---
sourceDocument: Australia IT Operations Management
sourceDocumentLink: https://www.servicenow.com/docs/r/it-operations-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia IT Operations Management

ft:clusterId :

    - itom

bundleId :

    - itom

workflow :

    - Technology


---

# AWS discovery

# AWS discovery using patterns {#ariaid-title1}

Release version: Australia  
Updated March 12, 2026  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 27 minutes to read
Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of AWS Discovery Using Patterns

ServiceNow's Discovery and Service Mapping Patterns leverage pattern-based discovery to identify and map various Amazon AWS Cloud resources during horizontal discovery.
This enables ServiceNow customers to automatically populate their CMDB with detailed information about AWS infrastructure, including regions, virtual machines, networks, storage, and more.
Updates to the Discovery and Service Mapping Patterns application from the ServiceNow Store are often required to access the latest AWS resource discovery capabilities.
Show full answer Show less  

## Key Features

* **Automated AWS Resource Discovery:** Supports identification and mapping of a broad range of AWS components such as EC2 instances, VPCs, load balancers, security groups, storage volumes, organizational units, and more.
* **AWS Datacenter Discovery Model:** Focuses discovery on datacenters (regions) that contain active resources, improving performance by avoiding empty or passive regions. This model uses the AWS Resource Explorer API for efficient detection.
* **AWS Organizations Support:** Enables discovery of AWS management accounts and member accounts, including dynamic credential handling to simplify access across accounts.
* **Tag-Based Discovery Integration:** Supports service instance mapping by activating cloud-related CI relationships and integrating with Service Mapping for enhanced service visibility.
* **Comprehensive CI Relationships:** Automatically establishes detailed relationships among AWS components, such as hosts, subnets, networks, load balancers, gateways, and endpoints to accurately represent your cloud environment topology.
* **Event-Driven Discovery:** Detects AWS cloud events that indicate state changes and triggers updated discovery for affected components.
* **Pattern Updates and Extensibility:** Regular quarterly pattern updates from the ServiceNow Store ensure coverage of new AWS services and features, including specialized patterns for services like Amazon API Gateway, Athena, CloudFront, RDS, and many others.
* **Support for AWS China Region:** Includes discovery capabilities specific to AWS China regions with region-specific endpoint configuration.

## Practical Setup and Configuration

* **Application Updates:** Ensure Discovery and Service Mapping Patterns, CMDB CI Class Models, and Visibility Content are current to utilize latest AWS discovery features.
* **AWS Service Accounts:** Set up IAM users or roles with appropriate read-only policies in AWS Management Console; optionally configure MID Server to assume roles for secure, dynamic credential management.
* **Discovery Scheduling:** Configure AWS discovery schedules via Discovery Admin Workspace, with options to discover only new or active datacenters to optimize performance.
* **Resource Explorer API Permissions:** Grant required IAM permissions for Resource Explorer API to enable optimized datacenter discovery and exclusion of specific resource types when needed.
* **Property Configuration:** Use MID Server properties such as `mid.cloud.discovery.sonar.discoverallawsdatacenters` to control whether discovery includes all or only active datacenters.
* **Populate Service Account and Logical Datacenter Fields:** Improve query performance by enabling direct field population in cloud CI tables from version 1.30.2 onward.

## Discovery Outputs and CMDB Integration

The discovery process populates numerous AWS configuration item (CI) classes with detailed attributes to represent your cloud infrastructure accurately, including but not limited to:

* Availability Zones
* Cloud Hosts (EC2 instances)
* Load Balancers and Load Balancer Pools
* Network Components such as Subnets, Internet Gateways, NAT Gateways, Route Tables, and Security Groups
* Storage Volumes and Block Endpoints
* Organizational Units and Cloud Service Accounts
* Web ACLs (AWS WAF integration for Security Operations)

Each CI is linked through defined relationships reflecting real-world dependencies and hosting structures, supporting comprehensive service mapping and impact analysis.

## Benefits for ServiceNow Customers

* **Improved Visibility:** Gain a complete and accurate view of your AWS environment within the ServiceNow CMDB.
* **Optimized Discovery Performance:** Focus discovery on active datacenters and resources, reducing time and system load.
* **Enhanced Security and Access Management:** Leverage AWS IAM roles and dynamic credential acquisition for secure discovery across AWS Organizations.
* **Up-to-Date Cloud Mapping:** Benefit from continuous pattern updates capturing new AWS services and features.
* **Service Mapping Integration:** Integrate cloud components into service instance maps for better operational insight and service impact modeling.

## Next Steps

* Verify and update Discovery and Service Mapping Patterns and related applications from the ServiceNow Store.
* Set up and configure AWS service accounts with appropriate IAM policies and credentials for discovery access.
* Configure discovery schedules and MID Server properties to optimize AWS discovery based on your environment and performance needs.
* Review and enable cloud-related CI relationships for tag-based discovery integration with Service Mapping.
* Monitor  
Discovery and Service Mapping Patterns uses patterns to discover components of the Amazon AWS Cloud deployment during horizontal discovery. Discovering some of these resources might require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.

## Request apps on the Store {#data-discovered-aws-patterns__section_y3k_3pl_rlb}

Visit the [ServiceNow Store](https://store.servicenow.com/sn_appstore_store.do#!/store/home) to view all the available apps, and for information about submitting requests to the store. For cumulative release notes information for all released apps, see the [ServiceNow Store version history release notes](https://www.servicenow.com/docs/r/store-release-notes/sn-store-release-notes.html).{#data-discovered-aws-patterns__inline-send-to-store}

## Prerequisites {#data-discovered-aws-patterns__section_p2g_1fm_kmb}

Verify that the applications are up to date:
:
    * Discovery and Service Mapping Patterns
    * CMDB CI Class Models
    * Visibility Content
    {#data-discovered-aws-patterns__ul_aln_qlb_5yb}

Update the method used for pointed discovery for the AWS CloudFormation Template (CFT) stack
:   If you use Cloud Provisioning and Governance, you must update the getOperationGR(type) method. This update enables the pointed discovery to list the resources correctly for the AWS CFT stack after provisioning. For further information about the steps required to update this method, see the Knowledge Base article [KB0858437](https://support.servicenow.com/nav_to.do?uri=kb_knowledge.do?sys_id=54ecb719db1f1cd0fb115583ca961917).

Activate the cloud-related CI relationships
:   To include discovered components into service instances, enable CI relationships used in tag-based discovery by Service Mapping. These CI relationships are available from the 1.0.68 release on the ServiceNow Store. For operational steps, see [Tag-based discovery configuration](https://www.servicenow.com/docs/__DAxI4a5uhCxFO3rZLOcw "You can refine the default configuration to control which CIs Service Mapping includes in application services during the tag-based discovery process.").

Set up service accounts on the AWS Management Console

:   An AWS Organization is a collection of AWS accounts under a single account. In AWS Organizations, parent accounts are called management accounts. The sub-accounts that belong to a management account are called member accounts.{#data-discovered-aws-patterns__service-account-management-console-aws-p}

    Note:  
    Cloud Discovery for AWS Organizations isn't fully supported in a [GovCloud](https://docs.aws.amazon.com/govcloud-us/latest/UserGuide/whatis.html) isolated region.  
    The advantages of using management accounts in Discovery are:

    Easy population of member accounts
    :   After you configure the management account and supply the necessary credentials, you can test the connection to the account. If the test succeeds, Discovery returns a list of the member accounts in that management account. From this list, you can choose one or more member account to include in the Discovery of the management account.

    (Optional) Discover member resources using dynamically acquired credentials

    :   When you run Discovery on your cloud resources, you don't need separate credentials for each member account. The Cloud Discovery process handles credentials automatically by acquiring a temporary credential for each member via an AWS API. You can elect to use the default configuration or customize the MID Server to assume other roles for additional controls and security.

    For more information, see [Setting up AWS service accounts](https://www.servicenow.com/docs/Ne9_EUn4j5vmLXgoJrnYnQ "Create and configure cloud service accounts at ServiceNow AI Platform for the corresponding Amazon Web Services (AWS) service accounts.").

Use IAM user policy on the AWS Management Console
:   To use the IAM user policy instead of credentials during discovery, configure the MID Server for AWS IAM roles. For more information, see [configure the MID Server for AWS IAM roles](https://www.servicenow.com/docs/D~U61iRTd0lP83FzvniWEw "Configure the MID Server to retrieve the temporary security credentials associated with an IAM role.").

    To create the IAM user policy for provisioning AWS resources, see [Control AWS access and permissions using policies](https://www.servicenow.com/docs/YQiEOCVl1XQSfYYJB75sPA "Configure policies with the necessary level of permissions to provide access to the AWS resources for Cloud Discovery and Cloud Provisioning and Governance.").

Configure access to the AWS resources

:   To discover a single account, create an IAM account in the AWS Management Console, and verify that it has the "ReadOnlyAccess" policy applied. To discover several member or child accounts, configure the credentials as described in [Access setup for AWS service accounts](https://www.servicenow.com/docs/aAgx5XgcWrd7JqD0NUDL9Q "Cloud Discovery and Cloud Provisioning and Governance need access to resources in the Amazon Web Services (AWS) service accounts. Learn about different methods of configuring such access.").

Configure a discovery schedule
:   [Create an AWS Discovery schedule in Discovery Admin Workspace](https://www.servicenow.com/docs/_q25r~sjoXX0atnOAhlwbA "Use the Discovery Admin Workspace dashboard to create an Amazon Web Services (AWS) Discovery schedule.").

(Optional) Discover datacenters only for new members
:   Starting with Zurich Patch 2, you can discover datacenters only for new members added since the last discovery. For more information, see [Discover datacenters only for new cloud accounts](https://www.servicenow.com/docs/ny0cMnbjtY6VKnTSbeirWw "If you have multiple cloud accounts and datacenters in AWS and Azure, you can discover datacenters for new cloud accounts only, instead of refreshing the entire list.").

Optimize discovery by including only datacenters with resources{#data-discovered-aws-patterns__discover-datacenter-aws-dt}
:   You can optimize discovery by limiting it to only AWS datacenters with resources.

    * Verify that your service account has the following IAM permissions to access the Resource Explorer API (starting with Discovery and Service Mapping Patterns version 1.35.0).  
      {#data-discovered-aws-patterns__table_flj_f25_zjc__entry__2}

      | IAM permission | Coverage |
      |-|-|
      | `resource-explorer-2:Search` | Partial |
      | `resource-explorer-2:Search` + `iam:CreateServiceLinkedRole` | Full |
      [Table 1. Resource Explorer API permissions and coverage]

      {#data-discovered-aws-patterns__table_flj_f25_zjc}For more information, go to the [AWS Documentation](https://docs.aws.amazon.com/) and search for the "Getting started with Resource Explorer" article.{#data-discovered-aws-patterns__verify-optimize-aws-resource-explorer-api}
    {#data-discovered-aws-patterns__verify-optimize-aws-resource-explorer-api}
    * Discover only datacenters with resources by setting the mid.cloud.discovery.sonar.discover_all_aws_datacenters MID Server property to false. For more information, see [Limit AWS discovery to datacenters with resources](https://www.servicenow.com/docs/_78Eb1iBFx8s_e7En7M87A "Optimize AWS discovery by limiting it to datacenters with resources.").{#data-discovered-aws-patterns__enable-discovery-aws-datacenters-property}
    {#data-discovered-aws-patterns__enable-discovery-aws-datacenters-property}
    * To exclude specific resource types from AWS datacenter discovery, configure the sn_itom_pattern.discovery.aws.ldc.excluded_resource_types system property with a comma-separated list of resource types to exclude (starting with Discovery and Service Mapping Patterns version 1.35.0). For more information, see [Exclude AWS resource types from datacenter discovery](https://www.servicenow.com/docs/M86mIO0WtPXVLinrMMY8~w "You can configure which AWS resource types to exclude from AWS datacenter discovery, to avoid triggering discovery patterns in regions with only default resources.").{#data-discovered-aws-patterns__exclude-aws-resource-types-postreq}
    {#data-discovered-aws-patterns__exclude-aws-resource-types}

    {#data-discovered-aws-patterns__ul_cqf_q1c_fhc}  
    Note:  
    Discovery and Service Mapping Patterns versions 1.29.0 through 1.32.0 used the AWS Config service instead of the Resource Explorer API to determine datacenter activity. For instructions on configuring AWS Config recorder, go to the [AWS Documentation](https://docs.aws.amazon.com/) and search for the "Recording resources in the AWS Config console" article.{#data-discovered-aws-patterns__discover-datacenter-aws-dd}
{#data-discovered-aws-patterns__discover-datacenter-aws-dd}
:   For more information, see the AWS resources discovery by datacenters section.

(Optional) Populate Service Account and Logical Datacenter fields in cloud CIs
:   Starting with Discovery and Service Mapping Patterns version 1.30.2, you can improve query performance by populating Service Account and Logical Datacenter fields directly in cloud CIs. For more information, see [Improved query performance with direct field population in CI tables](https://www.servicenow.com/docs/dikZ2lIS1bNpgxWtTOukSQ "The Populate Service Account and LDC IN CMDB scheduled job populates the Service Account and Logical Datacenter fields in cloud configuration item (CI) tables, and the Virtual Machine Object field in the Hardware [cmdb_ci_hardware] table. This direct population reduces query complexity and improves query performance.").

## Verify the REST API Permissions {#data-discovered-aws-patterns__id_ysv_22b_f1c}

Download the [Cloud Discovery patterns spreadsheet](https://downloads.docs.servicenow.com/resource/enus/api/servicenow-discovery-patterns-api-details.xlsx) so you can grant user permissions required for running the Discovery patterns. In addition to permissions, the spreadsheet also includes useful information such as pattern names, types, CI Classes, and links to vendor documentation. New patterns are available
quarterly, so check periodically to be sure you have the latest version of the spreadsheet.{#data-discovered-aws-patterns__cloud-discovery-api-ph-prereq}
Note:  
You can test the AWS REST APIs using Postman API platform. For more information, see the [How to test AWS REST API using POSTMAN \[KB0782183\]](https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB0782183) article in the Now Support Knowledge Base.

## Support for AWS services in the China region {#data-discovered-aws-patterns__id_izr_lqv_1dc}

The latest version of Discovery and Service Mapping Patterns supports discovering AWS services in the China region. You can discover these services on the ServiceNow AI Platform, starting from Xanadu Patch 3 and Washington DC Patch 9 instances.

Discovering AWS services in the China region requires using a datacenter URL when setting up an AWS service account. For example: <kbd class="ph userinput">https://organizations.cn-northwest-1.amazonaws.com.cn</kbd>.  
* To learn more about AWS master account and sub-account support in the China region, see [KB1704526](https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB1704526).
* To identify AWS patterns supported in the China region, refer to the Cloud Discovery patterns spreadsheet. The AWS China Region Support column has a Yes value for supported patterns.
{#data-discovered-aws-patterns__ul_zqf_qtn_1dc}

## AWS resources discovery by datacenters {#data-discovered-aws-patterns__active-datacenter-discovery}

Starting with version 1.29.0, Discovery and Service Mapping Patterns introduces a new AWS datacenter discovery model. The previous model discovered all datacenters, regardless of whether they contained relevant resources. The new model improves the AWS discovery performance by focusing only on datacenters that contain resources.

AWS has multiple datacenters around the world, but resources like load balancers and virtual machines are typically deployed in only some of them. The Amazon AWS Datacenter Discovery
pattern runs before all other AWS patterns to identify datacenters with resources related to your service account ("active") and those without ("passive"). A datacenter is classified as "empty" when the Resource Explorer API is
unavailable or lacks permissions, and patterns continue to run as normal. You can check the discovery log for the exact cause --- for more information, see [Logs for horizontal discovery](https://www.servicenow.com/docs/~SFrZYAcc4NFIiksRXec0w#r_DiscoveryLog "The system collects logs to reflect the activity that takes place during a horizontal discovery based on both patterns and probes. Use the logs to fine-tune or troubleshoot the discovery process.").

After identifying "active", "passive", or "empty" datacenters, the discovery schedule continues to execute all AWS patterns only for "active" or "empty" datacenters, to discover your AWS cloud resources. "Passive" datacenters are ignored during the schedule. The Refresh Datacenters flow continues to display all regions, not just active ones. You don't need to
create another schedule when a resource is added or a datacenter switches from passive to active.

The mid.cloud.discovery.sonar.discover_all_aws_datacenters
MID Server property is set to true by default, which discovers all datacenters. To limit discovery to the "active" or "empty" datacenters, set this property to
false. Starting with Discovery and Service Mapping Patterns version 1.35.0, you can exclude specific resource types
from AWS datacenter discovery to avoid marking regions with only default or unneeded resources as active. For information on setting up active datacenter discovery, see the Optimize discovery by including only datacenters with resources prerequisite.

Datacenters discovered before upgrading to version 1.29.0 remain in the Amazon AWS Datacenters table. Depending on the service account and MID Server property settings, you might notice differences in discovery time and CMDB data.  
{#data-discovered-aws-patterns__table_wzt_31d_dhc__entry__3}

| MID Server property setting | Flow | Discovered/displayed datacenters |
|-|-|-|
| False | New schedule | All datacenters except passive |
| False | Refresh Datacenters | All datacenters |
| True (default) | New schedule | All datacenters |
| True (default) | Refresh Datacenters | All datacenters |
[Table 2. Differences in datacenter discovery by mid.cloud.discovery.sonar.discover_all_aws_datacenters MID Server property setting]

{#data-discovered-aws-patterns__table_wzt_31d_dhc}  
Figure 1. AWS datacenter model flow by mid.cloud.discovery.sonar.discover_all_aws_datacenters MID Server property setting  
Note:  
Discovery and Service Mapping Patterns versions 1.29.0 through 1.32.0 used the AWS Config service instead of the Resource Explorer API to determine datacenter activity. For instructions on configuring AWS Config recorder, go to the [AWS Documentation](https://docs.aws.amazon.com/) and search for the "Recording resources in the AWS Config console" article.

## Data collected by Discovery during horizontal discovery {#data-discovered-aws-patterns__section_e1d_bfm_kmb}

Resources discovered using the Amazon
AWS - Availability Zone (LP) pattern
:
    {#data-discovered-aws-patterns__table_erd_wrw_mdc__entry__2}

    | Field | Description |
    |-|-|
    | Name \[name\] | Name of the Availability Zone. |
    | Object ID \[object_id\] | Unique identifier, allocated by Amazon AWS Cloud for this resource. |
    | State \[state\] | The state of the Availability Zone. The possible values are: available, information, impaired, and unavailable. |
    [Table 3. Availability Zone \[cmdb_ci_availability_zone\]]

    {#data-discovered-aws-patterns__table_erd_wrw_mdc}

Resources discovered using the Amazon
AWS - Classic LB (LP) pattern
:
    {#data-discovered-aws-patterns__table_h3y_1sw_mdc__entry__2}

    | Field | Description |
    |-|-|
    | Name \[name\] | The name of the load balancer. |
    | Fully Qualified Domain Name \[fqdn\] | The DNS name of the load balancer. |
    | Object ID \[object_id\] | Unique identifier, allocated by Amazon AWS Cloud for this resource. |
    | DNS Name \[dns_name\] | The DNS name of the load balancer. |
    | Canonical Hosted Zone Name \[canonical_hosted_zone_name\] | The DNS name of the load balancer. |
    | Canonical Hosted Zone ID \[canonical_hosted_zone_id\] | The ID of the Amazon Route 53 hosted zone for the load balancer. |
    [Table 4. Cloud Load Balancer \[cmdb_ci_cloud_load_balancer\]]

    {#data-discovered-aws-patterns__table_h3y_1sw_mdc}

    {#data-discovered-aws-patterns__table_o55_bsw_mdc__entry__2}

    | Field | Description |
    |-|-|
    | Name \[name\] | IP address of the Load Balancer. |
    | Object ID \[object_id\] | IP address of the Load Balancer. |
    | IP Address \[ip_address\] | IP address of the Load Balancer. |
    | Comments \[comments\] | Comments related to the Configuration Item (CI). |
    [Table 5. Cloud LB IPAddress \[cmdb_ci_cloud_lb_ipaddress\]]

    {#data-discovered-aws-patterns__table_o55_bsw_mdc}

    {#data-discovered-aws-patterns__table_t1w_bsw_mdc__entry__2}

    | Field | Description |
    |-|-|
    | Name \[name\] | Name of the Domain Name System (DNS). |
    | IP Address \[ip_address\] | IP address of the DNS. |
    | Comments \[comments\] | Comments related to the CI. |
    [Table 6. DNS Name \[cmdb_ci_dns_name\]]

    {#data-discovered-aws-patterns__table_t1w_bsw_mdc}

    {#data-discovered-aws-patterns__table_w1x_bsw_mdc__entry__2}

    | Field | Description |
    |-|-|
    | Name \[name\] | The name of the load balancer pool. |
    | Object ID \[object_id\] | Unique identifier, allocated by Amazon AWS Cloud for this resource. |
    | Comments \[comments\] | Comments related to the CI. |
    [Table 7. Load Balancer Pool \[cmdb_ci_lb_pool\]]

    {#data-discovered-aws-patterns__table_w1x_bsw_mdc}

    {#data-discovered-aws-patterns__table_zzx_bsw_mdc__entry__2}

    | Field | Description |
    |-|-|
    | Name \[name\] | The name of the load balancer pool member (known in AWS as a target). |
    | Object ID \[object_id\] | Unique identifier, allocated by Amazon AWS Cloud for this resource. |
    [Table 8. Load Balancer Pool Member \[cmdb_ci_lb_pool_member\]]

    {#data-discovered-aws-patterns__table_zzx_bsw_mdc}

    {#data-discovered-aws-patterns__table_a1z_bsw_mdc__entry__2}

    | Field | Description |
    |-|-|
    | Name \[name\] | Name of the load balancer service. |
    | Object ID \[object_id\] | Unique identifier, allocated by Amazon AWS Cloud for this resource. |
    | Port \[port\] | The port on which the load balancer is listening. |
    | Service Port \[service_port\] | The port on which the instance is listening. |
    | Server Protocol \[service_protocol\] | The protocol to use for routing traffic to instances: HTTP, HTTPS, TCP, or SSL. |
    | Listener Protocol \[service_protocol\] | The load balancer transport protocol to use for routing: HTTP, HTTPS, TCP, or SSL. |
    | Comments \[comments\] | Comments related to the CI. |
    [Table 9. Load Balancer Service \[cmdb_ci_lb_service\]]

    {#data-discovered-aws-patterns__table_a1z_bsw_mdc}

Resources discovered using the Amazon AWS - LB Pool Member(LP) pattern
:
    {#data-discovered-aws-patterns__table_ntq_x3y_p2c__entry__2}

    | Field | Description |
    |-|-|
    | Name \[name\] | Target ID, depending on the target type. For example: Instance ID, IP address, Lambda ARN, or Application Load Balancer ARN. |
    | Service port \[service_port\] | The port on which the target is listening, if available. |
    | Object ID \[object_id\] | Possible values are: * Target ID * Target ID and target port, if available, in the following format: <kbd class="ph userinput">&lt;target ID&gt;#&lt;target port&gt;</kbd>. For example: <kbd class="ph userinput">i-0123456789abcdef0#8080</kbd> {#data-discovered-aws-patterns__ul_z4s_sly_p2c} |
    | Comments \[comments\] | Comments related to the CI. |
    | Operational status \[operational_status\] | Operational status of the target. Possible values are Operational or Non-Operational. |
    | Install Status \[install_status\] | Installation status of the target. Possible values are Installed or Retired. |
    | Pool \[pool\] | References the Load Balancer Pool \[cmdb_ci_lb_pool\] table. |
    [Table 10. Load Balancer Pool Member \[cmdb_ci_lb_pool_member\]]

    {#data-discovered-aws-patterns__table_ntq_x3y_p2c}  
    Note:  
    By default, the Amazon AWS - LB Pool Member(LP) pattern doesn't execute discovery. To enable the discovery of AWS Application Load Balancer targets, set the sn_itom_pattern.discover_aws_app_pool_members MID Server property to true. For more information, see [Enable AWS Application Load Balancer target discovery](https://www.servicenow.com/docs/q2~uMF1b83QCsuqub2AOhQ "Enable the sn_itom_pattern.discover_aws_app_pool_members MID Server property to discover AWS Application Load Balancer targets.").

Resources discovered using the Amazon
AWS - Customer Gateway (LP) pattern
:
    {#data-discovered-aws-patterns__table_rtm_ltw_mdc__entry__2}

    | Field | Description |
    |-|-|
    | Name \[name\] | Name or ID if no Name is specified of the customer gateway. |
    | Object ID \[object_id\] | ID of the customer gateway. |
    | Connection Type \[connection_type\] | Type of VPN connection the customer gateway supports. |
    [Table 11. Customer Gateway \[cmdb_ci_customer_gateway\]]

    {#data-discovered-aws-patterns__table_rtm_ltw_mdc}

    {#data-discovered-aws-patterns__table_thc_mtw_mdc__entry__2}

    | Field | Description |
    |-|-|
    | Name \[name\] | Name or ID if no Name is specified of the customer gateway. |
    | Object ID \[object_id\] | ID of the customer gateway. |
    [Table 12. Customer Gateway Endpoint \[cmdb_ci_endpoint_cust_gateway\]]

    {#data-discovered-aws-patterns__table_thc_mtw_mdc}

Resources discovered using the Amazon
AWS - discover Organization pattern
:
    {#data-discovered-aws-patterns__table_sy5_b52_cbc__entry__2}

    | Field | Description |
    |-|-|
    | Name \[name\] | The unique identifier (ID) of the management account of an organization. |
    | Object ID \[object_id\] | The unique identifier (ID) of the management account of an organization. |
    | Root ID \[root_id\] | The unique identifier (ID) of an organization. |
    | Master Email \[master_email\] | The email address associated with the AWS account that is designated as the management account for the organization. |
    | Install Status \[install_status\] | The install status of the Organization based on the AvailablePolicyTypes status. |
    | Operational status \[operational_status\] | The operational status of the Organization based on the AvailablePolicyTypes status. |
    [Table 13. Cloud Organizations \[cmdb_ci_cloud_org\]]

    {#data-discovered-aws-patterns__table_sy5_b52_cbc}

Resources discovered the using the Amazon
AWS - Host (LP) pattern
:
    {#data-discovered-aws-patterns__table_l3d_fb2_h4b__entry__2}

    | Field | Description |
    |-|-|
    | Name \[name\] | Name of this host. |
    | Object ID \[object_id\] | Unique identifier, allocated by Amazon AWS Cloud for this resource. |
    | CPU Core Count \[cpu_core_count\] | The number of host cores. |
    | State \[state\] | The current state of the host. |
    | Host Type \[host_type\] | The host type (instanceFamily). |
    | Cloud Vendor \[cloud_vendor\] | The cloud vendor: AWS. |
    | Virtual \[virtual\] | Virtual host: False. |
    [Table 14. Cloud Host \[cmdb_ci_cloud_host\]]

    {#data-discovered-aws-patterns__table_l3d_fb2_h4b}

Resources discovered using the Amazon
AWS - Internet Gateway (LP) pattern
:
    {#data-discovered-aws-patterns__table_p3g_wfw_lmb__entry__2}

    | Field | Description |
    |-|-|
    | Name \[name\] | Name or ID if no Name is specified for the internet gateway. |
    | Object ID \[object_id\] | ID of the internet gateway. |
    [Table 15. Internet Gateway \[cmdb_ci_internet_gateway\]]

    {#data-discovered-aws-patterns__table_p3g_wfw_lmb}

    {#data-discovered-aws-patterns__table_zsl_m5w_mdc__entry__2}

    | Field | Description |
    |-|-|
    | Name \[name\] | Name or ID if no Name is specified for the internet gateway. |
    | Object ID \[object_id\] | ID of the internet gateway. |
    [Table 16. Internet Gateway Endpoint \[cmdb_ci_endpoint_intgateway\]]

    {#data-discovered-aws-patterns__table_zsl_m5w_mdc}

Resources discovered using the Amazon
AWS - IP Address (LP) pattern
:
    {#data-discovered-aws-patterns__table_qz4_zfw_lmb__entry__2}

    | Field | Description |
    |-|-|
    | Name \[name\] | The name or ID if no Name is specified for the Network Interface. |
    | IP Address \[ip_address\] | If available, the address of the Elastic IP address bound to the network interface. If not available, the Private IP. |
    | Object ID \[object_id\] | The ID of the Network Interface. |
    | Public DNS \[public_dns\] | The public DNS name if available. |
    | Private IP Address \[private_ip\] | The IPv4 address of the network interface within the subnet. |
    | Instance ID \[instance_id\] | The ID of the instance. |
    [Table 17. IP Address \[cmdb_ci_cloud_ip_address\]]

    {#data-discovered-aws-patterns__table_qz4_zfw_lmb}

Resources discovered the using the Amazon
AWS - Key Pair (LP) pattern
:
    {#data-discovered-aws-patterns__table_ttg_dgw_lmb__entry__2}

    | Field | Description |
    |-|-|
    | Name \[name\] | The name of the key pair. |
    | Object ID \[object_id\] | The ID of the key pair. |
    | Finger Print \[finger_print\] | If you used [CreateKeyPair](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateKeyPair.html) to create the key pair, this value is the SHA-1 digest of the DER encoded private key. If you used ImportKeyPair to provide AWS the public key, this value is the MD5 public key fingerprint as specified in section 4 of RFC 4716. |
    [Table 18. Cloud Key Pair \[cmdb_ci_cloud_key_pair\]]

    {#data-discovered-aws-patterns__table_ttg_dgw_lmb}

Resources discovered using the Amazon
AWS - LB Pool (LP) pattern
:
    {#data-discovered-aws-patterns__table_ldm_ggw_lmb__entry__2}

    | Field | Description |
    |-|-|
    | Name \[name\] | The name of the load balancer pool. |
    | Object ID \[object_id\] | Unique identifier, allocated by Amazon AWS Cloud for this resource. |
    | Comments \[comments\] | Comments related to the CI. |
    [Table 19. Load Balancer Pool \[cmdb_ci_lb_pool\]]

    {#data-discovered-aws-patterns__table_ldm_ggw_lmb}

Resources discovered using the Amazon
AWS - LB Service (LP) pattern
:
    {#data-discovered-aws-patterns__table_ums_3gw_lmb__entry__2}

    | Field | Description |
    |-|-|
    | Name \[name\] | Name of the load balancer service. |
    | Object ID \[object_id\] | Unique identifier, allocated by Amazon AWS Cloud for this resource. |
    | Port \[port\] | The port on which the load balancer is listening. |
    | Service Port \[service_port\] | The port on which the instance is listening. |
    | Server Protocol \[service_protocol\] | The protocol to use for routing traffic to instances: HTTP, HTTPS, TCP, or SSL. |
    | Listener Protocol \[service_protocol\] | The load balancer transport protocol to use for routing: HTTP, HTTPS, TCP, or SSL. |
    | Comments \[comments\] | Comments related to the CI. |
    [Table 20. Load Balancer Service \[cmdb_ci_lb_service\]]

    {#data-discovered-aws-patterns__table_ums_3gw_lmb}

Resources discovered using the Amazon
AWS - NAT Gateway (LP) pattern
:
    {#data-discovered-aws-patterns__table_ohk_kgw_lmb__entry__2}

    | Field | Description |
    |-|-|
    | Name \[name\] | Name of the NAT gateway. |
    | Object ID \[object_id\] | Unique identifier, allocated by Amazon AWS Cloud for this resource. |
    | Install Status \[install_status\] | Provisioning status of the NAT gateway. |
    [Table 21. NAT Gateway \[cmdb_ci_nat_gateway\]]

    {#data-discovered-aws-patterns__table_ohk_kgw_lmb}

    {#data-discovered-aws-patterns__table_i32_lzw_mdc__entry__2}

    | Field | Description |
    |-|-|
    | Name \[name\] | The name of the NAT endpoint. |
    | Object ID \[object_id\] | Unique identifier, allocated by Amazon AWS Cloud for this resource. |
    [Table 22. NAT Endpoint \[cmdb_ci_endpoint_nat\]]

    {#data-discovered-aws-patterns__table_i32_lzw_mdc}

Resources discovered using the Amazon
AWS - Network (LP) pattern
:
    {#data-discovered-aws-patterns__table_rt4_4gw_lmb__entry__2}

    | Field | Description |
    |-|-|
    | Name \[name\] | Name of the Virtual Private Cloud (VPC) network. |
    | Object ID \[object_id\] | Unique identifier, allocated by Amazon AWS Cloud for this resource. |
    | State \[state\] | The current state of the VPC: pending or available. |
    | CIDR \[cidr\] | CIDR representation of the subnet. For example, 10.0.0.0/24. |
    | Install Status \[install_status\] | Resource provisioning status. |
    [Table 23. Cloud Network \[cmdb_ci_network\]]

    {#data-discovered-aws-patterns__table_rt4_4gw_lmb}

Resources discovered using the Amazon
AWS - NIC (LP) pattern
:
    {#data-discovered-aws-patterns__table_wct_qgw_lmb__entry__2}

    | Field | Description |
    |-|-|
    | Name \[name\] | The Name or ID if no Name is specified for the Network Interface. |
    | Object ID \[object_id\] | The ID of the network interface. |
    | State \[state\] | The status of the network interface. The valid values are as follows: available, associated, attaching, in-use, or detaching. |
    | Private IP \[private_ip\] | The IPv4 address of the network interface within the subnet. |
    | IP Address \[ip_address\] | If available, the address of the Elastic IP address bound to the network interface. If not available, the Private IP. |
    | Public IP \[public_ip\] | The address of the Elastic IP address bound to the network interface. |
    [Table 24. Cloud Mgmt Network Interface \[cmdb_ci_nic\]]

    {#data-discovered-aws-patterns__table_wct_qgw_lmb}

    {#data-discovered-aws-patterns__table_aln_21x_mdc__entry__2}

    | Field | Description |
    |-|-|
    | Name \[name\] | IP address of the Load Balancer. |
    | Object ID \[object_id\] | If available, the address of the Elastic IP address bound to the network. If not available, the Private IP. |
    | IP Address \[ip_address\] | If available, the address of the Elastic IP address bound to the network interface. If not available, the Private IP. |
    | Comments \[comments\] | Comments related to the CI. |
    [Table 25. Cloud LB IPAddress \[cmdb_ci_cloud_lb_ipaddress\]]

    {#data-discovered-aws-patterns__table_aln_21x_mdc}

    {#data-discovered-aws-patterns__table_wdf_f1x_mdc__entry__2}

    | Field | Description |
    |-|-|
    | Name \[name\] | The name of the virtual network machine interface (VNIC) endpoint. |
    | Object ID \[object_id\] | Unique identifier, allocated by Amazon AWS Cloud for this resource. |
    | IP Address \[ip_address\] | If available, the address of the Elastic IP address bound to the network interface. If not available, the Private IP. |
    | Host \[host\] | The ID of the instance. |
    [Table 26. VNIC Endpoint \[cmdb_ci_endpoint_vnic\]]

    {#data-discovered-aws-patterns__table_wdf_f1x_mdc}

Resources discovered using the Amazon
AWS - Organizational Units (LP) pattern
:
    {#data-discovered-aws-patterns__table_b4d_kx2_cbc__entry__2}

    | Field | Description |
    |-|-|
    | Name \[name\] | The user-friendly name of the Organizational Unit (OU). |
    | Object ID \[object_id\] | The unique identifier (ID) associated with this OU. The ID is unique to the organization. |
    | Organizational ID \[aws_org_id\] | The unique identifier (ID) associated with this OU. The ID is unique to the organization. |
    | Org Unit Parent ID \[org_unit_parent_id\] | The ID of the root or the immediate parent OU. |
    [Table 27. AWS Organizational Unit \[cmdb_ci_aws_org_unit\]]

    {#data-discovered-aws-patterns__table_b4d_kx2_cbc}

Resources discovered using the Amazon
AWS - Public IP Address (LP) pattern
:
    {#data-discovered-aws-patterns__table_dbn_4hw_lmb__entry__2}

    | Field | Description |
    |-|-|
    | Name \[name\] | The name or allocation ID, if no name is specified for the public IP address. |
    | Object ID \[object_id\] | The ID representing the allocation of the address for the use with EC2-VPC. |
    | Public ID Address \[public_ip\] | The elastic IP address. |
    [Table 28. Cloud Public IP Address \[cmdb_ci_cloud_public_ipaddress\]]

    {#data-discovered-aws-patterns__table_dbn_4hw_lmb}

Resources discovered using the Amazon
AWS - Route Table (LP) pattern
:
    {#data-discovered-aws-patterns__table_uqv_rhw_lmb__entry__2}

    | Field | Description |
    |-|-|
    | Name \[name\] | The ID of the route table. |
    | State \[state\] | If the route table is discoverable, the value is available. |
    | Object ID \[object_id\] | The name or ID, if no name is specified for the route table. |
    [Table 29. Route Table \[cmdb_ci_route_table\]]

    {#data-discovered-aws-patterns__table_uqv_rhw_lmb}

    {#data-discovered-aws-patterns__table_gnx_fbx_mdc__entry__2}

    | Field | Description |
    |-|-|
    | Name \[name\] | The name or ID, if no name is specified for the route table. |
    | Object ID \[object_id\] | The ID of the route table. |
    [Table 30. Route Table Endpoint \[cmdb_ci_endpoint_route_table\]]

    {#data-discovered-aws-patterns__table_gnx_fbx_mdc}

Resources discovered using the Amazon
AWS - Security Group (LP) pattern
:
    {#data-discovered-aws-patterns__table_ws5_vhw_lmb__entry__2}

    | Field | Description |
    |-|-|
    | Name \[name\] | The name of the security group. |
    | Object ID \[object_id\] | The ID of the security group. |
    [Table 31. Compute Security Group \[cmdb_ci_compute_security_group\]]

    {#data-discovered-aws-patterns__table_ws5_vhw_lmb}

Resources discovered using the Amazon
AWS - SSM Cloud Agents (LP) pattern

:   The Amazon AWS - SSM Cloud Agents (LP) pattern introduces the following CI class that extends an existing CMDB class.

    {#data-discovered-aws-patterns__table_extends_ssm__entry__2}

    | CI class | Extends from |
    |-|-|
    | Cloud System Management Agent \[cmdb_ci_cloud_system_management_agent\] | Virtual Machine Object \[cmdb_ci_vm_object\] |
    [Table 32. CI class introduced by this pattern]

    {#data-discovered-aws-patterns__table_extends_ssm}  
    {#data-discovered-aws-patterns__table_dnd_xpy_1fc__entry__2}

    | Field | Description |
    |-|-|
    | Cloud Agent Type \[cloud_agent_type\] | Type of cloud agent: AWS SSM. |
    | Install Status \[install_status\] | Install status of the AWS Systems Manager (SSM) agent: * Installed: The agent is currently running. * Absent: The agent is not currently running. {#data-discovered-aws-patterns__ul_rlw_x2n_cfc} |
    | IP Address \[ip_address\] | Address of the VM instance. |
    | Name \[name\] | Name of the VM instance that the SSM agent is running on. |
    | Object ID \[object_id\] | ID of the VM instance. |
    | Operational status \[operational_status\] | Operational status of the agent service. Possible values are Operational or Non-Operational. |
    | Operating System Platform \[operating_system_platform\] | Operating system type of the VM instance. |
    | Resource Type \[resource_type\] | Type of resource managed by SSM. Possible values are EC2Instance or ManagedInstance. |
    | Version \[version\] | Version of the SSM agent. |
    [Table 33. Cloud System Management Agent \[cmdb_ci_cloud_system_management_agent\]]

    {#data-discovered-aws-patterns__table_dnd_xpy_1fc}

Resources discovered using the Amazon
AWS - Storage (LP) pattern
:
    {#data-discovered-aws-patterns__table_o5f_13w_lmb__entry__2}

    | Field | Description |
    |-|-|
    | State \[state\] | The volume state. The following values are valid: creating, available, in-use, deleting, deleted, or error. |
    | Storage Type \[storage_type\] | For example, hard-coded value: block. |
    | Volume ID \[volume_id\] | The volume type. For example, gp2 for General Purpose SSD, io1 for Provisioned IOPS SSD, st1 for Throughput Optimized HDD, sc1 for Cold HDD, or standard for Magnetic volumes. |
    | Name \[name\] | The name or ID, if no name is specified for the volume. |
    | Size Bytes \[size_bytes\] | The size of the volume, in bytes. |
    | Object ID \[object_id\] | The ID of the volume. |
    [Table 34. Storage Volume \[cmdb_ci_storage_volume\]]

    {#data-discovered-aws-patterns__table_o5f_13w_lmb}

    {#data-discovered-aws-patterns__table_gh5_tbx_mdc__entry__2}

    | Field | Description |
    |-|-|
    | Name \[name\] | The name or ID, if no name is specified for the volume. |
    | Object ID \[object_id\] | The ID of the volume. |
    [Table 35. Block Endpoint \[cmdb_ci_endpoint_block\]]

    {#data-discovered-aws-patterns__table_gh5_tbx_mdc}

Resources discovered using the Amazon
AWS - Sub Account (LP) pattern
:
    {#data-discovered-aws-patterns__table_ppq_c3w_lmb__entry__2}

    | Field | Description |
    |-|-|
    | Account ID \[account_id\] | Unique identifier (ID) of the account. |
    | Object ID \[object_id\] | Unique identifier (ID) of the account. |
    | Datacenter Type \[datacenter_type\] | Hard-coded value: cmdb_ci_aws_datacenter. |
    | Name \[name\] | User-friendly name of the account. |
    | Is Master Account \[is_master_account\] | Boolean attribute indicating if this account is the management account or not. |
    | Account Email \[account_email\] | Email address of the AWS service account. |
    [Table 36. Cloud Service Account \[cmdb_ci_cloud_service_account\]]

    {#data-discovered-aws-patterns__table_ppq_c3w_lmb}

Resources discovered using the Amazon
AWS - Subnet (LP) pattern
:
    {#data-discovered-aws-patterns__table_pjl_h3w_lmb__entry__2}

    | Field | Description |
    |-|-|
    | Name \[name\] | The name or ID, if no name is specified for the subnet. |
    | Object ID \[object_id\] | The ID of the subnet. |
    | CIDR \[cidr\] | The IPv4 CIDR block assigned to the subnet. |
    | Available IP Count \[available_ip_count\] | The number of unused private IPv4 addresses in the subnet. The IPv4 addresses for any stopped instances are considered unavailable. |
    | State \[state\] | The current state of the subnet. The following values are valid: pending or available. |
    [Table 37. Cloud Subnet \[cmdb_ci_cloud_subnet\]]

    {#data-discovered-aws-patterns__table_pjl_h3w_lmb}

Resources discovered using the Amazon
AWS - VPN Connections (LP) pattern
:
    {#data-discovered-aws-patterns__table_lkb_m3w_lmb__entry__2}

    | Field | Description |
    |-|-|
    | Name \[name\] | Name of the project that is used for the discovery. |
    | Object ID \[object_id\] | The name or ID, if no name is specified for the VPN connection. |
    | State \[state\] | The current state of the VPN connection. The following values are valid: pending, available, deleting, or deleted. |
    [Table 38. VPN Connection \[cmdb_ci_vpn_connection\]]

    {#data-discovered-aws-patterns__table_lkb_m3w_lmb}

Resources discovered using the Amazon
AWS - VPN Gateway (LP) pattern
:
    {#data-discovered-aws-patterns__table_mcw_43w_lmb__entry__2}

    | Field | Description |
    |-|-|
    | Name \[name\] | The name or ID, if no name is specified for the VPN Gateway. |
    | Object ID \[object_id\] | The ID of the virtual private gateway. |
    | Connection Type \[connection_type\] | The type of VPN connection the virtual private gateway supports. |
    [Table 39. Virtual Private Gateway \[cmdb_ci_virtual_pvt_gateway\]]

    {#data-discovered-aws-patterns__table_mcw_43w_lmb}

    {#data-discovered-aws-patterns__table_cmq_ldx_mdc__entry__2}

    | Field | Description |
    |-|-|
    | Name \[name\] | The name or ID, if no name is specified for the VPN Gateway. |
    | Object ID \[object_id\] | The ID of the virtual private gateway. |
    | Connection Type \[connection_type\] | The type of VPN connection the virtual private gateway supports. |
    [Table 40. Virtual Private Gateway Endpoint \[cmdb_ci_endpoint_vpg\]]

    {#data-discovered-aws-patterns__table_cmq_ldx_mdc}

Resources discovered using the Amazon
AWS - Web ACL (LP) pattern

:   The Amazon AWS - Web ACL (LP) pattern introduces the following CI class that extends an existing CMDB class.

    {#data-discovered-aws-patterns__table_extends_webacl__entry__2}

    | CI class | Extends from |
    |-|-|
    | Web ACL \[cmdb_ci_web_acl\] | Virtual Machine Object \[cmdb_ci_vm_object\] |
    [Table 41. CI class introduced by this pattern]

    {#data-discovered-aws-patterns__table_extends_webacl}  
    {#data-discovered-aws-patterns__table_il1_nbb_y2c__entry__2}

    | Field | Description |
    |-|-|
    | Name \[name\] | Name of the web access control list (web ACL). |
    | Object ID \[object_id\] | Unique ID for the web ACL from AWS. |
    | Default Action \[defaul_action\] | Default action when no rules in the web ACL match. Possible values are Allow or Deny. |
    | Description \[short_description\] | Description of web ACL provided by AWS. |
    | Operational status \[operational_status\] | Whether the web ACL is enabled or disabled. Possible values are Operational or Retired. |
    [Table 42. Web ACL \[cmdb_ci_web_acl\]]

    {#data-discovered-aws-patterns__table_il1_nbb_y2c}  
    Note:  
    Security Operations users can leverage the integration with Discovery to import web ACL rules and load balancers with attached web ACLs. For more information on setting ACL rules and using the Mitigation Controls Monitoring app, see [Configure the AWS WAF integration for mitigation controls monitoring](https://www.servicenow.com/docs/access?context=spc-install-config-aws-waf&version=australia&pubname=australia-security-management&ft:locale=en-US).

## Events discovered by Discovery during horizontal discovery {#data-discovered-aws-patterns__section_glt_jsd_mmb}

Discovery uses patterns to find events created for Amazon AWS Cloud components. If there are events that indicate the change of state in one of the Amazon AWS Cloud components, it triggers discovery of Amazon AWS Cloud components using the patterns.
{#data-discovered-aws-patterns__table_fmp_4td_mmb__entry__2}

| Pattern | CI |
|-|-|
| Amazon AWS Virtual Server Events | Virtual Machine Instance \[cmdb_ci_vm_instance\] |
| Amazon AWS Security Group Events | Compute Security Group \[cmdb_ci_compute_security_group\] |
| Amazon AWS Subnet Events | Cloud Subnet \[cmdb_ci_cloud_subnet\] |
| Amazon AWS Storage Events | Storage Volume \[cmdb_ci_storage_volume\] |
| Amazon AWS Network Events | Cloud Network \[cmdb_ci_network\] |
| Amazon AWS Classic LB Events | Cloud Load Balancer \[cmdb_ci_cloud_load_balancer\] |
| Amazon AWS Application and Network LBs Events | Cloud Load Balancer \[cmdb_ci_cloud_load_balancer\] |
[Table 43. Patterns used for event discovery]

{#data-discovered-aws-patterns__table_fmp_4td_mmb} Figure 2. Dependency Views displaying the cloud load balancer and connected components   

Figure 3. Dependency Views displaying components connected to the cloud network in the AWS environment   

Figure 4. Dependency Views showing Virtual Machine and connected components in the AWS environment   

## CI relationships and references {#data-discovered-aws-patterns__section_prw_ffm89wj}

The AWS patterns create the following relationships and references to support AWS discovery. References link to records in other tables and don't appear in the CI Relationship \[cmdb_rel_ci\] table.  

Relationships discovered using the Amazon
AWS - Availability Zone (LP) pattern
:
    {#data-discovered-aws-patterns__table_wy5_hlp_4mb__entry__3}

    | CI | Relationship | CI |
    |-|-|-|
    | AWS Datacenter \[cmdb_ci_aws_datacenter\] | Contains::Contained by | Availability Zone \[cmdb_ci_availability_zone\] |
    [Table 44. CI relationships]

    {#data-discovered-aws-patterns__table_wy5_hlp_4mb}

Relationships discovered using the Amazon
AWS - Classic LB (LP) pattern
:
    {#data-discovered-aws-patterns__table_xkw_hlp_4mb__entry__3}

    | CI | Relationship | CI |
    |-|-|-|
    | Load Balancer Service \[cmdb_ci_lb_service\] | Hosted on::Hosts | Cloud Load Balancer \[cmdb_ci_cloud_load_balancer\] |
    | Cloud Subnet \[cmdb_ci_cloud_subnet\] | Contains::Contained by | Cloud Load Balancer \[cmdb_ci_cloud_load_balancer\] |
    | Availability Zone \[cmdb_ci_availability_zone\] | Contains::Contained by | Cloud Load Balancer \[cmdb_ci_cloud_load_balancer\] |
    | Load Balancer Pool \[cmdb_ci_lb_pool\] | Hosted on::Hosts | Cloud Load Balancer \[cmdb_ci_cloud_load_balancer\] |
    | Load Balancer Pool \[cmdb_ci_lb_pool\] | Owns::Owned by | Load Balancer Pool Member \[cmdb_ci_lb_pool_member\] |
    | Cloud Load Balancer \[cmdb_ci_cloud_load_balancer\] | Contains::Contained by | DNS Name \[cmdb_ci_dns_name\] |
    | Cloud Load Balancer \[cmdb_ci_cloud_load_balancer\] | Owns::Owned by | Cloud LB IPAddress \[cmdb_ci_cloud_lb_ipaddress\] |
    | Cloud Load Balancer \[cmdb_ci_cloud_load_balancer\] | Hosted on::Hosts | AWS Datacenter \[cmdb_ci_aws_datacenter\] |
    | Cloud Load Balancer \[cmdb_ci_cloud_load_balancer\] | Contains::Contained by | Compute Security Group \[cmdb_ci_compute_security_group\] |
    [Table 45. CI relationships]

    {#data-discovered-aws-patterns__table_xkw_hlp_4mb}

Relationships discovered using the Amazon AWS - LB Pool Member(LP) pattern
:
    {#data-discovered-aws-patterns__table_s23_s3y_p2c__entry__3}

    | CI | Relationship | CI |
    |-|-|-|
    | Load Balancer Pool \[cmdb_ci_lb_pool\] | Owns::Owned by | Load Balancer Pool Member \[cmdb_ci_lb_pool_member\] |
    [Table 46. CI relationships]

    {#data-discovered-aws-patterns__table_s23_s3y_p2c}

    {#data-discovered-aws-patterns__table_ci_references_lbpm__entry__3}

    | CI | Field | Referenced CI |
    |-|-|-|
    | Load Balancer Pool Member \[cmdb_ci_lb_pool_member\] | Pool \[pool\] | Load Balancer Pool \[cmdb_ci_lb_pool\] |
    [Table 47. CI references]

    {#data-discovered-aws-patterns__table_ci_references_lbpm}  
    Note:  
    By default, the Amazon AWS - LB Pool Member(LP) pattern doesn't execute discovery. To enable the discovery of AWS Application Load Balancer targets, set the sn_itom_pattern.discover_aws_app_pool_members MID Server property to true. For more information, see [Enable AWS Application Load Balancer target discovery](https://www.servicenow.com/docs/q2~uMF1b83QCsuqub2AOhQ "Enable the sn_itom_pattern.discover_aws_app_pool_members MID Server property to discover AWS Application Load Balancer targets.").

Relationships discovered using the Amazon
AWS - Customer Gateway (LP) pattern
:
    {#data-discovered-aws-patterns__table_fjx_hlp_4mb__entry__3}

    | CI | Relationship | CI |
    |-|-|-|
    | Customer Gateway \[cmdb_ci_customer_gateway\] | Hosted on::Hosts | Virtual Machine Instance \[cmdb_ci_instance\] |
    | Customer Gateway \[cmdb_ci_customer_gateway\] | Implement End Point To::Implement End Point From | Customer Gateway \[cmdb_ci_endpoint_cust_gateway\] |
    [Table 48. CI relationships]

    {#data-discovered-aws-patterns__table_fjx_hlp_4mb}

Relationships discovered using the Amazon
AWS - Host (LP) pattern
:
    {#data-discovered-aws-patterns__table_emq_cf2_h4b__entry__3}

    | CI | Relationship | CI |
    |-|-|-|
    | Host \[cmdb_ci_cloud_host\] | Hosted on::Hosts | AWS Datacenter \[cmdb_ci_aws_datacenter\] |
    | Virtual Machine Instance \[cmdb_ci_vm_instance\] | Runs on::Runs | Host \[cmdb_ci_cloud_host\] |
    [Table 49. CI relationships]

    {#data-discovered-aws-patterns__table_emq_cf2_h4b}

Relationships discovered using the Amazon
AWS - Internet Gateway (LP) pattern
:
    {#data-discovered-aws-patterns__table_f4w_zqp_4mb__entry__3}

    | CI | Relationship | CI |
    |-|-|-|
    | Internet Gateway \[cmdb_ci_internet_gateway\] | Hosted on::Hosts | AWS Datacenter \[cmdb_ci_aws_datacenter\] |
    | Internet Gateway \[cmdb_ci_internet_gateway\] | Implement End Point To::Implement End Point From | Internet Gateway EP \[cmdb_ci_endpoint_intgateway\] |
    | Cloud Network \[cmdb_ci_network\] | Use End Point To::Use End Point From | Internet Gateway EP \[cmdb_ci_endpoint_intgateway\] |
    [Table 50. CI relationships]

    {#data-discovered-aws-patterns__table_f4w_zqp_4mb}

Relationships discovered using the Amazon
AWS - IP Address (LP) pattern
:
    {#data-discovered-aws-patterns__table_i5w_zqp_4mb__entry__3}

    | CI | Relationship | CI |
    |-|-|-|
    | Cloud Key Pair \[cmdb_ci_cloud_key_pair\] | Contains::Contained by | IP Address \[cmdb_ci_cloud_ip_address\] |
    [Table 51. CI relationships]

    {#data-discovered-aws-patterns__table_i5w_zqp_4mb}

Relationships discovered using the Amazon
AWS - Key Pair (LP) pattern
:
    {#data-discovered-aws-patterns__table_mcx_zqp_4mb__entry__3}

    | CI | Relationship | CI |
    |-|-|-|
    | Servers \[cmdb_ci_server\] | Hosted on::Hosts | AWS Datacenter \[cmdb_ci_aws_datacenter\] |
    [Table 52. CI relationships]

    {#data-discovered-aws-patterns__table_mcx_zqp_4mb}

Relationships discovered using the Amazon
AWS - LB Pool (LP) pattern
:
    {#data-discovered-aws-patterns__table_nkx_zqp_4mb__entry__3}

    | CI | Relationship | CI |
    |-|-|-|
    | Load Balancer Pool \[cmdb_ci_lb_pool\] | Hosted on::Hosts | Cloud Load Balancer \[cmdb_ci_cloud_load_balancer\] |
    [Table 53. CI relationships]

    {#data-discovered-aws-patterns__table_nkx_zqp_4mb}

Relationships discovered using the Amazon AWS - LB Service (LP) pattern
:
    {#data-discovered-aws-patterns__table_trr_wsp_4mb__entry__3}

    | CI | Relationship | CI |
    |-|-|-|
    | Load Balancer Service \[cmdb_ci_lb_service\] | Hosted on::Hosts | Cloud Load Balancer \[cmdb_ci_cloud_load_balancer\] |
    [Table 54. CI relationships]

    {#data-discovered-aws-patterns__table_trr_wsp_4mb}

Relationships discovered using the Amazon
AWS - NAT Gateway (LP) pattern
:
    {#data-discovered-aws-patterns__table_etx_zqp_4mb__entry__3}

    | CI | Relationship | CI |
    |-|-|-|
    | NAT Gateway \[cmdb_ci_nat_gateway\] | Hosted on::Hosts | AWS Datacenter \[cmdb_ci_aws_datacenter\] |
    | NAT Gateway \[cmdb_ci_nat_gateway\] | Implement End Point To::Implement End Point From | NAT EP \[cmdb_ci_endpoint_nat\] |
    | Network \[cmdb_ci_network\] | Use End Point To::Use End Point From | NAT EP \[cmdb_ci_endpoint_nat\] |
    [Table 55. CI relationships]

    {#data-discovered-aws-patterns__table_etx_zqp_4mb}

Relationships discovered using the Amazon
AWS - Network (LP) pattern
:
    {#data-discovered-aws-patterns__table_tcy_zqp_4mb__entry__3}

    | CI | Relationship | CI |
    |-|-|-|
    | Network \[cmdb_ci_network\] | Hosted on::Hosts | AWS Datacenter \[cmdb_ci_aws_datacenter\] |
    [Table 56. CI relationships]

    {#data-discovered-aws-patterns__table_tcy_zqp_4mb}

Relationships discovered using the Amazon
AWS - NIC (LP) pattern
:
    {#data-discovered-aws-patterns__table_ymy_zqp_4mb__entry__3}

    | CI | Relationship | CI |
    |-|-|-|
    | Cloud Load Balancer \[cmdb_ci_cloud_load_balancer\] | Owns::Owned by | Cloud LB IPAddress \[cmdb_ci_cloud_lb_ipaddress\] |
    | Virtual Machine Instance \[cmdb_ci_vm_instance\] | Use End Point To::Use End Point From | VNIC Endpoint \[cmdb_ci_endpoint_vnic\] |
    | Cloud Subnet \[cmdb_ci_cloud_subnet\] | Contains::Contained by | NIC \[cmdb_ci_nic\] |
    | VNIC Endpoint \[cmdb_ci_endpoint_vnic\] | Implement End Point To::Implement End Point From | NIC \[cmdb_ci_nic\] |
    | NIC \[cmdb_ci_nic\] | Hosted on::Hosts | AWS Datacenter \[cmdb_ci_aws_datacenter\] |
    [Table 57. CI relationships]

    {#data-discovered-aws-patterns__table_ymy_zqp_4mb}

Relationships discovered using the Amazon
AWS - Organizational Units (LP) pattern
:
    {#data-discovered-aws-patterns__table_ytd_kbf_cbc__entry__3}

    | CI | Relationship | CI |
    |-|-|-|
    | Cloud Organization \[cmdb_ci_cloud_org\] | Contains::Contained by | AWS Organizational Unit \[cmdb_ci_aws_org_unit\] |
    | AWS Organizational Unit \[cmdb_ci_aws_org_unit\] | Contains::Contained by | Cloud Service Account \[cmdb_ci_cloud_service_account\] |
    [Table 58. CI relationships]

    {#data-discovered-aws-patterns__table_ytd_kbf_cbc}

    {#data-discovered-aws-patterns__table_ci_references_org__entry__3}

    | CI | Field | Referenced CI |
    |-|-|-|
    | Key Value \[cmdb_key_value\] | Configuration item \[configuration_item\] | AWS Organizational Unit \[cmdb_ci_aws_org_unit\] |
    [Table 59. CI references]

    {#data-discovered-aws-patterns__table_ci_references_org}

Relationships discovered using the Amazon
AWS - Public IP Address (LP) pattern
:
    {#data-discovered-aws-patterns__table_dmd_gyp_4mb__entry__3}

    | CI | Relationship | CI |
    |-|-|-|
    | Cloud Public IP Address \[cmdb_ci_cloud_public_ipaddress\] | Hosted on::Hosts | AWS Datacenter \[cmdb_ci_aws_datacenter\] |
    [Table 60. CI relationships]

    {#data-discovered-aws-patterns__table_dmd_gyp_4mb}

Relationships discovered using the Amazon
AWS - Route Table (LP) pattern
:
    {#data-discovered-aws-patterns__table_dm2_gyp_4mb__entry__3}

    | CI | Relationship | CI |
    |-|-|-|
    | Network \[cmdb_ci_network\] | Contains::Contained by | Route Table \[cmdb_ci_route_table\] |
    | Cloud Subnet \[cmdb_ci_cloud_subnet\] | Use End Point To::Use End Point From | Route Table Endpoint \[cmdb_ci_endpoint_route_table\] |
    | Route Table \[cmdb_ci_route_table\] | Implement End Point To::Implement End Point From | Route Table Endpoint \[cmdb_ci_endpoint_route_table\] |
    [Table 61. CI relationships]

    {#data-discovered-aws-patterns__table_dm2_gyp_4mb}

Relationships discovered using the Amazon
AWS - Security Group (LP) pattern
:
    {#data-discovered-aws-patterns__table_nw2_gyp_4mb__entry__3}

    | CI | Relationship | CI |
    |-|-|-|
    | Network \[cmdb_ci_network\] | Contains::Contained by | Compute Security Group \[cmdb_ci_compute_security_group\] |
    | Compute Security Group \[cmdb_ci_compute_security_group\] | Hosted on::Hosts | AWS Datacenter \[cmdb_ci_aws_datacenter\] |
    [Table 62. CI relationships]

    {#data-discovered-aws-patterns__table_nw2_gyp_4mb}

Relationships discovered using the Amazon
AWS - SSM Cloud Agents (LP) pattern
:
    {#data-discovered-aws-patterns__table_ky5_2xx_bfc__entry__3}

    | CI | Relationship | CI |
    |-|-|-|
    | Cloud System Management Agent \[cmdb_ci_cloud_system_management_agent\] | Runs on::Runs | Virtual Machine Instance \[cmdb_ci_vm_instance\] |
    [Table 63. CI relationships]

    {#data-discovered-aws-patterns__table_ky5_2xx_bfc}

Relationships discovered using the Amazon
AWS - Storage (LP) pattern
:
    {#data-discovered-aws-patterns__table_yff_gyp_4mb__entry__3}

    | CI | Relationship | CI |
    |-|-|-|
    | Virtual Machine Instance \[cmdb_ci_instance\] | Use End Point To::Use End Point From | Block Endpoint \[cmdb_ci_endpoint_block\] |
    | Block Endpoint \[cmdb_ci_endpoint_block\] | Implement End Point To::Implement End Point From | Storage Volume \[cmdb_ci_storage_volume\] |
    | Availability Zone \[cmdb_ci_availability_zone\] | Contains::Contained by | Storage Volume \[cmdb_ci_storage_volume\] |
    | Storage Volume \[cmdb_ci_storage_volume\] | Hosted on::Hosts | AWS Datacenter \[cmdb_ci_aws_datacenter\] |
    [Table 64. CI relationships]

    {#data-discovered-aws-patterns__table_yff_gyp_4mb}

Relationships discovered using the Amazon
AWS - Subnet (LP) pattern
:
    {#data-discovered-aws-patterns__table_gpf_gyp_4mb__entry__3}

    | CI | Relationship | CI |
    |-|-|-|
    | Network \[cmdb_ci_network\] | Contains::Contained by | Cloud Subnet \[cmdb_ci_cloud_subnet\] |
    | Availability Zone \[cmdb_ci_availability_zone\] | Contains::Contained by | Cloud Subnet \[cmdb_ci_cloud_subnet\] |
    [Table 65. CI relationships]

    {#data-discovered-aws-patterns__table_gpf_gyp_4mb}

Relationships discovered using the Amazon
AWS - VPN Connections (LP) pattern
:
    {#data-discovered-aws-patterns__table_dkg_gyp_4mb__entry__3}

    | CI | Relationship | CI |
    |-|-|-|
    | Customer Gateway \[cmdb_ci_customer_gateway\] | Contains::Contained by | VPN Connection \[cmdb_ci_vpn_connection\] |
    | Virtual Private Gateway \[cmdb_ci_virtual_pvt_gateway\] | Contains::Contained by | VPN Connection \[cmdb_ci_vpn_connection\] |
    | VPN Connection \[cmdb_ci_vpn_connection\] | Hosted on::Hosts | AWS Datacenter \[cmdb_ci_aws_datacenter\] |
    [Table 66. CI relationships]

    {#data-discovered-aws-patterns__table_dkg_gyp_4mb}

Relationships discovered using the Amazon
AWS - VPN Gateway (LP) pattern
:
    {#data-discovered-aws-patterns__table_twg_gyp_4mb__entry__3}

    | CI | Relationship | CI |
    |-|-|-|
    | Virtual Private Gateway \[cmdb_ci_virtual_pvt_gateway\] | Hosted on::Hosts | AWS Datacenter \[cmdb_ci_aws_datacenter\] |
    | Virtual Private Gateway \[cmdb_ci_virtual_pvt_gateway\] | Implement End Point To::Implement End Point From | Virtual Private Gateway Endpoint \[cmdb_ci_endpoint_vpg\] |
    | Network \[cmdb_ci_network\] | Use End Point To::Use End Point From | Virtual Private Gateway Endpoint \[cmdb_ci_endpoint_vpg\] |
    [Table 67. CI relationships]

    {#data-discovered-aws-patterns__table_twg_gyp_4mb}

Relationships discovered using the Amazon
AWS - Web ACL (LP) pattern
:
    {#data-discovered-aws-patterns__table_acx_bdb_y2c__entry__3}

    | CI | Relationship | CI |
    |-|-|-|
    | Web ACL \[cmdb_ci_web_acl\] | Hosted on::Hosts | AWS Datacenter \[cmdb_ci_aws_datacenter\] |
    [Table 68. CI relationships]

    {#data-discovered-aws-patterns__table_acx_bdb_y2c}  
    Note:  
    Security Operations users can leverage the integration with Discovery to import web ACL rules and load balancers with attached web ACLs. For more information on setting ACL rules and using the Mitigation Controls Monitoring app, see [Configure the AWS WAF integration for mitigation controls monitoring](https://www.servicenow.com/docs/access?context=spc-install-config-aws-waf&version=australia&pubname=australia-security-management&ft:locale=en-US).

## Services discovered by patterns {#data-discovered-aws-patterns__section_kjs_st1_qmb}

Horizontal discovery finds EC2 and VPC services running on AWS resources.{#data-discovered-aws-patterns__table_n1n_yt1_qmb__entry__3}

| Service name | CI class | Pattern |
|-|-|-|
| AWS::EC2::SecurityGroup | Compute Security Group \[cmdb_ci_compute_security_group\] | Amazon AWS Security Group Events |
| AWS::EC2::Subnet | Cloud Subnet \[cmdb_ci_cloud_subnet\] | Amazon AWS Subnet Events |
| AWS::EC2::VPC | Cloud Network \[cmdb_ci_network\] | Amazon AWS Network Events |
| AWS::EC2::Instance | Virtual Machine Instance \[cmdb_ci_vm_instance\] | Amazon AWS Virtual Server Events |
| EQS::EC2::Volume | Storage Volume \[cmdb_ci_storage_volume\] | Amazon AWS Elastic Block Storage |
| AWS::ElasticLoadBalancingV2::LoadBalancer | Cloud Load Balancer \[cmdb_ci_cloud_load_balancer\] | Amazon AWS Application and Network LBs Events |
| AWS::ElasticLoadBalancing::LoadBalancer | Cloud Load Balancer \[cmdb_ci_cloud_load_balancer\] | Amazon AWS Classic LBs Events |
[Table 69. Services discovered by Discovery using patterns]

{#data-discovered-aws-patterns__table_n1n_yt1_qmb}

## Data collected by Service Mapping during tag-based discovery {#data-discovered-aws-patterns__section_kmf_r3y_qpb}

Service Mapping uses tag-based discovery to create service instance maps including the Cloud components. The Service Mapping application comes with the following preconfigured CI relationships used for tag-based discovery. These CI relationships are available from the 1.0.68 release on the ServiceNow Store. {#data-discovered-aws-patterns__id_yqp_xhy_qpb__entry__3}

| CI | Relationship | CI |
|-|-|-|
| Configuration Item \[cmdb_ci\] | Hosted on::Hosts | Logical Datacenter \[cmdb_ci_logical_datacenter\] |
| Logical Datacenter \[cmdb_ci_logical_datacenter\] | Hosted on::Hosts | Cloud Service Account \[cmdb_ci_cloud_service_account\] |
[ ]

{#data-discovered-aws-patterns__id_yqp_xhy_qpb}
* **[Amazon API Gateway discovery with Patterns](https://www.servicenow.com/docs/1BC2PtVmScpQ8mLSm9TIBA)**   
  The ServiceNow Discovery and Service Mapping applications use the Amazon AWS API Gateway pattern to find Amazon API Gateways and connections to other entities. Discovering some of these resources might require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
* **[Amazon API Gateway Domain Name pattern-based discovery](https://www.servicenow.com/docs/jmdzQeIAPjClMHNqHxDDIg)**   
  Discovery and Service Mapping Patterns finds AWS services on your cloud environment. Discovering some of these resources might require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
* **[Amazon Athena Workgroup pattern-based discovery](https://www.servicenow.com/docs/eI08sThcVvPMaGot37Dx3Q)**   
  Discovery and Service Mapping Patterns finds Amazon Athena Workgroups on your cloud environment. Discovering some of these resources might require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
* **[Amazon CloudFront Distribution pattern-based discovery](https://www.servicenow.com/docs/11_w8r8g1WeNWkzjTEEi9w)**   
  Discovery and Service Mapping Patterns finds Amazon CloudFront Distributions on your cloud environment. Discovering some of these resources might require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
* **[Amazon CloudWatch Log Group pattern-based discovery](https://www.servicenow.com/docs/AOsqArKCS3WaS8D5ULL5Sg)**   
  Discovery and Service Mapping Patterns finds Amazon CloudWatch Log Groups on your cloud environment. Discovering some of these resources might require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
* **[Amazon DynamoDB Cluster pattern-based discovery](https://www.servicenow.com/docs/KxpkIzMhb5rKbeGDMTACWA)**   
  Discovery and Service Mapping Patterns finds AWS services on your cloud environment. Discovering some of these resources might require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
* **[Amazon EC2 Amazon EBS Snapshot pattern-based discovery](https://www.servicenow.com/docs/ARNQQKBsfF4bLq~ae54Wyg)**   
  Discovery and Service Mapping Patterns finds AWS services on your cloud environment. Discovering some of these resources might require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
* **[Amazon EC2 Reserved Instance pattern-based discovery](https://www.servicenow.com/docs/sv_Ed8OD9U4wMLhpKd0VuA)**   
  Discovery and Service Mapping Patterns finds AWS services on your cloud environment. Discovering some of these resources might require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
* **[Amazon EC2 VPC Endpoint Service pattern-based discovery](https://www.servicenow.com/docs/Bs42X3lH_ij1ZnQFzvNrsA)**   
  Discovery and Service Mapping Patterns finds AWS services on your cloud environment. Discovering some of these resources might require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
* **[Amazon EC2 VPC Peering Connection pattern-based discovery](https://www.servicenow.com/docs/Y4VrwOE38L~216Hc3_p59Q)**   
  Discovery and Service Mapping Patterns finds AWS services on your cloud environment. Discovering some of these resources might require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
* **[Amazon Elastic File System (Amazon EFS) pattern-based discovery](https://www.servicenow.com/docs/qA3uSTKHD6Boy6lZgD5qcw)**   
  Discovery and Service Mapping Patterns finds AWS services on your cloud environment. Discovering some of these resources might require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
* **[Amazon ElastiCache Snapshot pattern-based discovery](https://www.servicenow.com/docs/1BeSDF9tLcAVNzdNPkv7dQ)**   
  Discovery and Service Mapping Patterns finds AWS services on your cloud environment. Discovering some of these resources might require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
* **[Amazon EMR Cluster pattern-based discovery](https://www.servicenow.com/docs/t7ITGzWAoQy5pICv8StCcg)**   
  Discovery and Service Mapping Patterns finds Amazon EMR Clusters on your cloud environment running on EC2. Discovering some of these resources might require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
* **[Amazon EventBridge Event Bus pattern-based discovery](https://www.servicenow.com/docs/9flHqYPmbJIp377vpa4Pug)**   
  Discovery and Service Mapping Patterns finds Amazon EventBridge Event Buses on your cloud environment. Discovering some of these resources might require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
* **[Amazon FSx Backup pattern-based discovery](https://www.servicenow.com/docs/zRvxErQPD5h5H8zSk5FwTw)**   
  Discovery and Service Mapping Patterns finds Amazon FSx Backups on your cloud environment. Discovering some of these resources might require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
* **[Amazon FSx File System pattern-based discovery](https://www.servicenow.com/docs/XDm8aAjcaejZxPDvEEitFQ)**   
  Discovery and Service Mapping Patterns finds Amazon FSx File Systems on your cloud environment. Discovering some of these resources might require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
* **[Amazon MQ Broker pattern-based discovery](https://www.servicenow.com/docs/zzTD2VGLR6VTOpwcVJ9osQ)**   
  Discovery and Service Mapping Patterns finds Amazon MQ Brokers on your cloud environment. Discovering some of these resources might require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
* **[Amazon MQ Configuration pattern-based discovery](https://www.servicenow.com/docs/XT3aYQBQSbMwufwGcu2vIQ)**   
  Discovery and Service Mapping Patterns finds Amazon MQ Configurations on your cloud environment. Discovering some of these resources might require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
* **[Amazon MWAA Environment pattern-based discovery](https://www.servicenow.com/docs/hhls5G3DONPc9jQa6E11mQ)**   
  Discovery and Service Mapping Patterns finds AWS services on your cloud environment. Discovering some of these resources might require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
* **[Amazon RDS DB Snapshot pattern-based discovery](https://www.servicenow.com/docs/yjwXLEAhsBri1LvzdJ3CsQ)**   
  Discovery and Service Mapping Patterns finds AWS services on your cloud environment. Discovering some of these resources might require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
* **[Amazon Redshift Serverless Namespace pattern-based discovery](https://www.servicenow.com/docs/UYgB84CTFb0TthIhVVL~BA)**   
  Discovery and Service Mapping Patterns finds AWS services on your cloud environment. Discovering some of these resources might require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
* **[Amazon Redshift Serverless Snapshot pattern-based discovery](https://www.servicenow.com/docs/FlXaWdmqZ25wkSnv8chg8g)**   
  Discovery and Service Mapping Patterns finds AWS services on your cloud environment. Discovering some of these resources might require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
* **[Amazon Redshift Serverless Workgroup pattern-based discovery](https://www.servicenow.com/docs/GQFkYFFM26xovwOgyVFuPg)**   
  Discovery and Service Mapping Patterns finds AWS services on your cloud environment. Discovering some of these resources might require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
* **[Amazon Route 53 pattern-based discovery](https://www.servicenow.com/docs/08vzeyc6Z~cfZq1mvEzl0Q)**   
  Discovery and Service Mapping Patterns finds Amazon Route 53 domain name systems (DNS) and aliases on your cloud environment. Discovering some of these resources might require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
* **[Amazon S3 Glacier Vault pattern-based discovery](https://www.servicenow.com/docs/0J4k3Cz3y1iH94IY12qHTg)**   
  Discovery and Service Mapping Patterns finds Amazon S3 Glacier Vaults on your cloud environment. Discovering some of these resources might require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
* **[Amazon SageMaker Notebook Instance pattern-based discovery](https://www.servicenow.com/docs/ImODyhGcORkZZzqOlz~yCA)**   
  Discovery and Service Mapping Patterns finds Amazon SageMaker Notebook Instances on your cloud environment. Discovering some of these resources might require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
* **[Amazon SageMaker Training Job pattern-based discovery](https://www.servicenow.com/docs/zQvLu2KkTO0bu5Lg3ef6MA)**   
  Discovery and Service Mapping Patterns finds AWS services on your cloud environment. Discovering some of these resources might require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
* **[Amazon Simple Email Service Identity pattern-based discovery](https://www.servicenow.com/docs/QIA2sXmiiTgiM9~WVomnqg)**   
  Discovery and Service Mapping Patterns finds Amazon Simple Email Service (SES) Identities on your cloud environment. Discovering some of these resources might require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
* **[Amazon SQS Queue pattern-based discovery](https://www.servicenow.com/docs/f7Wohisv1gOyP4VWLh4lcg)**   
  Discovery and Service Mapping Patterns finds Amazon SQS Queues on your cloud environment. Discovering some of these resources might require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
* **[Amazon Timestream for InfluxDB Database Instance pattern-based discovery](https://www.servicenow.com/docs/JqVHBR790HZxW6m3KdGoIA)**   
  Discovery and Service Mapping Patterns finds AWS services on your cloud environment. Discovering some of these resources might require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
* **[Amazon VPC Flow Log pattern-based discovery](https://www.servicenow.com/docs/f0kRvl3y5TRQkW_Q6ynNSg)**   
  Discovery and Service Mapping Patterns finds Amazon Virtual Private Cloud (Amazon VPC) Flow Logs on your cloud environment. Discovering some of these resources might require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
* **[Amazon Amazon VPC Managed Prefix List pattern-based discovery](https://www.servicenow.com/docs/h0PZYhxand28kjD3x4BQoA)**   
  Discovery and Service Mapping Patterns finds Amazon Virtual Private Cloud (Amazon VPC) Managed Prefix Lists on your cloud environment. Discovering some of these resources might require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
* **[AWS Application and Network LB pattern-based discovery](https://www.servicenow.com/docs/UsTPf0~T0IUitArQM2PibQ)**   
  Discovery and Service Mapping Patterns finds AWS Application Load Balancers and Network Load Balancers on your cloud environment. Discovering some of these resources might require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
* **[AWS AppSync API pattern-based discovery](https://www.servicenow.com/docs/UsMTswOaQESfjrC8nST73A)**   
  Discovery and Service Mapping Patterns finds AWS AppSync APIs on your cloud environment. Discovering some of these resources might require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
* **[AWS Backup Plan pattern-based discovery](https://www.servicenow.com/docs/cgSjYQwGDav8UvTv8OgCSg)**   
  Discovery and Service Mapping Patterns finds AWS Backup Plans on your cloud environment. Discovering some of these resources might require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
* **[AWS Backup Vault pattern-based discovery](https://www.servicenow.com/docs/3gbhuVktwoGnZRog8ZHpbA)**   
  Discovery and Service Mapping Patterns finds AWS Backup Vaults on your cloud environment. Discovering some of these resources might require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
* **[AWS Batch Compute Environment pattern-based discovery](https://www.servicenow.com/docs/VJRsDRyKGy4rGL_TVhOOEg)**   
  Discovery and Service Mapping Patterns finds AWS services on your cloud environment. Discovering some of these resources might require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
* **[AWS CloudHSM HSM pattern-based discovery](https://www.servicenow.com/docs/4mCQT9WF8C5giYGlEkvOAQ)**   
  Discovery and Service Mapping Patterns finds AWS services on your cloud environment. Discovering some of these resources might require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
* **[AWS CloudTrail Trail pattern-based discovery](https://www.servicenow.com/docs/jvBX2z5r5rodsmhshL1HXw)**   
  Discovery and Service Mapping Patterns finds AWS services on your cloud environment. Discovering some of these resources might require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
* **[AWS CodeDeploy Deployment pattern-based discovery](https://www.servicenow.com/docs/qubbpc6ZJDVCIlrjRvlPIQ)**   
  Discovery and Service Mapping Patterns finds AWS CodeDeploy Deployments on your cloud environment. Discovering some of these resources might require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
* **[AWS CodePipeline Pipeline pattern-based discovery](https://www.servicenow.com/docs/_LLMKIS7O9lYq0VgSDonBA)**   
  Discovery and Service Mapping Patterns finds AWS CodePipeline Pipelines on your cloud environment. Discovering some of these resources might require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
* **[AWS datacenter pattern-based discovery](https://www.servicenow.com/docs/UFfjc5m0ZfwXYWUkASro9A)**   
  Discovery and Service Mapping Patterns finds AWS Regions for your AWS account on your cloud environment. Discovering some of these resources might require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
* **[AWS DataSync Task pattern-based discovery](https://www.servicenow.com/docs/MMCXL2Idu6PajCNIIF~rNg)**   
  Discovery and Service Mapping Patterns finds AWS services on your cloud environment. Discovering some of these resources might require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
* **[AWS DMS Endpoints pattern-based discovery](https://www.servicenow.com/docs/BgvHYEnq~zTcGTxbvbrImA)**   
  Discovery and Service Mapping Patterns finds AWS DMS endpoints on your cloud environment. Discovering some of these resources might require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
* **[AWS Elastic Beanstalk Application pattern-based discovery](https://www.servicenow.com/docs/PMggFnug7lxRTGVnwAp0vw)**   
  Discovery and Service Mapping Patterns finds AWS Elastic Beanstalk Applications on your cloud environment. Discovering some of these resources might require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
* **[AWS Global Accelerator pattern-based discovery](https://www.servicenow.com/docs/Hxz7PYZQgggwYLhmvYNXHQ)**   
  Discovery and Service Mapping Patterns finds AWS services on your cloud environment. Discovering some of these resources might require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
* **[AWS Glue Database pattern-based discovery](https://www.servicenow.com/docs/6xyaYJ1KKJTgb26anE0q_g)**   
  Discovery and Service Mapping Patterns finds AWS Glue Databases on your cloud environment. Discovering some of these resources might require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
* **[AWS hardware type pattern-based discovery](https://www.servicenow.com/docs/nNmV4HiQBTCDbCSUAdu_nQ)**   
  Discovery and Service Mapping Patterns finds Amazon EC2 instance types on your cloud environment. Discovering some of these resources might require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
* **[AWS IAM Policy pattern-based discovery](https://www.servicenow.com/docs/GY0Cf3DanG0luImv1ObGzg)**   
  Discovery and Service Mapping Patterns finds AWS IAM Policies on your cloud environment. Discovering some of these resources might require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
* **[AWS IAM Role pattern-based discovery](https://www.servicenow.com/docs/iBfQNl2FxJh0JTwjJJ7Uxg)**   
  Discovery and Service Mapping Patterns finds AWS IAM Roles on your cloud environment. Discovering some of these resources might require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
* **[AWS IAM User pattern-based discovery](https://www.servicenow.com/docs/c9dp84Vp_fU00mekW1E~WQ)**   
  Discovery and Service Mapping Patterns finds AWS IAM Users on your cloud environment. Discovering some of these resources might require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
* **[AWS KMS Key pattern-based discovery](https://www.servicenow.com/docs/7DS5jxRQCUcVTMVa7vMbLQ)**   
  Discovery and Service Mapping Patterns finds AWS KMS Keys on your cloud environment. Discovering some of these resources might require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
* **[AWS Linux Server pattern-based discovery](https://www.servicenow.com/docs/caJzdt7H31At0Q1PfYJWpQ)**   
  Discovery and Service Mapping Patterns finds AWS Linux Server configuration items (CIs) in your cloud environment. Discovering some of these resources might require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
* **[AWS Marketplace pattern-based discovery](https://www.servicenow.com/docs/1i487heYz0Mytlv69fhMFw)**   
  Discovery and Service Mapping Patterns finds active AWS Marketplace subscriptions on your cloud environment. Discovering some of these resources might require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
* **[AWS Network ACL pattern-based discovery](https://www.servicenow.com/docs/WFa15VodWksBHZLf2BTS~A)**   
  Discovery and Service Mapping Patterns finds AWS Network access control lists (ACLs) on your cloud environment. Discovering some of these resources might require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
* **[AWS Network Firewall pattern-based discovery](https://www.servicenow.com/docs/sUe2g7RGtckmsn_nr4XxIw)**   
  Discovery and Service Mapping Patterns finds AWS services on your cloud environment. Discovering some of these resources might require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
* **[AWS Organizations pattern-based discovery](https://www.servicenow.com/docs/yNsea6kGsWxglVPyLS7MGQ)**   
  Discovery and Service Mapping Patterns finds AWS Organizations accounts on your cloud environment. Discovering some of these resources might require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
* **[AWS OS image pattern-based discovery](https://www.servicenow.com/docs/sslNvab5xnSTYlh3MHHFUQ)**   
  Discovery and Service Mapping Patterns finds AWS OS images (both owned and executable) on your cloud environment. Discovering some of these resources might require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
* **[AWS Secrets Manager Secret pattern-based discovery](https://www.servicenow.com/docs/80AB9_WoLhjqXzDs6lKFhg)**   
  Discovery and Service Mapping Patterns finds AWS Secrets Manager Secrets on your cloud environment. Discovering some of these resources might require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
* **[AWS Serverless Database pattern-based discovery](https://www.servicenow.com/docs/7JgiVE1leAIavAKvpKBVOg)**   
  Discovery and Service Mapping Patterns finds Amazon Aurora Serverless databases on your cloud environment. Discovering some of these resources might require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
* **[AWS Step Functions State Machine pattern-based discovery](https://www.servicenow.com/docs/1Q2am7c0XpfqVeaL8ftOTg)**   
  Discovery and Service Mapping Patterns finds AWS Step Functions State Machines on your cloud environment. Discovering some of these resources might require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
* **[AWS Storage Gateway File Share pattern-based discovery](https://www.servicenow.com/docs/~3PBBcnmDfJwZWekR276vg)**   
  Discovery and Service Mapping Patterns finds AWS services on your cloud environment. Discovering some of these resources might require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
* **[AWS Storage Gateway Gateway pattern-based discovery](https://www.servicenow.com/docs/AC9jaljK3KKQPFCInpfyCg)**   
  Discovery and Service Mapping Patterns finds AWS Storage Gateway Gateways on your cloud environment. Discovering some of these resources might require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
* **[AWS sub account pattern-based discovery](https://www.servicenow.com/docs/_e8ls7hUg0rN1SPzxyQUww)**   
  Discovery and Service Mapping Patterns finds member accounts and the primary account within an AWS Organization. Discovering some of these resources might require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
* **[AWS Systems Manager Document pattern-based discovery](https://www.servicenow.com/docs/USmSPv1GF2ugUFbB_tMcfg)**   
  Discovery and Service Mapping Patterns finds AWS Systems Manager Documents on your cloud environment. Discovering some of these resources might require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
* **[AWS Systems Manager Parameter Store pattern-based discovery](https://www.servicenow.com/docs/VVVEdciLqzuwY751A0ri~A)**   
  Discovery and Service Mapping Patterns finds AWS Systems Manager Parameter Store parameters on your cloud environment. Discovering some of these resources might require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
* **[AWS Transfer Family Server pattern-based discovery](https://www.servicenow.com/docs/tw5iXt1xggUmB_87XnFX~A)**   
  Discovery and Service Mapping Patterns finds AWS Transfer Family Servers on your cloud environment. Discovering some of these resources might require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
* **[AWS virtual server pattern-based discovery](https://www.servicenow.com/docs/uikOf6BQwinzq_7HDIYjAg)**   
  Discovery and Service Mapping Patterns finds AWS EC2 virtual machine instances on your cloud environment. Discovering some of these resources might require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
* **[AWS Windows Server pattern-based discovery](https://www.servicenow.com/docs/dTcAI9rmzF9il4G14MX1~Q)**   
  Discovery and Service Mapping Patterns finds AWS Windows Server configuration items (CIs) in your cloud environment. Discovering some of these resources might require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
* **[AWS X-Ray Sampling Rule pattern-based discovery](https://www.servicenow.com/docs/9wnW_4KJBEqK4E3jtoBniQ)**   
  Discovery and Service Mapping Patterns finds AWS X-Ray Sampling Rules on your cloud environment. Discovering some of these resources might require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
* **[Limit AWS discovery to datacenters with resources](https://www.servicenow.com/docs/_78Eb1iBFx8s_e7En7M87A)**   
  Optimize AWS discovery by limiting it to datacenters with resources.
* **[Exclude AWS resource types from datacenter discovery](https://www.servicenow.com/docs/M86mIO0WtPXVLinrMMY8~w)**   
  You can configure which AWS resource types to exclude from AWS datacenter discovery, to avoid triggering discovery patterns in regions with only default resources.
* **[Configure Server CI creation during AWS cloud discovery](https://www.servicenow.com/docs/TAwA5~6rxh7OQ4~LjkQsAg)**   
  Create Windows Server or Linux Server configuration items (CIs) during AWS cloud discovery by enabling the sn_itom_pattern.aws_cloud_discovery_populate_server_ci system property.

**Related concepts**   

* [Kubernetes discovery using patterns](https://www.servicenow.com/docs/nzEBIa1cCTkSNZxPmAi9ag "The ServiceNow ITOM Visibility finds Kubernetes and OpenShift components using patterns and creates application services containing them. Discovery also finds Kubernetes events and frequently updates the CMDB to reflect the dynamic Kubernetes environment.")  
**Related reference**   

* [AWS Certificate Manager discovery](https://www.servicenow.com/docs/fp~wSWPhKxdwAGjYiUQL2Q "Cloud Discovery uses Patterns to discover certificate data that the Amazon AWS Cloud Certificate Manager (ACM) manages. Discovering this data requires installing and updating Discovery and Service Mapping Patterns and Certificate Inventory and Management.")
* [Amazon Bedrock pattern-based discovery](https://www.servicenow.com/docs/AkBbRwlDERzcXwI6FEzVZA "AI Agent Topology Mapping discovers Amazon Bedrock AI services, agents, and models during horizontal discovery.")

