Can ServiceNow Collect Advanced Windows Details Without WMI/WinRM Credentials?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
2 hours ago
I have a question regarding Windows Discovery and alternative methods for collecting detailed Windows server information.
We are currently performing ServiceNow Discovery in a customer environment and have successfully validated SNMP connectivity to Windows servers. Using SNMP, we are able to retrieve basic information such as:
- Hostname
- System description
- Network interfaces
- Uptime
- IP addresses
- Other standard SNMP OIDs
However, when it comes to collecting detailed Windows information such as:
- Operating system details
- Installed software
- Running services
- Hardware inventory
- Disk and memory information
- IIS details
- SQL Server details
ServiceNow Discovery appears to require Windows credentials (WMI/WinRM) with the appropriate permissions on the target servers.
The customer currently uses PRTG and has indicated that they are able to retrieve much of this information through SNMP in their monitoring solution.
My Questions
Is there a supported agent-based approach within ServiceNow that can collect detailed Windows server information without relying on WMI/WinRM discovery credentials?
Can Agent Client Collector (ACC) be used as an alternative for Discovery and CMDB population in this scenario?
Has anyone successfully implemented Windows Discovery using:
- SNMP only
- ACC
- Another ServiceNow-supported agent
while avoiding local administrator or elevated Windows credentials?
If ACC is the recommended approach, are there any licensing, prerequisites, or limitations compared to traditional Discovery using WMI/WinRM?
Environment
- ServiceNow Discovery
- MID Server deployed and functioning correctly
- SNMP connectivity validated
- Customer prefers a least-privilege approach and would like to minimize administrative access requirements on Windows servers
I'd appreciate hearing about any real-world implementations, recommendations, or best practices from others who have addressed similar security concerns.
Thanks in advance for your help!
