Interested in a ServiceNow event built for developers? Registration for now[dev]26 is officially open!

IP-Based Certificate Discovery: How to verify created CI relationships and add new ones?

Dinh Nguyen
Kilo Sage

Hi everyone,

After a successful IP-Based Certificate Discovery, I can see relationship records being created in CI Relationships [cmdb_rel_ci].

I'd like to understand:

  • Where can I verify which relationships were generated by Discovery?
  • If I want Discovery to create additional/custom relationships, what is the recommended approach?

Any official documentation or implementation guidance would be very helpful.

Please someone help me!

Thanks!

1 ACCEPTED SOLUTION

sairamkoruk
Tera Expert

Hi @Dinh Nguyen ,

Sharing some findings that might help.

  1. In the CI Relationships [cmdb_rel_ci] table, relationships created by Discovery will show the MID Server service account as Created by. For non-dependent relationships, you can normally verify the source in the Relationship Sources [sys_rel_source] table.
  2. In IP-based Certificate Discovery, the relationship between the CI and the Certificate CI is created through script actions, using the "Used by::Uses" relationship type.
    These are triggered off two events:
  • discovery.device.complete triggers script action "Discovery - map device to certificates"
  • discovery.complete triggers script action "Discovery - map apps to certificates"

Both call into the DiscoveryCertificateManagementUtils script include (scope sn_disco_certmgmt), which handles the actual relationship creation.

Usually, in Pattern-Based Discovery of CIs, patterns create the relationships. If you need Discovery to create additional custom relationships for pattern-discovered CIs, the recommended approach is to add an Extension section to the pattern and use the Create Relation/Reference operation there.

Note: this Extension-section approach applies to standard pattern-based Discovery. IP-based Certificate Discovery specifically appears to use a separate, probe-based mechanism — it's built on the script actions above plus DiscoveryCertificateManagementUtils. So for custom certificate relationships specifically, the right extension point is those two script actions (or the utility script include they call), not a pattern's Extension section.

If this helped, please mark it as helpful/accept as solution.

Regards,
Sairam

 

View solution in original post

1 REPLY 1

sairamkoruk
Tera Expert

Hi @Dinh Nguyen ,

Sharing some findings that might help.

  1. In the CI Relationships [cmdb_rel_ci] table, relationships created by Discovery will show the MID Server service account as Created by. For non-dependent relationships, you can normally verify the source in the Relationship Sources [sys_rel_source] table.
  2. In IP-based Certificate Discovery, the relationship between the CI and the Certificate CI is created through script actions, using the "Used by::Uses" relationship type.
    These are triggered off two events:
  • discovery.device.complete triggers script action "Discovery - map device to certificates"
  • discovery.complete triggers script action "Discovery - map apps to certificates"

Both call into the DiscoveryCertificateManagementUtils script include (scope sn_disco_certmgmt), which handles the actual relationship creation.

Usually, in Pattern-Based Discovery of CIs, patterns create the relationships. If you need Discovery to create additional custom relationships for pattern-discovered CIs, the recommended approach is to add an Extension section to the pattern and use the Create Relation/Reference operation there.

Note: this Extension-section approach applies to standard pattern-based Discovery. IP-based Certificate Discovery specifically appears to use a separate, probe-based mechanism — it's built on the script actions above plus DiscoveryCertificateManagementUtils. So for custom certificate relationships specifically, the right extension point is those two script actions (or the utility script include they call), not a pattern's Extension section.

If this helped, please mark it as helpful/accept as solution.

Regards,
Sairam