ITOM Visibility & Governance Webinar Series: How to deploy Cloud Discovery at scale
all right so good morning good afternoon or good evening everyone and welcome to this amazing new session of the live on servicenow webinar specifically today we're going to host another item visibility and governance webinar episode and uh today we're gonna keep talking about Cloud Discovery and how to deploy that scale this is a follow-up session to the previous one we just had in April and today in particular we're going to focus more on the demo aspects of it as we're gonna see soon now as I said this is part of live on servicenow webinar Services which is an interactive event series that is aimed at explaining the deployment the adoption and ultimately achieve value faster with our Solutions you can see the schedule right here by sending this QR code and also the link is going to be shared via chat soon now a few housekeeping items please make sure that everyone is muted during those our session today and also please make sure to use whenever you have questions the Q a feature um this time we are not enabling the chat just to being able to manage the questions in a more efficient way and also please feel free to introduce yourself whenever you're asking questions because we'll really like to know who you are um also uh we all have a couple of polls so please make sure that you can participate into them we want to hear your feedback also this session is going to be recorded and will be shared on the servicenow community Forum specifically you will find in the same page from where you registered and also after this session hands you'll be prompted to fill out a short survey so please make sure that fill it up and your feedback is really really appreciated so thank you for that my name is John Mario de Luigi I'm part of the outbound product management team for item specifically covering visibility and governance and today Ram is going to present alongside me so Ram please introduce yourself hello everybody ramdev Natan Here I Am the inbound product manager I handle the cloud products including the cloud visibility the cloud provisioning and the cloud governance I've been in service now four years I spent a lot of time around the cloud space very happy to talk to you about discovering at scale today back to you again thank you so much from right so as I said before this is a follow-up session to the webinar that we hosted back in April and as many of you uh were asking for it specifically you were asking to have a more demo focused session and this is exactly what we're gonna offer you today so just as a quick recap of what we discussed about in a previous session and by the way we just posted in this slide you have the QR code that you can scan to go directly and see the recording of our previous session or you can go to our chat where we posted the specific link we talked about the multi-cloud invisibility concept with a item and also what is the difference of os level Discovery against the metadata Discovery capabilities that we offer we also talked about the cloud Discovery in particular regarding the solution decision process for both AWS and azure then we went in detail to analyze how the cloud Discovery schedules work and also how the discovering the cloud accounts and mass so in bulk is possible thanks to item and thanks to our Solutions and also how the event streaming discovery of cloud resources works now today we don't want to dedicate too much time going over everything that we said in the previous webinars so please feel free to go and re-watch the recording we also will attach we have already attached these slides of our previous session so you can also go and see the slides So today we're just going to do a quick recap of one of those particular aspects before the demo but before we get started with that we have already a poll so we're gonna launch it right now and we want to ask you how do you actually create in this moment of time your Cloud Discovery schedules so if you create them do you create them from cloud service account records or from the cloud Discovery home UI Wizard or would you rather create them from the cloud operations workspace in case you don't create any Cloud Discovery schedules please select the option here so I will give you a few seconds I see a lot of answers coming in so thank you very much for your participation it's very much appreciated interesting results so far another 10 seconds and then we're gonna see the poll results so five four three two one so I'm ending the poll now and we can see the results here so we can see that most of you are creating the cloud Discovery schedules from the UI from the cloud Discovery home or UI wizard followed by the ones that are creating them directly from the service account record we have then um many views that are still not creating Discovery schedule so this session uh you will see definitely how to create them also the minority of use it's using Cloud operations workspace in order to create them I would be very curious to find out why 31 percent of the people are still creating the schedules from the cloud service account record it's a very Legacy kind of an approach I would recommend moving to Cloud operations workspace but I would you know look at um how to uh you know where where we could improve things for you so please do fill in your feedback as to it's just a habituation or there's something special about going to the cloud service account record and doing it don't follow that Legacy pattern is what you're saying yeah so you know that is legacy and it'll be obsoleted so yeah yeah thanks for that Ram it's gonna be interesting to know more exactly of why you're you're actually going to do your Cloud Discovery schedules in this uh let's say a little bit of not old-fashioned but more traditional way now in this setting you also see how to create them from uh the for more new Innovative point of view let's say wow uh talking really quickly about a this concept because we believe that this is very important when we're talking about Cloud Discovery we need to differentiate between uh Cloud Discovery so metadata Discovery and and always level uh details and Discovery now when we are talking about the OS level details we are basically connecting via the network credentials or Os credentials to find everything that is running on the EO OS and then we're using the mid server and leveraging it through a rest API to actually connect to the service accounts and to perform a service account based Discovery for ispass and uh even function is a service or even a continuous service so in the following slide we're gonna see what we're talking about now starting from cloud Discovery and again uh we'll see different methods here and and it really depends on the use case so uh whenever we want to do a tag based service mapping event based Discovery and we only have read-only credentials on cloud provider and then we want to also do the API based Discovery Cloud Discovery it's definitely the foundational now Discovery method that is the most used in this scenario and as you can see we can discover availability zones we can discover tags storage volume data center etc etc the foundational part of our Cloud discovery then whenever we want to use and Leverage The uis Discovery capabilities um we can use the agentless IP Discovery now that in particular whenever we want to do the top-down and ml based service mapping and whenever we want to do certificate inventory and management and we want a enhanced Discovery so file based or Oracle glass and this is a very powerful method otherwise we can use the agent client collector whenever we want to do a software usage mattering or automate workflow or close the servers and we have local system account or local service accounts required and this is again a near real-time push-based discovery with the agent that you deploy eventually on your potentially even on your endpoints and then we can leverage otherwise the service graph connectors in this case we need only the read access to Cloud inventory repository as an example for AWS it's the system manager or in Azure it will be the log Azure log analytics and in this case we'll have an API based Discovery from the cloud inventory repositories this was again a really a quick introduction to uh again just remind yours all of yous about these very important distinction but now Ram is going to bring us through amazing demos for each of the possibilities that we have in each method that we have to discover our Cloud resources so run over to you you can now even share your screen Ram I think you're on mute I apologize thank you John I apologize for uh you know talking on mute uh there so very happy to uh you know uh be presenting uh a demo uh this time I want to get into a little bit of the detail here last where we uh kind of uh tapered off in the last uh call was I think there was a lot of interest around the cloud operations workspace itself so today the demo the presentation uh all of the features that I'll be presenting is through the cloud operations workspace and that should give you a good perspective as to the value and the benefits that you get out of plot operations workspace we'll get into details of the security and the architecture aspects also as the next steps there without any further Ado let me jump straight into you know the the cloud operations workspace for those who don't know around San Diego time frame we released a new store app it's called Cloud operations workspace the intent is to house all our Cloud capabilities and you'll hear more of this as we go through the in the coming quarters and months uh we will house all of our Cloud capabilities into a centralized console the cloud operations workspace is is being targeted as that place where Peter provisioning capabilities or governance capabilities or our visibility capabilities everything is coming together under Cloud operations workspace so if you haven't yet downloaded it go to the store store.servicesnow.com look for cloud operations workspace download it and uh I'll lead you through uh the rest of the steps here first and foremost in the cloud operations workspace you have a very nice uh view called the cloud resources Explorer it gives you an overall perspective of your entire landscape right you can drill down into specific uh uh you know clouds uh and and cloud types and actually drill down uh so if I choose AWS here for instance right it shows me all my AWS resources and then I can break it down to a specific region right and then within that region um if I needed I could break it down into specific accounts right and and also I can break it down to final CI classes and all that the beauty of it is any of these accounts for instance S3 bucket I can click on that chart I can go into the actual S3 bucket details and actually see at a glance again for those who have been using Cloud operations workspace is not going to be new but this is for those who are not because frankly I'm not I'm not I'm not I'm not seeing it picking up people are still not going to the store to pick up the store apps often so please do make it a point to go there and and like I said you know you come into the S3 bucket listing you can actually see something that several of you have asked in forums as in direct questions to me in cases and all that how do I establish the linkage between the object the SD bucket in this case the service account and the region and that's exactly the table that will present to you so clicking into each of these things these are references in traditional service now problems so you click on that you actually go into the resource and you can actually see the details there so you know very very Nifty and useful uh kind of uh you know top down drill down uh sort of a listing that you have available with Cloud resources uh explorer that you don't get with other tools as of today so just just want to bring that to Bear uh with uh you know before I get into some further details here but if I come back to Cloud resource Explorer I can now switch into maybe Azure and then it automatically switches to all regions again I can break down into specific regions within azure right um let me try West us and you have numbers straight away at a glancer so you know the idea is a quick navigation into into the specific details here and we have a very nice breakdown of uh total Cloud resources uh versus on-prem resources uh and over time it's a new instance I set up it doesn't have much data at this point of time I set up the cloud operations workspace today on this new instance so I just have one page data but actually if if you get more data you'll actually see the trend of uh over time as to how much on-prem resource how much Cloud resource you have so if your company is actually doing a migration of resources you'll actually see some on-prem numbers dropping down while your other numbers are picking up here so this is all by the way with the YouTube version uh this new capabilities that you have and uh yeah with Azure you have another drill down uh sorry a drop down where you can filter down to specific resource groups and and find out what's inside that uh Resource Group maybe my choice was not so great here but yeah but bottom line is you can actually switch to that there's another view called the kubernetes Explorer view I won't focus on that today we had separate session on that earlier so I won't focus on the kubernetes Explorer but intent is all equipment is resources we have a very nice dashboard for that I don't think I've even set up kubernetes Discovery here so you won't find it today's focus is on the cloud resources so just just a point to note uh you know please if you install a cloud operations workspace apart from Discovery and other capabilities Explorer and more things to come in the future feel free to post your questions uh in the in the in the Q a and uh you know we have very experience in learned people yeah Brian and we have John and I'll also step in and also add some inputs from there um let me dive into uh the cloud Discovery aspect I want to spend a little bit of time on the cloud Explorer which I hope I give you a taste of what is available there but if I go into uh Cloud the cloud Discovery scheduling here the cloud Discovery schedules um this is a nice dashboard view where you can see all of your schedules and what is upcoming and details and you know any errors and uh it's it's a combination of operational and uh you know scheduling uh kind of data that's why if there's any errors you can see the errors here uh like I said it's a new instance so the trended data is not it's not so great here but you get you get a fair idea of that there's been about um zero errors so far that's good news uh credentials and all those details if I go into the uh status I can actually see the status of each of the cloud Discovery schedules I can drill into each of those very very uh anybody who's used the older UI you know what I'm talking about here there's mid servers view where you can actually see the uh overall mid server details and all that but anyway without any uh you know spending too much time on the Cosmetics here let me get in the schedules part of it and show you how to set up a possibly a a single schedule there so first of all in the scheduling UI you're able to uh you know set up new schedules or even edit the existing schedules so as you can see here uh I can switch it in the multiple schedules I can filter it down to specific schedules right that I support here uh so for Azure for instance right I can I can see how many uh resources were picked up what's newly discovered right and uh what is the duration it took and details like that and newly discovered Ci's are all listed here absent Ci's are all just are mentioned here whatever was lost from the last time right those kinds of details are all mentioned here if I go into the status table I can actually see the status here and to actually edit the actual Azure Discovery schedules uh you know I can I can click on the edit Discovery schedule and then I go through it you know just uh step by step uh for uh people who have been on the either the cloud service account record and setting up schedules from there or people who have been on the uh uh you know the CDU or home page the cloud Discovery home home page um you know this this would be a little bit of a different experience but the intent is to give you a more wizard-like experience in this in this case and uh so first thing is uh give it a name you have chosen the cloud provider account and then you have a choice of actually supporting um a specific mid server or a mid cluster or a mid server so with Utah we introduce the concept of also specifying a mid cluster uh thereby if you have set up clusters which you are doing for your uh on-prem uh or ipe address based Discovery the similar kind of clusters can be set up with specific meds dedicated for this particular Cloud Discovery schedule right so but I've set up Auto Discovery uh Auto Select uh I can also choose a specific mid server if I do I then choose the specific mid server that I want to pick up here and uh it also takes into account which are the uh you know capabilities that have been set up there going to next I I will now be able to set up uh based on existing accounts or a new service account right and we are able to set up the schedules sorry we're able to set up the credentials we are able to edit the existing credentials and uh you know uh specify the subscription ID or the Management Group ID um one one interesting thing that is not available in the old uh cloud service account record UI is you cannot specify Management Group ID for Azure for instance right uh we'll talk about Management Group setup and and all that the intent is that you can specify the Management Group in in Azure cloud as the target of the discovery schedule and as you might know Azure management groups house a lot of individual Azure subscriptions so the schedule runs for all of those subscriptions so you don't have to set up individual schedules for your hundreds of azure Azure subscriptions but set up the management group and add the Management Group into the into the schedule and it the schedule just the schedule record will ensure that all the subscriptions are are handled there and there's also settings here they can use to ensure that uh as as and when new subscriptions might be added into an Azure Management Group right they will also get picked up there but yeah the rest of it pretty much is the same like in the in the in the old records here something called the pull events capability I'll talk about it in a minute here but uh once you add your credentials and all that you can basically test your account it's already proven to be valid uh here I'm just running it again uh and and uh testing uh you know the credentials and all that okay it's account is validated successfully and and when I go into the next step it will now also uh you know allow me to specify uh specific data centers that I wanted or if I choose to just do it for all data centers then we can do it um somebody's raised a hand was there a question that needs to be answered immediately feel free to use the Q a chat uh so yeah the way this works is you can multi-select uh you know multiple regions here right and uh you can basically yeah go through with that approach uh going to next uh Scotty seems to have a question is that some something Scotty that you can speak up on the phone and answer no I think I think we are good to go okay perfect let me just keep moving there uh uh okay and uh so you know you once you chose the regions then you are asked the standard question do you want to discover the virtual machines turning it on will ensure that using the specified mid or Auto selecting a mid you can also run um a virtual machine level IP Discovery based on the public IP of the of that of that server and if specific mids have been set up in that specific Network then those mids will be called in for uh you know based on the ranges that has been set up there and the last bit is um what is the scheduling that you want to do and uh you know you may choose to just finish and not run it or finish and run it either the case may be marking it active will uh will ensure that it appears in this UI but if you mark it inactive um you know it stops appearing in the UI and then you have to go back to the cloud Discovery schedule table and then turn it on there that's a little bit of a user usability Improvement that we need to do but but yeah um so yeah let me just go ahead finish and save it then it saves everything and uh you know uh if it if it were supposed to run it will start running now um that is about the General Schedule itself while while running you can actually find some more details about you know uh how the discovery has been running the status as I mentioned what devices are being obtained so sketch deals are actually coming in there let me go back in there I wanted to spend a little minute uh a little time to talk about um the pull events that I uh did mention earlier so um for those of you who have in the past used the Azure alert configuration you might have known that there's a little bit of a security issue with the Azure alert configuration uh that is used in the in the Legacy manner so we have improved the whole story uh again starting from Utah onwards Utah release onwards and if you install uh you know the cloud operations workspace and you're on Utah release you will find this nice feature saying cool events which is very similar to the way it is on the Google schedule for instance because the Google also is doing pull events connecting to Google stackdriver in this case we connect to azure uh resource changes and we run the resource changes API and we get all the latest changes that have happened in the in the last interval and by default the schedule uh runs every 10 minutes to get the latest changes in the last 10 minutes uh if you set that down to five minutes accordingly adjust and you'll get the changes uh in the Azure Cloud across all your accounts if you have set up a Management Group here by the way this is just a subscription it's not a management group but if you set up a Management Group across all your subscriptions in that management group it's going to pull all the changes and this method we found it to be phenomenally more scalable with uh you know the with the Azure cloud and uh we're not calling patterns for each event that comes in we're actually doing a more simpler approach by collecting the events and then running uh a sort of a transformation on those uh event payload and converting it into cmdb records and instances there just something to note there uh we'll we'll go into some more details on that and the the handling of the event driven Discovery starting with Utah is also moving into the patterns app itself so just ensure that you're on the latest patterns app you'll get this capabilities and uh you know you will you will be able to uh Drive the story uh for the Beyond right I'll talk a little about the migration from the old UI old Azure alerts configuration to the new event uh pull a kind of approach here there's a migration UI for that I'll talk about it in a little bit but in general I just wanted to give you a perspective of how to use this UI right if you want to set up a new service account that can also be done here within the schedule you can go ahead and you can add the credentials you can provide the name of the service account all that can be set up here credential Alias uh the as is the case with Azure you can do all of this stuff the management so as you notice here is ask for Management Group ID so you can provide a Management Group ID and then you could URL is pretty much for connecting to National Data Centers or Regional data centers or even to grab Cloud right that's basically the idea behind the URL in most cases if you're on Commercial Azure cloud just don't have to modify this uh URL page there um so yeah that's that's over all the general uh perspective of uh how to use the cloud Discovery home so if I go to Cloud Discovery home and schedules again and I click um we Sorry ROM for interrupt new we still we have now a few questions that are come via q a sure or I guess you can even see them yourself sure for sure and also in the meantime a couple of them sure sure any any suggestions any suggestion sorry yeah no worries um so they had so Scotty had a question around saying an up accessor account so anywhere it's fine name of the cloud subscription subscription post the discovery schedule completion yeah I'll I'll just uh I'll just talk about that I'll show that in the demos cardi um the accessor account set up within uh the connection with the accessor account setup uh done using cow yeah I hate to call it cow but it is cow finally abbreviation waste so but yeah um setting of access account we'll talk about it I intend to cover some more details about that um there's a question about Azure service graph connector doesn't appear to bring in the IP address on the service here is that being worked on to entertain attributes thesis you connect as a populating um I'll have to check back on that uh if if in general you're able to uh connect to the this for Azure right Azure analytics service you should be able to get all the details there um if if nobody else has an answer or a thought around that uh we will make it a point to get back to you uh on that but yeah Frankly Speaking you should be able to get the IP address if it's not coming in that's uh something else that's missing there yeah Rob I'm looking into that one thank you thank you um has asked a question uh anywhere to find the name of the cloud subscription post the discovery schedule completion um I I can I can I can go through I can go through that in the UI um Cloud Discovery seems to pull apps and resources in the previous and then we can leverage that to perhaps control their life cycle uh yes it should be possible uh we haven't dig deep into that but it should definitely be possible as to that but that said deletion strategy uh from our side should take care of that and when delete strategy runs you know the way delete strategy works is when when a resource is not found in the in the current schedule from the last run there's a difference there's a Delta it's not found it marks it as uh you know absent and it knocks it as absent you have anyway uh a br or some kind of an approach that you can a business rule or something that you can approach uh to actually drive that you don't have to necessarily look at this one you can just go through the resource record uh the the CI record and when it changes to State uh install status as absent then you know you can you can take some steps on that okay um run just really quickly for those of you that are asking if they're gonna get a copy of these slides yes you're gonna get a copy in a few days you'll also get a recording in the same page in the community page where you enrolled into this event if you went to that page but either way you will find it in our community so yeah yeah but that's it we haven't spent too much time on slide system it's more the demo and the YouTube video will also be available to you to answer your question okay um there's some other questions here um let's come back ground and we'll take a look at this back again okay so let me switch over to slides uh here right um maybe before that we want to run a poll um I'll I'll just go through Jan and maybe we can start off the poll after that uh the question is how are you managing your Cloud credentials and select more than one if more than one applies you might be going through a vault which could be a cyber Arc vault which we support out of the box we could also be going through other walls that we might support out of the box or not please specify also which Vault you are using especially if it's not supported I'd love to hear we'd love to hear what is there uh for for AWS accounts specifically again this is where if you're if you're you know having multiple cases where you're doing AWS plus Azure and all that for AWS if you're specifically using mid-based azim Pro uh go go with it and then securely starting username password in this in the service now it's secure enough all right but your Cloud team may not always agree to it so that's also something to keep in mind but but yeah we're seeing the poll results coming in probably another five seconds five four three two and one let me go ahead and end the ball okay thank you um yeah it looks like uh predominantly large population uh almost two thirds uh storing it inside uh service now and uh this mid-based resume rule used by about 28 percent of the people a cyber art thirty percent of the people that's a good number uh very very good to know again as I said if you're using other walls please specify in the Q and A or in the chat as to uh you know the the Vault that you're using there so let me move on here I want to spend a little bit of time about uh talking about you know and mass discovery in general uh I think many of you it also explains why you might be still doing a traditional sort of a approach having individual schedules for each subscription or indeed or schedules for each account you may not have moved to a what I call as discovering clouds and mass uh that's because you're not still using the new new UI so I'm going to the new UI will already give you some benefits of uh being able to call Cloud Discovery across multiple accounts there in the AWS context you use the master account uh kind of an approach there where you can run organizational discovery and there are you know the accessor account uh kind of approaches to do the uh secure lower privilege to higher privilege transfer you know in terms of the role as a role assumption rule changes that's what the AWS we already covered on the Azure side uh how to set up Azure Management Group right I want to talk a little about uh that and uh also where you can look up in the AWS in the Azure console as to where you can check your management groups and uh the last bit is uh the gcp where again uh if time permits are will also show you how to set up in gcp uh the scheduling uh to run across the entire organization if needed or if you're you're you're using folders in a gcp cloud context then you can set up the integral folder IDs and uh for everything under that folder all the projects under that folder will will you can you can manage it through one schedule right and it just just runs we've seen phenomenally large number of uh accounts and subscriptions being managed through this kind of an approach there uh most recent being a large customer of ours uh who's using uh one schedule to actually handle around 5000 subscriptions in Azure right and it's working just uh fine of course it's a pretty larger setup more worker nodes and all that but yeah 5000 accounts in one schedule that's what's being done there and that's apart from any other even turbine discovery that you want to do right and that even driven Discovery in parallel with the cloud schedule Discovery will ensure that your cmbb is upgraded something to keep in mind there the um a very good resource for AWS going back to AWS and I'll switch into the demo shortly there the very good resource for the AWS assume role setup is the KB again for which we provided the nice QR code there so you know the deck will be shared later so you can also look it up there it can be link is also there so you can you can go into that um let me switch now into credential into the into the discovery schedule setup in the in the UI here again let me go into Cloud Discovery home and going to schedules here right um let me take you through an existing setup here will be a little more uh easier to show right so if I go into edit mode it opens up a discovery through assume role that I've already set up here as you can see auto selection of the mid does done here in this case I have actually set up credentials for the the master account and I will be switching into a a member account by using assumed role here so let me go into the next and what you're seeing here is actually the service account here right for which there's an account ID and there's an account for access which is the master account that's been set up there right so just uh you know if I go to new service account and then come back here and then I I choose that same account here I choose this it automatically picks up because my uh cloud service account has been set up with that accessor account and the accessor account has been set up to the show in a minute here with this particular role here again uh please keep this view this these these links confidential because some of these account IDs are being shown here so do not share widely my recommendation and once you have set that up you can go ahead and test the account and yeah sure enough it should it should work here because um everything has been set up already and I should go through with that let me explain the background information uh as to how this has been set up by by showing you when I go back to the slides as to uh you know what's what's happening here I'll let this validation happen in the background while I I move to the slides here a very good schematic that uh Ryan here has created thanks Brian for uh excellent schematic it's a very very useful uh slide to explain the whole story here for those who don't know you know AWS basically the concept of the master account is very key there most organizations today that we're working with if not all are using the concept of master account and member account so there's a very high level in the hierarchy the master account and for that master account uh you know the there will be credentials but not all uh Cloud teams right that you're that we are typically engaged with are ready to share that master account credentials they prefer an approach to do a a trusting uh kind of approach without credentials right as I said earlier in my case in the demo setup that I have here I have set up the credentials for the master account but uh we could follow an approach like this the uh there's something called the accessor account the accessor account is typically having a lower privilege by default it might have a uh you know the the access accounts service account will have a read-only access or some custom permissions to enable discovery and uh it'll also have additionally a custom policy to enable the azim rule into a master account right if you have a mid server running in ec2 you can associate the mid server with the instance profile of this particular accessor account right basically that that instance profile role can be associated with that with the mid server here the accessor account and at the mid here now uh basically assumes role into a master account and when it assumes roll into the master account the master account provides read-only access and it also has obviously some roles some permissions to run the discovery additionally it should have a very nice uh you know Point here that Brian mentions a custom policy with custom roles to enable azim role we'll see how that looks in a minute here and it'll enable the assume role to all the member accounts right uh to one or more member accounts definitely for sure right and then organizations read-only access is also needed that's the third Point that's something to keep in mind to enable the discovery of the organization structure right uh if uh you know you you you would kind of go about uh you know getting all the member accounts then you need the access to the organization right that that's a very important thing to keep in mind that now when the assume role happens the master account access is obtained and when the master account access is obtained and you have the ability to assume role into these member accounts you know the rest is pretty much about an assumed role uh uh you know permissioned being available and that rule will allow this member accounts uh you know access into these member accounts there but again for the member accounts also you need a uh you need a trust uh Authority if you see here the member account has the trust Authority set up to the master account so the master account is trusted to actually reach into the under account where their Rolex is there that's something to keep in mind and configure our own instead right with with that basically you you're able to kind of switch from a master and to a member you can also set up the accessor account in a in a different way where you were doing a something called a cross assume role this is a orgasm role but you can also do a cross assume role with a cross assume rule the accessor account will possibly reach into one of the member accounts here rather than into the master account and is able to switch from the member account into another member account here again the trust and all that has to be set up there has something to keep in mind there right and uh just to keep in mind uh that additionally uh you have to set up you know the orgasium role configuration on the servicenow side uh such that uh on the on the service now uh side uh we are actually specifying which is the role to use in order to switch into the uh into the into the member account set right there's so much information uh it's a heady topic right feel free to bring up your questions uh in that area but we'll switch into the actual demo part of it uh here so I'll just give me a minute here okay there you go so What's Happening Here is uh and I'll show you in the in the in the uh in the actual cloud service account uh record here how this actually looks here so let's assume right you start a new here right you specified what is the account uh which is the specific name for that account which would be your account here right and then you specify the account ID whatever be the number right and then you specify the credential you don't have to specification that's the beauty of it you may actually go into if you where to specify the credentials Things become simple you just go ahead and you're set right no issues there and the complication is least in that in that in that case uh the interesting bit is you can actually specify uh or or pick which is the account for Access here that you want to pick here so so I could choose this and when I do that there will be a lookup that will happen against the account for Access for this particular thing and actually I will be able to pick up an access role name the Arn of that access role is actually uh Pro will actually be provided here right so you'll see all this happening in a minute if I if I switch to the Leo account here it's actually picking up all of these details and service now uh uh SW as the as the as the account that is provided as the access accessor account there and uh so in this case though the it's a little bit different from the picture I showed you because the target account here is a member account so I'm actually connecting into a member account and actually providing the the accessor via the the the master account here and this specifying the role to actually pick up there right with this uh when I as you noticed the earlier I already run the validation should be good and uh I can add as many as the rest of it is pretty much the standard stuff there and uh I can just click through and there you go I can just go ahead and finish and run the run the story there switching back uh into the deck while it's running right what what we did just now is actually we went from not from member to master we actually did a switch role from a master to the into the member account uh with the trust being in place and actually did a targeted discovery on a specific member account that's basically what's happening here but the reverse of that is definitely possible as I mentioned here right a couple of points to note here if you're using a custom role you need to add that uh role into you know this uh service now table setting as mentioned earlier and also very important if you're doing a organization level discovery just remember to actually add this property here Auto refresh sub accounts and ldc's because that will alone ensure that as more member accounts are added they are taken into account for the for the subsequent Discovery events otherwise it'll be a static set of accounts that will be taken into account or you have to manually add it right that's something to keep in mind there right so just points to note there and as I mentioned earlier the schematic uh view of things again I've blocked out the account IDs but uh the schematic view is there's a servicenow service uh service now software parent account no it's it doesn't have a parent right it's the it's the root account uh sorry it's a master account and the master account has a permission to zoom into this so This is the assume role settings that is given as part of the policy on the AWS side and and that will assume into the your account which is the member account in this case and that's exactly what I showed you in the in the in the UI there okay so um yeah let me stop here on on on this front and let me switch back to the UI there obviously this is running and all that right it's going to pick up the resources and come back but overall you get the perspective on uh uh how this is being done I'll pause a moment here to see if there's any questions specifically around AWS uh assume role because yeah it's a little bit of a you know conceptual understanding that's uh needed you're happy to clarify any doubts that you might have again yeah we have a few I believe most of them have been answered via chat I don't know Brian if you can bring up anything else some cautious of time as well we only have 10 minutes so maybe around sure sure sure okay gotcha um Brian feel free to let us know if there's anything that that should be answered live um okay so with with that said um let me also switch into the the sorry the Azure management groups discovery I want to talk a little about that uh very crucial and important to keep in mind as Azure management Discovery sorry Azure management Discovery you need to be having a root group or a high level management group like this one and uh instead of specifying uh what could be a subscription ID which will normally specify in the schedule you provide the management groups ID or the tenant root groups ID here in the in the in the schedule here so you take the schedule copy it and uh you know paste it in the into the into the schedule here when you're setting up the schedule account right when you spray a new schedule here you choose the provider azure new Azure or something right okay and then you Auto Select the mid server I'm going to that and then yeah okay azure mg and then here's where you put in that you know that Azure management group's ID here and then choose the credentials as always and then test accountant and if you want to start cooling events then that's that's also something you can do from here again if you're on the right patterns app if you're on the right UI level uh the right Cloud operational workspace and on Utah family release right um but yeah that'll solve you a lot of problems it will sequentially let you uh handle the multiple schedules there your conflicts between schedules can be resolved can be reduced by doing that um let me switch back into the into the deck here again feel free to bring up if there's any questions around that the last bit is as I mentioned earlier Google organizations and folders unfortunately I don't have a access to a Google Organization setup and a Google folder setup oh no that's that's not right sorry Brian has been kind enough to again give me a uh his setup where his personal Google account he's actually set it up there so I need to hop into this instance again but come come back to that in a minute here so there you go I'll come back to that in a minute here but let me switch back to the deck so the idea is uh you can set it up in such a way that if your project is set up in such a way that it can access the organization with the right permission then the when the when the Google project is set up uh in the in the schedule it'll automatically connect into the organization level and pick up all of the other projects inside the same organization there so setting up a um a single project like test or STG or fraud or whatever it is just set up one single project and give it the access to connect with the organization by giving the organization viewer access and uh it'll One schedule will basically pick up all of the other projects and do the discovery for all of them so Google again running in Mass is like going to be a lot going to is is actually a lot a lot easier again you need to be on the UI the cloud operations workspace or the even the cloud Discovery home but yeah preferably Cloud operations workspace should be your go-to right from that standpoint that's one approach to do a Google organization from a project level another approach is in the schedule itself provide the folder ID like marketing Eng or apps or you can also if you if you were to give a folder at a lower level like SAS here then it'll pick up just what's below SAS right but if you pick up a folder like marketing this is nothing under it right so there's no point in giving that but if you give SAS or engineering or even America for instance all of these will be picked up here so the schedule will pick up all of the projects in the subfolders and folders and you'll be able to run it at one shot in one schedule there Brian there was a gacha in this area uh do you want to probably mention about the the folder discovery it was I I failed to recollect all right I was uh I was uh responding some other questions uh what was the no the question the question was there was a gacha in this area about uh the folder Discovery when there's a very uh you know deep rooted uh hierarchy uh there were some issues around deer collector that that problem that came up in a couple of uh instances uh no I think that what I've run into before with this is you can't use the top level organization if you're doing the folder based one it has to be an actual folder ID uh so it's the gcp will give each folder a numeric ID that you would have to use unfortunately you can't use that top level organization uh for that you'd be using the related projects um to get all the the projects instead of the folder based one yeah so if you're going for the organization Discovery use the project and they will automatically pick up from the organization but if you're doing folder based Discovery it's top down so start from the top folder uh you know and then you'll pick up all of that good call thanks thanks uh for that Brian um so let me switch back into the UI and real quick uh bring up uh Brian's schedule uh here where I can edit it and I can quickly show you proof that you know we actually have the the projects actually uh discovered uh here so so again if it's if it were a folder ID uh as in this case you'll actually see that it says this is a folder when you click on test account it'll discover and you'll pick up that it's a folder and you can discover all the projects in that folder or you can discover specific projects and when you start to discover specific projects you can choose the projects that you are interested in you can add as many projects as you want there so very Nifty and nice looking UI there and by the way the pulley went so much similar to the weight you saw it in Azure that's also available here right and then the rest of it is pretty much the standard stuff there right okay um covered a little bit of the event driven Discovery aspects there if I go back to the UI here but uh real quick uh just two key points again complete details available in these in these links here Azure change processing I talked a little about how you turn it on it's a again a very simple switch that you turn on the schedule the migration aspect I'll talk about it in a minute I'll get back to the UI and talk about it AWS events very much as before except that we've brought in some changes around the parallelization I won't spend time on the demo there uh if there is interest please reach out I'm happy to share create and share a specific video a 10 minute video around what are the configuration steps around AWS events and how to parallelize and how to handle up to 2 million events right so that's something we've seen a tremendous speed Improvement in that area there again this was the slide from last time showing what are the demos but pretty much we covered all the demos that we wanted to cover there um any questions before we uh we close uh that we need to cover on yeah I think we can go around we only have three minutes and we answered most of these uh questions okay the only uh the only question that they had is there an implant to have the Azure skill set member discovered as VMS yes yes that's available but uh I believe the May release so the patterns app if you're not on that please upgrade to that the skill set uh VM skill set member discoveries is added there just uh something to look at and we are making also improvements about availability zones and availability sets and availability zones and availability sets and all that there was a little bit of a misnomer in that area that's coming with the August release but yeah the May release already has a VM skill set uh should should work for your case that's fantastic rum so if you can just keep moving these lights here are their resources guys that um for you folks that are attending will be available and very insightful next slide please um as I was saying via chat and not specifically for only that question but if you have any ideas on how to improve our products please feel free to use our portal and you can see here the link to submit your ideas so whenever we have 10 or more of the same ideas it will definitely jump to our PM team so we'll make sure to implement them in our process as much as possible next slide please run then please make sure to try out all these capabilities that we saw today and showcase the value to the stakeholders within your company and really prove them the value of our features then connect with your new friends outside of this Workshop because we saw a lot of your co-workers and sorry another of your peers from other companies and yeah as rum said don't forget the cow Cloud operations workspace we are here for you so please feel free to ask the service now subject matter experts for help and eventually please feel free to share your success with us next slide please rob and also uh join us for our future webinar sessions and meetups and vice coming in this call you will be prompted to all of our future sessions and so you're making sure not to miss out on anything and then after this live run um yeah thank you very much everyone and specifically thank you very much RAM and Brian for your leadership and your expertise this was another great session and we've seen a lot of interest so thanks everyone for attending and for participating via the quiz polls uh q a part we really appreciate your commitment so we're very looking forward to see you next time and yeah thank you thank you again everyone see you soon bye-bye thanks John thanks Brian bye thank you guys
https://www.youtube.com/watch?v=fHJnhCdV3MY