Exploring Instance Scan
Summarize
Summary of Exploring Instance Scan
Instance Scan is a tool within ServiceNow designed to help you assess and improve the health of your instance by detecting anomalies, security issues, upgrade best practices, manageability, user experience, and performance vulnerabilities. It analyzes tables, records, and metadata through focused rules called checks. Note that Instance Scan has limited support for domain separation, showing findings based on the source record's domain.
Show less
Key Features
- Checks: Singular rules that identify potential issues or opportunities. You can create individual checks or suites of checks to tailor scans to your needs.
- Scan Types:
- Full Scan: Runs all active checks across the entire instance.
- Point Scan: Targets a specific record, update set, or application, running only relevant checks against that selection.
- Test Scan: Allows testing of a single check to verify its accuracy before broader execution.
- Results and Findings: Scan outcomes report the status and detail records violating check rules, helping you pinpoint issues.
- Dashboard: Provides a visual system-wide representation of instance health, facilitating management and analysis of scan results.
- Quota Rule: Controls scan execution time to prevent long-running scans from impacting performance.
Roles and Usage
The scanuser role is required to create checks, execute various scans, schedule scans, monitor progress, and analyze results using the dashboard.
Practical Benefits for ServiceNow Customers
- Proactively identify and address security, upgrade, and performance issues to maintain instance health.
- Customize scans to focus on specific areas or the entire instance for comprehensive oversight.
- Schedule scans to run automatically, ensuring ongoing monitoring without manual initiation.
- Use the dashboard to easily visualize and prioritize remediation efforts based on scan findings.
- Prevent resource exhaustion during scans with quota rules, maintaining system stability.
Next Steps
To fully leverage Instance Scan, explore configuring the tool, creating and managing checks, executing different scan types, and interpreting results using the Instance Scan dashboard.
If you are new to Instance Scan, read this overview to learn what the tool can do. Follow the tutorial to create checks and execute scans that uses most basics of Instance Scan features.
Instance Scan overview
- Checks
- Checks are singular focused rules that detect anomalies or opportunities in an instance. These checks can run against tables, records, or metadata. Checks are defined to identify security, upgrade best practices, manageability, user experience and performance vulnerabilities. See Getting started with checks for more information.
- Results
- An Instance Scan result reports the status and type of the scan. See Results for more information.
- Findings
- A finding is a reference to a record that has violated a rule from a check on the instance. See Findings for more information.
- Dashboard
- The Instance Scan dashboard is a system-wide visual representation of the health of your instance. The dashboard helps you manage and analyze the full scan results against your instance. See Instance Scan dashboard for more information.
- Quota rule
- A quota rule determines the execution threshold of a scan. The quota rule prevents the instance from running long scans. For example, any scan running longer than the threshold set by the quota rule will result in a failure. See Quota rules for more information.
- Full scan
- Execute a scan for the entire instance by selecting Execute Full Scan. Implementing a full scan runs all the active checks present in your instance.
- Point scan
- Execute all applicable checks against a single record, update set, or an application by selecting Run Point Scan. For example, if you execute a point scan against a business rule, only the checks that are applicable to the business rule table run, and only that single target record is scanned. If you execute an update set scan or an application scan, all records related to that update set or application are scanned. See Execute an app scan and Execute an update set scan for more information.
- Test scan
- Execute a test scan to verify if the check works as expected. The test scan enables you to test a single check instead of a full scan by selecting a single check and selecting Test Check on the Check form.
Instance Scan users
| Users | Description |
|---|---|
| scan_user | The scan_user role can run different types of scans and view the findings and results. |
Instance Scan benefits
| Benefit | Feature | Users |
|---|---|---|
| Create checks and check suites to know the health of your instance | scan_user | |
| Execute scans on the created checks to review the instance health | Executing a scan | scan_user |
| Scheduling of scans and suite scan | scan_user | |
| Monitor your scans to ensure no health issues of your instance | Monitoring a scan | scan_user |
| Manage and analyze the results of full scan against your instance | Instance Scan dashboard | scan_user |