feel confident that our service account has been built out appropriately we're then in a position where we can scale it out across the various different endpoints and devices to allow a service account to operate successfully upon once we've run our just built this out you want to make sure that you're setting your audit log properly back to false we don't want to leave it in a debug mode so i come back in set this value and now we're in a position to continue to run our discovery across our entire environment populate all the great information such as the hardware information operating system information and coming down to some of these key characteristics that are often overlooked such as the installed software running processes and if you want to have effective application dependency mapping and feed into our service mapping capabilities having the tcp connectivity table completely populated is a must appreciate you taking the time out and i advise that you check out the mid server auto log thank you [Music] you
https://www.youtube.com/watch?v=yebwHRUjyEw