---
sourceDocument: Brazil IT Operations Management
sourceDocumentLink: https://www.servicenow.com/docs/r/it-operations-management

 Release :

    - brazil

ft:locale :

    - en-US

ft:publication_title :

    - Brazil IT Operations Management

ft:clusterId :

    - itom

bundleId :

    - itom

workflow :

    - Technology


---

# File-based Discovery

# File-based Discovery {#ariaid-title1}

Release version: Brazil  
Updated September 10, 2026  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 6 minutes to read
Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of File-based Discovery

File-based Discovery is a ServiceNow capability that identifies software running on Windows, UNIX, and macOS servers and devices, even without registration information.
It helps you maintain accurate software license records, detect unlicensed or forbidden files, and assess threats from unwanted files.
It complements standard discovery by scanning for known file signatures and matching files to software products.
Show full answer Show less  

## Key Features

* **Plugin Requirements:** Activation of the File-based Discovery plugin is necessary, which also enables the Software Asset Management (SAM) File Signature Normalization plugin.
* **Discovery Process:** Runs during the exploration phase, scanning configured paths for specific file names or extensions. The probe returns file details, which the sensor matches against known software using file name, size, and version.
* **File Signature Filtering:** Uses different methods for UNIX and Windows due to signature list sizes. UNIX filtering occurs on the target; Windows scanning uses the MID Server for filtering and normalization.
* **SAM Integration:** When SAM is active, matched files populate software installation records and update license data. Without SAM, file information is stored but no software records are created.
* **SWID Tag Support:** Enables enhanced software identification by populating SWID tag information when configured. Requires Base64 package for UNIX/Linux systems.
* **Unidentified Files:** Files not matched by normalization are saved in an Unidentified File Set table for manual review and classification.
* **Supported Platforms:** Supports Windows (2008 through later versions with PowerShell 3.0--7), UNIX (POSIX-compliant Linux, Solaris, AIX, HP/UX), and macOS. Specific configuration needed for PowerShell 7 and Ubuntu 20.

## Target System Permissions and Requirements

* **UNIX Permissions:** Discovery user requires sudo access to run scripts and read files across directories, including protected ones. Without sudo, only universally readable directories are scanned.
* **Windows Permissions:** Uses administrative credentials and runs signed scripts; sudo is not applicable.
* **Required OS Tools:** Standard tools such as find, wc, awk, grep, ps, nohup, sh/bash must be in the system path. SWID tag scanning also requires base64 or uuencode.
* **Sudoers Configuration:** Specific sudoers entries must be added on UNIX systems to grant the discovery user passwordless execution of required commands and scripts, including additional entries for SWID tag scanning.

## Practical Application

By enabling File-based Discovery, ServiceNow customers can gain comprehensive visibility into software installed on their managed servers, even when software registration data is missing. This improves software asset management accuracy, supports compliance efforts, and enhances security by identifying unwanted or unlicensed files.

Proper configuration of plugins, permissions, and environment settings is crucial to successful discovery. The integration with SAM allows discovered software to be linked to license records, enabling better license management and cost control.

File-based Discovery can be disabled anytime via the Discovery Configuration Console if needed, and it supports multiple operating systems with specific setup instructions to optimize scanning and results.  
File-based Discovery helps you identify what software is running on your Windows and UNIX servers and devices, even if there's no registration information available. You can then manage and maintain records of your software licenses, check for unlicensed files, detect forbidden or damaged files, and
help evaluate any threats from unwanted files.

## Required plugins {#file-based-discovery__section_cys_3jr_13b}

The File-based Discovery \[com.snc.discovery.file_based_discovery\] plugin is required for file signature filtering. Your Discovery subscription includes this plugin, but you must [request activation](https://www.servicenow.com/docs/access?context=t_RequestAPlugin&version=brazil&pubname=brazil-platform-administration&ft:locale=en-US). Once the File-based Discovery plugin is active, the Software Asset Management - File Signature Normalization \[com.snc.file_signature_normalization\] plugin is also activated. For more information on the File Signature Normalization plugin, see [File Signature Normalization](https://www.servicenow.com/docs/access?context=sam-file-based-discovery&version=brazil&pubname=brazil-it-asset-management&ft:locale=en-US).

## How File-based Discovery
works {#file-based-discovery__section_ifz_rbp_x2b}

File-based Discovery enhances the pre-existing discovery of installed software. It scans target servers for a known list of file signatures and processes those files with an established set of rules. The resulting data
enhances the identification of installed software and identifies unregistered software products. For information about using Agent Client Collector for Visibility Content to perform file-based discovery, see [Discover java installation data using Agent Client Collector for Visibility Content file-based discovery](https://www.servicenow.com/docs/ynI~VGyVg3CS1YYNP5A6tg "Discovering java installation data using Agent Client Collector for Visibility Content file-based discovery enables you to discover file information in your system.").

File-based Discovery is triggered in the exploration phase of normal Discovery. File-based Discovery probes execute a scan searching for specific file extensions or file names in paths that you configure. The resulting file information is returned in the probe payload. The sensor attempts to match
the discovered files with installed software, using the file name, size, and version returned by the probe. File-based Discovery uses file signatures to detect software that might not have been registered. This information is then stored in the File Information \[cmdb_file_information\] table with a reference to the CI of the
server. You can view the files found from each CI in a related list on this table. For more information, see [Related list of CI components](https://www.servicenow.com/docs/access?context=r_RelatedListsOfCIComponents&version=brazil&pubname=brazil-servicenow-platform&ft:locale=en-US). When [Software Asset Management](https://www.servicenow.com/docs/access?context=c_SoftwareAssetMgmt&version=brazil&pubname=brazil-it-asset-management&ft:locale=en-US) (SAM) is active, if any file matches a software product, Discovery populates the Product and Publisher information for that file. Use this information to understand what software is running on your server and to help evaluate any threats from unwanted files. Discovery uses lists of known file signatures for Windows and UNIX to constrain the scope of the search. The filtering process for Windows and UNIX hosts is executed differently because their signature lists differ greatly in size. The smaller UNIX signature list is included with the Unix - File Discovery probe and processed directly on the target. The Windows signature list is larger and can't be processed on the target. The Windows - File Discovery
probe scans the target for specific file extensions and paths and returns these results to the MID Server. The MID Server performs file signature filtering using the entire Windows list. The MID Server then sends all file information back to the instance for normalization and matching.

If SAMP is active on the instance, File-based Discovery creates or updates identified software products in the Software Installation \[cmdb_sam_sw_install\] table and updates matched software package licenses. Without SAMP, no software records are created. Only the file information goes into the File Information \[cmdb_file_information\] table.  
You can enable SWID tags in the Discovery Configuration Console. With SWID tag enabled, when running File-based Discovery, the SWID tag information then populates the \[cmdb_swid_tag\] table. Information about the software installed on a particular machine includes name, file information, publisher, version, installed on, and content. The software_installation column in the \[cmdb_swid_tag\] is a reference to the \[cmdb_sam_sw_install\] table.  
Note:  
Base64 package is a prerequisite for any UNIX or Linux servers to scan SWID tag files using File-based Discovery.

File-based Discovery inserts any file not matched by the normalization process into the Unidentified File Set \[cmdb_unidentified_file_set\] table. You can update the records in this table and provide additional details for
previously unidentified files. If you provide values for the Product and Publisher fields for a file, SAMP settings can enable File-based Discovery to use that file for installed software matching in future discoveries.

You can disable File-based Discovery at any time by changing the setting in the [Discovery Configuration Console](https://www.servicenow.com/docs/xwZtpGPWSkK1Ib7N7e3PYw#c_DiscoveryConfigurationConsole "Use the Discovery Configuration Console to manage what kind of configuration items (CIs) and CI information you want to discover."). If you disable File-based Discovery before scan results are returned, the file data is ignored.
Note:  
File-based Discovery supports Windows, UNIX, and macOS devices. The UNIX probe is POSIX-compliant and should run on any Linux/Solaris server. Discovery supports Windows versions 2008, 2008R2, 2012R2, 2016, 2019, and later with PowerShell 3.0--7. Discovery also supports AIX versions 5.3, 6.1, and 7.1 and HP/UX 8.11.

To use File-based Discovery on target hosts that run PowerShell 7, configure the MID Server to prefer PowerShell 7. For more information, see [Configure MID Server parameters for PowerShell 7](https://www.servicenow.com/docs/RPdP2lEw1csJ6lNWJWWjBg "Configure two MID Server parameters to run File-based Discovery and Windows ADME on target hosts that use PowerShell 7.").

If you're running File-based Discovery on Ubuntu version 20, modify the default Bourne shell (sh) to point to Bourne Again shell (bash).

Version information is populated only for the files with version information returned from probes. Not all files have versions. Files with extensions such as .exe, .jar, and so on, have versions.

## Target system permissions {#file-based-discovery__section_r2f_3wk_4jc}

File-based Discovery needs specific permissions on each UNIX target system to scan files and read software details. The following sections list the required permissions and the sudoers configuration for the discovery user.

The MID Server runs the discovery script on each UNIX system with sudo. When the discovery user has sudo access, File-based Discovery scans every directory in the scan path.

When the Discovery user doesn't have sudo access, File-based Discovery scans only the directories that all users can read. It skips protected directories and doesn't report an error for them.

On Windows systems, File-based Discovery uses the administrative discovery credential and runs a signed script. Windows systems don't use sudoers.

Require permissions

:   The Discovery user needs the following permissions on each UNIX target system:

    {#file-based-discovery__table_y3m_lwk_4jc__entry__2}

    | Permission | Description |
    |-|-|
    | Run the discovery script with sudo | Enables file-based Discovery to scan directories that aren't readable by all users. |
    | Read and run on the directories in the scan path | Enables the scan to move through the directory trees you select. |
    | Read on the files that match the scan list | Enables File-based Discovery to read each file's size and details. |
    | Read on the temporary directory, /tmp by default | Enables the scan to write and read its working files on the target system. |
    | Read on SWID files, when SWID tag scanning is enabled | Enables File-based Discovery to read software identification details from SWID files. |
    [ ]

    {#file-based-discovery__table_y3m_lwk_4jc}

Required operating system tools
:   File-based Discovery uses standard operating system tools on each target system. The following tools must be available in the system path:

    * find, wc, awk, and grep
    * ps and nohup
    * sh or bash

    {#file-based-discovery__ul_zv2_xwk_4jc}

    When SWID tag scanning is enabled, base64 or uuencode must also be available. File-based Discovery uses uuencode first and falls back to base64.

Sudoers configuration

:   Add entries to the sudoers file on each UNIX target system. These entries give the discovery user the sudo access that File-based Discovery needs. Replace discoUser with your discovery credential user and adjust the tool paths to match your installation.

    Linux, CentOS, Ubuntu, and RHel use the following entries for Linux systems:

        Cmnd_Alias FBD_SCRIPT = /bin/sh /tmp/SNC_File_Discovery_Script_*.sh
        Cmnd_Alias FBD_CMDS = /usr/bin/find *, /usr/bin/wc *, /bin/cat *
        discoUser ALL=(root) NOPASSWD:FBD_SCRIPT, FBD_CMDS
        Defaults!FBD_SCRIPT !requiretty
        Defaults!FBD_CMDS !requiretty

    To enable SWID tag scanning on Linux, add the following entry:

        Cmnd_Alias FBD_SWID = /usr/bin/base64 *, /usr/bin/uuencode *
        discoUser ALL=(root) NOPASSWD:FBD_SWID
        Defaults!FBD_SWID !requiretty

    Use the same script and command entries on AIX, Solaris, and HP-UX systems. For SWID tag scanning on these systems, use uuencode:

        Cmnd_Alias FBD_SWID = /usr/bin/uuencode *
        discoUser ALL=(root) NOPASSWD:FBD_SWID
        Defaults!FBD_SWID !requiretty

    On AIX, use this requiretty syntax instead of the Linux form:

        Defaults:discoUser ! requiretty

## Example {#file-based-discovery__section_vbx_lxk_4jc}

A Discovery user scans the /opt and /etc directories on a Linux system. These directories aren't readable by all users.

With the sudoers entries in place, the discovery user runs the scan with sudo. File-based Discovery reads the files in both directories and reports the software it finds.

Without the sudoers entries, File-based Discovery skips /opt and /etc. It reports only the software in directories that all users can read.
**Related tasks**   

* [Run File-based Discovery](https://www.servicenow.com/docs/QpnHWEivsWoySY0bhZCREw#run-file-based-discovery "Run File-based Discovery to find all of your installed software whether it is registered or not. You can enable and configure File-based Discovery at any time using the Discovery Configuration Console.")  
**Related reference**   

* [File-based Discovery references](https://www.servicenow.com/docs/Zs18qVirLYubsVCfYWM2eQ "Review this reference material for further details on File-based Discovery.")
* [File-based Discovery issue resolution](https://www.servicenow.com/docs/s8XzFQOVP6uA8BIx_sp9HQ "If you have any issues while setting up or running File-based Discovery, follow the actions listed here to help resolve them.")

