Requirements for Discovery Console for OT installation
Summarize
Summary of Requirements for Discovery Console for OT installation
The Discovery Console for OT installation requires specific infrastructure, system, and network configurations to ensure optimal performance and connectivity. This guidance helps ServiceNow customers prepare their environment for a successful deployment and operation of the Discovery Console for OT.
Show less
Infrastructure and System Requirements
- Operating System: A Linux OS capable of running in a virtualization environment or on a bare-metal server.
- Deployment: Installation must be on a virtual machine (VM) with at least 10 GB of free disk space after OS and Console installation.
- System Resources: Minimum requirements include 16 GB RAM, 100 GB hard drive, and 2 CPUs to support the Console's operations effectively.
Network Requirements
The Discovery Console for OT requires specific inbound ports to be open to enable communication with Sensors, the web interface, and ServiceNow instances or MID Servers. Key ports include:
- TCP 5671: Data communication between Sensors and the Console.
- TCP 8443: Access to the Console’s web interface and API.
- TCP 5002: Sensor updates communication.
- TCP 443: Network communication with ServiceNow instances or MID Servers via Service Graph Connector for OT Discovery.
- UDP 123: Critical for time synchronization between Sensors and the Console to maintain accurate event timestamps.
Important: Without UDP 123 open, clock drift can cause features that rely on precise timing to malfunction. If connectivity issues arise, verify firewall rules to unblock the required ports and IP addresses.
Configuration and Licensing
- Configuration Wizard: An interactive setup wizard guides users through initial Console configuration and license upload after login.
- License Requirement: A valid license from your ServiceNow account representative is mandatory before using the Console.
- License Upload: Licenses must be uploaded as a .zip file containing
license.pemandpubkey.pemfiles via the Settings page. - License Impact: Certain features are disabled if the license is expired or invalid, including auto query scans, network data consumption, API token management, and export of collections or raw XML results.
- License Warnings: The Console displays warnings before license expiration to prompt timely renewal, ensuring uninterrupted functionality.
Next Steps
Before installation, confirm your infrastructure meets the outlined requirements and network ports are properly configured. After installation, use the configuration wizard to set up the Console and upload your license to activate all features. For troubleshooting or support, contact ServiceNow Customer Service and Support.
For remote deployment at a facility or on a network, verify that the following requirements are met before installing the Discovery Console for OT.
Infrastructure requirements
You must have a Linux operating system installed that can operate in a virtualization environment or on a Bare-metal server. Install the Discovery Console for OT on a virtual machine.
System requirements
| Component | System Requirements |
|---|---|
| Discovery Console for OT |
|
Network requirements
| Ports | Description |
|---|---|
| TCP 5671 | Used by Discovery Sensor for OT to communicate with the Discovery Console for OT. This port is used by the Sensor to report data and receive configuration updates from the Console. |
| TCP 8443 | Used to connect to the Discovery Console for OT Web interface. This port is used by the API. |
| TCP 5002 | Enables Sensors to communicate with the Discovery Console for OT to receive updates. |
| TCP 443 | Used for network communication from the Console to a ServiceNow instance or MID Server via the Service Graph Connector for OT Discovery. |
| UDP 123 (Required) |
Enables Sensor devices to synchronize time (real-time clock) with the Discovery Console for OT to verify that the time associated with reported data and events is both precise and accurate. Note: Without port UDP 123 open on the firewall, the clocks of Sensors drift apart from the clock of the Console. When clock drift is present, various features that rely on precise clock synchronization don't work as expected. |
Discovery Console for OT configuration wizard
The Discovery Console for OT now provides a configuration wizard to guide you through your initial setup and configuration of the Console. If you choose to use the interactive configuration wizard after logging into the Console, it alerts you automatically to upload a Console license. See Use the Discovery Console for OT interactive configuration wizard for more information.
Discovery Console for OT license
- From the Home page, navigate to the Settings page.
- On the Settings page in the License section, select the Upload License button.
- Upload your license as a .zip file.
- Verify the ZIP file contains the license.pem and pubkey.pem files.
Once you have uploaded your license, you can use the Console.
Console features that require a license
It is important to understand that certain features are rendered inactive if the Discovery Console for OT license is expired. After the license expires, the locking mechanism is triggered and deactivates these features. No data is lost in the background. When a valid license is uploaded, the you can start or continue working. When the license is about to expire, the Console displays a warning banner as an alert.
The license:
- Enables the ability to run Auto Query and asset scans (inactive on expiration).
- Enables the consumption of network connection data (inactive on expiration).
- Enables the creation and viewing of API tokens (inactive on expiration).
- Enables the export of collections (for example, assets) to files (inactive on expiration).