Requirements for Discovery Console for OT installation
Summarize
Summary of Requirements for Discovery Console for OT installation
The Discovery Console for OT requires specific infrastructure, system, and network configurations to ensure proper installation and operation. This guide helps ServiceNow customers prepare their environments for remote deployment at facilities or networks.
Show less
Infrastructure and System Requirements
- Operating System: Linux OS capable of running in virtualization or on bare-metal servers.
- Installation: Must be installed on a virtual machine (VM) with at least 10 GB of free space post OS and Console installation.
- Hardware Specifications:
- 16 GB RAM
- 100 GB Hard Drive
- 2 CPUs
Network Requirements
The following inbound ports must be open to allow proper communication between sensors, the Console, and ServiceNow components:
- TCP 5671: Sensor to Console communication for data reporting and configuration updates.
- TCP 8443: Access to Discovery Console Web interface and API.
- TCP 5002: Sensor updates communication.
- TCP 443: Network communication from Console to ServiceNow instance or MID Server via Service Graph Connector for OT Discovery.
- UDP 123 (Required): Time synchronization between Sensor devices and Console to maintain accurate timestamps. Essential to prevent clock drift, which impacts feature functionality.
Note: If access issues occur, verify firewall rules to ensure the necessary IP addresses and ports are unblocked.
Configuration and Licensing
- Configuration Wizard: An interactive wizard guides initial setup post-login, including license upload prompts.
- License Requirement: A valid license is mandatory before using the Console. Obtain it through your ServiceNow account representative.
- License Upload: Upload a .zip file containing
license.pemandpubkey.pemvia the Settings page on the Console Home. - License Impact:
- Expired or missing licenses disable key features such as Auto Query, asset scans, network connection data consumption, API token management, and export of collections.
- No data loss occurs during license expiration; features resume once a valid license is uploaded.
- Warnings appear before license expiration to alert users.
- Exporting RAW XML results requires a valid license.
Support
If errors or difficulties arise during installation or usage, contact ServiceNow Customer Service and Support for assistance.
For remote deployment at a facility or on a network, verify that the following requirements are met before installing the Discovery Console for OT.
Infrastructure requirements
You must have a Linux operating system installed that can operate in a virtualization environment or on a Bare-metal server. Install the Discovery Console for OT on a virtual machine.
System requirements
| Component | System Requirements |
|---|---|
| Discovery Console for OT |
|
Network requirements
| Ports | Description |
|---|---|
| TCP 5671 | Used by Discovery Sensor for OT to communicate with the Discovery Console for OT. This port is used by the Sensor to report data and receive configuration updates from the Console. |
| TCP 8443 | Used to connect to the Discovery Console for OT Web interface. This port is used by the API. |
| TCP 5002 | Enables Sensors to communicate with the Discovery Console for OT to receive updates. |
| TCP 443 | Used for network communication from the Console to a ServiceNow instance or MID Server via the Service Graph Connector for OT Discovery. |
| UDP 123 (Required) |
Enables Sensor devices to synchronize time (real-time clock) with the Discovery Console for OT to verify that the time associated with reported data and events is both precise and accurate. Note: Without port UDP 123 open on the firewall, the clocks of Sensors drift apart from the clock of the Console. When clock drift is present, various features that rely on precise clock synchronization don't work as expected. |
Discovery Console for OT configuration wizard
The Discovery Console for OT now provides a configuration wizard to guide you through your initial setup and configuration of the Console. If you choose to use the interactive configuration wizard after logging into the Console, it alerts you automatically to upload a Console license. See Use the Discovery Console for OT interactive configuration wizard for more information.
Discovery Console for OT license
- From the Home page, navigate to the Settings page.
- On the Settings page in the License section, select the Upload License button.
- Upload your license as a .zip file.
- Verify the ZIP file contains the license.pem and pubkey.pem files.
Once you have uploaded your license, you can use the Console.
Console features that require a license
It is important to understand that certain features could be inactive if the Discovery Console for OT license is expired. After the license expires, the locking mechanism is triggered and disables these features. No data is lost in the background. When a valid license is uploaded, the user can start or continue working. When the license is about to expire, the Console displays a warning banner as an alert.
The license:
- Enables the ability to run Auto Query and asset scans (inactive on expiration).
- Enables the consumption of network connection data (inactive on expiration).
- Enables the creation and viewing of API tokens (inactive on expiration).
- Enables the export of collections (for example, assets) to files (inactive on expiration).