logo

NJP

ITOM Visibility and Cloud Accelerate Academy : Service Mapping leading practices Part 2

Import · Dec 14, 2023 · video

right I see good number of you have joined already so I guess we can start it so good morning good afternoon and good evening everyone and welcome to the session today it's actually the last session for 2023 of our itone visibility and Cloud accelerate webinar series and um so glad to I've had so many of yous I see familiar faces uh between different participants thanks everyone for joining today and in general for having supported us throughout the year it's been a very successful webinar series uh for this year as well following the positive trend of the previous year and that's uh thanks to the great contributions of Steve Emerson and everyone else so for today we're going to talk about again uh service mapping leading practices and this a follow-up session to the um to uh the previous session that we hosted two um months ago in particular this session not only is part as we said of the visibility and Cloud accelery webinar series but also of the live on service now webinars which is the interactive event series that helps deploy adopt and really achieve value faster with our Solutions uh you can either uh see the schedule by scanning this link right here or thanks Kim you can go directly to the chat and click that link that you will find right there as usual for those of you that are not used to the housekeeping items please make sure that everyone is muted and uh make sure to use the Q&A function if you want to ask questions and while you're doing that make sure that you introduce yourself we love to know who you are um we'll have a poll today today so please make sure you're engaged and in general throughout this session uh make sure to participate and ask as many questions as you will we're here to uh answer all of your questions and address any potential doubts and this session as per the other ones will be recorded and will be shared on the service now Community Forum uh after the session in particular after this session um ends you'll be prompted to fill out a short survey that's very important for us you've been doing a great job so far but please make sure that you fill out that survey and you include any feedback that you could uh potentially have to share with us now speakers introduction for those of you that don't know me my name is John Mario deluigi and I'm part of the outbound product management team for item covering itm visibility Cloud accelerate and Dex and together with me today we have one CE again the Superstar bill ifin so bill please introduce yourself good morning folks and Friends uh my name is Bill llin product success technical director working in the itom workspace and um happy to be here today I was formerly a practitioner from 2007 to 2018 then I joined service now as an itom itom Ranger work in again with service mapping cmdb csdm Etc that's great Bill thanks so much uh many of you will be familiar with Bill he's definitely the biggest expert you can find out there for service mapping so it's a honor to have him on board again today and offline by the way we're going to have other experts and Superstars today we have steam Emerson that you might know already we have Kim rasmusen and we have Ryan Zuli that will help us address all of your questions so you definitely have a great opportunity there to have all your doubts um clarified now safe Arbor no is for today as well we're going to make some forward looking statements so please don't make any purchase decisions based on what you're going to see today and uh last but not least uh we're going to have two sections today so uh we're going to go through the um slid so the a theoretical small introduction just to recap everything uh that was said last time and to finish up on the content that was not covered last time in terms of the service mapping methodologies and particularly this first section uh starts with the why of service mapping now if you're familiar with these workshops with these webinar series you are definitely familiar with this slide where we illustrate the value of of having the a service aware cmtb so the cmtb is the data foundation for your company and for your business and clearly is the data foundation for service now having a data aware cmdp means that not only you have all the configuration data of all of your Stacks both on premise and on cloud and everything that resides within your environments from a technological point of view but it also means that you can then correlate the information about your technology stack to your application services and ultimately establish the impact that they have on your businesses we'll see in the next slides here we can clearly see uh how it is possible uh to then have many many different use cases uh that will be covered uh but they were not going to go through each of them clearly today but it's very good to keep in mind that uh a good service aware seem to be enables all these different scenarios now we can have clearly a um a different set of uh levels of stages of awareness let's say for the cmdb um first of all we can start with the Technology stock so the technology layer which is the very basic step of awareness and that's achieved through discovery so you can discover configuration data about your entire technology States uh that is both on Prime and on private managed or even public clouds we're talking about databases web servers uh we're talking about middleware etc etc so that's a very basic step of awareness then if you want to step up a little bit and have uh the application layer for in terms of awareness then you're going to need service mapping service mapping will exactly correlate how the technology layer is related to your application services and how the application services are impacted by the uh different um elements that you have within your technology environments and then the ultimate stage is the business context so how can you relate the impact that we just talked about to your business in general so that's achieved through the uh csdm the common service data model and as a matter of fact this is the latest and greatest version of the csdm for those of you that are not familiar with the csdm I'm not going to go through each Single part of the csdm we just want to focus today on the application service first of all which is clearly at the center of the csdm and that correlates and that um merges let's say the outcomes and all the interest let's say of the different parts of your business and then we have the configuration items in the dynamic CI groups that together with the application service are extremely vital for your service mapping purposes we clearly have a big importance also of the service owner together with the application owners um uh but again it's very important to see how these three elements are vital for service mapping uh purposes now before we go through the different service mapping methods is really important to understand why you should have a service aware cmtp to enable all the different uh use cases we're talking about not only item but even sport itm uh or even SPM we're talking about APM DPM Etc um so to support different use cases so so if you were um uh in in a case where you would not have the knowledge of how the application services are uh and and your technology state is ultimately impacting your business then you'll have typically a longer meantime to resolution or it will be hard to understand the ownership or even the uh customers that are impacted if there is a particular outage uh it will be uh possible to have aages that are completely unplanned and it will be in general hard to allocate resources because they won't be then allocated uh with the based on the specific issue whereas if you adopt a service OFW cmdb and you really have the understanding of the impact of your um technology stack and application services on your business at that stage you will definitely shorten your meantime to resolution it will be possible uh to do proper change risk assessments and related approvals uh you will be able to really understand once you have an outage which customers will be impacted by that um you will have uh the outages that will be uh planned and they will be informed and managed and uh in general you will be able to allocate resources based on a specific issue that will arise now today I asked for a very engaged audience so please make sure that uh we participate to the poll um if I can I cannot seem to start the poll from here but hopefully uh anyone else is going to be able to start it so uh we want to know which of the following statements is the most accurate for your organization and again if you're not able to view the poll please make sure to use the Q&A to uh oh actually the poll is right here so uh please make sure to let us know um uh how are you uh what what is your current business situation basically so are you currently discovering the resources or uh in general are you discovering your resources via item discovery are you leveraging otherwise the service R connectors to populate your CB and in case you are discovering uh resources and mapping the application services please let us know now in this case I know that you could be somewhere in between but please make sure that you select just the statement that describes better the situation in your specific case I see a lot of um questions hold on oh there is apparently a problem with the poll that is been shown so uh I would just end the poll uh for the time being and please um I see that at least some of you still selected the poll based on the uh on the order of the description so yes thanks for letting us know but already um many of VI have replied to this poll uh sorry for the technical issues but we can see I will just interpret the results so far so for the second option so most of you are discovering the sources via item discovery some of us are primarily leveraging sgcs to populate the cdb and that's related to the 34% of use then uh we have uh the rest of use that are either not currently discovering the resources or leveraging uh the uh service mapping capabilities so um we apologize for this technical detail it's the end of the year perhaps that had an influence in this case but U that was it for the introduction part I will now um give uh the rights to present to bill so Bill over to you please thank you Sean so good morning good afternoon good evening once again and we're back part two and again we're going to focus on how do we up up dat or maintain or populate originally our uh application services to get all those outcomes that we spoke of earlier to revisit those approaches that we covered in part one that was the dynamic CI group manual and tag based approaches to populating the service maps and uh today I'm going to focus on our top down with the use of either service suggestion which is not highlighted here but that's going to be my first demo and then when you have a top- down discover map already what can I do with you know maps that are seemingly stuck I can show how connection suggestions can actually move you further and then also look at pattern-based connections but I wanted to share in that regards some best practices when it comes time to customize or configure the logic according to your Enterprise so um really three areas service suggestions connection suggestions and best practices around patterns around those connections for patterns so uh going to just jump right in and the this particular demo focuses on our uh machine learning solutions to service mapping and Hope hopefully we'll get over to there there you go and that is facilitated through our service mapping workspace and looking at the homepage here it gives me a quick um background on how much I have accomplished in this machine learning space uh if some of you may have already seen the capability here with uh Steve Emerson and the itom visibility workshops that were held uh around around the world actually this year so um we're going to be revisiting that same demo with the Powershell application but essentially the dashboard comes with an a component or workspace comes with a component here where we want to look at the Readiness and the critical success factors here are essentially these prerequisites and the primary one that I want to focus on is the application dependency mapping uh probe data uh where you're pulling the processes that are running and have open ports and established connections and that data is being populated through your horizontal Discovery um schedules so that's where we're going to uh begin and in the space what has happened with those running processes during your Discovery you can have um many many pieces of information that comes back but not all of the pieces of information that's coming back is going to be um consumed or useful to the machine learning what so that mean we require at least 10,000 records here to get the process to start and then the information that's being fed to the machine learning algorithm is the the records from your discoveries that are based on excuse me that are based on what's listening or what's connecting so let me go ahead and change that so so um kind of setting the uh expectation is that if I don't have a connecting going out I can't be a top level CI and if I don't have a listening Port open I can't be coming into CI on a c map and if I have both then I'm kind of being a pass through so all of this information with the IP the port data and the command line with the parameters are being clustered to come up with um Solutions or targets for for the the uh service suggestion so this approach is focused on I don't have entry points I don't know exactly uh all the applications in my Enterprise what we're going to do with this data is cluster it together and then look for those connections if you will that build chains from the top down to the m the middle and to the very bottom and typically you know looking at an inter tier application that could be a load balancer to presentation or application servers down to your database layers so the first for this first demo of service suggestion what chain you know were we looking at and those get displayed after the uh background jobs work and produce those candidates and let me move back over to that and that's where these candidates are provided based on the number of um connected processes and in my particular exercise here we're going to look at this particular um application if you will based on the connections that were found from uh the different servers and I was going to demonstrate those here so those process to process connections there's a lot of them out there that are being put together you 1 to two 2 to 3 three to four right in our Hops and in this particular uh demo I'm going to look at the ones that are based on Powershell now there's many Powershell connections out there uh but the one around the prediction around cluster 13 that is the one that matches my application or at least I recognize something about it right I have something listening and then connecting out and I can see that I have uh several servers here in this prediction so in this case it looks like I got uh four connections coming in and going out and that's exactly what the um process of building the canid is done done for me so I can actually look at the preview of those connections so and actually here based on the most recent discovery this is a predicted model but what we're going to do is actually map this as a service let's go back and we're going to map the application so this should be familiar if you attended any of the uh visibility workshops this year and and because it is still truly topped down it's going to go out and do host detection on all of those noes that you saw in the preview map and for the sake of time I'm going to let that run in the background now it actually showing more of the map right now if I refresh it it actually was able to look at all of the stuff from the horizontal Discovery and actually built it out so actually uh bonus today it ran faster than anticipated but what it did is it started with that top level CI based on the the port and used it as an entry point it was able to determine that the I server was my top CI and then pass through those connections to get to the uh server layer or the applic a logic layer and then ultimately the um databases and you can actually see the data as it pulled it from the process to process connection and extension data that it actually pulled it through had high confidence and it added by rule some of the connections now not not all connections are important and as you can see this High Port here wasn't important so it didn't have a high availability it did not map it you may or may not want to include it in your map and that is something that you can decide after the maps have been generated so that is a quick nutshell for the service candidates here as you can see there's many other uh distinct chains of Ip to Port connectivity that can represent other application Stacks in your Enterprise all right let's go back so what we're going to back to here is um going to look at connection suggestions but with that connection suggestions now we we were looking at service suggestions because it was looking at longer chains but with connection suggestions you can take an existing map and have it complete and revisiting our uh our presumed application stack from our part one session here I've got a software load balancer server that front ends three Apache servers that connects to my single uh database and the application here is Media Wiki similar um content engine that supports Wikipedia that's out in the open source Community excuse me so let's go and check that out so moving forward right this is our my service that I had started with right and I'm using out of the box I'm using out of the boox patterns and normally the what I would encounter here right I would get my URL I go into that first process or that first load balancer and I don't leave I I get stuck on the page if you will right and being stuck on the page how how can I further out further develop or discover my service map and that's through the connection suggestions function it's looking at the same uh core data of those running processes let's go back to the running processes and I have some idea of the architecture of my application right again I have spelled it out in the previous slide and I should be able to have those same connection chains and where the connection suggestions come into play here is that it can continue drawing those hops for me if you will which was discovered through the um um ADM probe in my horizontal Discovery I have a number of servers that are uh actually um yeah loading up here and uh let me go ahead and emulate that data being loaded um let's see here we go because each one of these servers right like starting with my ha proxy would have listening on and go outbound um connections so the I would be predicting that these these are my um application servers my Apache servers and then my Apache servers that are running httpd would have they're listening right it's coming from and connecting to so that's listening here from the AJ proxy and then connecting to my databases so this is typically my SQL server for 3306 so through the S connection suggestions I see that I have another layer that can come through here right even though I have not proceeded anywhere right if I look at my actual Discovery log it identified my application but uh as a generic application but I cannot determine how to get from or get out of it Downstream and that's where the connection suggestions come into play so what I'll do is show those connection suggestions here I will add them and notice that they're added manually and it tells who done it and because the data was already discovered in the cmdb it was able to con make those connections from the horizontal Discovery and I didn't have to write a pattern for that and so that's the the power of the uh ml connection suggestions is that um I did not have to um begin configuring or customizing the pattern so I'm going to go ahead and Discover it so that perhaps I might get the next layer right so it's going to continue to look at that and if you notice it's already found them from the Apache servers I have some connections that are not relevant to my service map these are actually Cloud strike connections versus to my database so I don't have to accept every connection type here but I can use the ones that are very um specific with those suggestions because if I didn't determine as a target of something that we've already discovered it would discover it could also be a target of our application finger printing so it still allows you to build out a map even though we may not have the application pattern to fully identify it but through the ml uh application fingerprinting it can give us a candidate name so like you saw Powershell 13 you might have something here that could be um my SQL D Dash or underscore four so the this is probably very um deep in the weeds but this is actually where the ml suggestions can help with service maps that have already begun so um to continue this uh Discovery I know it's going to take a little bit of time I can actually build one service suggestion here manually and it should load it up but what about the other two as it's discovering let me leverage some of our out of the boox rules we have a rule that identifies um databases based on their target class type which comes back through the identification section for those applications if I activate this now while it's doing the discovery it should connect them for me as it's doing the discovery again while it's doing it just want to prove that there is no connection suggestions being actually or connection patterns being used to to actually get those hops that's coming purely from the connection suggestion function right so all my connections are red here and another indicator of that uh behavior is that these are going to be if I link these right these connection suggestions we can tell that they're TCP end point type that's from the traffic based data this should be TCP as well so each one of these layers is um identified through through the the connection suggestion and it creates TCP endpoints so that's how you uh can confidently know that this came from the machine learning and I want to take I guess a quick pause here to to uh cover any questions was there anything that um we wanted to revisit or ask again great Bill great timing so we have a couple of questions that might need to be answered live so the first one in regards to connection suggestions uh Joshua is asking will the map update with infrastructure changes as an example adding another Apache server removing one of the Apache servers so the short answer is yes when you activate Global or local uh connection rules so as you saw here and that's what part of the one of the processes involved is once you begin uh using this feature you can come back and create additional rules that match your Enterprise so you may want to uh along with application fingerprinting if there was a particular pattern that um resulted in a target class or a particular map that had that didn't go anywhere right because the connection pattern couldn't find the config data or didn't have access to it you could use these Global rules and local rules to keep your service map up to date so these rules in tandem with the ADM data you satisfy that connectivity function where where you would use to use a pattern to read the config data now we're using using live TCP data and the rules to say if I see this class you can create it as a port you can create it as a command line right you can build these rules according to what you can find on the running and discovered processes and their ports great thanks Bill and we do have many many questions so first of all thanks everyone for the great engagement here so this was a question that has been asked a few minutes ago but still I think it's worth covering before we keep going head so um so vinil said that they're trying to implement in service mapping uh but mapping is trying to connect with public IP instead of actual IPS and how do they overcome this issue right right so that's also something that you can find here in the con suggestions let me go ahead and group by decision as well so I'll point something out here uh to answer this question and cover the rule adding it um so here's some external IP addresses that are to Cloud strike typically right we can exclude them we can also cre if necessary create a boundary or a temporary map that identif I this outside IP address as a placeholder map so that placeholder map will definitely error you'll get a red excuse me a yellow triangle but when you're doing the connectivity on either a top down discovered with patterns or top down discovered with connections suggestions because it has the entry point matches this IP import because that's what you would use in that temporary placeholder map then so it would render as a connected service on your desired map and as a submap or a child map or that placeholder map it just will still be a yellow triangle so it gives context it would be treated as a subordinate um service map but you would still not be able to discover these if they're third party providers right because you're not going to be able to um discover or probe their environment thank you Bill now last question and then I will let you keep going for T Based Services specifically is there a Best practice for populating an existing service via tag based mapping so the the the with tag based mapping right the the expectation or assumption is is that you're properly tagging it when you're provisioning those assets be it Cloud assets or VMware assets so first you have to properly tag them and then of course not every team is going to use the same key Valu so they you would have to do some analysis to understand those key values to be able to properly create your tag categories that was something that we covered in the in part one so once you've come up with a tag category that can normalize those various categories then you're prepared or ready to do families and the last part of the answer I want to give is that if these are um Azure AWS I believe Google Cloud as well you can use the tag governance um plug-in from the store to help build key policies key value policies such that if they uh aren't meant you can use the remediation functionality to actually push the missing key back into the cloud and in addition to what was already available being able to update the cmdb key value table with the rule it doesn't doesn't push it to the cloud it just makes the data whole in the cmdb but preferably you would use the remediation function to to fix it from the source nice thanks Bill I'm aware I'm cautious of time we have 20 minutes left so please keep going okay so the the because we're on the screen and I'm looking at the connection suggestions of the entire map right I'm seeing the Apache of the ha proxies but I wanted to show the ones that I added manually versus when I turned on known databases okay and also wanted to then let's go back to the map here we go and again just review that these are all tcpn points uh so um that's an indicator that these are traffic based and that they were M machine learned because we just know IP to Port IP port to IP to Port excuse me okay so let me get uh any anybody else have the questions that while I uh reset my demo system and but Bill please keep keep going okay so one of the uh challenges that we normally encounter is that the um we may have to go in and customize a section for for for top down service mapping and um let's see here we go going to get refreshed and when we do that there's some strategies you can use and I prefer to clone con particular sections if you will uh let me go ahead and reload this when we do our sections right there uh it gives us an advantage that when it comes time to compare and contrast our um out of the box updates right you usually see them through system upgrades or through uh Discovery pattern upgrades from the store versus um what's current or what has our update set name on them right so right now I'm just running with the default update set but what I need to do here is reset this as if I was never customizing it so I'm going to go ahead and roll back to patch nine and let's see let's revert to this version okay and then um shouldn't have anything here in drafts right because I just reverted it but I do want to sync it with the mid server so we're going to come back to our media Wiki and this is what would have discovered I run run Discovery here if I look at my Discovery log it was from my machine I'm Excuse machine learning uh I discovered it as a general application a generic application but I'm going ahead and Discover it now with the ha proxy to show that um when it can be configured right when I actually go into Discovery pattern let me go ahead and reload this so I've reset it back to out of box but when I want to make when I want to make changes I'm going let the other piece discover in the background when I want to make changes one approach is to actually create a new um create a new section and allow that to be happening at the very bottom of your patterns okay because what that'll do is um not only puts me in the draft mode but allows me to uh add again this is the publish pattern on this screen right it allows me to add at the very bottom here and there's an advantage to doing that so let me go ahead and uh go to the draft patterns and I'm I'm doing this edit quickly for our demo so I'm going to add the new connection section right here and then I'm going to go back to the designer um and reload so so what used to be the new section I'm going to go ahead and leave it in place actually you'll see that I've actually added stuff below that new section I could have replaced the new section but for now I'm going to just use this Fey here to remove it and by doing that my data or my customizations are now in a part of the that I can actually do the um after an upgrade I can actually go in and do a comparison and see what changed not only with my customizations but is there anything that came from the latest Discovery patterns so everything else is the same except the actual pattern text but what's convenient is that all of my work is at the bottom so that I don't have to um I can lift and shift that work right I can take it if I were to revert I can lift and shift this data and put it back into the origin or into the the patch pattern or the family release pattern the store pattern whatever become the latest right from the store and the the idea here is again rather than working in any of the other steps putting in preconditions uh changing uh other logic that that's because the way these sections work let's clone them or make your build your own such that it's in isolation and then because you did change it you know you you do not suffer all the challenges of you know trying to re update the um re-update the uh pattern manually or trying to use the merge facility right you can do that through um you can do that much easier to do those comparisons I know it's uh forgive the screen jumping here it can be challenging to try to get those updates and so rather than trying to fix or update a different one or two of the steps in an out of the box piece of the pattern clone it make your changes in that clone and then you can isolate that clone data um in a way that you can do those visual differences after this was much smoother my apologies here we go so this now becomes a part of the um after you do your upgrade you can then remerge your data because of the previous Delta that you did and you can put it back in the same place like you saw when I did the paste and now that it can actually be a part of the pattern so um here we go still hasn't fully updated so any questions on that technique maybe maybe I kind of moved quickly over it but I just wanted to make sure that e it can even apply to identification sections clone it and perhaps make it the first item in your ident uh in your identification section such that you use your customized data and then the the out of the boox patterns are um pristine and can match when you do a history UPG a history comparison or you can see how the out of the box have changed from version to version if there was an improvement or uh correction done in the outof thebox identifications and great Joseph so thank you Joseph for that but that's my last part of this functionality is that I can actually use the extension section for any significant replace ments or updates to my identification section but also you can use the extension section as a uh pseudo connection section and I wanted to show that we can do that through you know creating an extension section and and that extension section is a shared Library just like all the others used in extension sections and um let called going to go ahead and reconnect it here uh let me just go ahead and build the reconnection without showing the import so I'm going to add it back as an extension section and we should see it show up on here's my uh Unix so rather going from the ha proxy to the Apache servers now going from the Apache servers down to the database layer uh of of my uh demo application and if I reload this I should see the application section show excuse me extension section show up and to treat it like a connection section you need to put in two safeguards uh the first safeguard that you need to put in because is that you only want these pseudo connections to run when I'm doing top down or doing service mapping so the first step should be what runtime mode am I in if I'm not in service mapping then make it a match where I Then I then I terminate because it's not expected if if it is going horizontal Discovery and then the second one after that is that either for your application if you're going to make it specifically to your application or if you're going to make it generic make sure that the URL entry point is not empty so you can actually come into something like Apache or IIs and create a good number of these for all of your custom web applications internally you know app one app two app three app four put the check for top- down service mapping in and then put the second check in which application it is so yes it's a bit more um prescriptive and direct and specific to one application stack in your Enterprise but at the same time if those things add remove you already got the logic to add remove Downstream connections if it moved from one server to another server it will you know it'll still fire the connection you'll just have the new process on running on a second server so that that's the the last takeaway that I wanted to give was around the when you do customize compartmentalize your work consider using an extension section um and if you do it for con connectivity then put those safeguards in place and uh don't believe it actually was able to finish out here but the as I um would have hoped that we would have had a full-blown map here in the background I was not able to get that to finish in the time so um again thank you for your attention today and thank you for the great questions I hope this has been uh helpful and uh I'll pass it back to you John thank you Bill this was uh definitely very helpful we've had an amazing uh month of Engagement so uh this is uh great to see so thanks everyone uh for your great engagement for sure now uh as I said before in the introduction this was the last episode for this year but that doesn't mean that this series is not continuing on to the next year so please make sure uh you uh subscribe to the um uh live on service now webinar series you can scan the QR code right here or use the same uh link that has been previously put via chat and uh specifically next uh session in January will be focused on a new solution that will be debuting in Innovation lab and that will be cloud account management that's a very um exciting solution that will allow you to uh better manage your Cloud accounts uh deploy new accounts Etc so uh if you are not directly involved in Cloud teams please make sure to spread the word to your Cloud teams and make sure they um are able to attend where this is again the very first session of enablement on this revolutionary solution and it's going to be a great opportunity uh to increase your knowledge and actually to eventually try out the solution that is planned to um released on Innovation lab in January now uh that was everything for for today thanks Bill uh for your amazing session uh actually for both of your amazing sessions uh I'm absolutely delighted to have you had here presenting you did an amazing job and thanks Kim Steve and Brian for your great support and especially thank you all for attending until now uh this was another great session and we're really looking forward to see you soon so wishing you um a a great time during your holidays and we'll see you in January

View original source

https://www.youtube.com/watch?v=Tru255Aj6kU