logo

NJP

ITOM Visibility and Governance: Agent Client Collector, from deployment to achieving outcomes

Import · Jun 24, 2022 · video

all right good morning good afternoon and good evening everyone and welcome to our our to our webinar today uh today we're going to be covering agent client collector from deployment to achieving outcomes and this is the first in a series of item visibility and governance community webinars that we're going to be hosting we're going to do it the third tuesday of every month at this same time so please be sure to join us for future topics uh so my name is steve emerson and i'm the outbound product manager for itom visibility here at servicenow and i'm going to be your host for today's session and as an outbound pm i wear many hats product evangelism customer value realization and sales enablement just to name a few but what i love most about my role is that i get to meet with you guys and hear how you're using our products and how and i get to share information about how our products can help you solve your business challenges so i've been with servicenow for almost five years and i've been been with working with the platform for nine years as a customer as a partner and now an employee but i have spent most of my career in enterprise i.t roles just like yourselves and i did that across a multitude of functions right so i've been in your shoes and our main presenter for today is severin uh so several can you please just give your brief introduction hello everyone thank you very much for joining us today my name is severin i am the product manager for the agent client collector on the inbound so i drive the product roadmap for acc and i'm very pleased to be here today thank you very much steve and everyone on the call thanks everyone so before we get started with our our topic here today i just want to do a quick poll um i'm going to launch a poll here so what is your experience with agent client collector please answer the question here so you know what is acc uh or are you performing a proof of concept right now um are you undergoing an architecture review board or security review and are you using it in production you know we'd love to know that so let's give it a few more seconds i still see answers rolling in thank you you know thank you guys for for your participation here today all right looks like we've stopped getting answers so i'm gonna go ahead and end the poll and share the results so what we see here is a lot of you are not aware of what acc is and you know today obviously you will get to learn more about it and then some of you are performing a poc some of you are actually undergoing a arb or security review and we have very few of you who are using it in production so far today thank you guys for doing that we'll have one more poll that we're going to go through here just in just a few moments so what is acc right acc is our single agent that can be used for workflow automation across technology workflows directly on your endpoints and when i say endpoints i mean your servers your your workstations you know your end user computing devices right so of course it can be used for push-based discovery which is useful in many scenarios right so things like end user computing where if i go to discover my computer but it's not running well hey you're not going to find it online right the agent will actually push its configuration back to servicenow when it comes back online itv6 enabled computing uh which today we have support for ipv6 on our agent um and challenges what uh um obtaining credentials right so the agent that we have um is you know credential less we don't need to go out and get admin credentials to to you know to push data back to our servicenow instance and there's a few other scenarios like air gap networks which you know we may touch on here today as well uh so so beyond our push-based discovery of course acc drives value across many different technology workflows so when it comes to it service management we have our live ci view application that can really help speed the resolution by viewing those real-time system information uh that does that does not require a remote desktop connection right uh so remediation playbooks uh you know we we can reduce human intervention by automatically allowing your or or i should say um you know resolving common endpoint application issues uh for example we have one with zscaler today uh and virtual agent conversations are the ability to you know have a user request something using a virtual agent and if acc is installed on on the computer essentially be able to execute the deployment of software or deployment of remote you know of admin access for example with security operations we can help you redis reduce risk as well as drive that you know um that lower mean time to recover uh by allowing uh you know access to real-time system information from the agents themselves and of course with aiops that is our monitoring and health log analytics solution so we can use the agent to stream events metrics and logs back to servicenow and then do the correlation of course with you know with our app solution and then as far as software asset management goes right we can help you optimize your software spend by providing that software visibility and usage data whether it be through last use date or metering which we now have capabilities for so with that said i'm gonna i'm going to to also let you know that our acc is delivered via the servicenow store as you know we have two family releases every year but we do release quarterly via the servicenow store for most of the itom solutions so agent client collector you see a screenshot here if you go to store.servicenow.com you will see where to find these applications that were that you're going to learn more about today and i forgot to mention earlier if you guys do have any questions please use the q a panel uh we will be looking at that today uh so please feel free to ask questions throughout and if there's anything that is pressing we will um stop the session and you know we will ask it live and then here's just a bunch of the features that we have released recently through each of the acc apps i'm not going to go through all these here today but you know as you can see here's what you're missing out on if you're not using agent client collector uh and then finally we'll do one more poll before i turn it over to seven i'm gonna go ahead and launch our second poll around our acc use cases so of the ones i just described right which of the use cases do you see adding the most value to your organization and this is a multiple choice question here so please select as many as you'd like still have some results rolling in all right thank you all for answering i'll go ahead and share the results we still have a few more coming in okay all right so it looks like our biggest need right now is around push base discovery our second biggest need is around ai ops third biggest need itsm security operations and software asset management um thank you guys for answering those questions uh we will these will will certainly help us you know with future product development as well so i'll go ahead and stop sharing and i'm going to now turn this over to severn to talk about acc in more depth thank you very much and while i'm trying to share my screen please everyone have a closer look at what steer has been able to publish on the community site on the on youtube as well so on community on the white papers etc steve you have done an amazing job and well thank you for your contribution so thank you getting started here of course you have a zoom so this is the store i have zoom hiding here so i have no clue about uh what is behind but you can see all of these applications content delivered on the store for the agent clan collector so let's get started here and sorry i have a small calf it should be fine it should be fine for 30 minutes all right so this session is about getting you all the insights you need to get started with the asian clown collector beyond the simple initial deployment that you had at the beginning just trying out the agent so today i would like to cover a bit of a product architecture but more importantly share some insight some material from my own experience assisting my customers who engage with me directly and see if it can be helpful for you to go through your production and get the value to get the outcome of the asian clown collector so i'll give you some insights about who is the data when etc then we can discuss how to roll out the product we have multiple options there is not a single answer but at least to give you the clues on where you should get started to get your own plan for that after that but we will first part we can do some q a but then we'll get into a deep dive on on the agent clown collector so let's get started why are we here today well my manager asked me to but all right we have an increasing amazing adoption of the agent and we need to communicate to our customers not just with a docs on the portal not just with our account teams but we need ways like this community to reach out to you so thank you again for joining us here today and also well i was told a while back that um about the format short webinars 20 minutes were not technical enough so we were asked to provide more technical content for this kind of sessions so we still have about 45 minutes let's see how far we can go with that and last well i want you to be successful so getting all the information you need to have your path to your plan for production rollout is very important so i hope that this session will be very helpful for you to get to that stage and for those who are already in production you may want to revisit a few things and if so engage with your account team maybe reach out to us as well if if you have some specific questions so about the initial simple deployment maybe your proof of concept proof of value you deployed an agent on a couple of systems these agents connected to your mid server that was this time hosting a small web server on http or https and that mid server will connect back to the instance so this is a simple topology and i actually have some customers they tried out the agent but they didn't have a place to run the med without going through the request to a network team to get everything in place so they just deployed they made on their own laptop and then they're on the agent connecting to the maid on the same system and then went back to the instance easy for some customers it may take five minutes just to get that this is great but between that achievement to have a few agents connected to your instance and have it running at scale in production you have quite a bit of a gap let's put it that way so let's see a bit more what you can expect in your environment you may have data center infrastructure servers connecting maybe directly to the maids or through some load balancers uh maybe some network articles uh maybe the maze run on the dmz but this is the first use case is to get access to those devices on your data center a second situation may be in your office on our corporate network where you may have some workstations or laptops connected to your internal corporate network maybe there is a firewall in between i believe they will not access directly to your maid maybe the maid is actually hosted on the data center but all right you have a bit more to reach out to uh to those configurations and additionally you may have endpoints out of your corporate network even out of your vpn so for once going to vpn they may go back to your mail running for office but the other ones you may need another mechanism to reach back to those mids just like a regular website so you can see how things can get quite complex and this is just like a simple view of how it works in in real environments you may have a disaster recovery site you may have a global load balancing with with dns you may have a more complex infrastructure on the cloud with multiple providers etc etc so with that just repeating one more time if you can uh save a few a few tickets on the customer portal it is the agent that connects to the mid not the other way around and each agent will have just a single connection at a point in time to emit so with all of that a regular environment i.t infrastructure environment you can see that many components have to be put together in order to get things working in a real environment so of course you have your cmdb and servicenow platform admins right to get started but then you will need likely system administrators to deploy the agent even on a small scale you will need the assistance to do that except if you have a completely service environment you will likely have depending on the complexity complexity of your network a lot of to do on the networking with the dns configuration load balancing network acls of course and the certificates tls certificates potentially both certificates may be handled by your system means or potentially by a dedicated team we cannot tell you you have to figure that out so it may be a specific pki team for that then [Music] which user to assign the agent on your systems on linux on windows you may not have a single answer for every use case depending on your infrastructure your topology your security guidelines you may choose one option or another you may find a dedicated team on active directory who will handle that others may just uh handle that with a request with assistant main team you have to figure it out and then how do you distribute your package and maintain your package at scale again it depends on the environment you may have multiple teams like a mod one team for data center and a motu team for cloud deployments they may not handle things the same way so you will need to get those smes for each of these groups in order to be successful um in while first preparing uh your plan all right having your your architecture design in place and then having their support for ruling things out into production so stepping back for a second you need first to identify your initial at least use cases with the agent is it providing a an alternative let's say to horizontal discovery where you may find issues accessing specific parts of a network you cannot run a mid maybe on that specific vlan and you cannot access it remotely you may want more real-time information you know real-time information being collected by the agent instead of the horizontal discovery schedules or you may want to have a hybrid approach potentially where you will use deep dive discovery for including application configuration based discovery that surgical discovery and get top-down service mapping for example so try to identify those use cases um another one it may be just globally where you cannot use credentials to access remote to access those systems remotely and because of that you need a solution that is agent-based so this is another use case here then all of that interactions we have where we can collect data on demand execute commands like a remediation playbooks and enrich security incidents collect software metering well the agents the agents are a very good solution for that and it may be the why you are pushing this agent there and the last piece this is about a feature that we released back in may where we provide a way to collect data from completely disconnected networks it is obviously not using the online agent running a maid connecting to a maid but still we decompose the agent we took the scripts we re-bundled all of the scripts and invoke by yourself collect the output and then once you leave the secure facility you can upload that data to servicenow manually so not a single plan that will fit everyone but just think about how you will approach your work with the agent client collector again you may have started with a simple proof of concept or proof of value some customers may go to a poc and they released a production right after that so they got everything covered actually just before they turned onto proud but i recommend taking a phased approach for that where first you will confirm that you have a simple topology and you like the data points provided by the agent and you feel you can move forward with taking on the next step with it so after that you may want to pick up a couple of how we say representative uh operating systems running deploy the agent over there on a small scale and just to see what happens uh if you are facing any challenge that may be on the networking or that maybe on the os itself or issues with your servicenow instance potentially to identify them on the scale that is still limited and manageable let's say and so this is all to certify that the data collected by the agent is the one you expect and if not to take some action to recover these once you are done with data certification you can start the work uh engaging your other colleagues potentially and prepare for that architecture review board review or security review and have the right topology for that you will need to understand how many mades you need do you reuse existing needs or do you spin up new ones where so back to that complex network topology think about how things will work for that once you're done with that with that plan you need to automate it it's an agent you are deploying a piece of software in your core critical assets you need to be able to handle these at scale it is mandatory just like any other piece of software nowadays you must have that automation in peace to be successful and last what do you do after that you need to make sure that the cmdb is healthy just like the uh process when you ingest data from multiple data sources into that federated cmdb on servicenow platform you need to make sure that the data that gets in gets incorrectly if it doesn't you need to take action for that so you will need to update your operational slash governance process to keep the cmdb healthy and add that piece specifically to the agent client collector then how do you deal with a grade agent upgrades upgrades on your instance upgrade on the application upgrades maybe on your own custom scripts you may add and how do you deal with just agent configuration updates again being able to distribute and maintain your packages that scale and the configuration is highly highly important so before we go to the that was introduction before we take a deeper dive into the product steve do we have any question maybe yes we do um so we have so a question came out does it work the same way as the sccm agent and scan over the internet so essentially i think what you described the architecture where you could put a mid server uh you know behind load balancer on on a public cloud right yes so that's it it is not um always say um using using it on a cloud or somewhere where you can not back to a private ip you can get your agents on systems endpoints uh and user compute endpoints that are not connected to your copyright network yes so that will work over the internet but just to make it clear the maids will not scan the internet just to make it clear it is the agents that connect to the mids so just like your regular web server you may have some web servers websites in your internal corporate environment and you may have some of those republic but we are still hosted in your data centers on the cloud the same applies here okay thanks everyone um so as far as you know deploying the agent i'm sure you're going to get into this but so question came up can we install the agents all automatically for specific hosts right for example if we want to install the agent just on all my windows notebooks can i do this massively without using a third-party solution so if you know already these devices you could potentially let's say using the flow designer if you can access them remotely now um is it something that will work all the time as we just just mentioned devices that are not on the internet it may be but addressed on the internet and not on vpn it may be problematic okay and that and guys that's done with the um we have integration hub uh now it's called the the automation engine and that uses the agent client collector spoke that can help you do that um just a couple more questions seven before we move on and i'll keep answering them in the background as well uh so for existing customers that have deployed um you know mid servers for cloud discovery right private infrastructure as well and they have firewall ports open right what benefits does acc provide here and how to upsell it internally yes absolutely and it works in conjunction with cloud discovery so the agent will collect quite a significant amount of data points but are not represented with just your cloud topology so they work together we highly recommend you enforcing tagging on your cloud infrastructure and with without the cloud discovery then acc will create that relationship between the vm instance and the server that was discovered by acc great thank you and i think the rest of the ones we'll save because i think you're going to cover some of these next so okay thank you yeah all right well that was a long introduction we have 25 minutes okay all right so for this deep dive let's get a bit more into that network topology how you configure your mates and then i will actually go to how you run the agent how you connect the agent to the mates and then we'll get more into the whole cycle of how data is collected and transferred and processed into the instance to the cmdb so we can do some troubleshooting um as well that can be helpful last piece i would like to have a few words also on what you need to do for automation 25 minutes let's go all right you're made your mates host a web server so the mid will listen on the port i keep repeating hopefully we won't have any more cases on that your maid if it runs as privileged user so system account or root account it can listen on port for for free but of course if you have multiple maids on the system and if you have just one let's say ip address assigned to your system you cannot listen on port4 for free from multiple mids so you have to make a decision here if you run meets on dev and proud on the same systems if you run your maid on a gmsc account for example it will have to run on a non-privileged port that's that's what it is so you will have to make the decision ask your security uh what what is the best for for your standards then do you want the agents to connect to the maids or should they go through a load balancer again your infrastructure may be quite complex and maybe your network team will prefer handling network connections using load balancers because this is what we've been doing for years and that works very well if so just keep doing that for for this connectivity you can also configure the maid to return actually the list of all the maids to the agents and then the agents will identify the latency so we'll do a tcp run rubin and get the latency um for each mid and connect to the mid automatically but it still needs one mid at least to get started so you need maybe a cname or something that will make sure that when you resolve your first made but it in any point in your network it will be able to connect to that made alternatively you can just specify that list of mids and all load balancers just to make it clear of course with a maze running on the on the cloud provider for example if you have end user compute you will need something to put in front of your maid to get that nat so that from a external ip it resolves and it forwards to the internal ip that will hit the maid maybe you have something sorry some integration with the infograph so this scaler to manage the dns config and it will automatically get the right information very dns resolution to the agent whether it's on vpn or not or whether it's on the local office or not so think about that as well i mentioned how do you want your topology you will not connect all your agents in all your systems to both dev and production instances on servicenow so you will need a few test systems where you can switch the agent right first you start with dev with a made on a on a dev instance and then whenever you were good with that you switch it back to your production so think about the lifecycle you're going to have with that regarding the operating system the protocol between the agent and the mid is http websocket to be more specific it's an extension of http protocol therefore you do not need the how you say a windows with powershell to connect to your windows systems so if it is easier for you to manage mids on linux or more cost efficient et cetera et cetera you can get your windows agents or mac agents connecting to the made on linux not a problem next something that happens quite a few times you have network accounts where you have to allow that port but you also have host firewalls you have a windows defender on the local security policies you can just take the time it takes a minute or two to make sure that your host firewalls are correctly set up now dedicated nades versus multi multiple capabilities on the mid it depends on what you want to do but and it may work for dev you can use multi-purpose for dev but for proud let me ask you this would it be wise to run on the same system on the same process the workload of a web server with many many many multiple connections network connections for each browser each hr network client and run your database on the same system with your middleware in between to do some heavy processing data processing if you believe that the answer may be no to that question then you may want to use dedicated meds so that you have that specific workload on the agents and you can apply that mid-sizing rule of thumb for now steve we don't have nda i guess so uh um yeah we stick to that for now 1000 agents per gig of java hip size and last thing that can be problematic for customers i've seen on on that is on tls configuration because obviously we enable https by default but guess what the certificate we provide is posted on the medal it is not a signed certificate by your internal ca it's a self-signed certificate so agents by default skip the tls handshake verification if you are not so sure about what i just said please reach out to your security and uh hostess admin teams to help you to get it right and create a tls or digital certificate signed by their own ca and get that uploaded into your med key store let's keep going we do have a few tunables just a few we do have a couple of system properties and for this topic here enable or disable the automate selection how many agents you want to max out so on any server if you have ever programmed a server of any kind you put a value a max value to your queue to your tcp connection queue this is that number that is 4000 by default so you may want to adjust it to your needs and to the sizing that we discussed before we talked about the web server configuration so then load balancers what do you do about dns on load balancers do you terminate the connection or you just forward it that will decide your dns config and of course what you put in your tds certificate so make sure you consult again with your networking team and a pki team for that on the mids inbound https the max heap size for your mid default is one gig so you see you have one gig here four gig there by default you may want to do something about that i mentioned the key store to get the digital certificate for tls communication and then your mid-service how do you want your maid to run under which user because that will decide if you can use port 443 or a port that is above 1024. very cool on the agent you will specify your maid url which can be multiple ones that's an array so you can put multiple ones you can combine load balancers and other stuff uh direct meets it will be fine you will also say if you want to go through that automate selection algorithm that we provide by default and last thing if you do a cls handshake verification so everyone just a quick question yes that came up um so the question seems to be around is there a maximum number of agents per mid recommended but i think the answer is it depends how much memory the mid server has correct exactly yes then it's about how many concurrent tcp connections you're going to have by the way if you run as an on the road you may want to change the limits on how many file descriptors you can have open at the same time the agents stay active the connection will stay active that's how we can have at bi-directional communication so um just like going to a place let's say a pub you want to order the ring if there are many many many people at the desk to order a drink or just to catch the attention of a bartender it may be problematic that's the challenges with context switching on cpu so at some point memory may not become your limiting factor it may just be cpu with latency that accounts for cpu usage so you will have to revisit those metrics to make sure that everything is going the way you expect thanks sarah so now about the agent itself if you want data likely you need some privileges to some extent i am not the one who designed the linux kernel i'm not the one who designed the windows either and that's what it is on linux you want to collect the serial number any sale number on your system there are not so many options you need to get it from slash dev slash ram which is available normally using the mid code if you can convince i don't know nowadays who maintains that kernel alan cox or others convince them to make that readable from a normal user please proceed and let us know how it goes but it was asked already about more than 20 years ago same thing on windows you want the whole path of your executable and you want to be able to get the parameters of your running processes learn so many ways maybe you complained before about the privileges we required for service mapping and horizontal discovery on the on windows um with the high privilege access but it's what it is you need that debug programs privilege in order to get the full description of your running processes it's what it is same thing here we noticed on some old but still very widely used windows 2012 windows server 2012 to get the storage devices with wmi you need system account for that so think about all of these features what do you need and what do you want to deploy there and i see a raised hand blinking i don't know steve you can do something about that there is a raised hand on the screen so a couple of approaches here you may want to start small with just the minimum like with a pseudo dmid code nss and just take it from there or you want to immediately review how much data you absolutely need for your use cases and also beyond that initial deployment where do you want to go it's all to you for some places where your systems are not part of an active directory domain and you have to get people physically get into the systems well you may want that self upgrade capability that we released just a couple of months ago and for that it has to run as a system account so next i see 45 12 45 we should have two hours next time steve multiple ways to authenticate api key which is default it's just a key and with san diego you can have about 10 active keys in parallel http basic authentication which is user plus password that applies only to the maid configured with that whereas for the api key it applies to all the mates part of that same domain on servicenow instance and last piece if you need absolutely especially zero trust networks um you need to authenticate each client uniquely with a different set of credentials you don't have so many options and so for that we enabled mutual authentication using tls so client side certificate of course if you want to use mtls you need tls to be enabled all right so now about payload processing the agents receive a policy from the instance they will download the plugins so the mostly ruby scripts and os query that we store in the cache directory we then execute the scripts the agent will execute the scripts on the schedule get that output normally json payload and return it back through the maid to be transferred back to the instance for events and metrics it's using the rest api i believe with the check type events and metrics so you have a mid server script but for visibility in most of our use cases we'll just forward that payload to the instance and then the eccq will produce will unpack that payload and go through all of those data points and store them into the cmdb using the ire of course if it is for for every ci type obviously so that means you have an agent that is connected but you don't have any host associated with it you don't have any it says maybe data collecting but nothing is happening you have nothing in vccq well it's likely that something went wrong with any of these steps here and so for that you should check the logs acc logs if you have a payload it's on servicenow instance you can see it from eccu but still no ci it's likely on the ire it was blocked so you have to check the system logs for that so you can quickly identify about where the problem is and then take some action for that then on you can open a case maybe about tunables i put information on the store app release notes here for example on ipv6 on how to tweak the ci name trying to reuse the discovery tunables these properties i also made it was a decision it was a good one but didn't please a few of our customers on on windows should we use the bios serial number or the baseboard serial number for the uh ci uh the host ci and well uh discovery does both actually you have a tunable for that so well uh we're gonna provide some updates very soon i hope but you will have a flexibility to choose which sale number you put in your ci server on top of obviously all the serial numbers you put in the related list more and more tunables here but i still recommend enabling multi-source cmdb revisit your rules in ira to make sure that everything is working so let's see common issues well your agent service doesn't start or doesn't even connect to your maid could be that the credentials api key doesn't work you don't need the agent to check that just run the curl command and you will get it you may have invalid file accords especially if you switch the agent service from system to gmsc account and back to another user account you may have issues with your file accounts that's very simple so you have to review that if you don't have anything in the logs likely your agent is not even able to write into those logs check the file calls i also have that here typos happen if you have a typo in the config file the agent will not start so check the logs on the agent connectivity you should have everything here you need curl command but sometimes the maids themselves were already in a bad shape and they will be throwing all of memory issues so you may want to check the logs for that and in that case actually the agent was marked as up and running but on an old maid and the maid was dysfunctional it was quite misleading i would say then collecting the payload you may have some issues with your config sudoers on dmid code and ss some customers they have a they mount sludge var in a distinct directory and they have a no exact flag some others may have a blacklist on ruby.exe that will be blocked by carbon black you may want to have an allow list for that etcetera etcetera so see how you can quickly identify at least validate your assumptions assess your assumptions and see in which area you have a problem payload processing we have so many issues on our customers having mandatory customer attributes changed ira rules in the network adapters for example then we have business rules that will change the value of a serial number by themselves just completely custom it happens a lot but also some changes that were not applied when they upgrade the instance one customer they had like 2 000 skipped changes when they upgraded to the latest family release 2000. so all of these things here cmdb servicenow i mean team we have to make sure that everything works as expected under instance you can have a pdi instance take that payload and reprocess it onto servicenow pdi or dev instance something that is out of the box with no customization and by just doing that you will know if it's a problem with your instance configuration slash customization or if it is what never happens of course could be a defect in a product never happens so far so good five minutes left you have a self-test on the agent for these basic checks check the logs network connections curl slash web browser for the network connectivity on the maid you should be familiar with all of these logs and on the instance you have many places to look at but you will start with a ccq and a shortcut agent record to get to the ccq but then look at the system logs and deep dive into all of these things to understand what's going on the discovery source was introduced in quebec part 3. if you don't have the acc dash visibility discovery source nothing is going to work so if the data is not there you may want to start with that next automation we don't own how you automate the deployment of your products in your itune infrastructure but your infrastructure does and you have multiple ways and you can have a mixture of many things at the same time so you have to understand depending on which environment you are targeting how do they distribute packages in those environments do i use a third-party solution like sccm tanyam etc ssh loop just like in civil war commands do they use something that will enforce the configuration every time it executes with puppet chef and symbol etc or do they embed the agent in the base image on the cloud for example or vm instances so our product works with all of this automation capabilities we make it flexible so that you can tune it to make it happen going quickly here if you need to automate it you need to think about who runs the agent do you already have a servicenow user account because if you do you may want to use another one one that is not providing remote access for example consult with your infrastructure team packaging team not just for the installation but for the whole life cycle of the agent for the installation the upgrade and removal but also maintain those values in the config files as well as a few other places something that happens often also hidden files on the windows you may notice that you have a space here with program files i cannot tell you how many cases we had on that but program data is a hidden directory so if you look at where the config files are on windows they are in program data not in program files for automation if you want to have a same config file with the encrypted api key keep that agent key id and you put that everywhere it will not create any duplicate so if you are using something like puppet or ncball and it will look for changes since our agent will re-encrypt the api key at startup it will see a change all the time so instead just do it once keep it encrypted with the symmetrical key and you can deploy that at scale um also right now but very soon will be changed um the msi starts for service once the agent is installed so if you want to embed it into a c sprite make sure that you shut it down and the agent now id that is in the cache directory is deleted that way you avoid duplicates i was serious about that we need another hour yes we do um yeah there's been a lot of questions i've been trying to answer you know most of them um any answers that and and so guys any questions that we don't get to today we will follow up um so our plan is to publish what you saw here today to youtube as well as to the community channel which you registered so i'm going to share my screen one more time here and i just wanted to share with you a resource that you can see if you go to now now learning dot com sorry now learning.servicenow.com now create you will be able to find um you know resources right where you can download some additional functionality here as far as workshop information as well as process guides and some best practices that that you were all asking about and of course now create also has data you know i mean documents across any servicenow solution not just acc of course so our call to action here today right is check out the store look at the acc capabilities or applications that we have available today and try out some of these in your sub production instances right and as you are starting to see value share that value with your stakeholders right get them excited about it right and of course we are here for you so ask questions reach out to your servicenow account teams publish comments uh for example on the community article and then as you start to see success right share your story with us as well uh and then finally as i mentioned earlier this is a series uh so this was the first one today our next one is going to be on july 19th at the same time at 12 p.m eastern 9 a.m pacific where i'm going to cover uh how you can manage certificates and automate certificate fulfillment with a single platform being serviced now and there is the url there is the qr code you can scan to register those of you who have registered already um it is actually for the series so you don't need to register separately but you know share this link with your friends you know tell them about our solutions and you know we will you know we will endeavor to train you on all the latest capabilities here on our item visibility and governance solutions but with that said i want to thank severn here for presenting today i want to thank you all for attending i know you have plenty of things to do with your lives in work right now and we we really appreciate you being here uh so with that said i'm going to wrap up the session thank you all for attending and have a great rest of your day thanks everyone

View original source

https://www.youtube.com/watch?v=GiirbbUDnkk