Cloud Center of Excellence (CCOE) part 1: How to gain business context of your cloud resources
all right good morning good afternoon and good evening everyone and welcome to our webinar thank you all for joining today uh so today we'll be covering how to gain business context of your cloud resources uh and this is part one of a two-part series on the cloud center of excellence this is also part of the itom visibility and governance webinar series which we are running on the third tuesday of every month and you could attend our future sessions at the same time that we are here today so this is also part of the live on service now program which is a curated series of events that will help you to further gain adoption of your servicenow investment uh we help you with how to use the products so that you can achieve value faster so please be sure to join other webinars there will be a link posted here in the chat below and you will also be able to attend for all products beyond itom so csm hr etc just a little bit of housekeeping all of your lines are muted today so please use the q a feature in zoom to ask questions and if you would be willing to do so please introduce yourself your role uh we'd love to know more about you um we're going to have two polls today so we ask that you please answer those polls that'll just help us guide this webinar further this session is also being recorded and it's going to be shared on the servicenow community platform as well as on youtube after the session uh and then finally after the session ends uh you'll be prompted to take a survey uh we always appreciate your feedback so please complete that survey once you're done now a little bit more about me my name is steve emerson i'm the outbound product manager for itom visibility here at servicenow and i'm going to be your host for today i've been at servicenow for five years in a variety of roles and i've worked in enterprise i.t uh for for 20 plus years across a multitude of you know of discipline so i know what it's like to be in your shoes trying to be an i.t operations but what i love most about my role as the outbound product manager is sessions like these where we get to share with you information about how to use our products and services uh and then you can give us feedback as well as uh answer you know um ask questions so that we can answer uh and joining me today our our main presenter is rahm so rahm can you please uh do a brief introduction thanks steve and uh yeah it's great to be here talking to all of our customers here i really appreciate everybody who's on the uh who's on the webinar uh today i'm ram devanathan i'm senior principal product manager in charge of a few of our cloud products in the itom cloud management space starting from cloud discovery and cloud visibility going into the cloud governance and the cloud provisioning areas right happy to be talking more about it today as you know for me this is a great opportunity to also get some feedback so again as steve mentioned please do make sure to post your questions also the survey at the end we'll be running some posts during the co during the course of the presentation please do feel any uh feedback there thank you all right thanks rob and speaking of polls we have our first one to launch so let's go ahead and launch that poll and basically what we'd like to know here is what is your progress with setting up a cloud center of excellence or ccoe for short so our choices are what is a ccoe right maybe you don't know what that is we're thinking about it we're in the process of setting one up and we have a fully functioning ccoe i'm still seeing some answers come in so let's just give it a few more seconds maybe 10 more seconds aisha and then we'll close the poll thank you all for participating this is greatly helpful um okay but i think we can go ahead and close it and a lot of you don't know what a ccoe is so that's great we'll talk about what that is today we see some of you are thinking about it some of you are in the process of setting one up as well as uh you know very few of you have a fully functioning ccoe uh so congratulations that is uh that is a great achievement that you've accomplished there so we can go ahead and close that out and we can move on to talking about what a ccoe is so if you look across the cloud providers and these are just definitions we've copied from their websites every cloud provider has a different definition of what a cco is right but the main goal here is that these are teams of people that have a goal of making sure that the cloud investment is successful for the organization and of course if you're using multi-cloud right you need to have a cloud center of excellence that has a goal of not only managing uh one cloud but you know multiple cloud providers so what we've come up with is our own definition of what a cco is and i'll read this definition first but then i'll talk about how we implement that uh so the cloud center of excellence in our mind is you know those teams should foster the frictionless adoption of the right technology solutions to meet the challenges of the enterprise right they can accomplish this by sharing prior successes and best practices with project planners assisting with the creation and review of new architectures and also ensuring the ongoing security and governance of of active cloud services now servicenow believes that the best way to accomplish this that team needs a platform and we are uniquely positioned with a set of solutions to help you manage the entire uh you know life cycle from planning to production of your life cycle now it all starts with visibility just like your on-premise resources it's it's important to have visibility of your cloud resources right you cannot manage what you don't know about and we have full support for the major cloud providers you see there aws azure gcp ibm cloud as well as oracle cloud right so whether you're discovering is things that you've brought to the cloud yourself um paths resources that you are using that are provided by the cloud providers such as database as a service or other application stacks there as well as functions and containers right all of that data is extremely important to be able to make data-driven decisions and on the right-hand side you see why we need to put cloud data in the cmdb so whether it is for the purposes of live data that is actively there or whether it's data that is ephemeral in nature your security team is is going to want to know or maybe another team is going to want to know what the active configuration was at a given point in time um because they may need to know was it healthy right what was the configuration of that stack they want to be able to understand what was the cost involved with that from a software asset management perspective how do you know uh you know how do you manage between what you've brought to the cloud versus what you're paying for through the cloud services and also for security right there's always incidents there's always vulnerabilities that need to be managed and then of course regulatory compliance right how do you know what data which cloud resources have pci data or pii data these are all just different things that need to be kept track of whether it's live or maybe it was only stood up for a short period of time and we provide you with that near real-time visibility as well which rom will go into in more detail and my final slide here before i turn things over to rom is you know we've discovered the cloud resources with itom discovery the next step is to make to gain business context of those resources which means that you understand how a specific resource in the cloud that you've deployed relates back to a business capability or to a business value essentially so servicenow discovery can discover the tags across all of your resources natively then we automatically populate those tags into cmdb right tags are keys and values which we'll go into you know more detail here as well the tag governance application enables you to create tag policies or standards to audit against those standards and then to auto remediate the deviations uh in your cmdb uh we could also remediate tags in a cloud we'll talk about that in next month's webinar and then finally the last thing would be service mapping right to be able to use the tags that you have in your cmdb to create those tag based service maps um and then i believe i'm about to turn things over to rom so rom over to you thank you so much uh steve once again um let me go ahead and uh bring up my desktop uh steve just let me know once you you can see my desktop can you see that okay thank you thank you so much okay great so we're going to be talking about you know the overview of the cloud discovery uh using the cloud operations workspace which is a new app that we have introduced earlier this year right we'll talk about how to manage your cloud resources and also take a look at the cloud resource inventory dashboard which can give you a slice and nice view of your uh you know of your cloud landscape when i say cloud i also refer to vmware on-prem kind of landscape here but yeah more focus on the forward moving uh stuff around uh the public cloud really right to make this a little more simpler i'm going to use throughout the course of our presentation and demo today and also for the next month's continuation of this webinar i'll be using the fictional apparel company called sadajo right serago is a usd 10 million apparel company and established in uh 2016 uh basically they have traditionally been a on-prem uh kind of a shop oriented kind of a business they're getting into high-end fashion and online selling so obviously the whole thing around cloud transformation goals are coming into that and as a result they have upskilled their app teams the app teams have moved on uh to actually build stuff in the cloud you can see 67 app dev and devops teams who are actually devops team team members there right but uh there's not much cloud skills not much cloud talent on the id side right it's a six member uh small i t team uh obviously there is concerns about cloud security there's concerns about cost there's needs about cost more than concerns and then the cmdb is a work in progress right on premise covered well but moving to the cloud what is to be measured what is to be monitored so all those things actually come in there right so sarah jo is going to be our go forward story interesting choice of name there if anybody's interested i can tell you some more details about it is more humorous than otherwise so um the journey that uh sarajevo is undertaking is basically till recently four data center locations uh 130 data stores across 130 stores across the u.s and all on-prem apps is what they have been doing and today they're into a place where they're moving to the azure cloud right in this box devon devops teams are already set up and they are using azure subscriptions we hear this all the time from this is reminiscent to me of so many other customer calls i'm having where id team is saying okay all my app teams are already into cloud and id is trying to play establishing control so that the right use of cloud can happen there and the main focus is security and the compliance aspect so today where they are it all starts with you know as the old adage goes you can't and steve also mentioned that you can't manage what you don't measure but i'm taking a step back and saying you can't manage what you don't discover right so you have to actually discover to increase that visibility let's take a look at how this is going to happen there it starts with setting up the cloud discovery schedule right this is a screenshot from the on the top right is the screenshot of the discovery schedule in the cloud operations uh workspace ui wherein you basically specify your subscription id your credentials and management group id or whatever it might be master account id if it's aws and all that right and that in turn basically spawns off a cloud discovery schedule the cloud discovery schedule uh fires patterns and those patterns uh run through the mid or mid cluster as the case may be and then the the patterns uh basically make api request calls connecting to the clouds through the endpoint in the clouds right it just connects to uh you know management.azure.com uh the the basic endpoint where aws cloud.com you know it's not going to each and every region it's just connected to the world wide web location there querying for each and every account or subscription querying for each and every region getting all the details back and then getting all the details back and then pushing it via reconciliation process into cmdb basically it takes data in the cloud format converts it into a cmdb format i'm oversimplifying here but but yeah the intent is that this runs in a scheduled manner let's say every 24 hours or every 48 hours or so right in the interim period as we all know there's emerald resources that get created some come some go there are intermediate long-term resources also that get created in between schedules right so for that we also provide the option to do even driven discovery the even driven discovery basically starts from the cloud site in most cases aws and azure we set up the event forwarding from the aws and the azure site and for gcp we take a little bit of a different approach where we connect and but but still the data is flowing the same way so the arrow is pointed the same way but we connect and we get the data that data goes through an event filter and that even filter is used to further uh you know get the necessary events into the table as individual records and then additional processing happens so that sometimes we you know run a discovery on each of those individual resources on which certain events have occurred so that the you know the immediate updates to the services are updated into servicenow that's the way we keep up the updates there again in the interest of time i'm just keeping it high level the intent really is to now take you through the ui and show you some of how this is happening let's start with a look at the the cloud operations workspace i also use the opportunity to show you the cloud operations workspace for some for some of you who may not have yet seen it this is regarded as the ui where all of our cloud modules cloud applications uh will actually eventually come and you can find cloud discovery we made a release when we released this in february this year we added cloud discovery and then later we added the cloud resource inventory dashboard as we go further we'll add more and more apps into this where you'll see individual buttons like this you can go to a central place and you can take a look at it you know it all uh together uh if i take a look at the cloud discovery for instance uh again there's a video link at the in the same slide uh when we share it you can also see the other video which takes you into detail on the cloud operations workspace and other settings and other capabilities in that area if i go to a schedule here right real quick let's quickly show you okay i'm running an aws daily schedule and as your daily schedule i take the azure uh sarajevo is in azure so i'm going to focus for my examples on on azure here so you can find already 219 resources nearly discovered how many and what is the duration it ran for and stuff like that if i go into editing it's very much like the existing discovery ui you find the mid servers that are available you find details of the service account the management group id and details like that which data centers i'm interested in i'm interested in only the us data centers for azure at this point of time it gives me faster adding more data centers that you are not using at all it's just going to take more time to for the discovery to complete so always go for a if you're not using all regions all data centers always stick with just the ones that you're using there this is for actually uh calling uh additional ip discovery on on the actual vm virtual machines in the in the azure cloud in this case uh and then the last bit is uh what times it should run at i'm setting it up for an hour at one o'clock uh in the mornings uh us specific time that's basically how it's running and then if i click on finish and run it's just going to go ahead and complete it right if i come back to cloud discovery home here let me go into uh events here real quick so sorry about this azure alerts we're going to azure alert configuration i can real quick set up an azure alert configuration by basically showing with service account so cloud management as your subscription i have to pick a resource group into which certain rules i push actually goes and sits in those into the into that assigned to that resource group so i basically have to take away all my terminated you know once here let me pick maybe the cpg dnd which is not terminated which is available in active and then i have to add the username and the and the password here for the user to through which it should connect once i set this up certain rules are pushed out to the cloud right it varies between the various clouds on the setup here again there's videos about it which you should actually take a look at but once you do all that all the events flow into the table called sncmp cloud event not list yes i don't want to save it i might not have anything at this point of time but but basically once you're even start coming in you're you're in a good space you can basically let me just pull this away yeah you you'll start to see many more events uh actually coming in here i can real quick bring up a separate instance where there are more events that are of interest to you that basically gets processed and when that gets processed basically you will be able to see how the cmdb gets immediately updated let's say you turn off a vm right so there's a bunch of your events that are coming in and you can actually find right uh there is actually a separate discovery that runs on several of these where it is needed right and some are in processing state some are in process state so a bunch of events actually coming in there okay anyway but coming back to the point let's also take a quick look at another slice and dice view of the your cloud resources if i go to cloud operations workspace the other module here is the cloud resource inventory dashboard this is a new dashboard that we have introduced wherein you can basically go through your entire infrastructure quickly and be able to identify what's in each region what's in each uh you know class type or service account and what's in each platform here so for instance it's like uh if i choose aws here i'll see just my aws resources and i can go to specific region here right so east us yeah so i should choose azure sorry east us and then i just see the numbers for east us here now i can also break it down by just the accounts for which i'm i'm interested right it'll further break it down and then i can just look for maybe the vms here right this is again first version that we've actually built as we go through this we want to make this a lot more simpler and easier to deal with but clicking on any of these things for instance will take me to that actual object resource details for this we also introduce new tables so you find a whole new table structure with the resource in this case the ci the service account and the data center or the region actually connected there so if you haven't tried out this cloud resource inventory dashboard along with the cloud operations workspace please do try it out clicking on this resource will take me to the actual ci's details record page here and i can see some more details here that's basically the idea with the cloud cloud resource inventory dashboard here a quick way to look at not just your inventory data right if you get events you'll also see the events here but you can also look at the cloud discovery errors and other details actually come in there right if so if you're actually seeing some numbers drop down and all that you want a real quick look into it another way to check how your discovery is performing is by looking at these numbers of course there's a new instance uh this is supposed to show me a one year's data that's why the graphics looks looks like this but uh since the new instance i've just started to see some numbers here all you want to look at is this number is more or less consistently the same or if it drops down or if it goes up real big then you want to find out okay what's what's going on what's different what's happening there and stuff like that right so that's the uh you know the cloud operations workspace with the various components we have other details like the cloud provider selection again please do take a look at the youtube video which you'll share shortly okay so now where are we sadajo goes ahead they set up they set up the cloud discovery schedules if they have you know more than one subscription for azure they can set up an azure management group and in that management group they assign multiple of the azure subscriptions and they have only one schedule that runs at the management group level it will discover for all of the uh subscriptions right and same story with uh aws master account or a cross assume accessor account right you can basically start with one schedule adding a master account or accessor account and it will discover for all the member accounts or the related accounts right gcp similar case you can run it at scale by actually connecting to the organization for the gcp cloud or you can also connect into the folder and beneath the folder whatever is there you can discover all of those projects right so that's the idea there so you you basically have detailed in-depth in-depth discovery of all of the resources and additionally you can also get scale across multiple accounts let's kind of take a look now at we have these resources right the first step that comes to mind is um what is the purpose of several of these resources for which we are paying some money are there some some more details about uh the resources and uh who's the owner or who's the cost location what is the cost location and stuff like that right several questions i've obviously come to everybody's mind here before i go into any further we'd like to run a poll here does your organization have standards for tagging resources right your choices are yes we have well-defined standards for tagging our resources we don't have standards for tagging although some of our resources get tagged we don't have standards for tagging and tags are not used at all and we are starting on defining standards for tagging right so take a look at the choices pick where you fit best right you get it going for another uh 10 seconds or so right does your organization have standards for tagging resources that's a question so okay i think we can close thank you so much it looks like there's a sort of a mix here the lowest is no we don't have standards for tagging which is good news so there is some standard somewhere that is actually good but there's a sort of an even split between we have well-defined standards for tagging and no we don't have standards for tagging but some of our resources are are tagged first of all for the folks who are saying well-defined standards for tagging that's great news 30 of you are saying that um but but yeah it does mean that the remaining 70 percent you know it's somewhere in the process we're starting to define is what some people are saying uh as we go through the course uh as we go through the webinar today uh i hope to also be sharing with you some more details about this in fact it will come up very quickly now thank you so much let me move on to the the next part of the journey that sadajo is undertaking uh they come to the place where they have visibility and now they want to get their tags right very very you know uh close to or talking about our current situation here with the 24 percent who are saying we're starting to set up the tax they want to establish tagging policies for cost for project purpose security patching compliance etc tags are metadata they can just be anywhere they're just key value pairs you know when you think about it that way they are very trivial key value pairs but really they add a lot of value into into the picture there standardization drives outcome right you have to actually start with thinking and this is a conversation as an ide person you need to have with your actual end clients and say hey as well as your you know your folks in your organization to say what tags are interesting to you right what tags are important to you some people might come back and say yeah i want to actually ensure that application id and all those details are actually given right i want to find the connection between the cis and the sorry the resources in the cloud and the services that they actually uh you know impact in some way some people might come back and say interesting conversation with a customer uh power uh distribution customer uh in the in australia they said like um i have a bunch of servers for which environment has been not set up right i want to find out uh you know what is the environment and i want to track it to death to say if the environment is not set up those vms will be sort of uh you know killed after a particular point of time and and there are some synonyms for each of these things some people might call it environment some people might call it purpose and stuff like that right and there's cost center cost location without these details you are not able to break down your cloud cost you might get a hefty bill at the end of the month but where does that money go you just can't keep paying amazon and azure every month uh i don't know 50k or so and not actually find out where that cost is actually coming from so without the cost center cost location which is sacrosanct for this you are not able to do the showback uh data classification is important owned by supported by again important from a service management standpoint is shared to know whether a service or a resource is actually being used across multiple entities here these are the questions that typically come up before implementing tags right find out and finalize the key tags for your organization i know i've worked with customers who have said 13 tags are needed for each and every cloud resource that i that my company employees actually create um servicenow we have a concept of eight different tag keys that we are interested in right and there are other companies with 13 14 whatever standards that they have it's not though a one department or a one team approach something to keep in mind you have to ensure that you're working closely with the ccoe for actually building this the ccoe you know as steve said just to harp back on that right it's a multi-disciplinary team they look at various angles you'll have folks from finance you'll have folks from architecture folks from apps and uh folks from uh the cloud side as well as from the engineering side they're all coming in together and from it of course and it's it's a collusion of talent that comes into one place that actually has to drive the story because tags become very crucial in various places and once you have that finalized set up that tags policies in the tag governance app right you can set up the policies you can really quick identify failures we'll see a demo of the shortly you can that way you also kind of see that when you know you have the option when you're seeing a tag violation like some tag is missing you can also create a task so that change actually goes into cmdb right and the violations are visible to the leadership team then actually running it inside a report inside a compliance report inside your azure console you can actually kind of do it in in servicenow itself right and then you can also because of the tasks you're creating you can also work with the owners to fix the tags and to remediate it right so these are all the advantages of doing it via a centralized tool like servicenow with the cmdb as the as the subterfuge right then then doing it through individual cloud consoles if you're multi cloud even better you can actually centralize all of the rules into one place inside of servicenow in many cases we also find that there are cloud teams who are actually setting up tagging policies on the cloud but they may be setting up tagging policies for a wholly different reason servicenow needs might be very different because you are interested in csdm and service mapping and you know there are other centrality needs that you want like patching and stuff like that patching happens on the cloud also so you want to set up the right uh tags for that but the cloud team may not be looking at those things they may be setting totally different tags so the collision of things is also good there right and as i mentioned before change and impact analysis can best be done from servicenow so interesting to always get that story in here so we passed all this feedback to sadajo sarajou is basically looking at cost location tags data sensitivity tags support id tags app id all of these things are important for them right ask them start with the basic set so the cost center the owner and the app name tags right in fact just the owner on the app name tags starting with at this point of time right and the tag values can be set uh programmatically that's something to keep in mind i'll talk a little more about it in in when we come back from the demo but the important thing is when you're when you're running these policies you can also remediate uh the tags which are missing or tags which are wrong and stuff like that and when you're remediating what tag value to set becomes an actual question there right so that's i'll show you an example for that i don't intend to do a demo for that i'll show you more of screenshots but first i want to kind of show you the demo for this right again sarajevo firmly believes as they're going into servicenow like as they're starting in the cloud journey they want a central tool to be applying the rules and the governance through the uh through servicenow itself right there's more close tracking there's more oversight that happens in in this context that's basically the idea there can i just move over to uh the tag policy that has been created here as i mentioned before sirajo is interested in a few tags as the first step first phase right basically owner and app name are the two that they're interested in why i'll explain to you in a minute so owner again is for knowing who's the owner for the app and the app name is basically for their service mapping use case and that's kind of where we are leading into they have taken the azure subscription in this case you can also take an aws subscription or you know you know any any other subscription for that matter i also set it up for a specific data center east u.s again i'll tell you the reason for that if i go into the azure console here right basically i'm in the location east us and i'm basically looking at a bunch of you know resources here all starting with the name github these all are part of my sccs application my source code control system application that i'm running in the in the cloud right and i want to kind of tag all of these and bring it back that's basically the idea there okay so the first step i start with this i'm going to say uh i'm setting you know what is the scope of the policy the policies within a subscription within a day within a particular region in east u.s which is you know kind of kind of what what what i showed in the azure portal window there class can be anything i don't i can be specific or i can be more open there but for me importantly it's actually just any names that start with github and this is standard filter uh standard uh condition uh expression builder rule builder uh in service now so no uh you know worries there so with such a setup right i can basically now say and and i've also set it up to active when i set it to active i can basically set a schedule either i run a daily weekly monthly or whatever or on demand in my case i typically go for on demand when i find a failure i also want to assign a task i want to set up a group and a user and all that stuff i won't do it here but basically uh i'll just go ahead and i've saved this policy and just go ahead and run the audit so when i uh run the audit and it starts right real quick i i i see that it is completed because i'm just running it on a specific set of resources it tells me real quick you know depending on the number of resources that are in scope it can take a lot more time but uh that's where you probably run it scheduled and all that it tells me really quick that which are the tags that i'm missing if i'm if i want more tags to be checked i can add more tag keys into this right i can basically say check all of these things right so if i'm missing a value 2 it will basically tell me that in this case i'm just missing several tag keys for several of these and if you look at my cmdb key value table where all the tags are stored it kind of says the same thing only this vm has owner key and the values set for that the remaining with the starting with the name github in the filter right and don't have any of the tags there right so as you can see here the vm has the app name is missing the app name attack the others are missing both the things there okay so now we established real quick by setting up a simple rule by going and connecting into into cmdb based on the discovered information right that certain tags are missing let me go into uh the next step which is basically how do i go about and remediate it right i want to take a look at my remediation rule here again for interest of interest of time i set it up already but in reality this way the way it is set up is you basically give a name for the remediation task and you choose the specific tagging policy in this case sccs app check that i have already already created and assigned here and then it will automatically tell me what tag key what policy type it is tag governance supports three policy types out of the box and you can create custom policy types and i can set it to auto remediate i can also set it update tags in the cloud i'll come back to that in a minute when i choose this particular policy it will help me to generate the key values also right i can basically say my by clicking on this ui action here i can basically add this owner and app name and for owner and app name i can basically now also set what is the value to be set for that now this is where it gets interesting because i can also choose a script approach or i can choose a value as a static value in this case for all of these i'm setting the owner as cloud team right so i've set a value here the script is not being used so where the value is there and the script is or you know something like this only the value is taken into account so when you remediate it for these resources it'll go ahead and it'll you know basically fix the the tag values so for the app name again i've i've set the app name for just a second uh just loading there i've set the app name as sccs here so basically that's what you're seeing here so when i click on tag remediation preview remediation right these are all from my previous run don't mind that you can actually find all my failures that came up in the policy run earlier in the tagging policy they all come up here and the last bit is again from my previous remediation run testing before the before i started here so now it starts uh underlying it calls a flow designer flow which goes and fixes those while it is running let me also quickly talk to you about update tags in the cloud the update tags in the cloud is basically a feature by which you can by checking this box you can update these fixes into the cloud if you prefer that way go ahead and click on that and save the remediation and run the remediation it will go ahead and update it in the in the cloud this is part of our item governance offering it's not part of the item visibility capability well the rest of the app is available with item visibility capability this part we'll talk more in detail about it in the item governance part of the demo auto remediate is basically as soon as a issue is found automatically around the remediation as simple as the name suggest it shouldn't have taken this long i was speaking for a longer time but as you can see now my mass remediation is complete here and sure enough when i come back to the key values you find all of my tags have been updated here it is not updated in the cloud it is just updated in cmdb here which is good enough why because i'll talk about in the next step here right so very simply you have taken tag governance policy been able to use uh you know a quick check to see whether certain tags and values are actually been set up and you also run a quick remediation to actually fix the tags using some static values but like i said sometimes if you want to pick cost center for something you want to look up against a table you want to query against certain matching things you want to look at the ci's properties you want to get some details about that and then look up against a table and then come back there could be other information that you want to look up that has to be done through a script right so for that i just take an example of a cloud database here right the cloud database record page is it has a particular name an interesting name at that i'll explain what is the significance of all of these uh it is uh you know having the version and all that it also has the key values as the related uh table there right and you can find that there's an app name tag there but in reality environment region these are all missing there or it could also be an incorrect value in this case it has app name hrd1012 but the ci name is something different zero and there's a significance there the good thing is the details of the cloud db is present in the name itself i just took the ci name as an example here but there could be other ci properties that you want to look at now you can use the scripting approach to actually do a check you can also do the scripting approach to actually do a remediation in the key value policy of tag governance you can basically you know check against the ci's properties in this case the name and i'm basically doing a regex on the name right ci dot name i'm doing a reg x on that and i'm actually taking the first part of the name and i'm validating if that is the value that should match with the actual thing you remember it was hrd one zero one two and this so will obviously be a failure in this case and will point up that failure saying that it's not a valid thing right the next part is like okay you found the issue by doing a scripting and all that you found all your violations much similar to the policy that i showed earlier in the demo here you can actually run another reg x in that part of the remediation based on the ci name again so which you can go ahead and update the the value there right that's that's that's the simple approach to it it need not like i said be a naming convention it could be so many other properties you can look up against a different table because you can you can basically run a whole uh you know glide script here right so you can you can pretty much do anything you want in the in the power of the the scripting capabilities there right so that's basically uh how the scripting is actually used again at the end of the presentation there's some resources that you can take a look at one of them is also the tag governance free on-demand training please do take a look at the training is less than an hour you can easily go through all of the steps there and got examples there so try it out okay which brings me to the sort of the next step here right uh you've gone through the setup of the cloud discovery you've done the cloud discovery bought the resources into the cmdb along with their tags we validated the tags we checked whether the tags are fine we've also remediated the tags where the fixes are needed there again i showed only one or two rules but you can set up as many rules as you want and typically there are more needed right and the last bit is service mapping you want to now associate the cloud resources to the actual uh services inside of the definition uh the business services app services in in servicenow right that's exactly what what they're going towards right they want to know okay let's get the full hog done here right i want to map the ci to services i want to identify impact lines for change i want to identify the failures and which which will impact and uh how to associate it to that right this is the part where uh you know they have to go through the motions of creating uh using the tag based service mapping capabilities i mean we have like several ways of doing your service mapping uh ranging from uh you know pattern-based service mapping to manual service mapping to ml based service mapping to this of all the ones i would say this is the easy easiest and simplest if you're looking at a wide scale obviously the if it's a very small set of things manual is probably easiest right i shouldn't be saying this but yeah when it comes to automated approaches tag is a very very simplistic approach right basically go through the motions of setting up this uh steps here basically it works on the same key value table in cmdb cmdb underscore key underscore value right and you can basically use it to pretty much map all your resources in in the cmdb into that the steps are first you create a ci tag category then you create a tag base service family and then you run through and find the matches for the service family based on the tag categories right and then you can go ahead and generate a service map if you want the service map as multi-layered you set up traversal rules and then last bit is operationalize the creation of the service map there something that every service owner should know and i should should try and uh as mentioned here low effort right and low skill requirement because it doesn't take any coding or anything but the accuracy level is very high especially if you're bringing tax governance policies and remediation into the picture accuracy becomes even more higher okay so let me go into this now that we have this rich set of tags here let's start to see how uh we can actually uh you know go about setting up a service map for the sccs service sac is a source code control system just a name i coined up here so if i go to service mapping the first and foremost step if you remember the step-wise thing ci categories ci tag categories basically is is actually a little beyond just a single tag value sometimes you want to have a category because you are using those synonyms that i was talking about some teams might be using environment some teams might be using env some people might be using envt some people might be using purpose as different tag keys but they all have the same meaning so synonyms in that respect in this case i might be having app name i might also be having app id i might be having so many other possibilities actually coming in there right so because of that i am i'm basically saying for app mapping for the ci tag category i'm going to add c attack as app name i can add obviously many more things here i can also say app id and then app id without the space so many possibilities are there i can add so many of these right once i do that it now i i go and uh this is like the basic first step i i go into the you know tag based service family yeah never mind app name is what i want here in the service family basically i can take a look at this one already i have to give the service family a name which is all my apps so i call it apps very clever and i also check this box to say regularly update all your service candidates and talk about service candidates in a minute and here's where i add that tag category where i talk about you know one single tag in this case app name but it could be app name or app id or whatever it is and for that app mapping tag category i set what are my tag values that i'm interested in sccs hrms so many other apps can come in there now this is basically looking at all of the cis for which i have an app name tag so if i see show matching here for all the ci for which i have an app name tag and the value is sccs simple you saw how these apps are interlinked because they are all part of the same stack which is deployed on the cloud they're all enabling my particular service here right so let me come back to this i can now not have set up this i'm going to say view service candidates what should normally happen is the first time you add it it'll still be searching and you'll find a sort of a banner here that indicates that you're still searching wait a while you can wait a while and then open it again in my case i've already done the necessary stuff and so i'm going to say it is mapped for app mapping the sccs service name which is my tag value and uh now it goes ahead and creates a mapped service very simple it just took all the resources that are matching with app name and the value sccs right and when i come in here it says you know it's been done for good measure i also do recalculate service and once i recalculate service i can go ahead and basically view the the the map here we come back when i view the map here let's see if it has generated it'll show the full map if it doesn't it'll basically show uh only a part of the map but yeah there you go this is not a map you know as you can see it's just been added here uh this is not a map that was present only after that did the remediation and then i set up the map mapping real quick it just created that think about how that how much more difficult this could have been in a in a different context right so bottom line really quick you can actually build uh you know your tagging rules set your tagging right get your tag values right and in fact actually go the next hog next step and actually build the uh you know the the map also the map is not perfect primarily because we haven't set up traversal rules which are like i'll show you in a minute basically uh my server data and my uh vm should be on top here and the security group and vnet and all that should kind of come at the bottom here right that's important to keep in mind from an impact perspective but uh basically that can be set up using service traversal rules we ship a bunch out of the box but you can and and they have a certain order that has been set up so the order indicates the levels in your in your map here again youtube videos about this exist and documentation is available on that so please do play around with that and i can quickly build it up there okay so then the next step is once you have this service map all you know shiny and nice and squeaky clean go ahead and operationalize your service map you're set right the whole automation process has been really quick here set up the policies set up the remediation fix your tags and then go in and create your service maps that's basically it how do we go about all of these things download your store apps from here store.servicenow.com search for cloud operations workspace search for tag governance and uh of course uh there's other uh the plugin for service mapping is needed we also introduced uh the service mapping plus store app which is available uh for uh your uh you know pattern based service mapping it's not it's not for tag based service mapping it's only for this the other service mapping approach i spoke uh when i spoke earlier i mentioned about resources you have videos tag evidence demos available here workspace demos here the tax attack based service mapping video is also here and the tag governance training free on demand something i would really recommend for everybody to go through is also here right so where are we now uh kind of you know covered the visibility kind of covered the tagging and went through the service mapping again it was a visual stop tour the intent was to kind of give you a perspective on that also show you the video capabilities here and we haven't talked about custom policy types in tagging and all that but again happy to uh anybody reaches out to you can have some more discussion about that but there's more obviously there'll be several more steps that sadajo has to take wait for the next webinar for that with that said i'm stopping the sharing and i want to open up for questions and passing the handle back to steve here yeah thank you rom so we do have several questions uh that i've marked for answering live so i'll go ahead and ask you the first question is does the operation does this cloud operations workspace leverage data federated into the cmdb right from mainly the service graph connector you know approach or maybe from the out-of-box aws app we worked right on top of the cmdb tables and we additionally create special tables using the cmdb data that is available these are the special tables one of which i showed there where you have the resource and the you know the subscription and the region and all that so whether using service graph data or using discovery data it should work right because they all follow the same model there so the federator approach should also work as long as you're following the same model yeah thank you ron um charlie asks how do you deal with case sensitivity so they're going through you know they're going backwards to catch old instances of azure cloud and tagging is not clear to find and catch and remediate can you talk okay so as your tag keys are case sensitive our case is insensitive well the values are case sensitive right so uh we also kind of follow pretty much the same sort of approach there but if you really want to build in a quick check on case sensitivity again we can talk offline about that uh there is a way to create a custom policy there's a whole set of steps that are required for that which we are also documenting i won't plan to publish as a blog so you can actually build in a lot more capabilities into that that area so case sensitivity again out of the box supported but more sensitivity in that area can be built in using a custom policy type great thanks rahm um um so hardik asks uh is is the gcp azure event discovery also extended to cover paths and container types of resources in in addition to is not just white listing um so is it about even discovery or the schedule discovery yeah so in the event-driven discovery um we may not have what are called as the discrete event patterns uh for all of the past entities i need to check back on that but um it's a matter of time we just again gcp is a growing area right we have customers who are picking that up and moving on in fact recently we had a bunch of patterns for all the past but not for the event-driven aspects and that will kind of come in the natural course if you're if you're particularly affected by that please do log an idea in the ids portal which uh steve will point a link to later and uh we'd be happy to take it up here and then i guess a similar question around governance for the same types of resources um what is our plans for that uh so first step is you need to have the patterns to actually pick up the tags uh in this case so if the patterns are picking up the tags and it's brought into cmdb the rest of the rules will actually come into place there i would say if again you're thinking you're missing certain time it's a very simple check if you go to the patterns record you can find if there's an extension in the pattern page itself for the tags right if it is not there go ahead and you know file an idea again we can also provide you guidance about how to create that extension pattern for getting the additional tags uh details so both possibilities are there yep thanks ram and i'll share that slide in just a moment um there's three questions around traversal rules uh one being uh a question around limitations in older versions is there something updated in the newer versions i assume he's referring to or you know here she's referring to the instance versions i'm not sure what would be the uh yeah this is something and an anonymous attendee so if you can maybe clarify your question uh before we leave here in the next five minutes so we could help you answer that and then one was around documentation so our documentation on traversal rules you can find on our docs site just go to docs servicenow.com search for traversal rules and you should find it and uh want can you provide the most use traversal rules for azure i'm not sure if they're specific to clouds right aren't they just kind of looking at tables and seem to be um yeah it's a good question some of our traversal rules the ones that are shipped out of the box are pretty generic in that sense right um i would start by looking at at least for the vm and for the vms um you know components and things like that as well as for some pass entities right you should have those uh most used uh traversal rules uh that are uh available there again i will check and we can provide some details about it in a blog so that it's taken care of right i'll work with the service mapping team in this respect and come up with something that's helpful to you all awesome all right let me share my screen there's a mention about bottom two links are identical is that uh that must be in the resources we'll take a look at that um in the next minute or so before we close out if you stick around on the zoom we can and give you the correct link but we'll we'll put the correct links on the idea i'm sorry on the community portal for this webinar so that you have them um so uh as ron mentioned we love your ideas uh on the community.servicenow.com there is an idea portal um just click the idea portal and you can search for existing ideas to upvote them as soon as an idea gets 10 votes by 10 unique customers our product management team does look at those uh to possibly add those to the roadmap and if you don't find anything that you're looking for you can submit a new idea and you can get your friends and other customers to upvote it right so please use the idea portal so our call to action here today is to you know be a champion right champion the creation of a ccoe within your organization whether you're just getting started or maybe you want to help them mature right showcase some of the things that we talked about here today and we'll talk about actually next month in september uh so you know we encourage you to begin using some of these products in subfraud um and you know start to look at uh cloud discovery cloud operations workspace tag governance and as well as tag-based service mapping and then showcase the value of what you've done to your ccoe stakeholders to help them get excited about this and then of course we're here for you right so reach out to your servicenow account teams to engage us or you can um add comments on the community page where you're registered for this webinar and then of course once you have success please share it with us we'd love to know how you know how you have achieved your success uh so we as we mentioned earlier uh we have part two of the ccoe series coming up in september on september 20th um we'll talk about how you can plan your cloud migration and manage your cloud security posture um so please join us for that and the the registration page should be there shortly if it's not there already and with that said we we want to thank you all so thanks rahm for your you know for your presentation today and also thanks to everyone who attended thanks for your interaction and please join us at further events
https://www.youtube.com/watch?v=8FrOb0JWhKw