logo

NJP

How to: Get Started with ITOM Discovery

Import · Jan 31, 2023 · video

thank you everyone for joining today's recording of our Discovery how-to Workshop my name is Kyle Stefan and I'm a solution consultant here at servicenow and today we're going to cover item discovery and ultimately how you can get going successfully with the discovery deployment what we're going to accomplish today ultimately is covering how we're going to discuss and understand the business case for Discovery we're going to show you how to configure and gain momentum with Discovery as well as we're going to help you feel enabled to start leveraging Discovery and facilitate a healthy cmdb quick agenda here we'll cover cmdb healthy outcomes ultimately we'll cover discovery's architecture the discovery deployment with both midservice and credentials when you're running Discovery we'll cover the best way to get that set up with our guided setup as well as some additional resources at the end for you to leverage As you move forward with your journey with servicenow's discovery first let's discuss the importance of business outcomes and answer the question of why should we Implement and run Discovery in the first place and essentially what the business value of Discovery is and it starts with a healthy cmdb and at servicenow we often refer to your cmdb as your digital foundation and that's so true and it can be seen in the trickle of a healthy cmdb improving some of our critical itsm functions and to get a healthy cmdb you have to understand and implement the notes on the right here from having good data management to practicing good integration practices as well as service level reporting and understanding that the cmdb is not a project to be then be able to achieve something such as 38 faster incident resolution 82 percent fewer failed changes as well as 604 percent more incidents resolved from problem management and those are just some average metrics that we see our customers achieving when they Implement both I.T service management as well as it operations management and discovery and I mentioned you want to avoid thinking of the cmdb as a project then ultimately that's what we're spelling out here on this slide it's not a project or or go live date that it'll be good with Discovery will be set up it'll be good you don't need to worry about it uh it's ultimately an automated process and as that process goes on step one is you have that chaos you have clutter data you want to consolidate it you want to make sure you can pull it into the cmdb in automated fashion you take inventory of that with discovery you map it out to specific assets and then you start to bring all that data into the cmdb and have that holistic picture but again that's not complete you don't end at the cmdb it's important to note that you want to cycle through this process and it'll never be done um the you know the point of this picture is to make sure step three and four never occurs no magic happens where inventory assets become a cmdb too often there's a misconception that the implementer will magically take your assets deliver a cmdb at some point the relationships need to be discussed and this is missing from almost all engagements where we get called in to fix the foundation and so key Point here the difference is in going from glorified inventory Excel spreadsheet to a cmdb is that the relationships are being populated and servicenow's discovery also can populate relationships not just the data attributes and this is a key value item of Discovery versus different third-party tools and so another piece of this is why do cmdbs fail and ultimately it's spelled out for us here with some of the more common use cases from unreliable data sources and a lack of automation so bad data in bad data out if you're pulling in you know manual data from Bad data sources you're going to have a not healthy cmdb and if the cmdb is not driven by specific goals of the organization you know we're just going to be pulling in data for no reason you really want to make sure you set specific goals within your organization to know which outcomes need to be achieved as well as the cmdb data not being tied to other processes like Asset Management as well as change and release and problem management because if you're just pulling in data you're going to have visibility but where you're really going to start to achieve value and you know start to see success with having a healthy seem to be is when you start to leverage things like it Asset Management with that healthy data as well as diving into change and problem and release management with all that healthy data within the cmdb and having that visibility and it's important to understand as well that you can only automate what you can see and so if you don't know where data infrastructure lies within your organization you're not going to be able to start to automate processes and save time and money and that's what we see here is ultimately gaining that visibility of your it footprint automatically populating the data in the cmdb with service analysis Discovery and really emphasizing the fact that you can only start to act on what you know exists so the first step truly in getting an inventory of what you have is making sure that it's organized categorized effectively and that you're strategizing on the data points that you need to be pulling in and then we can start to layer on top of that data with capabilities like service mapping and event management to really further that Automation and drive those organization-wide outcomes that stem from having a strong digital Foundation and really re-emphasizing here that seem to be is the core of all things within servicenow it's that single source of Truth as we see here with the cmdb being that digital foundations from All Things physical infrastructure to running processes we see that it operations management and Discovery is going to allow you to pull that data into the cmdb start to Priority prioritize response based on business impact and then once you have that healthy data you're going to be able to leverage it from within things like it Asset Management having the added visibility into your hardware and software real estate as well as it service management getting that increased efficiency reducing risk when planning changes and many other portions of servicenow within here to touch on but ultimately it's really important to understand that the most successful cmdbs are business aware which allow you to understand the impact of a component to the business which Business Services does this does this server support for example and the operational decisions to be made in context to that business service and to ensure your cmdb has business context and remains healthy and trustworthy we recommend leveraging servicenow's Discovery populating it in that automated fashion as well as itom visibility with Discovery provides the fastest time to value for gaining visibility of your entire operations estate and drives differentiated outcomes with a vast set of solutions and ultimately that is value add to your it operations and executive leadership and now a question I get every day you know we touched on it there with the automating what you can't see is how do we know what we don't know and what if we start finding servers that we thought were long gone or we never knew existed at all so to address that let's start to take a look at how you can view your estate and how as you start pulling in all these configuration items into your cmdb it really all starts by defining here what a configuration item is and what an asset is and how those are defined within servicenow a configuration item is an entity or thing that you want to track and is required for the delivery of a service and so these are going to be things like Hardware software Services applications database simply an application infrastructure a service component that you're trying to manage but there's one rule some things either a configuration item or it's not so there's no in between if something's going to be defined as a configuration item once it must always be treated as a configuration item from that point forward and what's the difference now so we have assets as well assets typically are something that has intrinsic value to a person or an Enterprise so that could be the financial value and it's in addition we're going to have a life cycle as well associated with it and so an asset is often a configuration item but as we see here configuration items are not necessarily assets so the best way to think of that is for every 100 assets or so you could easily have upwards of a thousand configuration items and beyond that over 2000 CI relationships so it's really not the assets that you're managing when it comes to cmdb but it's the configuration items and the relationships and we'll take a look here as we jump into our instance what that looks like within servicenow so we could see here within our servicenow instance uh we're in our assets table so this is a list of all the assets within my specific demo instance here and we have about 4 000 assets here if we go ahead and group by our model category we'll now see that we have about 33 groups of assets within here again you can click into these These are going to be all our assets so Business Services computers with again a financial value and a life cycle Associated to them as well as anything from you know Hardware IPS which is Linux servers printers again these have that intrinsic value and so these are all defined as assets but these more likely than not our configuration items as well so these computers we'll all be configuration items within servicenow cmdb as well and as we jump into configuration items so where we saw about 300 assets within our asset table now we have about 30 000 configuration items within the cmdb and we can go ahead and group this by class and we can see from that small amount of model categories that were grouped we have now 220 specific groups of classes for these configuration items and again we could drill into these see specific applications there's going to be a lot more classes here so maybe Hardware type we're able to see we have a lot more Hardware essentially really helping you visualize that idea that we have many more configuration items than assets within the cmdb here and how are we going to manage that we have RCI class manager that helps you get a holistic view into the entire cmdb and as this loads up here it's important to preface that as we walk through this configuration item class manager here this is where a lot of Discovery happens as well from the deduplication reconciliation and we'll touch on these here within the CI class manager and I will double back on them towards the end of the slides as well but within the CI class manager we can pull up our Windows server and we see this breakdown of all the classes so 30 000 configuration items the subclass is associated all the way down to specific Windows servers and within here it's important to note as we're discovering these windows servers pulling this data into the cmdb we're looking for specific attributes these are out of the box for this Windows Server class you can always add additional attributes remove any attributes you can in addition set attributes to be mandatory or required to help ensure that you're pulling in all the data you need for each and every one of your configuration items and as these are being pulled in really want to highlight where the magic happens here with our identification rules and Reconciliation rules so our identification rules are going to allow you to set a unique identifier to specific configuration item being discovered to ensure that you're not pulling in any duplicate data and to ensure that if Hardware is being changed swapped out amongst let's say a server let's say the hard drive gets swapped out for example you can ensure that that information will be updated appropriately and you won't just be creating duplicate records so here we see that the unique identifier is going to be a serial number and the serial number table or serial number type on the serial number table and that's going to be our first unique identifier that will check as we discover this configuration item we check if this exists if it doesn't we have sequential unique identifiers here to ensure that we're covering every check before we can determined that this configuration item exists or does not within the cmdb so serial number on the hardware table is going to be our next check and we'll follow in sequence if it matches any of these unique identifiers we're going to go ahead and just update the attribute that have changed and if nothing matches here we're going to go ahead and create a new record within the cmdb and as we're pulling data in also important to note within our reconciliation rules that you can be pulling in data from multiple different Discovery sources and so here we can see that we have an integration our one of our service graph connectors with SCCM set up and that is the most trusted Discovery source for the assign to and the serial number attribute for all of our Windows servers and if nothing is found there then we're going to default to What servicenow's discovery picks up for those specific attributes really easy to go in here add additional reconciliation rules to ensure that you're pulling in data as accurately as possible from your most trusted Discovery sources you can set priority to it choose the specific attributes that you want to pull in and then you can set additional filter conditions as well and just to cover our bases with our data refresh rules you're able to say that if SCCM doesn't find anything for five days we're going to go ahead and auto default to servicenows Discovery as the main source of Discovery for those specific attributes and now we'll jump into one of our Windows servers here just to take a look at how that configuration item record looks within the cmdb and as we're pulling this up here we're going to be able to see the metrics that are pulled in for the specific Windows Server so for example the serial number manufacturer we can see it's VMware we can see the ram CPU speed CPU count disk space all this information is being pulled in Via discovery and in addition here on the bottom I really want to highlight some of the key metrics that are being pulled in as a piece of discovery starting with software installed so we can see for this Windows Server we see all the software installed the version that each of those softwares are running giving you that added visibility into your software real estate so again as you start to leverage it Asset Management you know exactly which software is installed on which devices you know the running processes on these devices for it troubleshooting as well as being able to track TCP connections to better understand the dependencies and relationships that are being brought in for these configuration items and to in and to assist in the process of service mapping as well and then track configuration files highlighting it here I will see a better visual within the one of the last few slides but we're discovering configuration files as unauthorized changes happen or changes are made Within These configuration files they're all noted down and tracked to these configuration files and we'll get a better visual of that in a little bit but really want to highlight those key metrics that are being discovered and in addition again that key differentiator between Discovery and other tools that organizations may use for pulling data into a cmdb discovery is able to pull in these dependencies so I'll zoom in here and we're able to see that for the specific Windows server we have all the relationships Associated to this Windows Server configuration item upstream and downstream we can hover over each of them we can drill and do any of these configuration items and ultimately view the form for this configuration item so what we were just looking at we can view related tasks we can view any recent outages associated with these configuration items and we can add additional relationships as well really a lot to leverage within this dependency view here across the platform you know one of the bigger use cases is with it service management again when it comes to scheduling changes you know what's going to be affected upstream and downstream so you can more confidently schedule changes and ensure they go through without any errors and there's minimal outages the appropriate people can be notified of the change that is going to be scheduled and with probable root cause as well with problem management just having this visibility helps you understand that if something does go down you can kind of follow back upstream or Downstream What affected that and really drill into that probable root cause now as we jump back in here I want to highlight the cmdb health dashboard and this is going to give you a central place to view essentially the health of the cmdb as you start to walk through this process I highly recommend leveraging the cmdb health score card here and this is going to work off in three C's so completeness compliance and correctness and this is going to allow you to drill into working from left to right with completeness any other configuration items missing required attributes so as we saw we can set require we can set attributes to be mandatory any of those configuration items missing those required or mandatory attributes will show up here as well as any missing recommended attributes and then within compliance we have an audit report that you can run essentially run that audio report on any portion of the cmdb maybe as a whole or drill into a specific CI class and within that you can report on maybe specific thresholds being breached or attributes that are missing a lot of freedom there for your organization to set up those guide rails and pull an accurate report on the compliance of your cmdb and for correctness pretty self-explanatory here but any duplicate configuration items any orphans So within that dependency view anything without a relationship associated with it and then stale which by default is 60 days within the cmdb but any configuration items that haven't been rediscovered or updated within the last 60 days are going to show up as stale and again highly recommend leveraging the same DB view as you start to walk through that process of building out your cmdb and the last thing I wanted to touch on here as we look took a look at the multi-source aspect of servicenow and those reconciliation rules is our multi-source data report Builder we're able to go in and essentially run a report on all of the configuration items and all the differences between Discovery sources that are being pulled in for those specific configuration items so we can you know pull up Discovery sources for all the configuration items we can look at all the configuration item records and show all the differences between different Discovery sources for those configuration items so you can better understand how to make those reconciliation rules in the first place and which data sources are bringing in that most trusted data and the last thing I wanted to highlight before hopping back into the slides here is one of our newer features within Tokyo actually is our intelligent search within our cmdb workspace so our cmdb workspace gives you gives you a centralized view into all things seem to be whether it's that cmdb Health dashboard some quick links to dependency views CI class lists data managers uh again list into specific deduplication tasks duplicate configuration items stale configuration items but really want highlighting here our intelligent search which works off of a natural language query gives you the ability to go in and build out tables search through the cmdb if you're not necessarily as tech savvy maybe if you are it's still awesome to leverage here you can see any of your recent searches so service is not related to Linux servers for example you can get some sample searches to get started as we happen to just tips to improve your search results as well we can see we can look up single tables so maybe just the applications table multi-table searches so all of our Linux servers we can search all the services that run on Linux servers that'll pull up kind of two different tables there as well as some Advanced filtering tips here with keywords to Leverage and in addition relationships so we can see all services that have no relationships with Linux servers a lot of stuff to leverage here for example if we just pull up servers we'll take a look at what this looks like so we'll go ahead and search for servers we'll search we can see that once it's confirmed we're looking at just a server table rather than the virtual machine instance table we do we're looking for servers we can view our search results here and now as this loads up here within our servers table we have this entire list we can see all of our servers we can give feedback to help improve the smart search as well because the machine is always learning with that natural language query and we can drill into all of our servers here and in addition let's say you wanted to search for maybe all the servers in San Diego that would be more of that multi-table search to then give you that visibility into just the servers existing in a location of our San Diego office for example that's the power of the intelligence search to help you manage your cmdb and search through your data now hopping back in here to the slides really want to emphasize these business outcomes of discovery and really emphasizing the middle here that you want to align with your strategic I.T and organizational business objectives because you can't work in silos the cmdb really doesn't work in silos we talked about how you can go in to find custom attributes to be pulled in and you want to touch base with your security team and ultimately see what use cases they may have talk to your it service management teams make sure they're aware of what this can mean for them for change management Incident Management problem management to help you build that strong Foundation and now taking a look at the architecture behind discovery we'll see two pieces of it one the ability to connect your existing tools with our service graph connectors whether that be SCCM titanium solarwinds allowing you to not have to rip and replace any of your existing tools to populate the cmdb and have this automated fashion as well as the mid server and our servicenows Discovery both agentless and agent based to have again that single source of Truth within the cmdb and so from a discovery perspective here the on-premise side of Discovery is what we're looking at here it starts with the mid server which is a lightweight Java application deployed beyond the firewall and that mid server is connected back to servicenow through outbound only Port 443 so you don't have to open up any additional ports keeping you secure and compliant but how we're pulling that data is by sending out all these different patterns and probes out under the network and ultimately that's going to run according to a schedule and go out collect information on these laptops storage servers or applications essentially any physical or virtual device that exists within a targeted IP range and then pass that information back to servicenow and so that's going to be how you get that holistic view into your entire network and pull that data back into servicenow via that agentless approach and we also have our Cloud Discovery as well which is going to follow a same structure of having a discovery schedule set up Cloud environment's going to talk back to the mid server kick that data back to servicenows Discovery but in addition the biggest difference with Cloud Discovery is its event base so cloud provider apis are going to push back any Discovery updates back to servicenow to keep your cmdb current with any changes that are being made in your Cloud environment so you don't have to wait until your next Sunday 1am Discovery schedule for example to run to pull in those updates you can get that more real real-time data for any events or changes that are being made within that cloud environment into your servicenow instance and for cloud environments as well the mid server can be installed either in your virtual Cloud environment or on premise and what does that process look like as we're sending out these different patterns and probes it starts with what we call our scanning phase it's gonna we're gonna send out our Shazam probe that's going to scan everything on the network ultimately determine within the IP range that's targeted what's there and let's say we find a server you know we want to determine whether it's a Windows server or a Linux server so we kick off into phase two here the classification phase and we're going to be able to say okay this server is a Windows server for example and once that's classified we're going to then look into bringing that data into the cmdb we covered all our identification rules with our identification and Reconciliation engine how all that works we saw that within the instance so ultimately we're going to say does this exist and this seem to be already based off those unique identifiers if it does let's update those attributes for this Windows Server if not let's create a new record and once that identification has happened we're going to send out our expiration probe to ultimately gather all those additional attributes that we took a look at and pull all that data in so you have as a holistic view as possible into that configuration item within the cmdb and so that's our agentless approach how our agent works is it's going to be push-based Discovery and so we have the agent it can be installed on a server or end user device and the agent's going to discover information on those end user devices push that data back to the mid server and then kick that data back out to the servicenow cloud and a key point to mention here one of the bigger use cases that the agent is leveraged for is for remote employees maybe that might not always be connected to the corporate Network or VPN so those end user devices are only connected on their home network the agent can be installed in those devices and configured in a way so that it can still talk back to the mid server and kick that data back to the servicenow cloud giving you that near real-time data to all of those end user devices whether they're connected or not to your corporate Network and we'll take a look here now at how the agents look within the servicenow instance so pulling up our agent client collector dashboard here we're going to be able to get a single pane of glass view into all of our agents here whether they're online they're off what versions they have and as we jump in here to our agents we're able to see all of them that are collecting data what has been collected we'll jump into the agent that I've configured here and we're able to see here the agent we're able to see its status it's online the IP address that it's associated with whether the data on the host has been collected or not and within here as well you can grab additional information from the logs from the configuration files you can go ahead and update the agent as well and you can see the checks that are running so we have two checks running for this agent the first be an enhanced Discovery that's going to go out discover all those metrics that we took a look at within that expiration phase of discovery pull that data in as well as we wanted to pull in all the software installed for this device so we have that set up as well to ensure we're pulling in all the software installed alongside all those additional metrics we took a look at earlier and jumping back in here you can also bulk upgrade agents as well if you're to select all of them you can go ahead and take action on all the selected rows and upgrade all those agents pause all the agents you can take action in bulk one thing that I want to highlight here is jumping into the host that's running this agent we can see that we're pulling in all the same metrics that agentless discoveries pulling in we can see running processes software installed and again we're able to see these relationships and dependencies that the specific Windows server has we're able to see that it is virtualizing this virtual machine we can see the hardware associated with that virtual machine and all the additional relationships here and now hopping back in here some additional use cases that we see our agent being leveraged for is within AI operations so kind of finally later down the road within your it operations management Journey as you get into service mapping and event management the agent can also be leveraged for pulling in metrics and logs we took a look at the agentless Discovery Gap use case within Discovery being able to cover that Network app another use case as well with it service management is by having that real-time information into your end user devices if they were to go in and leverage something like a virtual agent that's set up within the service portal the virtual agent would detect that the agent is running on that device and it'll be able to run diagnostics for that end user give them suggestions on what they should close out maybe they have too many running processes maybe their CPU usage is too high maybe they haven't restarted the computer in a while that virtual agent has that information at hand to give suggestions to that end user end user for them to then go maybe restart their computer close out some programs and deflect an incident from being created all together in addition when paired with software Asset Management you have added visibility into software usage metrics for the software installed on those end user devices as well as within security operations you have real-time visibility with incident response in addition to the out of the box functionality that we've seen kind of with Discovery here there's multiple Discovery plugins that can be leveraged for elements like Enterprise storage devices what specific software Integrations for example and that process can easily be initiated and activated via the support portal and getting these Discovery plugins activated won't spend too much time here feel free to pause the video if you want to jot down any of these additional plugins but these are some of the examples of Discovery plugins that you may need to reference during your deployment if you have any further questions please feel free to reach out to your servicenow account executive or solution consultant and now let's discuss mid servers and ultimately how they're broken down their architecture and how they work and so as mentioned previously the midserver is an important component of the servicenow's discovery deployment and some key points to note here are that you can pull the binaries from our website linked here and also referenced in our documentation and you should deploy mid servers in a cluster whether that's for failover or load balancing it's important to set that Baseline of a cluster of mid servers and you're not limited to the amount of mid servers you can leverage as well and so best practice is to deploy different mid-servers for different use cases for example one for event management or in one for Discovery so that you don't overload that specific Min server and now we take a look at this slide kind of talking about the number of mid-servers required here and this slide's meant to give an overview and expectations for scope in the requirements of mid servers and some advantages of practices like hosting mid servers on segments that are firewall separated so that the communications out to those devices don't need to Traverse a firewall and these numbers ultimately are guides and figures for helping up a single mid servers and estimates really will vary but um take this slide as a recommendation on being more intentional when setting up your mid servers and this is to support with that planning so definitely leverage these rough time frames that you should expect with your Discovery schedules and in addition when deploying mid servers servicenow automatically load balances across mid-service in a cluster in addition when you have more than 500 devices A good rule of thumb is to have multiple different mid servers and to remember that you're going to have more configuration items and relationships than the number of devices in your inventory as we sell but to the difference between assets and configuration items and from a security standpoint this is ultimately why ideally you would want to have your mid server installed on a network segment and so let's go ahead and take a look at the mid server within the servicenow instance here hopping into a list of our mid servers here similar to how we saw our agents listed we have a table view of all our mid servers we can see if they're validated see what their status is we can jump into my mid server I have running in AWS here okay and as we jump in here we can see the IP address associated with everything linked to this mid server we can see where we're going to be able to set up agent client collectors uh we see where we set up our agent client collector for visibility for listening as well as for log analytics and for monitoring all the different use cases of leveraging a single agent are available within this mid server here we can also see some metrics being pulled in so being pulled in is going to be all our statistics with our eccq that is going to be sending all the different patterns and probes in and out it's going to be a full list here as well as any additional threads for this mid server and logs being pulled in you have all this visibility Consolidated into the single Field view here and in addition some capabilities so we can see that our mid server is connected to our agent client collector and we can see that we're targeting all IP ranges for this specific mid server in addition I want to touch on the idea of leveraging mid servers for multiple different applications as we touched on so here we can see how we have a mid server set up for cloud management we have one set up for Discovery event management you can Leverage specific mid servers for specific use cases and it's definitely highly recommended and then when it comes to clustering we're able to go in we can easily create a new midserver cluster here determine whether it's for load balancing failover or a distributed cluster here and then once you go ahead and create that you can add mid servers into the specific cluster so really easy to leverage the platform for managing your mid servers and ensuring that they're all up validated and that they're clustered and assigned to specific applications appropriately and now hopping back into our Cloud resources dashboard here really want to highlight the cloud Discovery piece of service now so we saw that on-premise side of Discovery how that breaks down but as we're pulling in Cloud resources as well we have a cloud resources dashboard here this is out of the box going to give you that single point of view into all of your Cloud resources whether it's AWS Azure VMware as we hop into AWS here we can see a breakdown as this loads up here all right now that we have this loaded up here we can see that for AWS we have specific ec2 instances security groups API gateways you have the ability to sort by service account as well as by region and as we drill into this dashboard not only a single pane of glass but you can drill into it we're able to see all the ec2 instances that we have pulled up here if we go ahead and pull up my AWS ec2 instance as a piece of cloud Discovery we're able to see these same metrics the memory associated the tags being pulled in for the specific virtual machine as well as the dependency view where you can drill into the specific configuration items again you can see the specific virtual machine you can see that this Windows server is what's being virtualized if we were to hop into this Windows server this is where you start to see those metrics that we took a look at earlier so this is being virtualized by that virtual machine we have all the software installed running processes the same information here and that's a look into the cloud resources that we saw as we hop back in to the instance here I really want to touch on credentials next and that's going to be the next piece of our slides here with our credentials table here this gives the full list of all the credentials set up within service now if we hop in to create a new credential we can see all the out of the box credentials that we can create anything from creating credentials for certificate management down to Windows credentials for VMware credentials and as we hop in here pretty self-explanatory to go in create a name for this credential instead of username password to it give it Priority choose which mid server it applies to and then go ahead and test the credentials to ensure they're working this is going to be the single source of Truth to allow you to create all the credentials for Discovery whether it's agent lists or cloud-based Discovery and as well as things like credentials and when it comes to credentials as well hopping back into the slides here they're really the key to making Discovery work and so some things to note here about Discovery and credentials is that they're required for agentless Discovery we'll cover some use cases where you maybe can be able to get around that but the most common credential types are Unix Linux Windows SNMP as well as those Cloud credentials we touched on some other ones to know are applicative credentials apis for containers and microservices as well as some other protocols noted there and so now as we take a look at credentials and architecture behind it how they're being processed within servicenow how they're being tied to the mid server ultimately it's important to note at no point is credential password stored on the disk unencrypted and so as the users entering those credentials they're being encrypted in transit using TLS credentials in addition can be added to the instance in a record or you can use a mid-server service account as well and this slide really highlights that process of secure credential usage via the mid server and now talking about how we can get around using credentials for Discovery we'll cover three use cases here the first being an external credential vault which out of the box were compatible with cyber Arc allowing you to have that integration to all credentials stored there connect them back to the servicenow instance but if you're leveraging a different external credential bot as well and that is something that we don't have an integration for out of the box you can always set up an integration build that out to pull those credentials into servicenow in addition you can use credentialist Discovery or nmap this is not recommended because you wouldn't be pulling in the near amount of metrics and data that we've taken a look at so far today you'd be pulling in very high level data and more likely than not is not going to be super valuable to your organization however with the agent client collector you can leverage the agent client collector which is credential lists it does not require credentials and with those agents installed on those end user devices or servers you still be able to pull in all that data back to servicenow without the need for any credentials and now some security concerns with credentials more of things to note here I'll give you a chance to pause to get all these down but we kind of talked through them already ultimately this side goes over the things that are required for each and every one of the credentials so I'll give you a chance to pause there as we move on here we'll cover our guided setup and so I touched on the guided setup earlier we'll take a look at a demo here this at a high level is our it operations management guided setup allowing you to walk through step by step the process of getting it operations management set up we'll take a look at that within our instance here popping into our guided setup where we're now able to see the process and so as we hit continue here and we have multiple different guided setups for everything within servicenow from setting up service graph connectors which I personally have done very simple process to other products within servicenow as well but within itom here you can see that the process starts with creating a mid server getting that installed validating the mid server setting up Discovery schedules choosing which data you want to collect to then later down the line getting more into event management setting up service mapping as well as health log analytics and operational intelligence and going down the line there but as you jump into these it's spelled out for you tells you exactly what you need to do once it's done you mark it as complete and go along with the process and by clicking configure it'll give you links to each and every one of these processes highly recommend leveraging the guided setup for any portion of servicenow that you're tackling it's not going to go ahead and do it all for you but it gives you that high level breakdown of what is most important when setting up these processes and as we jump back in here the next thing we'll touch on is Discovery schedules and how we can get those set up so first you can go ahead and always run a quick Discovery targeting a specific IP address you can go ahead and run Cloud Discovery as well this will walk through the cloud Discovery process here where you're going to go ahead and select a provider and a service account and then you're going to go ahead and choose which data centers you want to discover you have the option to select if you want to discover virtual machines as well and then you're going to go ahead and create that schedule choose the time and date create that schedule again this is for cloud Discovery in addition to Cloud Discovery it's also event based as I touched on but another important thing to note about Discovery schedules for both on-premise and Cloud discoveries is that aside from running them on that regular schedule they can also be run ad hoc and discoveries are usually run against a range of IP addresses and now we'll go ahead and hop in here to how that looks within the instance here Discovery schedules this will bring you into all the discovery schedules if you have them set up they'll show here they'll show when they're set to run what they're going to discover we saw you can go ahead and create a quick Discovery Target a specific IP address we walk through the cloud Discovery process if we jump in to create a new discovery schedule this is just going to be an on-premise Discovery here as it loads up and now that we're in here we're able to see that we're going to go ahead and give it a name choose a time for that schedule to run we're going to go ahead and choose what we want to discover whether that's configuration items which will go ahead and pull everything in you want to Target specific web services networks specific certificates it gives you the option to select all that here choose which mid server you're going to run this discovery on whether it's a specific mid-server a cluster and then you can choose which mid server that is and ultimately this is how you're going to kick off that Discovery schedule to then bring in all that data in in the automated fashion and we walk through that process already just recapping here we took a look at Discovery dependencies we saw multiple different dependency views we saw how Discovery will bring in these relationships as we look through different TCP traffic connections we bring in these dependencies whether it's hosted component application to host application application and I touched on the configuration files as well so really highlighting that here we're tracking the configuration files associated with each of these configuration items we're tracking whether they change or not and by tracking those changes it gives you this visibility into a single line view of everything that changes with these configuration files so again really highlighting the fact of problem management and determining that proper root cause by having the single line view maybe an unauthorized change occurred on a configuration file which led to a service going down at that specific time you can track down what changes occurred and you have this added visibility into exactly what changed on that configuration file giving you that much more granularity into probable root cause and now some additional resources here to highlight are some links here to our Discovery documentation both on premise and in the cloud some YouTube videos that we put together for cloud Discovery certificate management as well as more information documentation on our specific Discovery reports and probes and protocols and if you have any additional questions reach out to your servicenow solution consultant or partner and before wrapping up here you go ahead and pause this screen if you want any of these resources I will highlight the future so once you have Discovery set up you're pulling in data you're starting to have these configuration items assets stored in your cmdb you have this holistic View you can then start to Leverage service mapping and event management and we'll take a quick look here at what a service looks like and within event management here you have service operations workspace you have all your services mapped out you can see based off of monitoring tools whether these services are red or green but really just highlighting the service map here and now that we're in here we can see this service map so this is order status service we can see the entry point so the HTTP connection we followed the TCP connections all the way down we're able to map out these Services all the way down to Oracle database and all the configuration items in between and within this service you can see that we have Services nested within it as well ultimately giving you the organization of view into your most critical services and time configuration items to these services to give you a slice of that dependency view that targets only the configuration items making up specific services and again this is further down the line of growth within building out your cdb you definitely want to start with that foundational piece of setting up Integrations making sure your cmdb has healthy accurate data before you get into mapping out services and tying in monitoring tools to these configuration items as well within our event management we have additional how-to videos and recordings on our service mapping and our event management as well so feel free to check those out if you want a deeper dive thank you for watching this video again feel free to reach out if there's any additional questions happy to help out thank you

View original source

https://www.youtube.com/watch?v=vLBDPIW-yT0