Cloud Discovery and SG-AWS
Cloud Discovery finds resources in the different cloud providers. It collects the logical data centres associated with the account, as well as any subaccounts. Collecting information about resources on the cloud is relevant for companies, organizations, and cloud companies providing Platform-as-a-Service solutions. Cloud Discovery uses discovery patterns to query devices and applications and collect information about them. Cloud Discovery collects metadata from APIs.
The Service Graph Connector for AWS (SG-AWS) is built to simplify the onboarding setup and ease the integration across multiple AWS accounts in an organization. This application uses one ServiceNow user account to pull data from all of the accounts in an AWS Organization. Service Graph Connector for AWS (SG-AWS) is the easiest and most optimized way to discover the cloud metadata and get inventory details.
In case, customers use the blended approach to use Cloud Discovery and SGC-AWS both. What it means –
- Cloud Discovery and MID server for cloud metadata
- Service Graph Connector for deep-dive inventory
- Use Tag-based Service Mapping or ML-based Service Mapping for service context
Capability Matrix
| | IaaS (Metadata for VMs) | IaaS (Deep dive discovery) | PaaS / DBaaS | Container (CaaS) | Requirements | |
| ----------------------------- | ------------------------------ | ------------------------------------------------------------------------------------------------ | ---------------------------------------------------------- | ------------------------- | ------------------------------------------------------------------------- |
| Cloud Discovery | Supported | NA | Load balancer / Cloud Database / Resource Inventory / Tags | AKS / EKS / GKE / AWS ECS | Service Account-based Master account Cross Assume Role MID IAM Role-based |
| SG-AWS | Supported | Basic SAM use cases with Installed software, running process, & traffic data for ADM/Service Map | Load balancer / Cloud Database / Resource Inventory / Tags | Roadmap H2 2022 | Minimum read access requires AWS Config & Systems Manager |
| | Cloud Discovery | SGC-AWS | |
| ----------------- | ---------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------- |
| Capabilities | API-based Discovery Cloud resource Inventory and Tags (metadata) | API-based Discovery Cloud Resource Inventory, Tags and Relationships Deep dive discovery – Server, OS, Software, Processes |
| Limitation | Cannot get “Server” level data (OS, Software inventory, Processes) Requires MID Server Wider Credential requirement | Requires AWS Systems Manager to be enabled Heavy reliance on AWS Config |
| When to recommend | Only needs cloud metadata Needs tag-based Service Mapping Do not use this approach for ITAM / Cloud Insights use cases | Needs deep dive Discovery but credentials and/or MID Servers are an issue Must be using AWS Systems Manager |
Below are the standalone advantages of SG-AWS:
- Easy to set up with guided steps
- Requires read access to limited APIs
- No MID is required
- Gets deep-dive application and inventory details
- Use Tag-based Service Mapping or ML-based Service Mapping for service
https://www.servicenow.com/community/cmdb-articles/cloud-discovery-and-sg-aws/ta-p/2300607
