logo

NJP

ServiceNow Quebec: Instance Scan, Part Deux

Import · Mar 18, 2021 · video

all right let's let's i'll tell you what we'll do we'll wind it back one moment we've got audio now let's try again good evening and welcome to phil goes deep this is uh part d of the intro for instant scan part d excuse the french on tonight's show we have got two very special guests i'm pleased to announce and with audio i'm going to bring them in and let them introduce themselves so i believe you should be on the show live and apologies for technical difficulties as always um andrew you're sitting above me in the zoom window so do you want to just give a quick intro absolutely i'm andrew barnes uh developer advocate at servicenow i have been developing on the platform for about seven years and i specialize in building integrations custom maps and managing large-scale development and you can find me over at developer.servicenow.com and uh super excited to be here talking about instant scan and quebec features excellent thank you mark do you want to go yeah mark magrudov uh working for queen technology as a platform architect in the netherlands and now into servicenow for a bit more than four years yeah loving it a lot uh yeah great to be here today uh diving again in a bit more of instant scan so uh yeah great excellent and thank you both for for joining me tonight once again apologies for the technical difficulties i always expect them uh and tonight we had some so that's good we tick one thing off the list already [Laughter] in terms of uh quebec and instant scan for me this is one of the biggest features that was coming out it was kind of mentioned orlando paris and i was like nothing in the release notes and then quebec it was announced and i thought excellent right can't wait to get into this and then i found out from mark actually it's been there in orlando or paris hiding so uh mark you've got a bit of a head start on um on instant scan so you know where do you see this fitting into the service now i don't say the ecosystem but in terms of you know as partners or as customers where's instant scan gonna fit in for you where do you see it being used um well uh i think it's it's a use usable for everyone if it's a partner or if it's at the customer themselves it doesn't really matter it's just you get a really powerful scan engine with which you can interrogate your your instance basically and you can check for things like well improving release upgrades assessing instance health but also accelerating devops automate doing automated code reviews but also centralize your best practices well and we can go on and on and on about this so yeah it's just a really great subject i mean don't get me wrong every release a lot of new things i introduce which are really great but like this with instascan for me this is really core and really essential it's it's yeah you really need this and like at our at our company we we did had a our own kind of health scan health check but now this is out of the box it's standard activated on every instance there are no additional license costs and the scan agent is just so powerful so that's also why we at quint are moving away from our own custom health check and we're just embracing now the the servicenow out of the box instascan um yeah it's just lovely yeah yeah it's great to see someone else share that excitement uh of instant scan so um andrew from a developer advocate perspective is this something that you get a chance to to play around with and and our service now using it themselves on is it like now on now or where does instant scan fit in for you yeah so i have uh gotten the pleasure to play with this uh hilariously i was playing with this uh in uh december and january of last year for the orlando release and i was visiting uh y'all know him most likely jace benson so i i was doing a little tour it was the last trip i actually took out of my city last year before covett hit so in february or january and february at that time frame and i had uh wrote this really long blog about instant scan and then the and it got published uh because i have automated publishing for the blog and i had to pull it out because they uh parts of instant scan weren't ready for orlando uh and you know they didn't make it uh into the the release and so i had to pull that down because it wasn't a promotable feature at that time uh so i think instant scan is really important um i think developers are going to find a lot of value in different ways with it and are we using it internally i'm not sure how widely it is used internally we've been using the precursor to instant scan you know so the health check engine that we've got um that was part of a you know professional services engagement i know we are using that tool uh internally for a bunch of instances uh and teams um and i don't know if they've started the transition to using instant scan or not um but i but i foresee them doing it if they haven't yet yeah i i think it will be great when when you start to see it in all areas of the system and i've certainly seen those uh health scans from the professional services side of things and and they add so much value to your delivery and i guess it's worth mentioning for anyone that's not aware live coding happy hour last friday and i'll um put a link or a card somewhere on the uh on the tube stream um to last week's where what you covered you had brad kai on there um who was part of the actual product release of of instant scan so um you were able to look at things like linter checks there's a little bit of a gap in the documentation at the moment andrew we got it there absolutely is uh so i've been working with brad on that so so brad from that uh episode so not our normal brad brad tilton but brad kai as you said uh was on the show with us and he wrote uh like almost all of the linter check part of instant scan and there is um some embedded help um and some documentation that is coming out um in a patch for instance scan that really helps bridge that gap and until then i will i'll publish some documentation or at least some examples that are close enough to get you rolling for the linter on the blog excellent and that's developer.servicenow.com blog.do exactly and i'll share that link and make sure that's in the description i don't think i can link to external sites at the moment i'm not i'm not that which which is a servicenow instance so that that blog.do gives it away a little bit but the developer site is a servicenow instance and i think it's it's had a facelift right it's uh looking a little bit uh it's looking a little bit more updated uh as of last week uh or this week it it did and in fact i was the product manager for all of the the dev site for the six months leading up to this release that that happened last week so it did get a facelift and some interesting new features especially once you move to quebec for your pdi um like uh when you log into the dev site it automatically wakes up your instance if it's uh not and will automatically log you in if you use the links from there um and we're really just trying to start building or something like that yeah that start building button will like take you right into your instance um which i think is great great little quality of life improvements there and if you have other ideas uh to improve the dev site for you the audience developers please share those uh to the advocate team you know so you can put a comment on a blog or one of our videos or just send me an email excellent and and it's certainly a great resource you know checking apis all the now component stuff is is very well documented on there so can't wait for instance and it's all built with with now components so i thought it might so that was kind of leading to is it is it or isn't it it looks like it is it is so all of the all of the parts that got refreshed last march are now components so the main site in navigation some of the side things like the blog are still statically rendered html but we're going to convert that over this year to now experience as well we're actually going to build the blog using ui builder that's what we want to hear that's exactly we want to see it getting used now on now basically so yeah um let's i think without further ado great intro great yeah and we'll continue that chat through this let's start the building right well yeah we're not quite sure what we're getting into but i want to make sure the screen share works and all of those uh technical challenges that i seem to be faced with so if i just share the screen on uh zoom to you guys and then if i just pop us in you should be let me hide self-view we don't need to be there twice i've got andrew and mark in the corner to my left to my left yes [Laughter] excellent so you should see my pdi and for anyone who hasn't got quebec on their pdi yet um not sure why you wouldn't but if you've upgraded to quebec patch one even the landing page now is looking a bit fresh as well so uh some some of the app engine studio stuff is out now but let's not get distracted we're talking about instant scan so um instant scan you can find in the menu instant scan i've already favorited it actually and we've got checks suites results findings dashboard table cleanup the dashboard there's a few there's a couple of different dashboards um in instant scan at the moment um any any kind of comments on that uh mark from the digging around mark scott mark scott comments on the dashboard uh so if i could say to all apply this um yeah i haven't got any results apparently but if i go into my results i have got results so yeah maybe i shouldn't do a full scan because there are some things on here oh um maybe just one thing uh in between if you go to the scan result list list view okay uh scan sorry let me from the results list view yeah yeah and um just customize your columns and add the actions column but um oh sorry yeah yeah yeah personalize this both as possible yeah yeah but we're not trying to this is a nice hidden one i i didn't even know it but uh now you'll see this is actually a ui action i didn't even know it yeah so he didn't feel type that and it's a d i i imagine the default value is the sys id of the ui action yeah yeah and you can do one or multiple but i didn't even know it but um this was anyway the the dashboard that you were going for so i thought let's just add this in so we go to the results and from that result then i get a dashboard of that result okay and this is where we start to see some progress perhaps within our instance scan because we've scanned it now but if i do a new scan rescan it for example i was that full i hope i haven't clicked on full scan but um that scan it runs in the background so me closing it hasn't i haven't lost it it's running i think this should start to give me a bit more information because i've got the first scan and then i've got the next scan and hopefully we start to see improvements or we see degradation yeah and that's also like this scan result dashboard compares the yeah the scan with the previous scan like well the same target and the same so it's really comparing the correct yeah scans to it with each other like if you go um and look at the the first dashboard that you touched on that would just show everything so that's a bit ah bit yeah a bit tougher yeah that dashboard which your shoe i was showing now hasn't got that real yeah distinct difference between all scans well if you go to the yeah the scan results dashboard that's a really nice one there you can actually compare all the yeah the correct scans with each other so i think it was this one results dashboard maybe the new one's not finished running it i think i went for a full scan yeah oh this is the first one can you sort uh the number differently or the updated differently because you opened the result one yeah it was a result one it was for combo 101 so i just right click show matching on combo combo's like my target is it open uh scan result 23 yeah because i think in that one you should already see the yeah the dashboard the results dashboard a bit better okay even though it's in progress that doesn't matter now i see my previous scan okay so the other one was looking at my first scan it can't see forward yeah you can only see back to the last previous scan yeah okay so it's not finished running yet so we can't judge this but i mean that's that's what we want to see we want to see a a down a downward trend in average of findings over time um a finding is a bad thing right a finding is something that we don't want to have coming up in our scans and something we want to take it's a thing it's a thing that we should investigate okay it may not be a bad thing it's it's a thing a human should inspect to decide if it's a bad thing or not in and then make a plan for remediation or decide it's not a bad thing so you could adjust your scan right your checks right you could say you can adjust right so if you if you're if your check was too broad um you know you you use this the finding to narrow it down and you can mute the scan or the you meet the check if you mute the check that means stop checking this thing um so you mute a finding yeah yeah because muting a check was possible with the paris release but that's uh deprecated okay i guess you would deactivate it if you want to mute it you would say yeah that that's a that's a good one but um you've also got the out-of-the-box scanning jacks but you can't deactivate those because they're read only so that's something to yeah to keep in mind okay yeah so this i mean this is the first proper release so we we see this stuff come out like this scan task in there but scan task doesn't it's not even on the menu right that's like chef special right now you can use um a scan task to take that action on the finding and say actually i want this to be investigated looked at but there's no from what i can tell there's no real workflow around that right now it's it's very much just here's a task assign it to somebody yeah yeah so that's an area that you could build out if you're if you're ready to go with this in in quebec and you want to start actually doing stuff with your findings can can instant scan should instant scan run in production uh well it can be run in production and um i i think i touched on it in the live coding happy hour of last friday i also created a suite with scan checks for data so actually which you yeah typically would run more on production because it would be about task data groups incidents uh whatever and that's typically yeah on production and just to to to bring possible issues in your production instance to the surface so you could for sure yeah run it on on your production instance yeah and obviously you can also easily schedule it so you can just schedule it in uh off of hours or something at four in the morning or something um so yeah i was just thinking i don't i don't think that there's oh no problem i don't think there's any um you know downside to running um the instant scan in production so it's not like atf where we we don't advise you to run it in production um because there's lots of overhead that goes in with atf um and you shouldn't be testing in production uh even though i've got a shirt that's very funny that says you know i don't always test but when i do it's in production but for instance scan a lot of what you're doing with instant scan can be uh useful against production data so um yes you want to do like the the the deep like you wouldn't do linting scanning in production so i think my answer is it's okay to do instant scanning in production but also it should be things that should be done in production are the ones that should be done there um the ones that are helping a developer during their development cycle no no those shouldn't be run in production because you're not doing development in production uh hopefully and therefore you don't need those checks in production to be run there at least yeah i was thinking about the scan tasks because you're not really going to work a task in development or test you you want your task in production so in some ways it's kind of you've got a little bit of like fingers in two pies there because you want like you say some of the stuff to be running in production to keep an eye on your production environment to make sure things are healthy there things you know there could be all sorts of things you want to scan for in production that you don't want to scan in sub production but you don't want to work a task go through and lose that task when you clone etc so there's some things i guess that kind of you've got to make the decision as the owner of the the platform but certainly for me it's going to be a development based non-prod environment where i see the value for for me personally in my day-to-day so um yeah this is so it's a good one like to to think about the way of uh working and the way of how you're going to embed into scan in your way of working and indeed what are you doing with the with those scan tasks in which environment or maybe you are also working with which stories which might be your production instance and hopefully with surfs now but some customers also use some other products for for yeah their stories uh and yeah and things so there's there's a lot to think about uh how to embed this in your way of working um so yeah so we talked about what should we cover on tonight's show and i realized we're doing quite a bit of uh discussion and we can keep talking of course a new thing does require like it it's we did a lot of talking on the friday show too uh like we did not a lot of development um because a lot of the power of this comes from the framing and how you use it and when you use it and why you use it um and and less so about like actually configuring these is the easy part like setting up a check is is the easy part like we we go to set one up and and we can do that now but the i think the real value to customers and you know the platform owners and the developers is is is the discussion we have so yes it is a little chatty but it's also where where all the uh the beef is here is in the is in the discussion yeah and probably you know this this is what we should be doing right before we just jump in and develop we should be talking about it what is the problem we're trying to solve here of course so you know maybe we're set in uh setting a good example in some ways but um we talked about maybe doing some undocumented apis so mark you you kind of suggested there might be some things that are going on in the background that haven't been truly uh exposed i know we talked about there's a gap in documentation but there's maybe something lurking that we might want to have a dig around on oh yeah there's so many things i was uh searching for and some i uh already um put in community blogs or articles what might be a good one [Music] i don't know can we go to the scan findings maybe that's an interesting one okay and if you just open uh random finding doesn't matter which one and if you open here the xml show xml because you've got some fields here like score max score min score scale and i don't know how the calculation exactly works yet but these values actually make that another table is yeah the score is being tracked for your instant scan so okay for example manageability will have a score of 95 percent and performance will have a score of i don't know 87 but these fields are influencing it but how the calculation exactly is i'm not sure yet um i haven't done oh yeah i haven't found any documentation on this also but um yeah these three are interesting yeah there's that use manifest i mentioned also um but i haven't seen that one anywhere so i don't know what that field does so if if i was looking at a brand new application that came out of the box and there was no documentation yet and we're trying to get our head around it there's a new release you know one of the things i used to do um every when grc was tied to the family release now it's broken off into store apps and you get actually monthly releases available which is great like i would not want to go back to family releases but i would go into code search and i'll put the table name in there and i would search it and i would take uh where were we so i went to show xml i would take a field name that i was maybe interested in and i'll go into code search just close these go into code search and i would paste that in search all applications obviously because using code search from studio you've got a switch app i i've got a couple of plugins that do it but i don't think anything does it quite as well but actually we've got three results in here so i've got some business rules i've got some ui policies and i've got some access control so probably the business rule is one of the um more interesting things that's the trigger stuff but code search doesn't search everything either so i can't rely on it entirely but it gives me some clues where is this thing being used and then we kind of go down a few rabbit holes and come out the other end hopefully at some point but this is this is an approach i take to try and figure stuff out that's that's undocumented so you know let's see here i bought if table is blacklisted okay so i didn't know the tables could be blacklisted so now i'm learning something right what does blacklisting mean is that something that you choose is it a setting um no i haven't seen a setting for this but i have one uh into this uh yeah into to this business rule a few times um but yeah i got um like it's also mentioning another yeah that's can util but we can't access that one no i've tried it i think i've tried before i'll try try a few ways into this it's not letting me you know json.stringify does that work no i just get an object back i'm pretty sure you know let's just see let's try it but you tried it i'm trying it now it's an object um and then this is of options on my object so okay um sorry mark um this is but this is a good example of the exploring and uh and the digging around right so this is a yeah nice that's a very that's a very similar pattern to how i approach uh this as well so even though uh you know so that's the same pattern i used when i was a customer and a partner uh is is exactly what you did which was gra grab uh grab the name of the thing grab the table grab a field uh see if i can find a function name and use code search and and and attack it that way um and it's still my go-to um so one of the things that i have access to is uh you know our full code repository and i don't go to that first i do it still as i you know as a customer developer will experience um so that i understand where the barrier of what they could learn is versus what uh you know what's actually behind under the hood in servicenow java land yeah you've got a lot more uh power in your in your toolbox now uh andrew being on you know part of the mother ship so is there anything more we can do to to look at these things or is it kind of actually you shouldn't you should wait for the docs i know there's probably two answers to that um i don't i don't mind you know doing exactly what you just did which is find all of the information and examples and data that you can that you can get to and then how you use that information should be based off of how how risky and how unsupported the thing is that you're doing is right so you know should you use undocumented apis um that's that's up to the riskiness level of how important is it to take advantage of that thing for your organization so that's a you know that's a nuanced decision that you'll have to make on a case-by-case basis i don't say no you should never use them or yes you should always use them but it's uh you know understand the risks when you do use when you find and use undocumented apis um and and the in the debt that will accrue uh because it can change out from under you with no warning that's that's the biggest risk with undocumented apis right so for the documented apis servicenow has to let you know and have a plan for how to move towards a new version if they're going to change how an api works but an undocumented one they could turn it off they can completely change what it accepts they can completely change what it re returns uh with no warning yeah so in that sense you shouldn't use them because if it breaks it's your own fault and you know there's no no ownership there um i've just checked the chat brad's on um brad won not brad two uh [Laughter] he said where's the ui builder that's funny yeah i know i'm taking a break from ui builder brad it's time to go back to instant scan jace is here as well hey jace um yeah i've got two guests on the show now and i'm uh getting well distracted so uh not distracted but i can't multitask i know this is a fact so um we were looking at a function a business rule uh mark you said this is a business rule you've come to a couple of times so i think this uh i came on this also with the task table so somehow the task table is blacklisted i don't know why but okay so if we run that on scan it scan underscore tasks just the regular task table oh i see oh okay i guess because yeah okay this is the thing right about undocumented stuff and trying to figure out you've got to find your own narrative to things you've got to say that that function there is blacklisted table okay there's now a concept called black listing of tables let's try and make sense of it and put our own context on it why would they blacklist the base task table i can only expect because there's so much volume on there that they want you to be class specific and say you can interrogate incidents of course but when you interrogate an incident you shouldn't be interrogating change and literally the rest of the universe at the same time i mean it's a performance thing to me i'm assuming there have you found any other narrative for for that um well it depends also like which uh scan types you're using because if you're just using the the the table check that performs so quickly so yeah i wouldn't assume there would be issues with that one but if you are using the script only check for example um no not a script only check the uh the other one um the column type check that one can actually run for minutes the same like the linte check that can really run for minutes so i yeah i can imagine that using yeah the larger tables on those checks would be more harmful but actually on on the column type check you're not performing a check against a specific table because this is just running on all in this case all script fields out there so i'm not sure where this black list that fits in um yeah i'm not sure yet i'm just creating yeah i don't i don't have a great narrative other than it's likely some performance related reason that that's my default like why would you stop someone accessing tasks directly and i assume it's performance um but like you say you might want to do some generic checks on the baseline on all of those things like assign to fields make sure you're you haven't got any active tasks that are assigned to an inactive user um if i've got to now create multiple checks there i want to check incident change etc um i i shouldn't have to you know performance it's a false economy to tell me i've got to do that for every single task type um yeah i'd agree with that column type right i'm giving some generic names here one thing i was interested in and it doesn't look like it's possible oh it is okay i didn't think it was hovering because it hadn't saved yet so can i put something or i can run this without without i guess test check is it going to trigger asynchronously yeah i think everything is triggered asynchronously yes going through scan ajax processor it is possible to run it it is possible to run it directly um so if you go to if i look at some of my local update sets i'm sure i've got something already for instance scan this is tonight's one yeah instant scan one two three let me just see because i built something around scanning batched update sets and and the design was not quite right but i've got ui action here ui action is calling the api directly when i say api by the way i mean like script include or whatever just generically i've got my own api there so what's that doing run scan from update set and this is where i'm like i have to remember where did i go so we need breadcrumbs um like hansel and gretel so the i created a column type check didn't i and i want to do that test check and if we look at what it's doing it passes in i think we can access the ajax processor yeah and it passes in execute test scan there we are execute test scan which just calls this thing okay so i can just grab that that's what i was looking for and i've got the test check open this record and explore so that's my sis id table name why so what happens on that one did i miss something is it passing in table name as a parameter uh let me check this one's the desk scan right um yeah because it's an extended because these checks extend a check table i've not i've not got that in the data model yet so i've kind of i've built out a couple of things here yeah um so because you can copy the the system from from this one because you need to the sys id from this column type check i've got that here yeah table name is scan instance no scan column type check okay nice there are some really nice sensible names for things i'm not sure if you actually need that table because eventually all the four different scan checks are um you know you've got the scan the yes can check table and then the extent yeah they're extended off the same base table and so the sys id will be at the parents level anyway so we've got an engine object here we don't know what it is let me just do gs.info json.stringify stringify engine i mean i'm not sure let me put something in front of that i'm just wondering whether script debugger fires on this can i access script debugger if i call that scan directly because that is not asynchronous there is it i've bypassed all the ajax i'm going straight in i'm just closing some windows down just uh may not feels like you you'll have access let's find out click run no missed it so there's a break point where did you where did you throw a break point online yeah let's try it again i've i've moved the break point no so does it show up in in here it is there yeah so it's possible that that is not uh is not marked to be usable by the script debugger no and it didn't like me trying to [Music] oh wow it's run a lot as well has it run for okay it's wrong for every column yeah for every uh yeah every uh script uh type field it finds so yeah so when i pass in column this is this is different to so what's the difference between this in a linter check mark i'm confused now i'm not sure yet the lintel check is also fairly new for me but i know with this column type check previously you had in the function you had finding and column value now you can call them both from the engine object so you actually have the yeah the column value which is everything from that script field so if you use now engine dot column value and a value with uppercase yeah that would now be everything from the script field yeah i'm i'm struggling there mark so so this scan is going to go along and it's going to pick up all of the cis dictionary entries i presume it's going to script type yeah yeah so it's going into basically going into that's stopped working for me shifting up sys dictionary dot let me do dot filter because i don't know if everyone knows about dot filter but um now i can just add my own filter on there um i know you guys must know about it but not everyone who's watching let's try and throw a little nugget in there uh i want type i love that accidental nuggets like they're the best you said oh i didn't know about that one um so type the script yeah script like this so i've got 207 script fields in my instance right now so this scan check is coming in and saying right those 207 go through them and run condition i mean what can we pass in here the rune condition is also added with quebec and basically this just has to evaluate to true but you could do anything like for example you were checking if it's a production instance or some plugin is installed or whatever but yeah if you just hit true or even if you leave it empty it will run yep so if i say current dot for example current dot oh it's on the table so what does it have current is current the thing that is evaluating against don't think so what sort of conditions would you say oh is this like i only run on a wednesday so is today wednesday oh okay yeah yeah possible or well checking if a plugin is installed or uh okay abstracted from the actual record itself it's not saying the record i'm looking at because that's down here in this kind of script this is where we're checking the target or the the engine dot and that would be interesting to know what more possibilities are there with that engine object because now we only know you've got column value and finding and with column value we know we've got the context all the contents of that script field but yeah it would be nice to know if that engine object also holds information about the business rule for example the updated buyer updated on and and stuff like that because then you could make even more interesting scan checks but anyway yeah we've got the column value so we could build a check around this like uh does that script contain um well gr or does the script contain well something else against which you want to check so what's the syntax here that we need so i've got engine.column value i assume that's the function well um that that's basically against what you can check because the column value just holds everything of the script field but what so you could just build an if statement a regex match or whatever or yeah engine.com value and then contains or index off um that could already be the start but then after that if statement yeah this could already be the start indeed and now every script field will be checked if it contains gr and if it contains gr yeah then well now on line five you would have something like engine dot finding dot increment and then um yeah brackets uh the yeah uh oh nothing in between just say yeah just like that and now this will already create the finding for that record or yeah that matches so whether where the script field contains gr i wonder if i can log out for example string column value have i done that syntax right so i'm going a bit blind here uh engine dot column value dot index of is that accurate in excel i've created a minus one that looks fine to me um and and to circle back to you you know you had a question about when would i use this versus the linting check and um brad i talked about this a little bit on friday and i think i can get close to an accurate answer which is the linting check builds you a structure for the code so that you can analyze it uh without having to do um you know things like is this inside of a comment or not so you're doing a check for gr here you would find that gr might be inside comments and you'd get a finding from that and then you'd be like well but that's not what i want to find and then you try and add complexity into this column check to find that and that's where the linting check would you know be to your advantages because it understands the code format and structure and allows you to search the different kinds and types of that structure for what you're looking for and and gr task is okay but gr on its own is not okay so linter gives us that right i can only imagine what you said there it gives you the structure this is something that i've struggled with a little bit before i created uh a bit of a crazy uh application to it was like discovery if you imagine discovery but on my instance and then mapping in tables business rules script includes methods down to the functional calls between different applications that then manifested or represented themselves in the cmdb so you could go into the cmdb and view your application i've got these tables running these business rules data all of the components so then if you change something or you want to change something you could visualize it and then i realized that my regex isn't that good so um i only got so far down the road and said this this is going to take a little bit longer than you know but the idea is there um and you know now it's out there so i'll put it on record what's the date it's saint patrick's day so shout out to cassie um uh sent patty's day i don't know if that's a different thing um if you it's the day you eat patties normally we drink guinness [Laughter] so i i don't have any guinness i'm drinking water but yeah shout out to cassie um that linter check andrew sounds like amazing but how do you how do you work with it how do you say are you on like gr is not in a comment and and the rules of that engagement how any ideas on that um so i have just enough to be dangerous i have it a little a little bit of information so it's got a object off the engine um that's called root node so root capital in node and then you can do dot visit to traverse the nodes that so it creates this node structure and gives you this object to to you know travel along that structure and then you can do things like say evaluate each of the nodes um for uh like get the name identifier um and see if it's of this particular type um and um and then you know move further down the notes so you could you could check to see if um you know a a node has children that has a thing that it shouldn't have and so you wouldn't find that if it's if it's its own top level thing but if it's buried under or or that it is a good thing for it to be buried and that's okay um but if it's at the top level no no no you can't do that so that traversal of that tree and structure allows you that flexibility to um you know actually understand that this is code and there's hierarchies and there's you know functions inside of there and and comments um and and and actually build your checks based off that and gives you some structure to that so that you don't have to figure out super complicated you know regex for every check you want to do which is what you'd have to do if you were using the script checker the column checker against your script field yeah so they've kind of bundled regex patterns and solutions and rules of then incrementing into the next go to the next bit if this happens it sounds amazing it sounds beautiful um yeah and and i need to learn more about it and and then share that yeah that's a that's a task on my on on my plate right now it's it's going to be so powerful and then we've got to like you say enough to be dangerous work out where's the right place to point this thing mark when that documentation comes out what's the first thing you're going to do with linter check like what's the first thing you're ready to build can you can you comment on that at all is there something that you're i need this lin to check yeah for sure because it it could already be like well the example we're touching on now every time is like is your code in comment that's the first thing i want to check because i've created several checks for well uh script fields uh that it contains deprecated apis or direct package calls and and whatever but what if it's in commented code and well i haven't got that now in in my in my scan check so yeah you will get findings now and you would say oh it's commented so i would just say hey there shouldn't be any commented code in production but but actually if i could have a better check so a linter check with which you really could filter this out that would be awesome so that would be definitely the first thing i would look at yeah and and there's uh good times and places for there to be comments in production code yeah um do you want to move you know away from them but like a good example is is what you brought up is that like the packages check so when you went through and replaced your packages calls with non-packaged calls when you did that it was appropriate for you to either leave that code there or to even just say this is replacing this package call so that you could troubleshoot it for the next six months after that you know you probably don't need that comment anymore but like you needed that in production for x amount of time after you deployed that change so that you could resolve incidents as a result of that faster yeah that's a good one yeah i i always try and remember to comment if i use set workflow false or something like this because when you read someone else's code and go why are you setting workflow false and you don't know is that is that causing my problem or is there a reason that this was turned off is are you deliberately not doing anything after this and there are some use cases probably i don't want to try and find them now but there are some cases where you want to set workflow false in a not just in a background script and if you make that decision then that's something where it should be definitely commented i didn't know there was an argument for no comments in production i thought you were being uh ironic uh well not the basic comments but more leaving but like code like code commented is what yeah trying this doesn't work comment x i don't want to delete it and lose it i want to know what did i try and you keep trying things and then it finally works don't leave that in there yeah you'd get quite a few for flow designer imagine you're in your code snippets because there's kind of you get your asynchronous synchronous optional thing there so that's a case where it's there by default and then you you do have to actively strip that back and say i've made my decision now it's it's going to be asynchronous so it's going to be synchronous yeah and i would say that that's actually a good finding to to have is to check to see are we leaving behind cruft like that that just makes this harder to consume by the next human like because that it's auto-generated code that that is intended for you to remove the half of it right because you you're only going to execute at one of the one of the two ways and wherever you're using that code so you should delete the other half and so that finding would be that like i'd be like yeah no that is a standard that we have here is that that auto generated code from flow designer you should only have half of that in your in your usage so so comments are okay but keeping loose code that was some thinking or some planning or some trial and error probably not so good yeah like i i don't like to leave code commented in production is is is you know is the shortest way i can summarize it because code common in production uh just like i was saying with the the flow designer auto-generated code it just inhibits the the next human to look at it which might be me uh from understanding what's going on because it's not actually adding value to what's being executed there like information about why i did the thing good uh code that is no longer getting executed why do i care about that code it's not getting executed that's just uh that's i don't want to call it laziness but sloppiness maybe um it's like this thing needs to go in now get it out it's working um but i haven't cleared all my comments up i don't care get it get it moving we will fix it later and then you don't so the instant scan can help you drive your backlog and fix those uh those issues and hopefully as well i'm seeing here the the opportunity for um like improving you you've got a section on here around upgradeability right um uh it's in one of the findings uh yeah it's in the check itself right it's in the check and therefore it's then inherited from the finding but upgradeability maybe you made some decisions at that point in time that you thought oh we will go back and fix this here gives your backlog um you know something to start with and prioritize it accordingly but upgradability i think is something that upgradability performance security i think they're in the right order no security should be at the top right security should be at the top uh so we took a real diversion there we really did there was something on live code in happy hour that you there's more checks available mark you had like you had some stuff in plugins is it you mean the instance troubleshooter perhaps it's a it's a store um yeah store yeah but you can also install it from the plugins indeed but it's um yeah it's a store app and you get 4142 checks something like that uh and that's categorized a bit differently like uh email mid server etc um yeah nice uh nice addition again so there's new there's new categories with it as well yeah it's well it's um not categories that's a wrong word actually it's uh uh the the switch the scan suites right so we still got upgradability manager maintainability or manageability yeah because those are the five categories indeed and then you could also classify it with four priorities from the top of my mind but it's more about the scan suites because that's the container yeah under which you place all your scan checks or some of them uh so with the instance troubleshooter you'll get yeah email mid server yes can switch like those is this an instance troubleshooter is that the same thing yeah that's the one yeah and actually that's a strange one because um this is also for paris available and it's using the instant scan but instant scan is officially introduced this is great stuff because you see an instant scan and when i found out from your posts mark that it's been there all along it's been hiding actually i went and checked a few instances that had orlando and paris in there and just run a few checks and it works so you know i think that's great people can start to take some value from this now but i got the feeling from from what brad was saying brad kai was saying that um it's like there's a few changes to some of those apis it won't break if you pass finding an engine indirectly is it finding an engine or was it finding in there was a landing and yeah engine is the new one so it's because engine dot finding now so you pass in a single object um but it won't break those ones are still there backwards compatible but you don't want to go and build out loads of scripts now and then have to go and change it like the all the scan checks will still work and that's not really an issue but it's more like the the instant scan in total just improved uh on several points um again so yeah quebec just offers a lot more with with the instant scan for example the combo record we we touched on that's new with quebec and that's a really good improvement again so the basic scan checks will work on orlando and and paris but um yeah on quebec just the insta scan in total has been yeah it's it's a it's a it's a first-class type citizen versus a a hidden feature [Laughter] yeah so i was um uh sorry completely lost my my trailer thought there um uh on on the uh instant scan object not you know changing it still works in the future from the old release i was thinking more from a readability perspective so you might have these old scans in there and then you see it in the new world and people are still using the old way because the scans are just going to live on uh because they're there from the beginning like some of our commented out applications i'm not overly worried about it since it's basically the same data structure you know engine dot finding versus just finding is like it's not a drastic enough change for me to be overly concerned myself about that okay if you're not concerned and you're you know you can see how that's going to work then i think this is uh this is all good so i've just i got a bit lost what we were doing in the background trying to find myself around so we did that column type check this this this stuff is deep like this i said we we go deep on this channel um and i feel like we're still only at the surface but because there's so many different avenues that this thing can permeate in your instance in your workflow as a developer into your just general business practices you know i was thinking about application best practices thinking about coding best practices health of the instance so many things here uh that trying to maintain a conversation talking about those things and share the screen uh i got lost but we created a scan check um which is here type column check and i said finding increments in there so that's what it's that finding increment that creates these things yeah and it's called count one because i guess if it found the same one again it would be count two and that would be the increment well that's that's an interesting one which i still want to find out what else should that purpose be for that count field because when would that count field be 2 or when will it be 0 because i only see scan findings with 1. so that's still um yeah something i want to find out if it has any different purpose maybe so sorry sorry uh what happens if i do this um just as why would you do that well here i'm doing something as a check obviously that's beautiful code there i'm doing this as a check and then i'm saying but also if it's this then it's double bad yeah so uh one of the potentials here is you know in your simple check here you're you're seeing uh if the script contains gr at all and you could do a you know you could use the increment to show how many gr's there are so you're doing a single check does it have this and instead you could you know be inspecting and looping through the data and incrementing for every finding so that you had some sense of how many times that occurs in that script well that sounds interesting yeah i i'm not sure if i feel like that that's valuable right off the top of my head but that's that's a you know one of the the uses for that is well let me know uh and and maybe i need to find odds and evens like you know maybe i decrement when it cancels itself out like there are there are situations where you can say oh i need to make sure that i'm doing both the the start and the end and even numbers you know like they're matching and therefore if the increments one you know if the finding is one or or anything that's non-zero that's actually uh you know bad so those are just off the top of my head of ways that i could use increments to to show me information without having to open the script all right i so sure what instance i was on there contains last hour should be fine for this let's see what's in column value do we get okay so we get the whole script chucked out here okay so that's column value am i getting anything else on my object like i can't access the engine and yeah it's still so is that a preventative measure that's in lockdown apis um to stop us just chucking the whole thing out any other way to see what else is in here because i'd love it if we type ng weird service now java objects are weird [Laughter] so if i go engine dot how nice would this be engine dot which would you like do you want a finding do you want a column value what what else is on engine yeah because like um you had the scan result okay go back to the scan result and then show the scan findings uh okay because like in these findings you will also see well okay uh client scripts fine but you will also see like sp instance or even if you run a background script now it will also create a record and that will also be scanned but are you really interested in that record i guess not it shouldn't be a finding so if we know that that engine object holds more and that you perhaps can exclude certain tables then you can prevent some of this yeah rubbish because there will be some tables mentioned here that you think hey i'm not doing anything with this it's uh automatic generated it's um yeah and maybe you want to have and maintain your own black list of tables for certain purposes right for data checks like hold on a minute that's you you shouldn't be creating a scan check and i'm putting that in there and because once what so this is one other thing i wanted to check from a security and and kind of privacy position is that value stored or is it just a pointer so if i said show me anything that's got a credit card detail in like number matches credit card format 16 digits something like this and i want to make sure that the additional comments on my incidents don't contain or my short description or my description doesn't contain a credit card number will this kind of um make matters worse by taking that value and saying and this is the credit card number i found and storing it off rep like in its own record here so now i've got the credit card number twice no no it's not being stored in anywhere they're pointers yeah yeah just the source record so it's just pointing to the actual yeah the actual uh finding uh so in this case it's a widget but then it would be just that incident or that well other records but it's not storing anything additional or something so no it doesn't say you know if i said it doesn't say pull the offending thing and store it locally in the in the finding record no okay and it doesn't say line line 22 is the one that's got var gr on it i wonder if it's got a line number in there that would be nice wouldn't it if it told us where where on there well maybe that's hidden in the engine object i don't know no no i haven't seen anything about that uh here no because there's so we've got engine.finding when we look at the scan results as well we've got i know sorry on the finding record we've got resolution details but that comes from the check doesn't it when you define the check you say yeah and this is how to solve the thing yeah yeah it's uh you've got um yeah the the name and the short description then you've got the description and the resolution details and a url and those are all coming from the from the scan checking yeah when we click test check is test check different to run point scan yeah yeah because of when points can well in this case it's also visible here but run points can could be also visible on a ui action or a business rule okay he's saying get me all the things that are scanning this so that'll be script checkers but only for me i want a point scan on this thing i want all my checks on this is it yes okay so running a point scan here am i scanning my own check yes right so that shouldn't be there it's got a it's got a script field and it so a table check and a script uh you know type so a column script check would and could produce a finding i think someone commented on live code in appio on friday inception um yes so i won't run that one just in case i just wanted to kick this one off again i can go to result now i'm wondering if i've got any count increments do i get anything which is not one not right now okay maybe is it actually increasing the count or is it now then potentially inserting the same finding twice or yeah multiple times i guess our updated might give us a clue they look different there i know i know we don't go down to milliseconds in the logs but um they look different at the same time so okay um so mark we didn't quite get to undocumented apis so much we're still kind of uh touching the surface and and he's sad yeah well there's so much like like here you've got also the related lists with scan statistics but actually that's that table somehow always is empty so i'm not sure what's hidden behind this but what we touched on at the beginning of this show is the the score fields but those are going to another table and that's the scan score table because this can statistics is a scan underscore statistics table so yeah it's um yeah like in the this scan score table uh yeah it looks pretty interesting but it's it's nowhere used as related lists or whatever so we do know it's influenced by those three score fields on the scan finding so yeah that's interesting to yeah to look in later a bit more like how is that calculation exactly exactly working now so this is an interesting one is there any performance analytics indicators that are already set up against instant scan so so i believe that the yes there there should be because the dashboard should be using those uh for the over the time performance of the you know the category so that you can tell when you transitioned from you know 98 to 96 and then back up to 98. so let me just while i haven't seen them i expect them to be here okay facts table contains scan not there yet i think it's the uh the answer unless i've done something wrong it's been a while since i uh opened the dashboard okay and and see if they're reports or if they're pa so go to the scan findings you know go to the instant scan what just go down why am i typing dashboard i know that's going to give me loads of results um thankfully you had a favorite yes i'll go back and type instant scan um who was was it you mark that was uh yes you were sharing on live code and happy hour you did a little trick there with like for business rules i think you went oh yes ss space r right yeah ss space r and that gets you to to business rules or class rules here and uh that was a nice little trick i noticed i i love the the navigator like uh interesting ways to get to a table uh or to a module there like one t they're so good so so so my favorite one is d space g what's that going to give us d space g i'm not even sure what would it be d space g advantage gets me the users gets me in a in a base instance it actually only gets me the users and groups module so if i want to get to users groups and roles with the shortest number of characters uh on on a like flat instance that doesn't have grc it's d space g that's a good one yeah i don't know how often that's going to get used now so i've got in it in a more generic one to get to the same space it's uh i type user in space to and now that will probably work on yours to get you down to just that users i'll use s yeah yeah sorry yeah of course that's more characters it is d space g it's just a nice little hack um you know it's not going to change the world and of course you've got you know it's worth mentioning sn util slash commands as well which allows you to do many many other things but let's not go there right now um but yeah yeah we do whole we could do a whole hour show on snutils and how it saves us time so yeah uh yt for performance analytics uh we were going to the dashboard i'm on the dashboard sorry i'm reloading it yeah that looked like a straight report i have seen it must have been a forward-looking thing that it was a pa dashboard so so it must have been a forward-looking thing just check here so this is just a regular report oh i see right you're actually looking at a report not the dashboard so i was just checking that if i switch to global i can configure this this looks custom in some way like uh it's not quite an interactive filter it's a ui page that's embedded similar to some of the heat maps you might see it's not even it's not even letting me in is it oh there we go oh it is an interactive filter but it looks different but yeah there's a that appears to be just a regular report not a uh not a pa it's not pa not yet okay good stuff um unconscious of time i said uh i'm i think it's later where you are mark your your one hour plus on me um it's earlier where you are andrew and you've got other things but it's still dinner time [Laughter] is it dinner time there what time is it is it uh 6 24. okay so you're starting to get that just your belly starting to tell you oh dinner is ready oh it's ready dinner is ready are you smoking something um on the no not today not today i'm i'm gonna smoke something on friday so i i do like to do a little uh use my uh smoker and uh i'm i've got uh my next cook will be friday i'm gonna do some uh a whole chicken and a uh rack of ribs excellent i'm going to i think unless there's anything else to cover on the screen share i'll switch it over to the final kind of the final screens let me prepare for this to if i stop sharing and we're there i think you're up there somewhere you said we're on your left no but now you're in the oh but now we're stacked hello let me switch then this to show self view and then i will come out of there right excellent so we're all on zoom on the main screen and we can just have a little debrief i think on on instant scan did we tick off all our things that we wanted to do no is there more hiding somewhere underneath it's just you need a lot of more hours like conversations like these um because you see there's so much to explore and and to find out and it's it's just so interesting um yeah how to get even more out of it because already instant scan by default is already so valuable but um just getting to know more about it having a discussion why are you using it how are you using it what's still hidden that's yeah just great and i love powerful tools that that allow us to you know you know have depth like like you said it's you can pick it up and use it you know pretty pretty straightforward but then there's depth behind it that you know you really can derive a lot more value uh with the you know a little more investment in time and understanding like so i love tools that have you know immediately usable but also depth i like games like that too yeah i i've got some ideas for trying to gamify things on the platform as well but that's a completely different topic entirely um chasing your scan results around and something like this but um i don't want to put you on the spot andrew but i know you're fully prepped to answer questions on the spot what's the anticipated or eta for more documentation on instant scan and you said you're going to do a blog post we've got the developer site which everyone who's watching this should obviously be checking i'll make sure the link's in the description um you're going to do some blog posts but then there's more documentation coming quebec is now in is it general release now it is yeah as of last thursday and so i do have a blog um it was i was hoping to get it done this week but uh it is now uh set uh for tuesday uh is my target uh so next tuesday is my target for the release of the instant scan blog and uh i believe uh april um should have some updated uh documentation so the doc site uh gets big releases every month so i believe that the the documentation that exists that's not yet published will get released in april for instance scam excellent so you're not going to automatically publish this blog this time um for instance that would be nice is the old one still available somewhere is it on the internet archive uh links that you can find or is it worth looking i don't think it's findable by anyone i've still got it it's still in our uh blog uh repository it's just not published yeah so it still exists but yeah um well actually i'll have it it actually had it was it was a pretty good blog so it might still be referenced we'll take a dig around on the internet and see if uh i'll have to i'll have to pull it up it was only up for an hour so it's unlikely that any of the uh you know way back machines or anything uh crawled it in that amount of time uh so it was only up for a little while but that was that was the first time that i was like really prepared for you know a release and had uh blogs lined up ahead of time uh and then uh they told me you know they taught me a lesson of not everything makes it into the release i i i knew that uh but uh you know i i got taught that lesson we sometimes we have to learn lessons the hard way i think that's uh that's clear that's one of life's lessons um is there anything you guys want anything else we should be talking about plug-in that people should know about in terms of um quebec features events anything else coming up obviously you've got live coding happy hour each and every friday on the servicenow dev channel um is there something coming up there that's do you know what you're doing friday yeah or is it still are we doing okay so the first thing is we're actually going to run a day earlier so we're we're taking a little holiday on friday so um we'll be doing the show tomorrow roughly the same time as usual uh just a day earlier and we're going to be featuring the new app engine studio so we'll be we'll be walking through that um and uh so i'll be showing how to um there's an automated uh deployment pipeline system in aes um so the the citizen dev uh type person can request for their thing to be promoted up the stack and then the admin type persona comes in and approves that deployment request or rejects it and it will automatically get moved up the stack if if it's approved and so that's what i'll be showing uh on the next episode um and then next week brad's gonna be showing off uh ui builder theming wow on on the show so we're going back to ui builder don't worry don't worry brad i haven't forgotten about ui builders [Laughter] excellent so that means that leaves a gap open on friday maybe for upside down andrew to do another unofficial event it does yeah we'll give him a shout out make sure he knows that thursday is this week's live coding happy hour um yeah thanks uh andrew mark anything from your side that you want to shout out plug shamelessly or otherwise no no oh all fine uh no great uh great to have done this one uh today yeah well thank you both so much for for coming on the show i really appreciate uh having guests and and learning i'm learning how to have guests on the show as well i think it brings a new dynamic uh so this is absolutely excellent i'm honored to have you both here um i mentioned upside down andrew i guess if anyone is wondering why there's a little bit of pink going on at the back and what is happening there check out his podcast um between two functions um episodes one to twelve i'm somewhere in there and there's other people that are somewhere in there so yeah check out the podcast but thanks uh everyone and um yes anyone else we've got a shout out on the chat thanks to everyone on the chat it's not been that lively tonight but i appreciate everyone tuning in and we will switch over and say good night so thanks everyone and take care bye you

View original source

https://www.youtube.com/watch?v=RunFOyd6YNI