Get started with ITOM Visibility
all right so good morning good afternoon and good evening everyone and Welcome to our webinar uh today I'm going to cover how to get started with item visibility so whether you're a new customer that has just acquired item visibility or if you're a customer that is just running some of the components but aren't sure what else you know um you have access to you'll learn all about that in this webinar this webinar is part of the live on servicenow program which is a series you know of events that you can attend to connect you with servicenow experts uh it is to help you more easily gain adoption with the with the products and and features that you have invested in today we're covering itom uh but certainly you know you can attend any of these sessions uh and you'll get to learn all about different servicenow products uh the chat will have the link in there as well or you can scan that QR code if you want to see what else we have to register for just a little bit of housekeeping so everyone's line is muted please use the Q a feature to ask your questions throughout the session we have disabled chat so please use q a so please feel free to introduce yourself as well when you ask a question so we'd love to know who you are and where you're from we have a couple of polls today so we ask that you please participate in those polls um we are recording this session and it will be shared on the servicenow community as well as on YouTube and then finally after the session ends you will be prompted to fill out a survey we we always appreciate your feedback it helps us to improve these sessions for the future so my name is Steve Emerson I am an outbound product manager here at servicenow for item visibility and itom governance I've been here for around five and a half years already but I spent the bulk of my career in Enterprise it roles so I know what it's like to be in your shoes so as an app on product manager I wear a lot of different hats but the one I love most is is kind of connecting these sessions to tell you about all the greatness that we offer and I also get to hear from you as to how you're using our products and we like and of course we always welcome your feedback to help us improve the products in the future with me today we have a team of of great folks behind the scenes who will be answering your questions as well as helping out with some of the polls that we'll be launching and things like that so thanks John thanks Ryan thanks Bill and thanks Doug so our agenda for today is pretty straightforward I'm going to cover why item visibility is important I'll give you an overview of all the features I'll go pretty in depth on all of the 10 features that we have uh we'll talk about next you know things you can do for next steps to get started as well as uh I have some slides about learning resources that you could take advantage of so why I Tom visibility so uh so visibility in and of itself is what we call the key to service operations excellence and visibility is what helps you populate that that single data store right the cmdb is your digital foundation for your for your organization but it's also the digital foundation for servicenow and a well-populated cmdb uh that is also service aware helps you drive data-driven decisions across all the outcomes you see on the screen here these um what you see here are typical functions that exist inside of an IT organization some of these are servicenow product names of course they are but when you think about the things that are happening in your org you you know you've got an I.T operations Department that where they would be able to take advantage and you know better prioritize their response to those operational issues and alerts based upon the impact that a resource has to your business so if you get an alert on a specific Ci or I mean a you know a specific computer you'll be able to understand how that computer relates back to the business think about it service management as well we'll help you better increase efficiency when you're planning a change and also to you know to reduce the risk so when you plan a change and you put a Ci or multiple CIS in that field you'll be able to automatically see how the business is impacted you'll be able to know who to notify in case there's going to be an upcoming planned service window things like that when you think about certificate management and firewall workflows these are things that every organization has but don't necessarily keep a good track of and we'll talk about how we can help you improve that when it comes to security you know same thing as it operations management we can help you better prioritize your response to security incidents and vulnerabilities based upon the impact that the affected component has to your business and then Cloud right there's just always there's this challenge or this question about whether or not Cloud resources or microservice resources belong in the seem to be today you're going to learn why it is just as important to have those resources in there as it is to your on-premise and your virtualized resources uh so I'm not going to go through everything here but as you can see this is just a subset of the things that a cmdb drives value for and of course why do cmdbs fail everyone would love to build a a fantastic cmdb that they can rely on right but oftentimes there's lots of issues that cause it to fail I'm going to focus on the ones today in this webinar the ones that I've highlighted in bold here number one being unreliable data sources or a lack of automation if you're populating your cmdb manually or if you have unreliable data sources that don't feed the seam to be correctly uh perhaps that are not going through our ire right um that is going to cause lots of issues right perhaps duplicates or stale information as soon as it's put in there if it's manual it's not driven by the goals of your organization so when you populate a cmdb any data that you put in there has to be managed but you have to ask yourself why you're putting data in the same DB every time so that is another challenge that that we see uh you know organizations trying to boil the ocean by putting everything possible in the cmdb without understanding why why or where the data is going to be used or too much or too little data right the critical few versus the trivial money don't put too much don't put everything in there just put in there what you need and vice versa don't put too little data right we'll talk about that as well and then of course inaccurate data right which is giving you the lack of trust your customers that use the cmdb that lack of trust in your configuration management process in which they stop using it so automated population of the cndb is critical to success what we found is that improper population of the cmdb it leads to that inaccurate and unreliable data right duplicates misclassified or unclassified or incomplete data which results in the folks that are using it having to make poor decisions and do things over again right there was a study conducted by The Institute of configuration management that states that when people perform work from information that's not clear concise and accurate they spend 40 percent of their time on corrective action or is essentially going back and doing things again or right so we want to avoid that as much as possible so just a quick poll here um we'd like to know where you are in your cmdb journey are you just planning are you in the initial steps are you Full Speed Ahead with your cmdb or maybe you want to know what's a cmdb and I see some answers coming in right now we'll give it um 10 more seconds five four three two and one which let's see what the results are we see that the bulk of you are Full Speed Ahead that's great to hear some of you are new are in your initial steps uh some of you are just planning what you're going to do with the cmdb and then uh at least one of you has said what's it seem to be that's interesting um we will talk about what that is in further detail today as well as helping you to understand why it's important to use our products to populate that so thank you all right thank you for that now uh let's get into the meat of this presentation today which is giving you guys an overview of the features the most important thing that you can do before you implement anything is to understand what you own and what you have and how those features can help your business achieve better value now the item visibility Suite includes at least uh you know these 10 features right here and we will be iterating this uh over time as well as as we release more and more features that help you populate the scene to even better now I'm not going to go into details here because I have detailed slides for each of these features so but as you can see it's it's tremendous value just across the board instead of just relying on the family releases to introduce new features to you we use the store so if you go to store.servicenow.com you will find the the majority of the applications I just showed you on that prior slide on the store which means that you're able to be to actually install some of these applications on current releases as well as prior releases for each application you go to here you will be able to see what what releases it supported on but just want to make sure that you are aware to go here all the time don't rely on just a family releases because you will be missing out our first feature is servicenow Discovery I would assume the majority of you here are using servicenow discovery but if you're not that's okay Discovery is the feature that enables you to scan your entire estate to get and then um you know discover your servers your network devices your storage devices your Cloud resources anything that exists in your environment and put those into the cmdb we collect data about them such as all the attributes uh you know operating system version um what's the IP address is right all all the basic things you would need in a cmdb CI but also we collect running process data TCP data in order to build out those automated relationships so that you can get those automated dependency Maps built so this is the agentless version and I'll talk about the agent based version in just a few moments let's talk about automated dependency mapping how does that work so servicenow Discovery scans your network and basically it finds devices with open ports right that are in the IP ranges that you define so we're trying to understand who is listening on what port right and then we classify reduce some further interrogation to determine what is the device type are you a Windows Server are you a Linux server Etc then we identify we collect additional information about that CI and we add that we check the cmdb for an existing CI if one exists we update it if it doesn't exist we just create a new one and then we explore it for further details to basically gather all the additional information and create the relationships so on the left you saw that the process on the right you saw all the different things that are collected at each step and in the middle you see that we have that mesh right we can understand which components are talking to each other because of that automated dependency mapping and here's what that looks like on servicenow so we do host to component which you see here the Windows server and all the components that are part of that Windows server we see application to host so we have this IIs server we have the SQL Server right and then we see application application we have this website to this IIs server our next feature of Discovery is file based discovery so those of you that have use cases for software asset management for example that need to be able to detect the in the existence of software that is not necessarily not necessarily listed in your package manager whether it's windows or Linux we can do a file based discovery to detect to search certain folders and as you can see in the middle you can configure which folders you want to scan don't turn this on for everything because you'll you're not gonna you know like the results of the performance that on the hosts but essentially turn it on for specific files that you're searching for or folders those get added to the cmdb as a file information table and then you'll be able to run a report and see what you have out there a big use case for this last year was the log 4J we're able to help customers detect the you know the existence of log4j in their environment through this file based discovery and you will all get a copy of this deck as well it'll be uploaded to the community site for your you know for your use later on as part of Discovery it's not um it's not a separate product by any means but I want to call it out separately because Cloud Discovery is something that is uh it's it's a little bit different than than a regular you know um than regular Discovery what we do is we use an API to discover the cloud what you see on the left hand side are the five clouds that we support out of the box so AWS azure gcp IBM Cloud as well as Oracle clown and we can discover I as or platform as a service or function or container as a service from those clouds and we can put those resources into the cmdb build their relationships and so forth but it's important to understand why you want to do that well your security team and as well as your software asset teams and your Finance teams are going to want that data in the seam to be because and and then also your SRE teams to you know better manage health all those Cloud resources need to be you know maintained from a health perspective from a configuration governance perspective we need to be able to control costs uh software costs as well and then also of course their security incidents there's vulnerabilities that happen against Cloud resources they're not immune to that as well as uh you know Regulatory Compliance PCI and pii so a good example is if your security team would like to know what was the configuration of a particular application at a given point in time because it had PCI Data on it you can go back and produce a report for the security team that shows exactly what was on there now when I talk about the two different types of Discovery data what cloud Discovery does is the bottom it gives you and we do this across those five clouds as I mentioned we give you the resource with the you know so for example here we see the virtual machine instance and a bunch of different virtual machine instances we see Cloud management networks we see the AWS Data Center we see storage volumes we see the availability zones and so forth it's all of the cloud metadata that you would get from your cloud provider and these are things that tags are associated with on the Deep dive Discovery portion this is the OS information this is the typical thing you would do with a deep dive discovery that I talked about earlier you would have to supply credentials that have access to these devices in order to query them to get their OS level information start to build out the details of those systems those of you that are using cloud and you are bringing your own license there's an option when you deploy software in AWS or Azure to say whether it's bring your own license pay as you go spot licenses if you check that box AWS and Azure basically say okay that's you know we're not charging you for that but you need to take care of it yourself so there is a flag that gets set on the resources we collect those flags and put them into the cmdb so that you can better manage your the licenses uh for be what you know your own licenses essentially right byol pay as you go and spot uh when we talk about Cloud discovery we let's talk about Cloud native Discovery right we've got the concept of kubernetes what is kubernetes right is it's something that is very agile changes a lot but customers are using it like crazy uh in you know in their environments uh because it is easier it's Cloud native it's easier to you know to deploy and stand things up in a rapid manner and it saves you from having to have specific you know virtual machines and physical Machines of course things like that we have three methods to discover kubernetes one is the Ageless Discovery with the kubernetes patterns we talked about agentless Discovery already but essentially what we do is we bring in the topology the kubernetes tags as well as the software that's running in those containers um this here we need Bara tokens or a cloud credentials to set that up correctly so if you're familiar with kubernetes you know that you have to go ask your teams for the bearer tokens you also need some urls or the Clusters and and things like that so it's a little bit of a manual process to set this one up and you got to set up a discovery schedule for each kubernetes cluster so this is really the best suited for those customers that are self-hosted kubernetes on premise or using cloud deployments but you have access to the bearer tokens and and to the credentials with the automated the second approach here is if you are running uh Azure AWS or gcp they have managed kubernetes Services you can subscribe to eks AKs and gke servicenow will automatic during Cloud Discovery servicenow will automatically discover those clusters and it will create serverless Discovery schedules for each cluster you need Cloud credentials right in in you know specifically for AWS you need the assume role to make sure so that you don't need to gather additional credentials on top of that these are best suited for those managed uh kubernetes deployments and then finally we have something called Cloud operations Cloud native operations for visibility this provides continuous kubernetes topology tags services and software inside of the containers all security access for this is handled outside of servicenow and essentially you what you would do is you would give your kubernetes admins a single line command to install a containerized mid and agent client collector in each kubernetes cluster and then we would essentially have continuous Discovery there so it's best suited for deployment by Cloud native app teams as well as you have the optional ability to mount to to monitor kubernetes with our AI op solution as well and I mentioned on that previous slide about software Discovery and containers something in in the industry known as software decomposition is trying to understand what software is installed in your containerized environments so we've partnered with aqua trivia it's an open source tool we will be including Aqua tree actually in a future Discovery pattern but today we have we download it separately so kubernetes we skip you know once we do Discovery we scan the container images uh with you know with aqua trivia to understand the software installations so what you see over here on the right is this container image scan this MySQL instance and it's my you know this mongodb those are the applications that are created and then down here we can see a on a specific Docker container what software is installed on that container so these helps with software Asset Management use cases as well as the security use cases when you deploy our servicenow discovery you want to make sure that you're constantly updating your patterns Discovery and service mapping patterns and visibility content apps are what include the latest and greatest patterns whether it's new patterns like you see here this is some Innovation we've done over the last year or if it's updates to existing patterns now we've included this visibility content app on the right that you see there uh that is available from the store as well that app is for updating patterns that did that were originally part only of the family releases we've moved all that stuff over to this this visibility content app so that you could update those on a regular basis so for example Windows patterns um if we if Microsoft releases a new version of Windows in the past we had to wait for a family release in order to release that now we have the ability to provide a pattern for that in this visibility content app because we're we're updating a host pattern the host patterns were traditionally only kept in the in the on I'm sorry in the family release and with Cloud Discovery we provide you with a UI called Cloud operations workspace if you have a if you have upgraded to San Diego or later you can enable something called the next experience which is our our new UI and you could install Cloud operations workspace Cloud operations workspace today is your One-Stop shop for setting up Cloud discovery for viewing your Cloud resources that you have and also we also have the ability to view all of your kubernetes uh you know on resources in the future Cloud operations workspace will have additional applications on it as we scale out more and more Cloud applications for your Cloud center of excellence so we talked about agentless discovery and then we also talked about Cloud discovery we provide another method of discovery that is Agent based servicenow released an agent back in 2020 that you install to your windows Linux or Mac OS computers that can push Discovery information to servicenow the agent is useful for scenarios where you have a gap you know whether that be you can't get credentials from from your teams perhaps you have a domain controller or a cloud environment that you know you just are not able to get those credentials from those teams you could deploy agent client collector and send that data back to servicenow uh it's useful in in DMZ environments it's useful mostly though uh also on endpoints so on your laptop uh if you run an agent you know whenever the the laptop boots back up again they can check in with servicenow and send its configuration back to servicenow it's also useful Beyond just push-based discovery which you see here matter of fact our our original um use case for agent client collector was for monitoring we provided a monitoring agent and that monitoring agent was can send metrics logs and events to servicenow for our AI op solution to process agent client collector also has use cases for IT service management as well as security operations as well as software Asset Management for itsm we provide you with the ability to look into a computer or system to see what the currents um you know real-time system information is so that you can so that the service desk can do some troubleshooting remotely we have remediation playbooks uh for automating the running of certain actions to get a service or or I'm sorry to fix an application and we also have virtual agent conversations so if I have the agent on my laptop I can chat with servicenow and it you know servicenow knows that the agent's on here I can request something like access to a specific piece of software right or I could ask for specific admin rights or something like that and the ACC can can grant that for security operations we provide security incident response those analysts with you know additional enrichment from the hosts in real time just by clicking a button to collect that extra data and then for software Asset Management we can our ACC board visibility natively collects installed software data as well as software usage data I'll show you what that looks like here in just a second so so for those of you that use Microsoft SCCM for metering total usage time this we've introduced a capability that does the same thing for Windows uh if you're moving from secm to InTune you will notice that Microsoft no longer provides the software metering which is the total usage time right so here we see that this piece of software has been used by you know this many minutes this many seconds this is the usage count and we give you the you know the year and the month as well also we have um the ability to track last use date which you don't see here but uh so those two factors go into software Asset Management and if you're running software Asset Management you know that you can use that data to then determine to set up Reclamation rules automatically uninstall software that are that are not used quote unquote so you do need software asset management for that just just to be clear here is the agent client collector 4 investigation I mentioned and but and so by the way our our Polaris UI or our next experience does support dark mode as well um big dark mode guy I have it turned on on my phone you know my phone my laptop Etc so here's an example I took of my laptop where I could see the memory utilization disk utilizations CPU uptime as well as top processes by CPU and memory I see the details about the CI up here as well so if you're a service desk and somebody submits a ticket that their computer is running slowly you could actually go into your service operations workspace the investigation tab if the computer has ACC you'll see this type of data here that type of data is something you're only able to get from let's say a um a remote control tool finally we also support IPv6 Discovery so those of you that are maybe in federal organizations that have a um you know a memorandum to meet a compliance requirement to have all of your systems on IPv6 by a certain date well you just be rest assured we that you can discover those with servicenow via agent lists or agent based discovery so that was discovery our next feature is service mapping service mapping is the feature that lets you gain business context for your specific resources so if you have a database that is installed on a host and then that database if you if you receive an alert for that host let's say or you're putting in a change for that server that the database sits on you'll be able to see a view like this that says all right that that host that hosts that Oracle database that supports this order status service or this order Logistics service and then you'll eventually be able to tie that back to I need to notify these people about the outage or on or about the upcoming maintenance window or get them involved in the approval process so service mapping we have three different approaches for you to map your services if you're cloud-based or microservice based like kubernetes or containers or if you have tags your virtualized resources in VMware you can use Tag based mapping to gain business context like you know literally in minutes or hundreds of services at the same time and we have a an application I'll talk about next called tag governance that helps you establish better tagging processes for your resources so these tag-based service Maps essentially we create them you know very quickly like I said that's more for your mic you know for your Cloud native your your Cloud resources your virtualized resources our second method that helps you build maps at scale is with this um it's it's new within the last few years but it's called um ml based mapping uses machine learning to identify Intelligent Traffic based connections that you may want to add to service maps and it also has the ability to suggest services for you to map as a starting point so you'll have a set of connections already established as part of that service and you'll have a service map already built with the click of a button and then finally top down those of you that have been around service now a long time have heard about the top down method will you point servicenow at an entry point and then it has to go through the you know that process to build it out which I'll talk about actually on my next slide so three methods two of which are very fast the tag based and the ml based the last one that the top down there is um that's really for your mission critical Services where you want to make sure that they're you have every single possible uh you know resource aligned let's talk about the top-down mapping process first thing you do is you point servicenow at an entry point say my billing app and you give it the URL or any kind of connection parameters second thing that happens is host detection so what you do is you is it runs the required steps of the discovery process because service mapping relies on servicenow Discovery to gather all the details for mapping next part is CI identification which is where we identify the applications that are running on the discovered host and the information from the you know based on the information from that entry point and then we um we discover the additional details and we look for configured relations typically in configuration files to determine what's the next host that I need to you know create a connection to oftentimes you have to build these things out yourself those connection points which is why this method takes you know much longer than the other two methods that I talked about you could use ml-based mapping to enrich a top-down map it's essentially a top-down map anyway to add additional connections to the map that maybe you didn't gather from meeting with your architecture teams or meeting with your application teams those are just examples of services over there on the right attack based mapping servicenow Discovery natively discovers tags as it from clouds or from VMware or from nutanix Etc anything that's tagged we we discover the tags which are the keys and the values we put those into the cmdb key value table next what you'll do is you'll create the CI tag categories which are essentially tags that equal the same thing a lot of times you'll see application or APPL or app but really they all relate back to one thing which is app so you're essentially normalizing tags to one area so maybe you've done that for app and environment those two tags next what you do is you create tag-based service families so that you'll uh select which of those categories you just created that want to be included in the map so oftentimes we see customers doing app and environment so you'll get basically you know application in prod application and Dev right so you know such as train operations operations Dev and down the line this is where you can easily map if you have things tagged in your environments you could easily map hundreds to thousands of services in minutes you would then select which candidates you want to create service maps from and then once you've done that you'll operationalize them by by setting them to to the status of operational and start using those in in your daily work next we have ml based service mapping which we can discover it leverages two capabilities that are underneath the covers one is a feature from Discovery it is called application fingerprinting which clusters like processes together so oftentimes your your applications may be built with wrappers Java wrappers uh the powershellwrappers.net and so forth but how do you distinguish the actual application that's sitting in that wrapper from each other well that's where the you know the the the command line parameters come in and and there's other parameters underneath there that will help you that that will help us group like things into groups or to clusters that's the application fingerprinting um then the ml um uses afps or as part of its ml um let's call it ml analysis it you know we look at cmdb TCP table and the cmdb running process table and we factor in what suggestions would be meaningful for you to add to your service Maps or to you to create complete services from fast forward here are our Evolution for ML based mapping is we started in 2021 with Quebec and as you can see here we have iterated out through Tokyo in Rome we introduced the service mapping Plus application which is where all service mapping Innovations will now be going forward so if you have service mapping and you want to use the latest and greatest Technologies install the service mapping Plus application to continue getting all the latest updates now in Tokyo we also introduced something or in the Tokyo time frame we introduced something called automated service suggestions where you can map your services in mere minutes so we have that cluster data right that that running process data that TCP traffic data we do the ml clustering we suggest Services what you see there on the left on the screen those are application service candidates with the click of a button you can click on create application service fill in a couple of values and then you can have a service mapped in minutes we have webinars on all these topics that I'm talking about today and like later on I'll show you where you can point to for those resources our next feature is certificate inventory and management which our goal is to help prevent outages from expired certificates for you I was once a person that had to manage certificates out in a you know corporate environment and I would do that via spreadsheets that first certificates that people told me about or maybe ones that I I you know submitted orders for myself but inevitably I always missed things because no one told me about it or for you know for whatever reason we didn't have it which what you know what happens is you're not keeping track of your expiration dates and you don't renew this certificate it can expire cause an outage cause maybe a a cost impact or possible security breach so what we can do with this solution is discover all of your certificates across your entire state via three methods one is Port based so during your regular Discovery scans we can scan for common ports you can add additional ports to scan for such so that we can discover all those certs that exist in your environment and with Port base we also create a relationship from the certificate to the host so you know where it's installed the next option is CA based and with CA based we support digisert and Trust GoDaddy sectigo and Microsoft we can discover the certificates from those cas put them into the cmdb um but what you won't get with that is you will not get where it's installed only with the port base you get where it's installed up next is is URL based Discovery basically point servicenow at a URL we see this being used in DMZ environments uh essentially that you will not be able to scan with a port based so I can point servicenow at even any public URL discover their cert and compare it up to the details from the security lock in your browser to see in fact yes it does match that's exactly what I was looking for so all the certs get populated into the same to be with installed locations and and again installed means um the port based option and then we help you if you have service mapping you'll be able to gain business contacts through automated relationship creation we also then that's the inventory part the management part is basically being able to we create automated task records 60 days prior to renewal and we also create incidents or alerts for event management for already expired certificates so there's a seamless integration with I.T service management there we provide you with a standard catalog for requesting certificates we provide a manual method and an automated method this slide shows the automated method so you can request a new or a renew or a revoke we can automate the request out to your ca for automation we support digisert and trust and Microsoft so a subset of the ones I talked I told you about earlier we have a roadmap to add more over time and then at the same time we create a change request so that you could track that that process with your change process and then of course they give you a dashboard to visualize um you know the inventory the trends and complete lifecycle of yours of your TLS certificate data and here's just some screenshots here we see some dashboards of the inventory of the automation tab of the request form and of the automated relationships you can see that are created so here I have a a unique certificate running on a on an ha proxy that ha proxy load balancer is part of this mapped application service called it's called locomotive maintenance then as part of this business application called called Railway operations our next feature is is firewall auditing and Reporting if you have if you have Palo Alto firewall manager we can discover not only your firewall devices and your but we could also discover your firewall security policies your your firewall groups and all the different things that are part of the firewall structure put it into the cmdb but then we can also help you manage firewall requests through a standard process the biggest benefit here is is actually auditing of the fire of the security policies if you don't attest to your security policies on a regular basis they can become stale you could possibly have security breaches and so forth so you want to make sure that you're doing that on a consistent basis and then of course a dashboard to see everything that exists in your environment and we also automate change requests as part of the firewall you know request process now we don't automatically provision firewall rules but we do allow we we do make it easier for you to request them so when I used to do this process I would submit a Word document to the firewall team via email not the best way to track that here are just some screenshots here you can see the firewall dashboard that shows you your audit tasks and your open requests for new rules this one over here on the right is all of the firewall devices that you have here's the firewall rule request and of course here is a firewall auditing request any any reports that you see here can be tweaked to what you need any firewall I'm sorry any uh you know catalog items can also be tweaked our next feature is tag governance this allows you to set tag standards in your organization oftentimes we see most organizations have lots of tagging going on but there's really no standards so as you can see down there you've got some keys that are common that we like to see out there we can put them there with tag governance so what we do is we discover the tags which is the key values right we put those tags into the seem to be in the key value table that's discovery that happens automatically even if you don't have this app with tag governance you can set up uh tag auditing policies to help you verify compliance with those policies and you can Auto remediate Tags with workflows which is essentially adding tags those keys and values to your resources and that happens in the seam to be automatically and of course if you have your tags if you um vendors tags could be used to create tag-based service Maps now if you have uh an entitlement to item governance you can also update tags actually in AWS and azure here's some screenshots here we see the tug governance dashboards you can see exactly what your health is the tab governance efficacy dashboard helps you understand where you want to be versus your current um stance Down Below on it's kind of blurry there sorry about that that is a tag policy where you set up an auditing policy you can do that against a specific service account a specific set of CI classes data centers Etc on the right on the bottom you see a tag remediation as well as what I've done is there is clicked a tag or mutation preview which would show you what would happen if I ran this tag remediation customers that are using Oracle are now able to so servicenow is now a verified Oracle third-party vendor for database middleware and database options so Oracle comes to you and asks you to run the LMS scripts if you're audited by them what this app does it's a discovery application that includes a bunch of of patterns that are verified by Oracle we can discover all of the Oracle data that they would necessarily ask you for in those LMS Scripts and we'd it we would enable the you then to export that data very easily so this saves countless hours uh six to eight weeks we've seen customers that are being asked to run these Scripts we can do that in just a matter of minutes so here is what that looks like we have a dashboard here uh for you to easily download the data once you've collected it so the glass data right the the vcenter hardware information as well as the the virtual machine information because you have to factor in the cores and CPUs and such here are some dashboards that we provide and here is a link here that you can verify for yourself that we are in fact a verified vendor these are the six tables that that we put the data in the cmdb you don't need software asset management for this uh because this is just for collecting the audit data if you had software Asset Management you can understand your license position at any given point in time but this application here is really for you to collect the data needed for an oracle audit so once again just more value with icon visibility our next feature are service graph connectors these are third-party cmdb Integrations that you can install from our servicenow store and I'll show you the slide next that has all of the Integrations on it but instead of writing your own integration that may or may not go through the proper processes what we suggest that you do is go to store.service.com go click on Integrations in the tab up here click on service graph connector and you'll see I think there's over 30 uh if not more that you can install in your environment and connect to those systems to ingest data now later on I'll tell you about when to use service graph versus Discovery and so forth but lots of innovation we continue to work with with third-party vendors to build new service graph connectors sometimes we build it sometimes they build it just just note that they are certified and verified by servicenow our next feature is cloud native operations for visibility I talked about this feature earlier I'm not going to go much more in depth but to say that this is just another option this is another app you can install it's called Cloud native operations that has a visibility component it deploys the agent client collector it deploys a containerized mid server and it will give you that continuous kubernetes discovery and then if you have itom health you can then manage the health of your kubernetes environment on a continuous basis here's what here's how that process works here's the mid and the ACC deployed as a stateful set we have continuous streaming of of events um from configuration events as well as operational events and then we do that through an ACC check we send that data back to servicenow at the same time we also set up those automated serverless Discovery schedules so that you could discover the the Clusters on a you know get a Baseline and do that maybe once a week or maybe once a day but this is this is what gives you the continuous Discovery here and you can do that on any of these platforms the final feature that comes with servicenow icon visibility is called multi-source teamdb this enables you it's a it's actually a a plug-in that you'll have to enable I'm sorry a property that you have to enable that allows you to do do what I'm going to say here so traditionally with our ire we would uh just if it was a it would you configure it just to pull in one golden source of um or it um or a discovery source of an attribute or a host and we would not ingest the rest of the data we just kind of leave it out with with the multi-source seem to be we ingest all the data but we only store the golden attribute in the cmdb this allows you to go back and look at multi-source data at any given point in time with the cmdb 360 dashboard to then see maybe I want to make a different Source maybe Titanium or jamf as the as the golden source for a specific attribute and you change it on a fly and change it back again if you don't like it with that said as a result of what you've just seen here so far which of the icon visibility features would you like to implement next and thanks John for launching the poll we have Discovery agent client collector for visibility service mapping certificate inventory and management firewall Audits and Reporting data collection for Oracle Global licensing advisory services service graph connectors Cloud native operations for visibility and finally multi-source seem to be thank you guys for taking the poll here let's leave it open for another 20 seconds or so John and what I'm going to move on to next while that poll is open let's keep that poll open we'll talk about next steps that you can do to be successful I have a call to action for you here one I want you to convey the importance of the full of having full visibility into your it resources across the organization next we want you to use all the learning resources that are available to understand when to use each of these features and then finally we want you to follow the five steps for successfully deploying a healthy cdb so thanks John for let's go ahead and share the results okay so it's already being shared sorry uh so okay so so from what I see here the majority of you are next going to try out service mapping certificate management agent client Collective for for visibility and tag governance thank you for that I'll go ahead and end the poll and of course always seek to engage a Services partner if you want faster time to Value these are very complex applications to install because you need to factor in three things people process in technology the technology pretty straightforward we can discover your environment we can put in the cmdb but you know how to use each of these features and also the policy and process behind each one that is where a a Services partner really helps you gain that fastest time to value so I want you guys to go ahead and follow these five steps and I'm going to focus on two of these in today's webinar set your direction this is where you're making sure that you're seem to be the any data you put in seem to be aligns with organization you know on business goals and and I T goals build a team in governance model which is where you're essentially building out that configuration management team so standardize the processes and kind of manage that data going forward design your data model which is really how are you going to align with this with the csdm common service data model you want to operationalize the team to be this is where you populate it this is where you make make the data come to life and then of course you want to create ongoing strategic alignment making sure that folks that are using the data have alignment right so also having your leadership kind of set cut you know kind of set their Direction incorporating configuration management into your projects to make sure that people think about the cdb so if somebody goes out and says that they need to that they want to discover the kubernetes environment well guess what you have a solution that you could tell them about right so make sure that they're aware of all these features so so I'm going to focus on setting your direction and operationalizing the cmdb so before you put anything in the same DB right before you turn on your Discovery or service mapping or whatever make sure that your data aligns with business or it objectives make sure that you understand what someone's trying to accomplish how or you know what is the approach or constraints and you know um and assumptions of putting that data in there and of course why what business outcomes will your seem to be or the data you're putting in there support then of course you have to measure this on a regular basis to know if you're on track right but the but the key point there is making sure that that you know that it aligns with the business and how if we map this back how do strategic initiatives map back to the cmdb but this slides a little bit older from covid right so but it's still we can put in anything here and and it'll make sense so once you know one strategic initiative might be you know to to in you know to enable the employees to work from home seamlessly so so some of the use cases with that might be you know do my employees have the VPN client on her laptop is the hardware and software up to date for my VPN what about you know when troubleshooting VPN outages how can I quickly determine the root cause so what you need to put in the cmdb is an accurate count of current inventory sorry of hardware and software from end user devices across your entire estate right so that could be done with ACC or perhaps a service graph connector also but how the infrastructure and application components support each other in the business from your VPN so that's just one example there um you know the the second example talks about ensuring citizens are able to file for for unemployment when needed most but essentially they're getting into pii data and so forth and keeping track of all that so when to use each method you want to make sure that you of course do do automated population so what we recommend is starting with discovery or agent or agent list based right so our item visibility application you see on the right are designed with configuration Management in mind service graph connectors can be used to enrich your cmdb or fill in any gaps that you have perhaps that you cannot discover I say that because most third-party tools are not designed with configuration Management in mind so you may connect to a service graph connector to pull in additional enrichment data into your cmdb but those but some of these service graph protectors may not have everything you want in a you know you know NACI so you've got to determine what the use cases are where to get the data from best so think about that but make sure that you always automatically populate I'm going to share a few you know a few learning resources with you now and then we'll wrap up so thanks to all the you know that you know thanks for you guys for your questions I see that our team has been answering them feverishly behind the scenes first thing we hear we have these technology workflow workshops these are practitioner workshops where you can attend we have lots and lots of Icon visibility ones scheduled throughout the year so John if you can please put that in the chat put that link and you guys can sign up for a new item visibility workshops across you know that's close to a city near you next we have our icon visibility resource Library which is a single One-Stop shop blog for helpful links whether it's how-to blogs videos webinars process guides presentations troubleshooting links Etc that link is in there and then finally John and I conduct this item visibility and governance Community webinar series where you can register for future webinars and view on demand webinars these are conducted on the third Tuesday of every month as best as we can hold that schedule and then of course this slide here and you know and and again you'll get a copy of this deck content this is all different types of resources that you have available to you to learn more about servicenow Solutions in general so we're out of time for live questions unless we have one here that we feel well I see one that was marked so in what way does service mapping and and Discovery align with the csdm it aligns I should I didn't have a slide in here for it but our Technologies natively follow the csdm to populate this cmdb discovery at the bottom we'll give you your technology layer your hosts your applications and their you know the relationships between them the service mapping is the application service which if you're familiar with the c the csdm it sits right in the center of the csdm it is perhaps the most important element of the csdm so you want to make sure you automate your service maps and not build those out manually so that they're always up to date and when you go to build out your app your business applications your capabilities you can rely on the data because you know that it is current it is from your existing you know let you know it's near real time and then finally we'd like you to join us on our next webinar uh on March 21st where we're going to cover how to extend agent client collector capabilities and we'll have John Severn and Richard to host that one thank you all for watching and have a great rest of your day
https://www.youtube.com/watch?v=HVaQwaWF9hc