ITOM Visibility & Governance Webinar Series: How to extend Agent Client Collector capabilities
all right so I guess we can get started so good morning good afternoon and good evening everyone thank you very much for joining today's session of the item visibility in governance webinar Series where I have very happy to see you here again and even if this is your first time attending this series we are definitely looking forward to see you not only today but for the future uh event So today we're gonna talk again about agent client collector as per we did in January session but today specifically we're gonna focus on how to extend the ACC capabilities this event is also part of lion live on servicenow program which is an interactive event series that is going to help you in adopting and deploying our Solutions but also in general to really achieve value faster with them you can see the full schedule of live on service now series here with this QR code or alternatively you can look at the chart where we're going to post the link so you can even access this full schedule from there now a few housekeeping items for today and please make sure that everyone is muted if you want to interact with us please use the Q a function and whenever you're doing so also please make sure to introduce yourself we're very happy to get to know you and know who you are and why you were joining us today so today we're gonna also have two interactive polls so just please make sure they will take part to them also uh this session is going to be recorded and will be sharing not only in the servicenow community but also on YouTube and actually just the session that was mentioning before and about how to deploy um ACC at scale you can find it already on our service now Community as well as all the other webinar episodes that we run and that are part of the same series then after the session uh you'll be prompted to fill out a short survey so we will really appreciate your feedback please make sure that you will share it with us so uh presentations here today uh Severin is going to present uh together with me and my name is John Mario de Luigi and I am part of the outbound product management team for item and specifically a cover visibility and governance I joined servicenow a few months ago now and I'm very happy and looking forward to see you and to have you as guests in today's session Severin do you want to introduce yourself thank you very much Gian for for the introduction my name is Savannah new I'm the product manager for the agent client collector very happy to be here today and thank you all for joining us in this session thank you thank you seven so first things first as I said we're gonna add two polls today and this is the first one that you're gonna see today so we're basically asking you what are you in your agent client collector Journey as of today and so do you still don't know what ACC is or are you performing a proof of concept of it or are you undergoing an ARB or Security review or instead are you rolling out the agent pilot or in Pilot or soap production or are you already used again a production I'm gonna give you a few seconds so you can select all the options that apply to your case and I see yeah I definitely see the answer is coming in so please I will give you 10 more seconds and then we're gonna see the results right I see a good few of you and have replied so five four three two one and we can see the results so interestingly enough the majority of you is not familiar yet with the ACC concept and also a lot of you are performing your proof of concept for ACC and then the rest of you are equally either undergoing an Erb or a Security review or using it in production or even rolling out the agent in a product or a production environment right so um now uh we're gonna talk about the actual topic of today which is expanding ACC capabilities and slavery is gonna now share the screen and bring us through uh very interesting slides and demos so back over to you seven thank you very much can you just confirm you can see my screen yes we can all right so let's get started um so just quick introduction on the agent client collector it is an agent-based solution to collect so extract data on target systems send them back to service now to be stored into the cmdb for example and support other use cases so in terms of topology we do have the agent running on the endpoint or server so end user compute Cloud instances and data center VMS and physical servers you have a mid in between so the agent connects to the mid and the mid keeps the communication also open with the instance and so without topology we can have that bi-directional communication on the HTTP layer to to exchange with the agent and collect data points as needed so we do have many components in that architecture just mentioning a few here on service now instance you do have plugins plugins that will contain scripts that will be used by the agent to extract those data points these plugins have a mention of a platform for for this particular plugin as well as an allow list so list of commands that are allowed by the agent to execute so this is a security feature this plugin is tied then to a set of commands that we call check definitions so check definition has the actual command list of plugins that are required as dependencies and also a check type we get to attractive in a minute those check definitions are then orchestrated by the Agent following a policy that policy as a schedule with an interval or con job type of scheduling and um the um the check so it's not the check definition itself is a check definition instance that we uh so it's a copy of the check definition that we have there so let's let's keep going here we do have these plugins there are we are seeing top onto the nade that will host a small web server and then the agents will execute those checks following the requirements with the plugins to collect and execute with scripts following this command within the security restrictions boundaries that you set up now that payload is collected by the agent sent back for the made and back to the instance on the instance we do have additional types of components a business role and that will pick up and pack the input message from the eccq and process where they're going to the cmdb and we also have scheduled jobs like the one that will associate an agent or group of agents to a group of policies it's a lot of information so let's see how it looks for real on servicenow instance This Is My Demo instance I do have a couple of Agents running going there we can see the plugins the check definitions and the policies so plugins the ones for the framework for visibility and additional content obviously for ECC monitoring etc etc those plugins you have an attachment this is where you have your scripts the Oliver box ones that the agent will retrieve unpack verify the signature making sure it's not embedding a Motorway or something and then execute them on the agent the platforms you can see all of the attributes that are here to Target the specific operating system CPU architecture Etc then check definitions do we have that enhanced no we don't fantastic that's the plugins check definitions we do have this enhanced discovery that has a command that endpoint discovery it is actually embedded in the one of the framework models but we collect all sorts of attributes that you can see here if there are some data points you just do not want to collect you can just edit the check definition and take that off here scrolling down a little bit you should see the plugins associated with a check definition so that will tell the agent to fetch those plugins as we are requested for proper execution of a check last piece is my policy somewhere I do have my enhanced policy that will have a copy of a check definition we discussed before it is all blank this is great what's going on and no I'm seeing the check definition sorry going to policies enhanced over here there you go so we do have our policy with the copy of a check definition here check instance and that will run at a specific schedule defined by the tab as I'm always very patient my default it runs once a day but here I made it just every every what every 20 minutes so whenever we republish the policy through the uh the action items here via UI actions here that will push the policy with the appropriate schedule with interval or crown based to the agent and then the agent will be autonomous to execute that check definition at the defined schedule which means when you list all your agents let's pick up one from that list I open the agent record from here going to the eccq recent eccues you should see a bunch of input messages mostly that's because the agent is autonomous in the execution of a policy so every time it will return but payload and I will go to the ones I'm describing here in just a bit if you see messages with output input output input Etc that's the sign that potentially your agent gets disconnected for some reason maybe because you have a firewall in between so the timeout needs to be adjusted on on the TCP connection this is one example so this is out of the box how things work something we have not covered yet is that check type here so this column in the check definition you have a check type this is what will be executed to process the payload that gets into vccq so back from the agent into the instance in vccq opening that up you can do it by yourself you will see all the code that we have to process that payload use the ire for the CI tables and get all the relationships and everything so this is how it works it is using the check type here all right let's pass this for a moment a team is there any question so far on the chat about the out of the box capabilities so so far we have a few questions that have been answered so um well definitely let you know whenever there is we're going to have some that needed to be answered live thank you very much so we can start next with the second poll yeah so uh I just launched the poll there so um again poll number two um we would like to really understand for all of you how important will be the extended HCC capabilities that are not coming out of the box for you so um are there capabilities that are again not of the box that are mission critical for you or do you think it would be nice to have or you don't think they'll be required at all so um I will just leave a few seconds for everyone to reply to this and then we'll share the results in about 10 seconds I see a lot of answers coming so thank you everyone for being disengaged is always a big pleasure and yeah few seconds looks like the results for now are pretty clear so um five four three two one right as you can see the vast majority of you thinks that the capabilities that now are not out of the box will be nice to have followed by those that um actually believe it will be Mission critical one out of five everything is that and uh actually about 11 things that they are not required at the moment so again thank you very much for your participation and now back over to you sovereign thank you very much Gian so if I understand correctly this session um was quite useful to schedule so hopefully I will advise your questions by attending this session thank you next slide there you go so trying to take a step back about these tasks you need to get done by the agent try to identify them and see which ones are more of the um static kind of attributes or data points in general and is it supposed to be a one-time thing or on demand something that doesn't move so much it can be maybe a location um for for assets that are not supposed to move around too often maybe a business application that is associated with uh with that uh with a device or a support group something that is supposed to be quite static and then see which of these attributes or data points are much more on the dynamic side that change quite frequently and um and you may need to refresh them more on the uh on the schedule type of of refresh so once you have that in mind well we do offer two main ways to get to help you to get those data points into servicenow one is to create your custom checks plugins and policies so you've seen what is done out of the box you can create your own business option one and option two yeah is to use the automation flows with the ACC spoke for example we get into these two scenarios today so if you have some spare time you want to share your use case I don't know if we have a chat enabled on that session but you want to share that with us as a question feel free to do it so now about extracting the data you have three main ways to do it one is to use OS query OS query is what we normally use for ECC for visibility for most of the attributes we collect on the target system it is already shipped with servicenow there is nothing to change there you don't have security requirements to adjust in vlr list and Os query provides for those who don't know about that very nice SQL like interface to represent data on your system so it is very extensivable extensible sorry and can be used by customers as is so this is option one option two you can run local commands both commands or programs are already on your operating system some of them maybe shared how we say or published on those systems with another set of automation maybe or they have custom custom scripts on specific systems but the point is these commands are available for the agent to execute as is so this is option two option three you can build up your custom plugin with your own scripting likely your it department has some scripts to do some maintenance on systems for end user compute for servers you can embed those scripts into custom plugins and for them to be propagated by servicenow platform on each of these agents and execute those scripts locally by the agent it requires a bit more of preparation let's say to get these plugins on servicenow instance because well we do care about security at servicenow and the scripts that we embed on service no platform we do sign them with servicenow certificate Authority and each agent has the service now CA certificate and we check for the signature to make sure that that comes from our CA if you build your own you likely need help from your pki team to sign those plugins and you need to get the ca certificate of your pki team published as well on on those particular systems so that's all for today on custom plugins and you do have some material to explore it further but today I want to focus on these two use cases OS query and system command let's start with system command first add service now we do have some requirements on the systems we spin up on our Cloud environments and I know that some of our customers do have that requirement to collect the agent ID of other agents running on your systems for agents that do security stuff agents that do uh yes overuse cases and so they store that normally they try to extract that agent ID and store it into a cmdb in the computer itself in the computer record itself it may not be the best way for every single use case but I just wanted to take that as an example here so for us we do have to run Cloud strike on our systems and on Linux there is a very nice command that we just extract the agent ID actually yes so just extracting that agent ID is very easy on on those commands best construct is not correct sorry um and this is what we're going to do here with the agent so I created a custom attribute on the cmdb computer class crowdstrike agent ID the line here is 32 characters so this is what I did here and then what did I do check definitions I created a simple check that will execute that command with sudo and so if it's too small let's see if you can see it now so about the comments sorry but my screenshot before was not good I will update it so just to retrieve the current agent ID on 32 characters sorry 10 minutes and I then created a check type this one so that will be a custom check type opening that up here this check type I took a simple script and just added my own requirements since a given payload can contain the um in vccq can contain messages from multiple agents or from a single agent but for multiple check definitions we have to unpack it in Loop from here I get the computer CI associated with my agent I will just run a simple regexp to collect the agent ID and if it is there I will just assign it to my custom field custom attributes edit my computer I record and this is it that's done that check definition is then part of I have a few tabs open as usual what was unami as a policy but I run once in a while over here once a day but this one I override it to put it every 10 minutes looking back I can then I did let's say update my view and I did my trust for Linux systems for the scope of this example here in the view I added the agent ID so let's say on all of these systems I want to filter on the ones that do have uh no that's actually the opposite that do have an an object ID here and we can see that for all of my systems that are on the cloud providers I have for the scope of this exercise of course very few gaps where the agent the crowdstrike agent is not working and for sure within minutes I will take an action item to get that solved so this is one approach where you can very easily extract data and store that into servicenow cmdb any question on this I think for now we're good all right very well thank you so next let's go to the Second Use case which is how we can have data points collected by OS query and here I took the example of the assigned to where customers normally have or many of our customers normally have a strong procurement process and new hire process as well so that Hardware is associated to the user assigned to it this is normally done in the computer record under the assign 2. attribute but sometimes especially for secondary assets this may not be well collected or maybe Hardware will move around and maybe you want to audit what's going on so we've always query there are many ways to collect data there are many data points actually to collect and so I picked up a few ones here that you normally have with just OS query schema you can query five tables at least I mean one specific to Linux two of them specific to Windows to get that kind of information so just to show you here the examples of SQL queries you can run with OS query you can even do some drawing here on Windows Event log if you are familiar with XPath you can take benefit of it I am not expecting that I didn't spend time on it but you can catch those kind of events just from the windows event logs so many things you can do here but for now FYI if you go to the store you will see that agent Clan collector for visibility already collect some information for computers for who is supposedly assigned to that system we even show you we even provide you a assist property to say which source is your preferred source to assign it so let's give it a try here I do have that sorry this property it's this one here so let's go to CIS properties let's see what we've got there we go right now the volume is enabled I Believe by default we disable it because if you just update it and you already have those processes maybe you did not revisit your reconstitution rules and something uh could happen so we keep that feature disabled by the default but you can enable it by yourself if you do so again make sure that you revisit your constitutional rules so that you do not overwrite what is supposed to be there from different sources or workflows so now we do have a preferences here and this is for Windows only on the assign 2 for now we take the computer so the the computer user username so the username assigned to a given computer this is one option another one is to pull from the logged in users so for instance here let's pick up in my list of Agents a device that is just sitting at my desk right now just here Intel knock I open the agent record that is assigned to my computer CI let's take off the user that was created here we just modify it manually all right and at the same time I will do collect host data so that we force the data collection the enhanced discovery on that agent this is why you see a output message and once this is done it should return an input message with the right content another way to get it as it sounds like it is pretty slow there you go it's done input message let's open that up let's confirm that this is the enhanced Discovery yes it is let's go to my payload assign to there we go it's Json we already Json for breakfast we can see the login user severon and system username algorith7 as well we collected both okay so where are we here there you go it's back set to that user and that is a sys user record so it has to be it has to be um defined in service no instance now let's say that user was Brian which is my Starbucks name let's change that and I can just rerun that payload here I don't need to click on collect host data again I just reprocess the payload from vccq so let's do that again what do we see now and back to sevron so this works out of the box but now let's say you want to do your own stuff let's disable that thing of course it's asking me for that yeah yeah sorry let's put that to force now I can use the second way to execute data collection which is using I'm going to close a few tabs I promise using the flow designer using the flow designer sorry I can pick up the list of agents that are up and running that have a host associated with it the host is not retired everything is fine create a loop get my computer CR record and here check if we assigned to is empty because if it is maybe we want to do something about that so you see that we are putting some conditions here and only target the specific systems we want from that system that doesn't have an assigned to I can run the ACC spoke and run a specific query on it for example this one see who is logged in from there I can process that payload what is it okay I created some local flow variables over here FYI so I get the response the responses Json format it goes here then I will process that payload in Json format and from very very simple I will just return the user attribute that was written by the SQL query once we are here I look up in this user table see the user exists and if it does I update the recorder very simply you can create a flow and adapt it to your needs if you want to create maybe a task let's say if you were not able to edit the record create a ticket to the it support team and take action on it you can do that then what you can do also is audit your current cmdb and take some action if there is a discrepancy so in this example same thing I select the agents I want to see I want to query I get my computer record from here what I'm going to do is just list the windows events to see if there was a login action on that device so not at the time I'm running my query to see who is logged in but in the past over the past few events here did anybody logged in login on that system same thing in there I collect the data so convert to Json and from here what do I do I get an event message like this and there's just one type of events that they want to see that's Vlog on type number five the rest I want to see them so log on type I think 2 11 and 17 whatever and once I find it I just return the user Sid from that user Sid in my specific example it's not converted nicely so I need to run another query to get the actual username once I have a username so let me just show you the query here oh there you go I query the user table twice once with the um so to get the Sid and nobody have esid I get my username here in clear text once I have a username I compare if the assigned to on that device doesn't match the username who actually logged in early on today let's create a task for that task what do I do again yes system in a security incident and I put in the message with variables that I was maintaining here assigned to name and here the logon username all together let's go back to Brian here and Let's test that flow see what happens so in a few seconds I should be able to see the execution of the flow we'll give it a bit of time to process all of it yes I likely have just five computers registered as such and I believe that's the first one that we need here which one is it is it my desktop I think I can see it yeah that's the desktop here all right it did collect some information with voice query a lot of so that's the query itself let's see the return a lot of messages sent back see that logon logon type there we go we have five quite a lot but in one of them hopefully we have uh another one another type we'll see that it did uh so what did we return with that let's see we're going to set flow variables there we go we found that Sid from that Sid we run OS query again that in return send us the username here from that username I can test and what did happen in my condition oh Brian is not seven email doesn't matter so we created a task that task is here sir open record we wait and here we are we do have our ticket of course this is just an example it works for for one device think about doing that for 10 000 devices you don't want to create a security incident for each of them it maybe it would never grow up so maybe you want to store that into your custom table use the data certification and audits plugins we offer on service now platform to have more features on the on the handling those discrepancies any question here for now I don't see anything in the Q a to be answered live so I guess we can keep going and everyone please just post your question in the QA section and um we'll we'll reply either answer the questions there in the chat or live thank you and if you have specific use cases just post them you know what what do you think would be the best approach uh with a spoke or with a schedule for the specific attributes you're looking for in the meantime I would like to uh thank uh well everyone on the call here but in particular as you go to this knowledge base article that I believe Ryan you you posted on the chat here take the time to open a couple of links including this free from Will from Benoit and Kim because just looking at them what do we see how we can build or own processing or extraction and processing of Records coming from OS query and actually the one I did with a chord strike I did literally a copy paste here I changed the name here and there and I was able to make it happen so this is a very easy convenient way to get it another way um or other options from Benoit on this call here so you can ask him questions one step further with customers who who do have a resource file with some key values in that file to describe the environment describe the support groups or business application ownership etc etc so benowa was able to propose a a script that will take the content of that file and then process that payload and store that in two key values so if you are more into the key value table to manage your attributes you can use that directly some other options that when were covered I believe using this bespoke ACC spoke here so please take the time to go through this material see how you can expand the the agent capabilities with with those features that are out of the box and please let us know and you have a question all right just to show you here on OS query um see for example one that was a question that is asked once in a while internally is can we collect browser plugins well we can it is possible and our agent is flexible enough so that you can do it by yourself in the tables that you want if we don't have a table already in the cmdb schema like he likely you need a custom table and for that you see this one is just for Mac for now but they provide the extension to list all of these plugins and once we extract them you can store them into the cmdb somehow we do for the we do have questions also on USB devices oh how can I list my USB devices well possibly here let's see yes we do have a table for Linux and for Mac to list those USB devices for Windows I presume very likely you can get some information by querying the windows events or with wmi potentially so you do have a couple of options if not well you can use your custom Scripts to get that extracted all right so I'm gonna pause here ask her one more time for questions I guess there was one question around uh if you're gonna uh Supply the update set to the stuff that you were doing today that way they can do it in their own PDI or Dev instance this is a great question Ryan I need you to do a uh great a bit set with me and once once you do it please go to the knowledgeable I put a link to the ncbolo role I published and then we publish it there so let me share my screen again the KB was the KB it's here that on GitHub I will be able to put your dead sets over there good question and I guess we have another question from Joshua so he's asking OS query works for most computers without the need to install it as a program that's correct this is what we embed it as a plugin but some customers they they do have their own version of os query and we make sure that we we don't interfere with it but customers have a choice if they prefer to use the OS query from the system for for various reasons they may want to do that so um yes you don't have to install it symbolically for these use cases great already there and just make sure that's your check definition sorry it's tied to the plugin because by doing that that will enable vlr list to execute OS query from that particular path well I think um any other questions before I I guess I will start sharing my screen again severeign anything you would like to add um from uh from the field or your experience on the customizing was plugins uh the only thing I would add just another opportunity kind of touched on it before was that if you don't want to create your own custom plugin and you do have a the ability to run and you're familiar with flow designer you can use the agent client click or spoke and that can also go out and grab attributes and assign them to the cmdb the CI as well so different ways to do the same thing but what you showed is perfect uh yeah the only thing I have is uh watch out for the white list um it's a really good idea that we have the white listing uh there is some OS query where there is some defined with the asterix's use those instead of specifically query them so you don't need to change the white list I have mentioned it in the document but instead of just getting one ID get used to the asterisks so you don't need to change the white list and then just you know sieve it out in the in this grip yeah so just rephrase to allow any command from OS query instead of specifying every single OS query parameter so that yeah you have more more flexibility for additional use cases given that vlr list for now is stored on the agent at the time of the installation yeah thank you Gian the floor is yours thank you Severin let me share my screen again I see another question was answered via chat so um just a resources um we're gonna share I think we already shared the comprehensive link for item C documentation materials and you'll see a lot of different links in in that link so it's definitely very useful KB article for you to read and also this presentation will be shared in the attachment of the specific Community page for this particular event so you will see that together with the recording of this session we always encourage you also to submit your ideas in support.servicenow.com ideas because especially for those ideas that are the most popular and specifically for those ideas that have uh more than 10 submissions then they will go straight away into our roadmap talks in the product management team so you're very well welcome to share all of your potential ideas for the products then we have a few call to actions uh for you that stayed with us until now so first of all please try out all these capabilities at least in sub-production environments to see um how how they will be for you if there will be meeting all of your needs and we're pretty confident that they will and and also in doing that just showcase the value of these capabilities to your stakeholders so they can really appreciate the value of them and also there are a lot of attendees today with us and so um just connect with them once at this this webinar is finished and we're here for you so in general just paying us um ask questions as you did we're very happy to um answer all of them I see for their q a is coming in so it's all great and thank you for answering um these questions to my colleagues as well um and also of course share your success stories with us that's always a great great idea so the next episode of the uh webinar thesis for item visibility in governance is going to be uh in April and it's gonna focus on how to run Cloud Discovery at scale uh I'm gonna present alongside with ram and uh we're gonna go through these very exciting topics but again just please make sure that you register for the overall event series and that we shared with you earlier on this is going to be great for you to attend and again so we're constantly showing you how to really achieve service operations extends without invisibility and these are all the different topics that we're talking about in our webinars and we know that there's a lot of interest from your site so keep giving us inputs uh even in the survey that is going to be provided to you at the end of this webinar just um make sure that you include all of your questions all of your use cases and again if you have any success stories to bring up to us we're more than happy to hear and if you need further assistance just make sure to let us know and I guess for today that's it really I see um a couple of uh questions ask everyone if you can double check if we have anything else to answer live uh in our q a box yeah so uh one more question I think it's on the registration link of cloud Discovery I have no clue let me give me a second yeah we'll definitely send it over to you um yes and the last one was uh on the pros and cons of the agent so let's say depending on which environment where would you choose the agent this is another approach um I think this was already answered by Kim earlier today in this session on the the topology the first question from uh that came answered so um think about all of these scenarios were having an agent on the target system makes things easier so that you don't have to manage credentials so you don't need an external credential storage for example or Networks um user and user compute obviously you don't want to do credential based discovery on on those systems if you don't have a full control on them environments that are highly Dynamic on Cloud for example embedding an agent is a very good way to get that payload as soon as the instance is spun up wherever you have hibernation policies or Auto scaling capabilities I think that is like near even based Discovery so this is a very good use case as well another one is um uh well on those networks that are very constraints you can even say you can deploy version there with uh how we say egress connection to to the mid server and not the other way around so many use cases wait it works very well and our customers adopt that vdi as well vdi not for the actual licensing like how much it costs but to know if a software is actually used on vdi environments because for some licenses as I understand applications are associated with a group of users a group let's say an active directory and when a vdi instance is spun up for that particular user it will deploy the applications tied to that group and that's where you get charged understanding software metering that you can get with ACC will help you make better decisions on the allocation of these licenses so I hope it helps thank you so much Severin I'm just posting here I think everyone has seen that but the registration link for the webinar and Series so everyone has it there in the chat um severing do you mind posting the links to the um actually documents you were demoing today not the document specifically but the blogs uh will they be included in that main article as well on the on the update set I will I will put that on GitHub so there's a have a look on it whenever we refresh the kbrtc caller I will I will get that on on GitHub as well all right and the questions about roadmap we'll have to take it offline as you can understand yeah yeah perfect so thanks I guess and anyone else wants to add more before we end this session and see and again thank you so much everyone for attending this session it's always great to have you in these great sessions right so yeah I guess that's it for today so again thanks all thanks to everyone and Ryan King Benoit and Steve it was another great session we're really looking forward to see you in our upcoming webinar series episodes and uh we'll definitely reach out to you in case you will express any interest in Need for the help from us so have a great rest of your day and we'll see you soon thank you
https://www.youtube.com/watch?v=bocpBQQtqxw