Agent Client Collector installation

  • Release version: Australia
  • Updated March 12, 2026
  • 2 minutes to read
  • Summarize
    Summarized using AI
    This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.

    Summary of Agent Client Collector installation

    The Agent Client Collector (ACC) can be installed on any supported host machine and connects to a MID Server via HTTP/S to maintain an active connection. A single MID Server can manage multiple agents, while each agent connects to one MID Server at a time and can switch to another MID Server to ensure failover protection. Agents select a MID Server based on their configured list, especially if their IP address changes.

    Show full answer Show less

    Key Features

    • Scalability: The maximum agents per MID Server is configurable; default is 4,000 agents. For example, a 1 GiB MID Server supports about 700 agents concurrently, while an 8 GiB MID Server can manage up to 8,000 agents. Multiple MID Servers can be used to scale up (e.g., 5 MID Servers with 8 GiB each can handle 40,000 agents).
    • Agent Software: Installed with Ruby version 3.3.2, the default user account is a local user named servicenow with basic permissions.
    • Permissions: Different OS-specific permissions are required to support various deployment features such as inventory collection, serial number retrieval, process debugging, mapping TCP connections, storage device access, logged-in user tracking, and package self-upgrades.
    • Agent Management: When reinstalling an agent on a host using ITOM Cloud Services, the existing agent record must be deleted to allow re-registration. Agents with status "Down" or "Disconnected" are automatically deleted after 30 days by default, configurable via the Autoflush form.
    • Security: Supports Manual Transport Layer Security (mTLS) for secure authentication between the MID Web Server and agents.
    • Special Configurations: Supports operation in air-gapped environments and features a golden image mode for cloning instances.
    • Domain Separation: The agent’s domain and the Configuration Items (CIs) it creates are set by the domain of the connected MID Server. User domains must be leaf domains to enable Websocket endpoint extensions on the MID Server.

    Practical Considerations for ServiceNow Customers

    • Plan MID Server capacity and memory allocation based on the number of agents to be managed.
    • Ensure appropriate permissions are configured on agents for required features, especially when deploying across different operating systems (Windows, Linux, macOS).
    • Use mTLS for secure, authenticated connections between agents and MID Servers.
    • Manage agent lifecycle by deleting old or reinstalled agents as required for smooth re-registration.
    • Consider golden image mode for efficient deployment of multiple agent instances.
    • Account for domain separation settings to maintain proper segregation of data and configurations across organizational units.

    You can install the Agent Client Collector on any supported host machine. The Agent Client Collector connects to a MID Server using the HTTP/S protocol, and the connection remains active after being established. One MID Server may handle several agents simultaneously, while a single agent works with one MID Server at a time and switches to a different MID Server when necessary to provide failover protection.

    When an agent's IP address changes, it selects a MID Server to connect to based on the agent's MID Server list.

    The maximum number of agents that can be connected to a single MID Server is configurable in the sn_agent.mid.max_allowed_agents MID Server property. The default value is 4,000.

    For ACC-VC, a default 1 GiB MID Server can support 700 agents concurrently. An 8 GiB configuration for a MID Server can support 8,000 agents concurrently. You can also scale out. For example, 5 MID Servers with 8 GiB of heap size can handle up to 40k agents.

    Agent Client Collector is installed with ruby version 3.3.2.

    The default user account is a local user called servicenow. This user has basic level permissions.

    The following table describes the permissions required to work with various features associated with the agent, per OS. An asterisk (*) indicates that no special permissions are required.
    Table 1. Agent on Endpoints Deployment
    Feature Windows Linux macOS
    Basic inventory * * *
    Serial number(s) *

    sudo

    dmidecode

    *
    Running processes Debug programs * *
    Mapping TCP connections to running processes * sudo ss *
    Storage devices LOCAL SYSTEM * *
    Logged-in users LOCAL SYSTEM * *
    Package self-upgrade LOCAL SYSTEM sudo rpm/dpkg Not supported

    If you completely reinstall the agent on a single host server, and you're using ITOM Cloud Services, you must delete the agent record to allow for re-registration. Delete the original agent on the Agent Client Collectors page (All > Agent Client Collector > Agents).

    Agents whose Status = Down or Disconnected which haven't been deleted are deleted automatically after 30 days. You can modify this setting on the Autoflush form page (see Autoflush form).

    Use the Manual Transport Layer Security protocol (mTLS) for secure authentication between your MID Web Server and the agent (the client). For details, see Connect the agent to the MID Server using mTLS.

    For details on using Agent Client Collector in an air-gapped environment, see the Agent Client Collector Framework Air Gapped Configuration Item Management Solution [KB1585753] article in the Now Support Knowledge Base.

    Golden image mode enables cloning of additional instances. Setting golden image mode is described in the installation procedure prerequisites for each OS. For information on the structure and modularity of the golden image plugin by operating system, see Golden image structure and modularity.

    Agent Client Collector supports domain separation. The domain of the agent and the CIs it creates is determined by the domain of the MID Server that the agent is connected to. The user's domain must be the lowest domain level (known as a leaf domain) to enable creating a Websocket endpoint extension for the MID Server.