---
sourceDocument: Australia ServiceNow AI Platform Capabilities
sourceDocumentLink: https://www.servicenow.com/docs/r/servicenow-platform

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia ServiceNow AI Platform Capabilities

ft:clusterId :

    - platcap

bundleId :

    - platcap

workflow :

    - Platform


---

# Configure using SGC Central

# Configure Service Graph Connector for AWS using SGC Central {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 10 minutes to read

Use the playbook available with the SGC Central application to set up the Service Graph Connector for AWS for pulling in AWS data into the CMDB

## Before you begin

* Install Service Graph Connector for AWS version 2.7.0 or later from the ServiceNow Store. For ServiceNow Store installation steps, see [Install a ServiceNow Store application](https://www.servicenow.com/docs/access?context=installing-applications-in-application-manager&version=australia&pubname=australia-platform-administration&ft:locale=en-US).
* Verify that you've completed the prerequisites for setting up AWS. See [Configure the AWS environment](https://www.servicenow.com/docs/5PbQIlbVtFeBoA9JJ4Cg0Q "Configure your Amazon Web Services (AWS) environment to import data using the Service Graph Connector for AWS.").

{#sgcc-configure-aws-integ__ul_jsj_l51_fdc}  
Role required: The following table shows the roles required for each stage of the playbook.{#sgcc-configure-aws-integ__table_u12_qcp_l3c__entry__2}

| Stage | Role |
|-|-|
| Prerequisites | admin |
| Setup | SGC-Admin (sn_cmdb_int_util.sgc_admin) or admin |
[Table 1. Role required for each playbook stage]

{#sgcc-configure-aws-integ__table_u12_qcp_l3c}  
Note:  
The admin user role is required to run background scripts and to provide access to global tables to the SGC-Admin user. For information about the user roles for Service Graph Connectors, see [Service Graph Connector user roles](https://www.servicenow.com/docs/llR5whccV6~8Oi~Q_e8~xQ#cmdb-sgc-intro__section_ett_spp_4hc).

## About this task

The playbook experience for onboarding connectors is activated with SGC Central in the Service Graph Workspace or CMDB Workspace. To configure the SGC Central application, see [Configuring SGC Central](https://www.servicenow.com/docs/7dDf5rxNMnkcccCA02GxmQ "Set up the SGC Central application for onboarding and maintaining Service Graph Connectors and monitoring the errors related to connections added using Service Graph Connectors.") and for more information on how to interact with a playbook, see [Interact with Playbook](https://www.servicenow.com/docs/access?context=playbook-ui&version=australia&pubname=australia-build-workflows&ft:locale=en-US).

## Procedure

1. Use one of the following methods to open SGC Central:
   * Navigate to WorkspacesService Graph Workspace, and from the left navigation panel, select the Ingestion icon ![]() to open the SGC Central view.
   * Navigate to WorkspacesCMDB WorkspaceSGC Central.
   {#sgcc-configure-aws-integ__choices_bd1_nrz_k3c}
2. On the Overview page, select Create connection.  
   Tip:  
   Alternatively, you can select Create connection on the All connections page.
3. On the Create connection window, select the AWS connector type and then select Create connection.
4. Complete the initial prerequisites when setting up a connection for the first time using a connector.  
   Note:  
   This step is required only during the first-time setup. See [Perform initial setup tasks when creating a connection in SGC Central](https://www.servicenow.com/docs/0vWb7VG8kY9kzX25jOf72Q "Complete the prerequisites for setting up a connection for the first time using a Service Graph Connector within the SGC Central view of the Service Graph Workspace or CMDB Workspace.").
5. Complete the prerequisites for setting up the AWS environment.
   1. Configure the basic setup in the AWS environment required for importing data using the connector.  
      1. In the Prerequisites stage of the playbook, select the Download basic scripts activity.
      2. Execute the scripts to configure the AWS environment.

         For more information on executing scripts, see [Basic scripts](https://www.servicenow.com/docs/3RY69g208Sr5UUaV0K~Qcg#sgc-cmdb-aws-script-op__section_vfh_wyf_4zb).
      3. Select the I have read the instructions and executed the script accordingly check box to confirm that you have executed the scripts.
      4. Select Continue.
      {#sgcc-configure-aws-integ__ol_f3x_ypk_wbc}
   2. Set up deep discovery on Amazon Elastic Compute Cloud (Amazon EC2) instances.  
      Note:  
      Complete this step only to perform deep discovery on EC2 instances. Else, select Skip.
      1. In the Prerequisites stage of the playbook, select the Download deep discovery scripts activity.
      2. Execute the scripts to configure Amazon EC2 instances for deep discovery.

         For more information on executing scripts, see [Deep discovery scripts](https://www.servicenow.com/docs/3RY69g208Sr5UUaV0K~Qcg#sgc-cmdb-aws-script-op__section_ahc_jwf_4zb).
      3. Select Continue.
      {#sgcc-configure-aws-integ__ol_ddh_frk_wbc}
   3. Set up Amazon Elastic Kubernetes Service (EKS) clusters.  
      Note:  
      Complete this step only when the Amazon EKS service for Kubernetes clusters is required. Else, select Skip.
      1. In the Prerequisites stage of the playbook, select the Download Amazon EKS scripts activity.
      2. Execute the scripts to set up Amazon EKS clusters.For more information on executing scripts, see [Amazon EKS scripts](https://www.servicenow.com/docs/3RY69g208Sr5UUaV0K~Qcg#sgc-cmdb-aws-script-op__section_osh_4zf_4zb).

      3. Select Continue.
      {#sgcc-configure-aws-integ__ol_hrt_xrk_wbc}
6. Complete the setup for configuring the connector for importing data.
   1. Create and test connection.  
      1. In the Setup stage of the playbook, select the Create and test connection activity.
      2. On the form, fill in the fields.{#sgcc-configure-aws-integ__table_iw5_j5k_wbc__entry__2}

         | Field |   |
         |-|-|
         | Connection name | Name to identify the AWS connection record. For example, <kbd class="ph userinput">SG_AWS_CredentialAlias_Org</kbd>. |
         | Access Key ID | Access key ID of the IAM user that has permissions to interact with the AWS resources. |
         | Secret Access Key | Secret access key that corresponds to the Access key ID required for authenticating the connection securely. |
         | Use MID Server | Option to use a MID Server. Note: Use of a MID Server is optional. |
         | Mid Selection | Name of the MID Server used by the connector. This field appears only when the Use MID Server check box is selected. |
         [Table 2. Create and test connection form]

         {#sgcc-configure-aws-integ__table_iw5_j5k_wbc}{#sgcc-configure-aws-integ__aws-cred-0}
      {#sgcc-configure-aws-integ__aws-cred-0}
      3. Select Create and test connection.
      4. Once the connection test is complete, select Continue.
      {#sgcc-configure-aws-integ__ol_hfg_3gy_prb}
   2. Set configuration properties for the connection to access the AWS resources.  
      1. In the Setup stage of the playbook, select the Set configuration properties activity.
      2. In the Organization details section, fill in the organization details including the account identifier, name and description of the AWS organization.
      3. In the S3 account details section, fill in the details.{#sgcc-configure-aws-integ__table_xxk_h1m_wbc__entry__2}

         | Field | Description |
         |-|-|
         | S3 account ID | Numeric identifier of the AWS account that hosts the Amazon Simple Storage Service (Amazon S3) bucket. |
         | S3 bucket name | Name of the Amazon S3 bucket that collects the details from Amazon EC2 instances. |
         | S3 region | Region where the Amazon S3 bucket resides. |
         [Table 3. S3 account details]

         {#sgcc-configure-aws-integ__table_xxk_h1m_wbc}
      4. In the AWS regions field of the AWS regions and STS assume role name section, enter the AWS regions to collect the CI data.

         By default, the Service Graph Connector for AWS runs through all the AWS regions to collect the CI data.

         You can enter AWS specific regions to speed up the CI data import process. For example, `us-east1,
         us-east-2`.

         If
         you update the AWS regions field value later, clear the value of the Last run datetime field in all the data sources related to the Service Graph Connector for AWS to import a new set of data.
      5. In the STS assume role name field of the AWS regions and STS assume role name section, enter the AWS Identity and Access Management (IAM) role name.  
         The AWS IAM role name is obtained by the ServiceNow user by calling the AssumeRole API offered by the AWS Security Token Service (STS). The AssumeRole API returns a set of temporary security credentials for the ServiceNow user to access the AWS resources.  
         Note:  
         Enter the IAM role name but don't prefix `arn` in the name. If you leave this field is empty, the value of this field is automatically set to SnowOrganizationAccountAccessRole, which is the default IAM role name for the ServiceNow user.
      6. In the SSM SendCommand document details section, enter the name of the document that defines the actions run by the AWS Systems Manager (SSM) on a Linux-based Amazon EC2 instance or a Windows-based Amazon EC2 instance in their respective fields.
      7. In the Management account ID field of the Management account ID and standalone account ID section, enter the management account ID in the AWS organization.

         Enter a value for this field when the ServiceNow user was created in an AWS member account.

         The account calls the ListAccounts API associated with the AWS organization to collect CI information from all the accounts. For more information, see [ListAccounts](https://docs.aws.amazon.com/organizations/latest/APIReference/API_ListAccounts.html) on the AWS documentation site.
      8. In the Standalone account ID field of the Management account ID and standalone account ID section, enter the ID of a member account in the AWS organization.  
         Note:  
         When specifying a standalone account, the AWS organization-related data such as the organization name, organization units, organization ID, and service accounts are not imported. To import the full data later, clear any value mentioned in the Standalone account ID field. See the [Service Graph Connector for AWS - Standalone Setup \[KB1642159\]](https://hi.service-now.com/kb_view.do?sysparm_article=KB1642159) article in the Now Support Knowledge Base.
      9. In the AWS config aggregator details section, enter the AWS account details for the aggregator resource type.{#sgcc-configure-aws-integ__table_ztj_2cm_wbc__entry__2}

         | Field | Description |
         |-|-|
         | Config aggregator account | AWS account where the aggregator resource type in the AWS Config service has been configured. Enter a value in this field when you're using an AWS Config aggregator. |
         | Config aggregator name | Name of the aggregator resource type. This field is available only when you enter a value in the Config aggregator account field. |
         | Config aggregator region | Region where the aggregator resource type resides. This field is available only when you enter a value in the Config aggregator account field. |
         [Table 4. AWS config aggregator details]

         {#sgcc-configure-aws-integ__table_ztj_2cm_wbc}
      10. In the AWS key rotation setup section, enter the key rotation process details.{#sgcc-configure-aws-integ__table_gdq_mcm_wbc__entry__2}

          | Field | Description |
          |-|-|
          | AWS rotate keys | Option to enable the key rotation process. |
          | AWS key rotation date | Key rotation date. Set the value to the required key rotation date for the first run. For subsequent runs, this field is automatically set to the rotation date. This field is available only when you select the AWS Rotate Keys check box. |
          | AWS key rotation period (in days) | Key rotation period in days. This field is available only when you select the AWS rotate keys check box. |
          | AWS key rotation status | Status message of a key rotation displaying whether the rotation was a success or a failure. This field is automatically set to display the key rotation status message. This field is available only when you select the AWS rotate keys check box. If the rotation status is a failure, an email notification is triggered, if configured. |
          | Email accounts for receiving error notifications | Comma-separated list of the email addresses of recipients who receive notifications about the AWS key rotation errors. |
          | Email account groups for receiving error notifications | Comma-separated list of the ServiceNow groups who receive notifications about the AWS key rotation errors. |
          [Table 5. AWS key rotation setup]

          {#sgcc-configure-aws-integ__table_gdq_mcm_wbc}
      11. Select the Is gov cloud check box in the Gov cloud setup section to indicate that the connection setup is for the AWS GovCloud.
      12. In the SSM EKS SendCommand document details section, enter the AWS SSM document details.{#sgcc-configure-aws-integ__table_phc_bdm_wbc__entry__2}

          | Field | Description |
          |-|-|
          | EKS cluster names document | Name of the AWS SSM document to discover EKS clusters associated with EC2 Bastion hosts. |
          | EKS shell script document | Name of the AWS SSM document to fetch CIs related to Kubernetes components, such as pods, services, and deployments, from EKS clusters. |
          [Table 6. SSM EKS SendCommand document details]

          {#sgcc-configure-aws-integ__table_phc_bdm_wbc}
      13. Select Save properties.
      14. Select Continue.
      {#sgcc-configure-aws-integ__ol_ssq_x5l_wbc}
   3. Configure the required EC2 resources for Amazon Elastic Kubernetes Service (EKS) to import EKS cluster data.  
      Note:  
      Complete this step only when EC2 resources are needed. Else, select Skip for the Configure EKS EC2 resources activity.
      An EKS EC2 resource is a bastion host that has network access to EKS clusters. The EKS clusters aren't directly accessible to the connector. Therefore, you must provide the EKS EC2 resource details. For importing EKS cluster data, the connector uses the SSM Send Command on EKS EC2 resources to run kubectl commands remotely.  
      Note:  
      Ensure that you've configured your AWS environment for the EKS integration. For more information, see the [Service Graph Connector for AWS - Amazon EKS Integration \[KB1437138\]](https://support.servicenow.com/kb_view.do?sysparm_article=KB1437138) article in the Now Support Knowledge Base.
      1. In the Setup stage of the playbook, select the Configure EKS EC2 resources activity.
      2. On the Configure EKS EC2 resources page, select New.{#sgcc-configure-aws-integ__eks-ec2-add}
      {#sgcc-configure-aws-integ__eks-ec2-add}
      3. On the Configure EKS EC2 resources window that appears, fill in the fields.{#sgcc-configure-aws-integ__table_dlp_xnv_1yb__entry__2}

         | Field | Description |
         |-|-|
         | EKS EC2 Resource Id | Identifier of the EKS EC2 resource. |
         | EC2 Region | AWS region where the EKS EC2 resource is located. |
         | EC2 Account | User name assigned to the EKS EC2 resource account. |
         | Connection Alias | Connection alias associated with the AWS environment setup and configured in step [6.a.ii](https://www.servicenow.com/docs/swwv9knfDRSZ44AnfazGwg#sgcc-configure-aws-integ__aws-cred-0). |
         | Connection | Connection name associated with the AWS environment setup and configured in step [6.a.ii](https://www.servicenow.com/docs/swwv9knfDRSZ44AnfazGwg#sgcc-configure-aws-integ__aws-cred-0). |
         | Active | Option to activate the EKS EC2 resource. |
         [Table 7. Configure EKS EC2 resources fields]

         {#sgcc-configure-aws-integ__table_dlp_xnv_1yb}
      4. Select Save.{#sgcc-configure-aws-integ__eks-ec2-save}
      {#sgcc-configure-aws-integ__eks-ec2-save}
      5. Repeat steps from [6.c.ii](https://www.servicenow.com/docs/swwv9knfDRSZ44AnfazGwg#sgcc-configure-aws-integ__eks-ec2-add) to [6.c.iv](https://www.servicenow.com/docs/swwv9knfDRSZ44AnfazGwg#sgcc-configure-aws-integ__eks-ec2-save) to add more EKS EC2 resources.
      6. Select Continue.
      {#sgcc-configure-aws-integ__ol_n4c_qgm_wbc}
   4. Run the AWS diagnostic tool before running a scheduled import job to identify any issues in the AWS environment setup.  
      1. In the Setup stage of the playbook, select the Run diagnostic tests activity.
      2. On the Run diagnostic test page, select an option to exclude the corresponding test results from the diagnostic summary.

         Skip SSM setup tests
         :   Excludes the software inventory data from the summary results by not calling the GetInventory API. Select this option when you've opted out or not set up the configuration for
             SSM.

         Skip SSM Deep Discovery tests
         :   Excludes the deep discovery data from the summary results. Select this option when you've opted out or not set up the configuration for SSM deep discovery.

         Skip EKS setup tests
         :   Excludes the EKS data from the summary results by not running the kubectl commands.  
             Note:  
             This check box appears only when you've configured EC2 resources in the Configure EKS EC2 resources activity.
      3. Select Run diagnostic test and wait for the test to complete.
      4. Review the diagnostic summary, the API access results, and the IAM permission validation logs.
      5. When the test results are successful, select Continue.
      {#sgcc-configure-aws-integ__ol_swj_4km_wbc}
   5. Configure the import schedule to import data at regular intervals.  
      1. In the Setup stage of the playbook, select the Configure import schedule activity.
      2. Expand the Parent scheduled data import within the Import schedules list to select the SG-AWS-Organization import schedule.
      3. In the Configure import schedule dialog box, select the Active check box, and then fill in the run schedule and time details.

         For more information, see [Schedule a data import](https://www.servicenow.com/docs/access?context=t_ScheduleADataImport&version=australia&pubname=australia-integrate-applications&ft:locale=en-US#table_r53_5hm_xp).
      4. Select Save.

         Alternatively, select Execute Now to execute the import schedule immediately.
      5. Select Continue.
      {#sgcc-configure-aws-integ__ol_mcx_blm_wbc}
   6. In the Setup stage of the playbook, select the Confirm connection setup activity to verify whether the connection was created.
   {#sgcc-configure-aws-integ__substeps_vrw_2tk_wbc}

## What to do next

Select View all connections to review the connection details. The configured connection appears in the Installed connections list.
**Related concepts**   

* [Service Graph Connector for AWS](https://www.servicenow.com/docs/LQNZ9RRaFKMHeX5NTgN89w "Use the Service Graph Connector for AWS to securely bring in Amazon Web Services (AWS) data into your ServiceNow instance.")
* [Accessing the connection details of Service Graph Connector for AWS](https://www.servicenow.com/docs/1nGXyy6RR8r~igFUTEHAIw#sgc-cmdb-aws-conn "You can access the connection details of the Service Graph Connector for AWS in a single view using the common connection framework (CCF) included within the Integration Commons for CMDB (sn_cmdb_int_util) store app.")
* [Additional features within the Service Graph Connector for AWS](https://www.servicenow.com/docs/OMgrsXMHFAEPVZoThkJpLg "Use the additional features available within the Service Graph Connector for AWS to maximize its use for importing data.")  
**Related reference**   

* [CMDB classes targeted in Service Graph Connector for AWS](https://www.servicenow.com/docs/ArfsXfAbkNxejifoYS8lHQ "When you complete setting up the connection, you can configure the integration to periodically pull data from AWS. The data is saved in tables that extend from the Configuration item [cmdb_ci] table.")
* [Supported AWS resource types](https://www.servicenow.com/docs/rOlD1ZFUBdxpJMvvwMJZRQ "Several AWS resource types are imported as CMDB data by the Service Graph Connector for AWS.")

*[\>]: and then


