Subnet Discovery

Amit39
Kilo Expert

Hello Team,

I am working on a project where I need to discover all the Subnets and get them discovered and added to CMDB.

Just wanted to check what all are the steps I need to perform for the successful discovery on all the Subnet targets.

Here are the few things I have done as of now

- Working with Network team for required ports to be open

- MID server creation done with respective user have given the required access to perform the discovery, however not created additional MID instances from the same server to make load balancing, do I need to create more so that I can assigned them to different subnets run the scheduled discovery

- Account and credential setup done for Windows, Linux, vCenters etcs

- Working with Network team to remove all the firewall between source MID servers and all the targeted Subnets

Is there anything else I need to be taken care before setup all the discovery on those subnets.

Also I need to disable EUC devices (Laptops/Desktops/Tablets) discovery as we already have another tool setup who only take care of those EUC devices discovery and integrated with CMDB to push the data with required computer table attributes information.

I am bit concern here because on those same subnets, there is a possibility of EUC devices IPs as well and that will make any further problems as I need to only keep Infrastructure devices to be discovered under SNOW Discovery and getting added to CMDB with making required relationship.

Appreciate your quick help.

 

Thank you.

Regards,
Amit

-  

2 REPLIES 2

dcwilson
Kilo Expert

Off the top of my head a couple of things I can think of to avoid discovering EUC:

  1. Don't give access to those EUC devices for the service accounts you are using to discover your infrastructure.  You'll get a lot of authentication errors but they won't be discovered.  
  2. Create a business rule to run before insert and you would need to specify the OS's not to create or if you have a strict naming standard that you could filter off of for the business rule to run.  Printers will be more difficult to filter out.
  3. If the EUC devices are using static IPs you can add those IPs to an Exclude List for the subnet.  

doug_schulze
ServiceNow Employee
ServiceNow Employee

If possible don't open those FW ports, just put the midserver(s) on the other side. Keep your security in tact!

 

For computers very easy to do..You can use the configuration console to select what you want and do not want to discover, or even easier just goto the windows computer classifier in discovery definition and disable it