Vivektietsood
Tera Guru

Hi All

In this article, I am going to talk about discovery process step by step:

There are four steps of discovery process (Scanning, Classification, Identification DiscoveryExploration) . Please refer to my following article to understand these steps in detail:

Discovery Fundamentals

 

Step 1 - Go to discovery schedules, create newfind_real_file.png

 

I am calling mine VM discovery

Step 2 - First I am going to run IP address discovery which is step 1 or Shazzam. In this step discovery happens only to check if the target is alive on network and the information returned is minimal like type of the device, Unix or windows. You would need to ensure that firewall ports are open from ServiceNow instance to target.

This step is characterized by discovery probes or patterns scanning targets and finding out the ports on which ports are configured. For example if a target is responding to port 22 then it's likely be a Unix device and if responding on WMI 135 then it is likely be a windows device

Remember to configure IP Ranges or targets

find_real_file.png

Step 3 - Press Discover Now and it should create an Unique id like DIS0010108 and after completion, you should see the following screens.

find_real_file.png

Please note that IP discovery corresponds to Shazzam

find_real_file.png

Step 4 - In this step, we will run Configuration Items discovery. In this step, logging into device using the credentials provided happens and detailed info on the device is captured.

 

find_real_file.png.

 

find_real_file.png

Detailed Information on the device scanned is displayed:

find_real_file.png

Step 5- In this step, Identification of targets takes place and more information about the device is gathered through the use of additional probes and sensors

  find_real_file.png

You will also notice that information related to probes starts getting populated in the discovery log

 

find_real_file.png
 

 Step 6 - This last step is all about finding applications and software running on the host. Step 5 and 6 are completed as a part of classification step (Step 4)

 

 

I hope that you find this article useful. Please like and or comment if it helps you.

Comments
VS7
Tera Explorer
Very Helpful
Tony McPhail
Mega Contributor

Great article. One thing I have been having trouble understanding is how to use IP address ranges to match to locations and how may discovery scheduled you should create. I understand the different ways to do this it is more the reason why you would choose one method over another.

Vivektietsood
Tera Guru

Appreciate the feedback. I don't believe that there is an automated way to match IP ranges with location. This is something you should check with your network admins, they typically assign VLANs or IP ranges to different locations 

How many schedules: I think it depends upon which location or which VLANs face the maximum number of churns for servers. The environments that face a large churn should be discovered more hence should have a different schedule than the envs or locations that face less churn. The other factor could be business requirement that is, for which location the most fresh data is required.

Please mark helpful so that it helps other with a similar question. 

 

 

Larry Youngquis
Kilo Expert

Great article, Vivektietsood!

If associating locations to ranges, rather than overall Discovery Schedules, is important, please upvote this idea.

Discovery Location attribute in Range Sets

Thanks!

Larry

Vivektietsood
Tera Guru

Done. Thanks for sharing.

Tony McPhail
Mega Contributor

Yes Vivektietsood, that is what I have determined and until Larry's idea gets implemented it would seem I will need to continue to create a schedule for each location (we have over 500 locations in our environment)

Version history
Last update:
‎06-03-2020 04:48 PM
Updated by: