Use the playbook available with the SGC Central application to set up the Service Graph Connector for Microsoft Azure for pulling in Microsoft Azure data into the CMDB.
Before you begin
Install Service Graph Connector for Microsoft Azure version 1.9.0 or later from the ServiceNow Store. For ServiceNow Store installation steps, see Install a ServiceNow Store application.Role required: The following table shows the roles required for each stage of the playbook.
Note: The admin user role is required to run background scripts and to provide access to global tables to the SGC-Admin user. For information about the user roles for
Service Graph Connectors, see
Service Graph Connector user roles.
About this task
The playbook experience for onboarding connectors is activated with SGC Central in the Service Graph Workspace or CMDB Workspace. To configure the SGC Central application, see Configuring SGC Central and for more information on how to interact with a playbook, see Interact with Playbook.
The connector uses the Azure Management APIs for the complete pull of data from Azure. However, to pull delta changes from Azure, the Azure Resource Graph APIs are used. The domain name system (DNS) is Microsoft Azure Management, but the path is a resource graph.
Procedure
-
Use one of the following methods to open SGC Central:
-
On the Overview page, select Create connection.
Tip: Alternatively, you can select Create connection on the All connections page.
-
On the Create connection window, select the Microsoft Azure connector type and then select Create connection.
-
Complete the initial prerequisites when setting up a connection for the first time using a connector.
-
Complete the prerequisites for setting up the Azure environment.
-
Complete the instructions required for setting up the Azure environment.
- In the Prerequisites stage of the playbook, select the Review setup instructions activity.
- Obtain the OAuth credentials including client ID, client secret, and token URL from your Microsoft Azure administrator.
- For importing hardware data, grant the
User.Read permission on the Microsoft Graph API in the Azure environment. Also, ensure that the IAM policy for the Azure subscription has the Reader role. See Assign a user as an administrator of an Azure subscription with conditions on the Microsoft Azure documentation site.
- For importing software data, grant the
Data.Read permission on the Log Analytics API in the Azure environment. In addition, set up a Log Analytics workspace in the Azure environment.
- After completing the Review setup instructions activity, select Continue.
-
Determine whether to import only hardware data or both hardware and software data.
-
In the Setup stage of the playbook, select the Select services activity.
If needed, expand the Setup stage to select an activity.
- Optional:
To import both hardware and software data, select the Hardware and software check box.
Note: Importing software data requires a hardware connection.
If you need to import only hardware data, the Hardware only check box is already selected by default.
-
Select Continue.
-
Enter the connection details and test the API connection for importing hardware data.
-
In the Setup stage of the playbook, select the Create and test hardware connection activity.
-
On the form, fill in the fields.
-
Select Create and test connection.
-
Once the connection test is complete, select Continue.
-
Configure the import schedule to import hardware data at regular intervals.
-
In the Setup stage of the playbook, select the Configure hardware import schedule activity.
-
Select Configure import schedule.
-
Expand the Parent scheduled data import within the Import schedules list to select the Connection name-SG-Azure Subscriptions import schedule.
-
In the Configure import schedule dialog box, select the Active check box, and then fill in the run schedule and time details.
-
Select Save.
Alternatively, select Execute Now to execute the import schedule immediately.
-
Select Continue.
-
Enter the connection details and test the API connection for importing software data.
The Create and test software connection activity for importing software data appears only when the Hardware and software check box is selected in step 6.b.
-
In the Setup stage of the playbook, select the Create and test software connection activity.
-
On the form, fill in the fields.
-
Select Create and test connection.
-
Once the connection test is complete, select Continue.
-
Configure the import schedule to import software data at regular intervals.
The Configure software import schedule activity for importing software data appears only when the Hardware and software check box is selected in step 6.b.
-
In the Setup stage of the playbook, select the Configure software import schedule activity.
-
Expand the Parent scheduled data import within the Import schedules list to select the Connection name-SG-Azure TCP import schedule.
-
In the Configure import schedule dialog box, select the Active check box, and then fill in the run schedule and time details.
-
Select Save.
Alternatively, select Execute Now to execute the import schedule immediately.
-
Repeat steps 10.b to 10.d for any other parent import schedule if not already set to active.
-
Select Continue.
-
In the Setup stage of the playbook, select the Connection setup complete activity to verify whether the connection was created.
What to do next
Select View all connections to review the connection details. The created connection appears in the Installed connections list.