---
sourceDocument: Brazil IT Operations Management
sourceDocumentLink: https://www.servicenow.com/docs/r/it-operations-management

 Release :

    - brazil

ft:locale :

    - en-US

ft:publication_title :

    - Brazil IT Operations Management

ft:clusterId :

    - itom

bundleId :

    - itom

workflow :

    - Technology


---

# Discovery for AWS

# Discovery for AWS {#ariaid-title1}

Release version: Brazil  
Updated September 10, 2026  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 3 minutes to read
Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Discovery for AWS

Discovery for AWS in ServiceNow enables automated, continuous identification and mapping of AWS cloud resources to populate and update the Configuration Management Database (CMDB).
This visibility supports key business outcomes such as cloud transformation, operational efficiency (ITOM/ITSM/AIOps), regulatory compliance, and security operations.
Discovery can be executed through various methods including agent-based, agentless, cloud APIs, and IP-level OS discovery, with options for near real-time event-driven or scheduled discovery.
Show full answer Show less  

## Key Features

* **Discovery Methods:** Horizontal discovery identifies configuration items (CIs) without dependencies; top-down service mapping reveals application dependencies, connection paths, and service impact.
* **Discovery Approaches:**
  * Cloud metadata discovery for high-level AWS infrastructure visibility.
  * Cloud OS-level discovery for detailed status including installed software and system configurations.
  * Event-driven discovery to track lifecycle and configuration changes in AWS resources.
  * Agent-based discovery using AWS Systems Manager (SSM) for EC2 instances.
  * IP-based discovery using Agent Client Collector (ACC-VC) for OS attributes.
  * Service Graph Connectors to import AWS data into CMDB and handle AWS Organizations data.
* **Integration with ITOM Visibility Apps:** Includes Discovery Admin Workspace, Discovery for Amazon EKS, Service Mapping, Discovery and Service Mapping Patterns, and Certificate Inventory and Management.
* **Roles and Permissions:** Discovery requires proper AWS IAM role configuration and ServiceNow AI Platform user roles (discoveryadmin) to execute discovery workflows securely and effectively.
* **Ongoing Maintenance:** Regularly update discovery patterns using the Cloud Discovery spreadsheet, which details required REST API permissions, pattern names, CI classes, and vendor documentation links.

## Key Outcomes

* **Regulatory Compliance:** Supports alignment with compliance frameworks such as MRA and DORA by providing accurate cloud resource data.
* **Software Asset Management (SAM):** Improves management of cloud software deployments through enhanced visibility.
* **Financial Operations (FinOps):** Enables cost optimization and resource usage tracking with comprehensive AWS resource visibility.
* **Security Operations (SecOps):** Enhances continuous monitoring of cloud resource configurations for security management.
* **Certificate Management:** Discovers and tracks certificates, including their expiry and usage.
* **AIOps Enablement:** Supports artificial intelligence-driven operations by providing detailed mapping of cloud resources and configurations.  
Amazon Web Services (AWS) cloud discovery enables visibility to your AWS cloud resources, to populate and update the Configuration Management Database (CMDB). Visibility into AWS supports business outcomes such as cloud transformation and optimizing efficiency for operations (ITOM/ITSM/AIOps).

## What is AWS cloud discovery {#understanding-aws-discovery__section_xjy_34q_mhc}

AWS cloud discovery is an automated process that continuously identifies and maps AWS resources and populates the data in the Configuration Management Database (CMDB).

AWS discovery can be performed by a combination of approaches such as agent-based or agentless, cloud APIs for metadata discovery, or IPs for OS-level discovery. The visibility can be
provided near real time (using event-based discovery for example) or by timed discovery schedules.

The Discovery and Service Mapping apps perform discovery by methods refereed to as horizontal discovery and top‑down mapping. Horizontal discovery identifies configuration items (CIs) without dependency mapping.
Top‑down service mapping identifies application dependencies, connection paths, and service impact.

## Key outcomes and business value {#understanding-aws-discovery__section_icp_5vx_1hc}

AWS discovery facilitates several vital business outcomes by populating the CMDB with essential cloud data:

* Regulatory compliance enabled by the data support. Visibility can promote alignment with compliance frameworks such as the Mutual Recognition Agreement (MRA) or Digital Operational Resilience Act (DORA).
* Software asset management (SAM) enabled by visibility into cloud software deployments.
* Financial operations(FinOps) enabled by comprehensive visibility into AWS resources and their usage,
* Security operations(SecOps) enabled by continuous visibility into cloud resources and their configurations.
* Certificate management enabled by the discovery of certificates, their expiry, and usage.
* Artificial intelligence for IT operations (AIOps) enabled by Identifying and mapping all cloud resources, and their configurations.
{#understanding-aws-discovery__ul_a2s_gvx_1hc}

## AWS discovery approaches {#understanding-aws-discovery__section_s3n_svx_1hc}

There are several approaches for discovering AWS environments.

1. Cloud metadata discovery: Provides a high-level view of the AWS cloud infrastructure.
2. Cloud OS-Level discovery: Provides a deeper level of discovery that indicates the state of the AWS cloud resources, such as installed software, active services, running processes, and system configurations.
3. Event‑driven cloud discovery: Tracks changes in the life-cycle state or the configuration of AWS cloud resources. For more information, see [AWS events-driven discovery](https://www.servicenow.com/docs/_5Go0h8BtYcHPcsVTUsu7g "The Amazon Web Services (AWS) Config service can raise events for any changes in the life-cycle state or the configuration of a cloud resource. The ServiceNow event-driven discovery uses the events to auto-update the latest resource information in the Configuration Management Database (CMDB).")
4. Collecting data with AWS Systems Manager: Provides a streamlined, agent-based approach to discovering Amazon Elastic Compute Cloud (EC2). For more information, see [AWS SSM discovery](https://www.servicenow.com/docs/e_eslCSX6c4MPTq5ydCEPw "AWS Systems Manager (SSM) Agent discovery introduces a streamlined, agent-based approach to discovering Amazon Elastic Compute Cloud (EC2) using AWS SSM. This integration enhances Discovery by leveraging SSM agents to reduce dependency on traditional MID Server configurations, simplify credential management, and improve scalability across multi-region environments.")
5. Collecting data with Agent Client Collector (ACC-VC): Performs horizontal IP-based discovery for OS-related attributes such as system configurations, network interfaces, and running process. For more information, see [Agent Client Collector Discovery](https://www.servicenow.com/docs/_gtb8zqMn8d9RkpiBkPGbQ "Discover CIs in your environment by using Agent Client Collector for Visibility Content (ACC-VC) Discovery. ACC-VC works with both horizontal IP-based Discovery, and you can also use push-based Discovery.").
6. Collecting data with Service Graph Connectors: Imports and integrates AWS data into CMDB and non-CMDB tables. Specializes in collecting the data for AWS Organizations. For more information, see [AWS discovery solutions comparison](https://www.servicenow.com/docs/l~_7iFtaeOkHodwZDIY5EQ "ITOM Visibility applications discover a variety of AWS resources and populate the relevant configuration item (CI) classes in the Configuration Management Database (CMDB) with their attributes.") and [Service Graph Connector for AWS](https://www.servicenow.com/docs/access?context=cmdb-integration-aws-sg&version=brazil&pubname=brazil-servicenow-platform&ft:locale=en-US).
{#understanding-aws-discovery__ol_cmv_mmk_khc}

For comparison of AWS cloud discovery methods and requirements, see [AWS cloud discovery methods and use cases](https://www.servicenow.com/docs/MsQ70mdsdLiVjHfMGaiN1g "Comparison of use cases and requirements for cloud discovery methods in AWS.")

## How to perform AWS cloud discovery {#understanding-aws-discovery__section_uh2_dpq_mhc}

Multiple ITOM Visibility apps can collect (or discover) your data, visualize it, and help you monitor your AWS resources.

* [Discovery Admin Workspace](https://www.servicenow.com/docs/nnD7xwnmHUU8lxpGghliog "The Discovery Admin Workspace serves as a central location for monitoring, tracking, and completing discovery-related tasks. Experience a streamlined discovery process and greater efficiency with the integration of schedules, diagnostics, tuning, anomaly detection, and more within this single workspace.")
* [Discovery for Amazon Elastic Kubernetes Service (EKS)](https://www.servicenow.com/docs/gkG4kMzd8LpFmjbBm8GELA "The ServiceNow ITOM Visibility finds Kubernetes and OpenShift components using patterns and creates application services containing them. Discovery also finds Kubernetes events and frequently updates the CMDB to reflect the dynamic Kubernetes environment.")
* [Service Mapping](https://www.servicenow.com/docs/ixzowoHiuxuhv1nFM8OA~Q "Service Mapping in cloud environments provides critical visibility into application dependencies and connections. By identifying how different application components interact within IaaS and PaaS environments, your organization can gain better insight into its application services and improve overall service management.")
* [Discovery and Service Mapping Patterns](https://www.servicenow.com/docs/Y0yjdHKR~_I76hi21l9C4A "Discovery and Service Mapping Patterns uses patterns to discover components of the Amazon AWS Cloud deployment during horizontal discovery. Discovering some of these resources might require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.")
* [Certificate Inventory and Management](https://www.servicenow.com/docs/fB9C00nIoWVtsBkIarr8WQ "Cloud Discovery uses Patterns to discover certificate data that the Amazon AWS Cloud Certificate Manager (ACM) manages. Discovering this data requires installing and updating Discovery and Service Mapping Patterns and Certificate Inventory and Management.")
{#understanding-aws-discovery__ul_qzt_gqq_mhc}

Enabling Discovery or other Visibility solutions to access your AWS infrastructure depends on roles and permissions configured both in AWS and in ServiceNow AI Platform. The discovery process requires configuration within AWS, like setting up Identity and Access Management roles.  
{#understanding-aws-discovery__table_ajm_35s_ghc__entry__2}

| AWS Users | Discovery permissions |
|-|-|
| AWS Organizations with master and member accounts | Access is based on the IAM roles defined for the master and member accounts. |
| AWS account root user | Has complete access to all AWS services and resources in the account. |
| IAM users/IAM user group | Has access to specific resources and services based on IAM roles or temporary access based on assumed roles. |
[Table 1. AWS user discovery permissions]

{#understanding-aws-discovery__table_ajm_35s_ghc} For more information, see [Access to cloud environments for ITOM products](https://www.servicenow.com/docs/Jr4DyLzQU2nhM8bIdzgn5A "If your organization deploys IT assets on the cloud, ITOM products must access your cloud environment to collect information about the IT infrastructure.")  
In the ServiceNow AI Platform side, there are user configurations needed if you choose to use Discovery.

* You must configure the discovery_admin role for a user, to be able to run the discovery. For more information, see [Managing roles](https://www.servicenow.com/docs/access?context=ua-creating-roles&version=brazil&pubname=brazil-platform-administration&ft:locale=en-US)
* Discovery runs commands and API queries to access and discover your AWS infrastructure. Before starting to configure Discovery roles and permissions, review the Cloud discovery spreadsheet and verify the REST API permissions.

{#understanding-aws-discovery__ul_vym_w5g_lhc}

## Verify the REST API Permissions {#understanding-aws-discovery__id_wxp_lh3_chc}

Download the [Cloud Discovery patterns spreadsheet](https://downloads.docs.servicenow.com/resource/enus/api/servicenow-discovery-patterns-api-details.xlsx) so you can grant user permissions required for running the Discovery patterns. In addition to permissions, the spreadsheet also includes useful information such as pattern names, types, CI Classes, and links to vendor documentation. New patterns are available
quarterly, so check periodically to be sure you have the latest version of the spreadsheet.{#understanding-aws-discovery__cloud-discovery-api-ph-prereq}

