CMDB Best Practices session
is navin sharma head of product for the cmdb uh he'll be presenting to us the great work that our team is doing for servicenow's customers in addition we're also joined by my colleague emilia iminovic who will be assisting in any q a you may have during the session welcome and thanks for joining us now without further ado navin the floor is yours please share your screen and take it away good morning good afternoon and good evening thank you for joining us today my name is niven sharma and i lead the cmdb and service craft product management team today we have roughly 60 minutes together and what i will cover is going to be cmdb best practice uh what i'll start off doing is you know focusing a little bit of time in terms of what is the cmdb and giving a quick peek at what are the new functionality that's coming in the san diego release after that we'll spend some time on the cmdb data model right and again cmdb data model is sort of a core understanding is a core requirement to to really understand how that to best uh configure the cmdb and then we'll spend the majority of the time talking about really the goal of configuring and creating a process and uh tooling such that cmdb becomes sustainable over the long run uh two key points i wanna make sure i i point to uh number one is uh that you know there's a lot of content that's gonna be covered but luckily this presentation is getting recorded so you know if you get the chance you know please come back and review it and don't feel too overwhelmed if there's too much stuff and you're not able to follow second is that you know we did a presentation a couple of months ago focused on really cmdb vision strategy and roadmap i would highly recommend going and referring to that as well which is in our in our uh uh the forum that you know tony mentioned earlier right and then what we'll continue to do is like we will also ask you for a little bit more feedback on the session right and this session got set up because the overwhelming response last time was that you know our customers really wanted a best practice session there are other things you want to deep dive on and focus on please provide that feedback and we'll make sure we we bring that to you okay so let's focus on through the basics of cmdb what is a cmdb the term cmdb obviously has been around for quite a long time and you know but the cmdb of service now is quite unique the way i like to describe it is that you know it is really where you will store people process technology data all tied to and connected to each other right and then you layer on things like the the actual services and products that a company is sort of providing to its internal external customers what makes it so so unique is that it's all under the notion of a single data model where end to end coverage from the life cycle of plan build operate service within the same you know database one kind of a euphemism i always use here is that you know if i had to rename the cmdb i'd actually call it you know the the silo buster database because again it's really about you know all these different parts of the organization all coming in with a single data view end to end so let's talk about how does it help in terms of driving an outcome right and the key there is that the cmdb data is is used across pretty much everything in servicenow and somebody asked hey do you need a healthy cmd if you actually run some of these things the answer is no but when you have a healthy cmdb you actually get a lot more value from them and an example here could be you know somebody's doing it asset management and they want to do you know software asset reclamation right the cmd provides that data to make that successful it could be somebody's doing itsm and then cmdb is really where you know you long change against you get the understanding of impact and then similarly when you have an incident that you can actually action that incident understand priority and understand ownership right that's all sort of driven from having a robust cmdb data and you know if you look at other items such as cloud or devops the concept is very similar right that having that unifying data model really enables you to automate and action things and again from for the modern technology stack just means that typeless ci's may be different how often you you insert there may be different but the overall concept is still absolutely consistent and similar so let's now move on to the cmdb data model like i mentioned i'm not going to talk deep dive you know in the weeds but i definitely want to give a high level overview what it is so you have a good sense of you know going forward so what exactly is in the cmd right the way i like to talk about it is there's really two key pieces within the cmdb right i'd say maybe three different pieces here within the cmdb today one is for the infrastructure data and when i say infrastructure that means applications that could mean uh servers that could mean cloud resources that could be containers but it's a physical logical you know entity that's actually running right and then second it's not just the single entity but it's also the relationship so meaning it's uh you know tomcat war that's running on a server that's connected to a database right so that's kind of the the data you have from the infrastructure perspective the second piece is that that is connected to what we call foundational data think about foundation data as you know like who's the essentially user groups uh users locations right all these other common data that's you know within a servicenow platform that is you know kind of very very much related to the cmdb and the final item here is like you know this is part of the cmd but there's also sort of business constructs you know on top of sort of infrastructure data right think of this as you know application services think of this as business applications think of this as service offering right those are essentially sort of a a higher level construct that sort of group a lot of the cables you have from an infrastructure perspective you know to drive a lot of more you know kind of uh calculate a lot of automation as well as make that simpler to manage essentially right so that's really what makes up you know kind of what's in the cmdb today right so if you double click on the foundation data right like i mentioned it's very related to the cmdb but it's not part of the cmdb right most of the time they're located in something called you know cmn underscore table right and they could be like in this example like you know location costs in our department and then similarly there are also things you know with a fifth underscore and those are office user and you know uh group tables right and the key takeaway from this is that you know you absolutely need to make sure you have an understanding of how these data are coming in where are you getting your users and how are you making sure that your user your location your company tables are also sort of managed properly so they don't become you know just more of a smorgasbord of just you know random data points right and if you look at the the cmdb right when i say cmd it really refers to cmdb underscore ci is where all the tables within cmdb really live right and then what really happens is that within the cmdb it's actually referencing back all these common you know data points that i mentioned right in in terms of assist users and from the assist user groups right along the same lines we're also sure of have a reference to when you say alm assets right and those are really asset management records and cmdb models which are also really you know very very relevant for asset management right and like i said they're not part of the cme they're very very related and very much required for for successful implementation so so double clicking a little bit on relationship what does relationship mean uh relationship is really the notion of you know connecting two different ci's they generally fall under you know different types of relationship types that you have you know example and it runs runs on virtualized by virtualizes but at the very core is really sort of you know trying to get a parent-child relationship to figure out you know when something goes down you know what's the impact radius right that's how we sort of can articulate you know that dependency and one question we get a lot is like okay how do we actually maintain and add these relationships right and for the most part i have not seen companies be successful manually trying to manage the relationship right across infrastructure you can you definitely need to do that in terms of higher level constructs right but when you're really talking about the core infrastructure level you want to rely on automated tools to do this if you have something like discovery or service graph connector it will automatically add the relationship what relationship added is added really depends on what your what the source is right so again even if you're not using discovery service graph connector i highly recommend you know leveraging something like ihtl which does help you you know bring in some of these uh relationship and map them very very easily but again right pay attention to your source and just understand what relationship do they bring and how is that going to really help me with you know drive some of the outcomes i have in mind so moving on right if you look at a cmdbci that i had that i showed you before right there's more than 167 attributes right do you need all of them no you know so the key here would be you know you need to understand a little bit of you know what you're trying to do and figure out okay what are the attributes you absolutely need so here what i have a list of it is that what i consider to be must have right and i deem that if you don't have some of these things then you know fundamentally there's something you know you cannot get right and let me explain all of these you know one at a time so the first three i want to call out is your name serial number and mac address right and the subset of those would be like process name object object id id would be another one in there as well depending on if it's a cloud resource or not right or if an application or not right but the net net here is that those you know three items are really foundational in terms of identifying something right when a ci comes in you know all the logic we're going to use to say hey is this the same ci is it already exists you know or do we need to create a new one or do we not create anything right it's really determined by you know some variation of those three attributes right so those are must-haves second is you know what i follow here is life cycle stage and status so think about stage and status as really the you know reflecting some kind of operational status of that ci right and this is also very very important this is actually something new field that's been introduced right we used to have you know operational status hardware status right so we're sort of combining all those into this unified life cycle staging status and i'll talk about in a bit in terms of you know kind of the best practices in terms of what to do and what are some of the functionality we have to actually get on that journey so second you know set of attributes here are again discoverable for the most part right but it'd be something like manufacturer model number and i put in there because again you know asset management is highly highly highly important you know in terms of a lot of use cases customers do right and these two are you know become pretty much a requirement to get that correct and the final two is sort of location and environment right location as the name implies is just where is this you know asset logical physical located right and those can sort of be driven from you know different tooling in terms of looking at the ip ranges there are some integrations that actually provide this data for you right but this may also be something you would need to maintain manually right and then the final item here is environment and that's really talking about is this prod is this sub prod is this dev right is this ring one ring two what have you and the concept here is again there are some toolings depending on what you're integrating with that can bring this input but this is also something you may have to really kind of add yourself right and the final item here is all the things we call non-discoverable attributes right and these are things that for the most part you cannot uh get directly from different tools right in fact this is where you're sort of really managing data within sermons now and these things are something like a support group right which is really about uh who's going to actually support you know when there's an issue managed by group which is really foundationally about who is going to actually manage the ci as a record entity right and it's something new but highly important in terms of having you know accountability and and longevity of cmdb third one is change group as the name implies is you know used to be call assignment group this is like who actually approves when a change record is created right and the file item here is not an attribute per se but it is actually a a type of ci which is called information object right and this is for the most part linked to a business application and this is where you would actually specify you know your criticality of an application or pci or hipaa requirement right and how it would work is like you'd specify the criticality in business application you'd connect to an application service and you'd have the infrastructure supporting that you know within the application service and then those infrastructure components really gets the criticality gets the hipaa compliance from you know the information object rather than sort of managing them individually at the ci level right again very very fundamental fundamentally uh import and required in terms of what we're trying to achieve so one point that i cannot have any conversation on cmdb without mentioning is that i always get a question of you know what's the difference between cmdb and asset right and key is that even though they're very very related they're actually two different tables right and think about you know just a notion of what is an asset right the asset record really gets created once you have a demand right and it gets more and more data as you go through the asset life cycle right when at the point where you actually have something deployed it becomes a ci right and that ci life cycle again can actually have multiple life cycle you know for a single asset lifecycle right meaning that you know you may have a an asset that became a revenue generating server right and that regenerating server eventually got decommissioned right and now you're going to use that same hardware for again making into an email server example right so it's really two different ci in terms of life cycle right but net the asset was still singular it was still the same and we have a lot of things within servicenow in terms of syncing data between you know live uh between asset and cmdb and also sort of making sure some of the lifecycle stage shares are synced right and key takeaway here is that do pay attention they're not one of the same and when you delete one or the other do not understand like a repercussion of what that happens to either one of the life cycles so let's get into finally through the data governance fees right and like i mentioned before what i want to do here is really prescriptively walk in terms of the key steps you know that we need to do in terms of getting success right and then follow that through in terms of what are the the toolings we have in place to make that a reality so one quick anecdote here is like you know so before you do anything you know kind of understanding use case process alignment and org alignment is i would say the number one reason i have heard customers talk about not getting value out of the cmdb right and over the years they're talking to customers on just you know implementing and realizing value these are for me like foundational pieces that need to be figured out ahead of time and really in a use case what it really means is that a lot of times i see customers you know think about boiling the ocean and not necessarily having an outcome in mind right and when you're trying to sort of boil the ocean it's likely that you're going to fail right second is sort of process alignment like i mentioned before right getting the data into the cmdb is really the first part you really need to have you know process in terms of maintaining that data over time right and really having understanding of who owns it who are the stakeholders who are sort of deeply involved with that and this doesn't mean you need 50 people meeting every day you know looking at every ci but there's some basic things you need to do and let some of the workflow and the automation we have to solve those problem for you third is really org alignment which really means you know the reality is that when you want to maintain a scene maybe it's not going to be you know a single person or single team that can do it right it's really going to be across the board different people own the different data and different people really are driving different outcomes and how do you make sure you're sort of aligned so that you're sort of doing things in step-wise motion right and a great example like i'm just trying to think of it would be you know a great use case would be like if a customer comes in say hey i'm sort of starting my cmdb or redoing some of my you know trying to get into a healthier state and maybe they start with say my use case is that i'm going to look at all the computers meaning pc you know macs or laptops and i'm actually going to do software as software asset management and focus on license management for those right and there we said it's like we focus on the use case not everything so a particular type of class we're going to get a particular type of data to run the outcome of hey can i manage the license uh that i'm spending and a goal would be hey i'm sort of able to take down some efficiencies right the process here would be alignment would require okay now i need to sort of specify what are the data points that i need in this example you'd be like okay i need to get somehow notion of what are the computers that i have in my enterprise second you need to align in terms of uh understanding what data types right it could be like install software and usage right and the final point you want to understand from you know this process alignment as well is that you know invariably you will have data issues and so how do you figure out you know who do you work with how do you work with to get that correct right and one other item here is like when you think about the data data source you know in this example right you probably thought about secm right or jmf as being you know good data sources and here the nuance here is like it's highly unlikely the cmdb team owns those data sources right it's going to be the server team the compute team right the mac team owning those data sources so now how do we make sure we have an org level alignment in terms of understanding you know hey i need this data for this outcome when there's data issues here's you know how we you know figure that out jointly and then through asset management books are there to understand okay this is sort of the life cycle of the data and making sure that aligns with you know the policies they have in place right so when you think about all these together then you're sort of really set up for success so next would be once you have through the process in terms of like i figured out the use case i figured out the data i have a way to get the data i have a way to manage the data once you've sort of hammered that down the next sort of five things you know we like to talk through it'd be first is ingest and this is you know talking about identified at a deeper level what are the classes identifying what are the data sources identifying what are the attributes i need to bring in right that's step one step two is reconcile and this really focuses on okay now i have the data how do you make sure i am not you know kind of bringing garbage and garbage out right meaning how do i make sure i'm not creating duplicates how do i identify how do i reconcile different data points coming in right and this is something you you know you need to think about right out of the box there's a lot of cables already but again it's not something you can just take for granted so i highly recommend at least understanding what servicenow does in this space and i'll go deep dive on this subject as well in a few uh third aspect would be data life cycle and like i said right a great example here would be you know like for containers right would be you know a container could come in it's operationally useful for a little bit but then after a while you know you don't necessarily want to have it in the cmdb right so now how do i figure out an operational aspect of making that reality right so this really ensures like hey do we have ownership defined for these do we have the right lifecycle stages defined for these and then finally do i have sort of an automated policy created such that this can become a reality a third point is a data completeness right and what this means is that you know for the particular outcome you have in mind example you know like i want to do asset management on my software titles right maybe you don't necessarily need a support group right but you definitely would maybe want to have something like a location or a user that would help me kind of understand who is using what and you know if i take away some licenses who may be impacted right just and just throwing that out there right so again so just deciding what attributes actually require something you want to do and then second would be figuring out a process whereby you can check for these critical attributes right and have a flow so that you can remediate them as they pop up right and again this would be critical in the starting phase terms understanding what's required how do you track it such that you have success down the line and the final point is really about you know auditing the data you know one example i throw out there is like you know hey if customers wanna find all windows 95 servers you know servers running windows 95 how would you do it right and again so the auditing piece is really going to be you know determined on exactly what you're doing as a company and what you know what audits or compliance requirements you have but the point being you know you need to pay attention in terms of what are the things you want to monitor right and then importantly making sure you're setting up the different automated toolings we have so that some of these things can be sort of flagged remediated right and then continuously monitoring them right so the point like if you do these things uh together the goal is like not to make it incredibly complicated and require 50 people to manage it but rather you know it sort of sort of define steps you can do and let some of the automated tooling help you achieve the outcome you need okay uh i sort of just mentioned through the ingest piece right so going back to that and a couple of key pieces you know number one is really identify data sources and you know for the eye for the use case and like i was mentioning before you know if it's software ask management you know you may need like i said computer and software titles if it's something different you may need to get some different data scores i mean data types right and similarly based on that you may need different data types uh or you know in this case you know you may need something like a user maybe you need group right maybe you need location but again very much not just the ci but also the foundational data you need for drive that you case and then third piece is really about identifying how you're going to get the data right again we have sort of out of the box things like source not discovery acc or you know lots of service graph connectors right and if you can't for some reason use any any three of these things i would highly recommend leveraging uh integration hub etl right and ihtl is really the defacto standard we've said in terms of ingesting data into service now it uses the rte engine it uses ire right in the back end but it just gives you a very very visual and very easy to kind of sort of a debugging ide experience right once you've done that depending on the use case one other key aspect here is really about registering application service and again application service is the concept about you know logically grouping things together right such that you know you know how that's theirs they're being used from a business perspective right so it is absolutely critical to have application services created right and then filled with the actual cis and finally have it all connected to more of a business application and service offering or even higher level you know uh business construct and again what we've tried to do is make this sort of wizard-driven straight forward operation and not make it you know kind of rocket science you're trying to get this correct uh and the final item here that you need to pay attention for injection is really about defining sort of an ingestion schedule right and again it could be porous it could be poor it could be every day every hour every month right really depending on the use case what do you need the data for and making sure you're setting up the right schedule such that you can be successful so uh um in terms of data sources right uh again like i mentioned you know for one big piece we need to get right is for the foundational data and for that it's really about you know for user groups it's how do i get the ldap data you know ad data for location it could be you know hey i have my map wise where i maintain my data or it could be some erp system where i have some other department or you know company data right and the critical item here would be you know please definitely make sure you're bringing them in and making bringing them correctly uh second piece is a lot of the logical components components that i talked about right and here again is that you know you we have provided sort of uh wizards and uh you know step-by-step ways of creating these things and i would highly recommend leveraging them right and we even have things like you know clies and rest apis if you really want to be fully automated and fully modern right that's also available you know for you to use and then from the actual discovered ci pieces you know the recommendation here is that you know it is going to be far easier for you to use out of the box tooling like discovery like acc like service graph connectors right and then they like servicenow is going to support these integrations right but again for whatever reason if that's not available to you right the recommendation would be to use integration hub etl right and this again is uh going to just make your life a lot easier so just focusing on the integration of etl and i mentioned a little bit earlier what it does is that it can do push or pull it can connect to you know excel files it can connect to uh different data sources progress by jdbc right and then net net is going to be you know you can sort of easily connect to a data source it leverages the rte engine so it's highly performed and gives you a lot more out-of-box functionality and then the final step here is that you know you're going to leverage ire under the cover so that whatever data you generate is going to be clean and you're going to have a single way of reconciling everything and i'll talk about the reconciling step in a bit right second item is service graph connector right and then the gotcha here is that you know we have a whole bunch of service craft connector released where we're here you know we have a lot of traction here in terms of customer usage and we have a pretty robust road map and we'll do another follow-up session just on this but just be aware that you know it is there for you to leverage so third piece is sort of the application service creation population and what i want to show you here is really the the application service wizard right and again it's it's you know obviously a free thing that's there right and what it helps you do is register an application service it helps you populate the application service some are required or paid things others are free right and finally there's a dashboard that comes with it that really gives you impact and it keeps you tracked in terms of how are you in terms of your overall uh application service are there different things that are should be within an application contact do you have some orphan servers or infrastructure right it sort of points to problem areas as well and just overall keeps you you know sort of helps you sort of keep track of where you are in your journey so what does reconcile really mean you know reconcile really is about you know when you have the same data source or multiple data stores bringing in data how do we ensure we're not creating duplicates right or overriding each other and this is really about you know kind of where the ire comes in right ire is sort of the reconciliation engine that makes sure that you're getting you know clean data and it's sort of doing the the gatekeeping for the data as it comes with cmdb right and the key core concept is that if you send every data every source to the ire then you have a single gatekeeper that can really really make sure you know garbage doesn't get into the cmdb right so that's number one so number two point in terms of you know kind of the reconciliation is really about tracking your data help and there's really two things here that i'll i'll talk about one is using cmdb health dashboard right and then second is really focusing on cmdb and csdm you know data foundation dashboard those things are your friends in terms of making and understanding where you are and also making you know different teams and different folks accountable for the data right final item here is you know what i'll talk about is sort of multi-source cmdb and what this enables you to really is to get a you know a bird's eye view a double click of all the data coming in and to understand if something is wrong why is it wrong and how do i fix it right so these are all things really really you know you know to be you know very very important to make sure you have this correctly so again so the identification rule as an example right it is about you know identifying which is like i mentioned right it's really it determines whether or not a ci is matching with an existing record is this a new record or third do we even have enough data to create an actual record right just because you know you bring in the cmd data and the cme doesn't necessarily mean it's good enough to actually you know have right and the nuance here is like bad data is always better than no data right bad data is really kind of the crust of where things go wrong and you really lose a lot of credibility when you have bad data second is reconciliation and it is really about you know given multiple sources bringing in data how do i manage who whose data you know gets to be in the cmdb and the key you know kind of take away here is that you know just because you have the same tools running on the same thing doesn't necessarily mean they're all going to bring in the same data right there's a lot of you know temporal anomalies that happen whereby you're not going to get exactly the same thing and then final thing that ire does is sort of you know make sure the relationship integrity within the cmdb is preserved and an example there would be like if you're using like a tomcat war with a server right how do i make sure you know that i'm not inserting lots of tomcats right and creating you know duplicates whereby the real way you want to identify a tomcat war would have been you know the server that's running on plus the actual cert process will identify something you know who does that checking right it is ire right and then so the way to access ire as well as a lot of the class attributes and basic things is through class manager right you go into class manager it's you know it's a single place to manage and understand a lot of the items i just mentioned next so the identification rules you know the good part here is that for the for most classes you know there's already going to be out of box you know identification rules right it's not something you necessarily will need to sort of do yourself from scratch it is going to be there right and the second point is you know just make sure if you're going to change it be very careful and do some basic sanity checks to make sure it's not going to you know have adverse impact and here the key is that whenever you change an ire rule it impacts every source that's bringing data to the cmdb right not just you know maybe you're sort of trying to tweak something for a particular source you know keep in mind discovery would use this service graph connector uses this anything with ihtl uses this right so just make that you know kind of very clear a couple other things is that a lot of the identification rules are hierarchical right what that really means is that you know if you define it on a cmdbci it's gonna you know accrue to its child if you don't do anything on a child but you can add child roots as well which is going to override whatever parent rule you have right so again there are some nuances here in terms of how this thing works you know do do do pay attention to them second is you know the the same thing you do in class managers setting up reconciliation rule right and what i'm showing you here is like a you know screenshot of you know soon to be released san diego whereby you know you have the ability to do static rules which is really saying per class per attribute you can define priority order in terms of who gets to write it an example could be like hey you want the you know let's say the the ram value you trust secm right that's number one and maybe there's another you know source x that you trust less right that'll be you know item two for some things right that's where you set it up and then similarly now there's an ability to sort of do reconciliation and dynamic reconciliation which i mentioned before it's really about you set up rules saying you know it's the most reported value as an example right and the key with that with reconciliation is that out of the box we do not populate it right it is completely empty right and then so what happens out of the box is like whichever source the right to last is what's gonna be the data value right so here again you know you definitely want to pay attention and just you know essentially either use dynamic rule or make it such that you know your trusted sources are set up to write it to to be the the key you know priority data source and this again you know is follows hierarchy so again if you know you can set it up you know once at the highest level of the ci and it's going to follow through right and in each ci child class you may set up differently depending on exactly what circumstance you're in uh final point here is on class manager uh and and sort of looking at uh multi-source right so what multi-source does is that it is you know again you can sort of go to the screen to sort of look at it right look at the data but what multi-source does is like if you have a bunch of different data sources reporting on the ci it actually captures that data under the covers right and what gives you is that number one really visibility in terms of okay if my data got corrupted i can really tell you which attribute and which source corrupted it number one which is very very valuable number two is that you actually have ability to sort of recompute you know your cmdb like meaning let's say your actual cmd value in the ram example you end up using you know some you know source x and you realize ah source x is actually garbage right so what you can do is simply go and recompute by changing the priority to fpcm and then cmdb will actually go and recompute itself in terms of you know leveraging you know the right data point right and then finally there is something called multi-source report builder as well and this is really about understanding you know obviously a lot of data gaps you may have and you know coverage gaps you may have right but you know from a data management perspective this really gives you the ability to say you know show me any time sccm and you know source x are not agreeing on ram value right so you can sort of do these wide area sweeps and understand where's my data discrepancies is there some places where you know some sources are reporting something completely different from others right and that's where it gives you a notion of okay you know these sources may not be reliable and then i can you know judicially do what i need but do all that you actually need that access to that data right and the final point here is that you know we have something you know called health dashboard which to do to track um your health right and your data health and this again can be uh accessed through class manager and there's three parts of it i'll go through all of them but let's focus on correctness you know in terms of kind of the the reconciliation is where that is impacted the most right and then in terms of correctness there's three fields here which is stillness meaning you know how old or new is your data orphans meaning hey these are sort of you know the relation of integrity has been you know compromised or third is going to be really duplicate right and the key things take away here is number one turn your health you know thing you know health uh data on second is that leverage or the health inclusion rules right and what this gives you is the ability to sort of start small and not to have you know health run on everything and one key things i see customers do is like you know they try to get a help on everything right and it's like you know just it's it's nearly in a haystack at that point right you're just gonna be inundated with data rather really focus on okay if i'm doing asset management on computer class let's only look at the health for the computer class and now if i have a process of maintaining that data i'm going to now turn on you know some other class right to start small and then sort of go through that and a couple things here to call that right in terms of stillness right you can define what does scale mean per class right again it's it's variable in terms of what steel is mean but again it gives you a good rule of thumb saying hey if i haven't touched something in 60 days or 90 days maybe that thing is you know something we need to pay attention to uh third is creating orphan rules again what does it mean to be an orphan what what relationship do we care right we give you some of that flexibility in terms of setting that up and with a lot of that you know health dashboard items one key item is that it does generate a score and then second you can actually generate follow-on tasks right so that it doesn't just become a dashboard it's really like it actually becomes an actionable thing assigned to somebody some team to go and remediate okay let's let's get into uh get into the the data life cycle right and again if you remember data lifecycle is really about you know once you have a ci and cmdb right doesn't mean it's going to be accurate and require and operational throughout the life cycle right a great example here would be like you know we have customers who bring in you know a lot of uh you know container data right again container data have a value you know for a short life stamp lifespan right but you know after a couple of days or even like uh you know even in maybe a week or so right they may not have any operational value all they are doing is we're clogging up the cmdb and what we want to do is sort of define a policy saying hey you terminated you know uh containers after i know a week go get archives that you still have to an audit trail right but you're not necessarily having you know thousands and millions of containers just for the sake of containers right but now the question is like okay how do i actually make that operational in a reality right so that's really kind of what data life cycle is all about and the steps here is that you know first you need to understand and align on through the data life cycle right and some things like containers you know again have a specific life cycle other things like a server may have a different life cycle because again it's not just a ci but it is also an asset record tied to it right and there you just want to make sure you don't delete a ci right or archive sdi and then have another asset being you know created where you buy you lose context of anything else that had gone to a ci before you know it changed into a different ci right so that's really about identifying that life cycle requirement second is you know identify the data owners right net net here is like you know some of these things you can all obviously automatically do others you'd want somebody some group to say you know yeah go for it you know this makes sense right in terms of changing a life cycle and here you know the recommendation is to use manage by group within the ci right and there's ways to automatically fill this managed by group in right and i'll talk about that a little bit but again best practices like do use them to be the kind of the guardian of life cycle here third is going to be you know setting up the life cycle fields you know we've had a lot of historic operational uh status hardware status we are going to you know life cycle stage and status going forward right it is highly recommended to go set that up uh and then finally is you can now once you've done this you can sort of create a lifecycle policy with data manager right and then key takeaway here is that once you do it once it sort of you know continues on right essentially in infinity and you don't have to do this every time right so that's really the key in terms of making sure it's somewhat automated so one key uh item here i want to talk about is you know sort of the lifecycle mapping right so what we used to have previously is that you know folks had a lot of different life cycle attributes within a ci right and a lot of times they actually weren't even consistent with each other they were causing a lot of issues in terms of connecting to the asset side of the house right so what we did was created something called stage and saturn right and staging status are essentially choiceless but they're fixed we've gone through the pains of you know i don't know i didn't know how many customers we went through their life cycle in terms of making sure we had a complete set of stage status and then what we give you is that ability to sort of first when you turn on this life cycle mapping it gives you here is my legacy life cycle maps that i have right and it's sort of you know if you haven't modified any of them it out of box how does this map into the state status field right and if you had sort of done a lot more optimizat or optimization or you know kind of custom customization in terms of operational feel this is the screen where you can come in and map that that field that you've defined into something in you know kind of stage status right and once you activate it it actually does a bi-directional sync whereby you now have this you know more consistent life cycle stage status without having you know to you know get rid of all the you know stuff you already have and it gives you more of a a slow roll in to just leveraging you know stage data in the future in order to leverage data manager right and the key item is that you know data manager is all about automating you know your you know your your life cycle management and if you don't have a consistent you know way to kind of specify that then it kind of can do its job and then the final item here is like i know a lot of folks said they were not aware of what data manager is right so data manager was released couple that released ago right uh it's a completely free feature right and what it helps customers to do is sort of define retire archive delete policies right that automatically clean up the cmdb right it actually does a lot more like it does add a station it does dependency i clean up and the likes but you know the key things we released this for was for the retire archive delete you know functionalities and here's a great example here be like if you want the container example i mentioned right you know in order to make sure like you don't have overwhelmed with containers you can actually go set up a policy saying you know i'm going to target all containers that have been on a state equals retired and i'm going to archive them and i'm going to save that for i don't know like two years right it's a pause you can create and just press go and what happens is like you know incrementally right again you can set up how often you want to go do this let's say every couple hours it goes and you know kind of find all the containers that are sort of been retired and it archives them essentially right and then you can sort of do a lot of these different types of policies right whereby again a lot of the burden of keeping the you know cmdb healthy you know and not with a lot of junk is up to this feature and not the user having to maintain this day in and day out right again highly highly you know kind of useful feature but it does have that prerequisite of defining some of your you know state status just so we don't go and do something terrible uh let's talk next about you know again like i said one other thing i want to talk about is like even with the the the life cycle is that there is a a way to kind of track these open policies right from a user perspective as well as from an admin perspective right so again so that's all about you know you don't have to do this every day you don't need to spend hours on it it's like when things are you know about to happen there is some you know kind of task that gets created for the various folks and they can just look at it review it approve it right and sort of the you know it goes on his merry way right that's really how we want to sort of make this as automated as possible uh i don't know run out of time very quickly so let me talk about data completeness uh data completeness you know as the name implies is going to be you know for certain use cases you mean you need to sort of define what data do we need right it's not 167 different to be populated but it is not none either right so this is really a place in terms of defining what is required so you can understand where you're not making that requirement right and remediate them as needed so first step is really understanding how do i define what attributes are required very use case specific like i mentioned right for asset management case you don't necessarily need a support group right but if you're doing itsm support group is a must right so that's what i'm talking about in terms of that requirement second is you know for some of these discard provide an automated way to sync that data so you're not having to manage these you know one by one on a ci right so that's something just to pay attention to third is that you know you need to sort of identify key sort of attributes that need human verification right like for example like how much ram do you have right not something you want human verification right but you may want a verification saying hey is this support group on these bunch of servers still correct right so now like this is really about like you know how do you identify those and how do you set it up so that there's a workflow for this rather than again having to do manually so let's get into a little bit of the deep dive here and you know one functionality here in terms of you know once you've sort of identified let's say your non-discoverable fields are required is that we do provide you a way to sort of have these populated right and this is really up to using sort of dynamic ci groups right which are sort of a way you can sort of logically group different types of ci's together right and then second is connect that to a technical service offering an example here would be like if i have you know servers in seattle and servers in let's say san diego right i could create you know two different dynamic groups that say hey these are all the servers in seattle these are a different group with all the services in san diego and ad servers come in and out right it automatically gets updated and i connect that to uh you know techno service offerings saying hey this is a support group this is the managed by group for those you know kind of service offering right and that that data is automatically synced to whichever ci's are part of that service offering right that's kind of the beauty of you know kind of automating some of these things and managing it at a you know at a higher meta level rather than having to do at a hci level right one gotcha there is that it does not use relationships there right it's more or less you know it's not creating a relationship from a service offering to each ci rather it goes through the dynamic ci groups which gives us a lot more flexibility and fungibility in terms of how that would work next is really about the verification workflow right so there is a feature called data certification which should be used for for this purpose you know an example of how this would work is like you know you would go create a a schedule saying go verify all my you know computers right that my pcs that i that i want to use for software asset management and make sure let's say in this example you know that the location is correct right and then the way you would do is that you set up that policy and you schedule say hey i have you know i want to make sure it goes to let's say the manage by group to sort of verify this data right and then second you can set up things like hey report on this you know you have sort of 90 days to do this there's this job right so once you set it up you click it off what happens is that task gets created for the different folks within that managed by group that would need to go approve or verify the location right they can provide feedback right there in terms of it is correct or not correct and then finally you know there's a there's a data certification dashboard you can get to right where you can keep track not just from a user perspective in terms of admin perspective you know what are the different certifications where is it at right and from a user perspective what are things that to do for me right again goal being yeah this does require some human you know intervention but how do you make it so you can swarm on it it's automated it's workflow so that it's not you know a lot of time and effort to do this you know all the time uh similarly in terms of you know sort of required and you know some of these required attributes there is something called completeness in the you know cmdb health dashboard it is for this purpose right you need to go you know define what is required on a actually a table level right and this is really about if i want to create a record in cmdb what are the required attributes that's where it gets the required and you can add recommended on top of this saying hey these are some of the recommended fields right and then net net is like once you've set this up in class manager right per class what happens is that you know you can do a follow-on task when things are not there right so that they become a remediation task for somebody to go help and go you know fixed right so that's another key part of the health dashboard again so the last key point here is is data audit uh what does data audit really mean uh data audit is really the in one of the examples i mentioned right it's like okay i want to make sure there's no windows 95 server running in my environment right you can leverage the cmd db to actually find those areas and then create you know kind of follow-on tasks to go remediate them right and this is very much you know dependent obviously on a customer i have a lot of customers who have you know very strict you know pci requirement so they're trying to make sure you know some of these you know these applications there are sort of pci requirement have much more stringent you know audit in terms of what software is installed what software is not installed right but you know this you know is something obviously some everybody needs to pay attention to the good news here is is again you know we do not want to make this sort of uh you know uh kneeling in haystack again right so we actually have ability to set these things as policies where you can sort of go and set up a policy saying go find me any server that's running you know windows 95 as an example right and go send that to the support group to go and you know dcom hopefully in this case and not update the software right but those are some things you can do right and then the key things here would be like you know you set up a policy based on what you what's required right uh second is that you can set up your you know data audit uh policies and then third would be you would need to go remediate it right from the different groups and just keep keep track of it so what this looks like is in two different states right one is called desired state audit and here what you do is really create a filter in terms of you know what ci you want a particular policy to be applied against you actually create enough sort of figure out which sys group or user you want to assign the remediation tasks to and then you actually create an audit and it could be something like something is installed something doesn't have a relationship you know the ram value is less than desired you know lots of you know flexibility there right this is where you set it up and you can do this on demand or schedule it to run once or quarter once a day you know once a year however whatever makes sense right that's num key point one second is you know scripted audit which is does the same thing but it is really can be very very complex right and it is really about you can actually script some of these queries right and make it very very customized to exactly what you're doing right and i've seen customers use both of them right within the same environment for some of the basic ones they would use desired state audit and when they really want to focus on very very specific things they'll switch on to you know scripted audits and both of these items you know do show up in compliance right in the health dashboard there's a compliance section and you know what that really is is any of the audits that fail that you've defined from a scripted audit or bizarre state audit will show up within the compliance dashboard saying those are failures and here are some remediation tasks that have been assigned right again so it's again a single place where you can look at completeness compliance correctness but it's all there you know and please do leverage them and similar to what i showed you before there is this compliance dashboard as well which actually has a really high level right and you know it sort of captures you know everything from uh what's going on with different you know uh artists where the failures are when things are gonna you know kind of complete and so on and so forth right again this bird's eye views you're not sort of you know looking through individual records individually and then final show of hand here is really going to be sort of a cmdb data foundation and csdm data foundation dashboard right these are unlike the health dashboard you know a store ab and it actually comes pre-populated with data points meaning these are more you know prescribed things from service time in terms of how do i look at somebody's cmdb health right again it's not going to be you know it's not slicing dice on a particular you know ci it's going to look at everything right and again there may be situations where you know you don't necessarily need some of the things it's asking for right but the net net is like this is going to be if you haven't done it yet this is a very good high level view of where you are in your cmdb health and then more importantly it also gives you remediation tasks and even remediation services that are attached to some of these you know kind of metrics we're collecting right so again i would sort of highly recommend leveraging them uh uh so i'm totally out of time but i'm just going to show you two slides here and then you know we'll continue right and this is going to be part of the presentation so you can go check it out after the fact as well right so what i have here is sort of really highlighting sort of five things you need for overall for visibility success right meaning if your use case is like hey i want to make cmdb the system a record which is for many customers it's absolutely true right how do i we recommend you get a go about and some of the five things you really need to do to be successful there right i don't have time to go through it individually here again hopefully it's pretty you know self-evident but again take that into account similarly if you're really looking at idea asset management these are all sorts of the five things we recommend must do right we should definitely you know uh go through this and you know understand and read this and again if you have any questions do put it in the in the forum and and i can absolutely come answer some of this question any of these topics there may be and the final item here is like you know for five things for itsm or even management success right same things right these are sort of the things we say are absolutely required for you to be successful right you know and again it's not just these but these are sort of the foundational pieces that you need to sort of pay attention to so with that that was you know kind of the end of my presentation again i do appreciate everybody bearing through i know there's a lot of content there so again but really really appreciate everybody's time all right and thanks again for uh participating uh in this session and we look forward to seeing at the next session
https://www.youtube.com/watch?v=HiFnXe5Hyic