---
sourceDocument: Xanadu IT Operations Management
sourceDocumentLink: https://www.servicenow.com/docs/r/xanadu/it-operations-management

 Release :

    - xanadu

ft:locale :

    - en-US

ft:publication_title :

    - Xanadu IT Operations Management

ft:clusterId :

    - itom

bundleId :

    - itom

workflow :

    - Technology


---

# Port probes

# Port probes {#ariaid-title1}

* Release version: Xanadu
* 
* Updated August 1, 2024
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read

Port probes are used in Discovery by the Shazzam probe to detect protocol activity on open ports on devices it encounters.{#r_PortProbes__ph_port-probe-intro}
When a port probe encounters a protocol in use, the Shazzam
sensor checks the port probe record to determine which classification probe to launch. The
common protocols WMI, SSH, SNMP, and HTTP in the base system have priority numbers that
control the order in which they are launched.{#r_PortProbes__p_port-probe-content1}

The priority is as follows:  
* 1 - WMI
* 2 - SSH
* 3 - SNMP
* 4 - HTTP
{#r_PortProbes__ul_bbr_kbw_dp}

In the base system, the WMI probe is always launched first, and
if it is successful on a device, no other port probes are launched for that device. If the
WMI probe is not successful, then the SSH probe is launched to gather information on the
device. If it is not successful, the SNMP probe is launched. This method allows Discovery to classify a device correctly if the device is running more than one
protocol (for example, SSH, SNMP, and HTTP).{#r_PortProbes__p_port-probe-content2}

## Discovery Port Probe form

To access the Port Probe form, navigate to Discovery DefinitionPort Probes.  
To add multiple classification probes to a port probe, create a link between the port probe and the actual classification probe itself. See the bottom of the form to add additional Trigger probes. That way, if one classification fails, it does not affect the others, thus Discovery performance may be enhanced.  
The Port Probe form provides the following fields:{#r_PortProbes__table_zzx_q1w_dp__entry__2}

| Field | Input Value |
|-|-|
| Name | Simple name for the port probe that reflects its function (for example, SNMP). |
| Description | Definition of the acronym for the protocol. (For example, SSH is Secure Shell login). |
| Scanner | Shazzam techniques for exploring a port. Some of these are protocol-specific, and others are generic. For example, a WMI port probe uses a Scanner value of Generic TCP, and the SNMP port probe uses a value of SNMP. |
| Active | Indicates whether this port probe is enabled or disabled. |
| CIs | Indicates whether this port probe is enabled or disabled for discovering Configuration Items. |
| IPs | Indicates whether this port probe is enabled or disabled for discovering IP addresses. |
| Triggered by services | Indicates which services define the port usage. Use this setting to define non-standard port usage and pair the port number with the protocol. |
| Use classification | Names the appropriate classification table, based on the protocol being explored. |
| Classification priority | Establishes the priority in which this port probe runs. If the first port probe fails, then the next probe runs on the device, and so forth, until the correct data is returned. This allows for the proper classification of a device that has two running protocols, such as SSH and SNMP. The default priorities for the Discovery protocols are: * 1 - WMI * 2 - SSH * 3 - SNMP * 4 - HTTP {#r_PortProbes__d12887e395} |
| Supplementary | Launches supplementary classifications after a higher-priority identification succeeds, in order of priority. |
| Conditional | Runs this port probe if any one of the non-conditional probes returns an open port. The conditional port probes in the base system attempt to resolve the names of Windows devices and DNS names. These ports probes take additional resources and are not used unless activity is detected on open ports. |
| Script | Script to run. |
[Table 1. Port probes]

{#r_PortProbes__table_zzx_q1w_dp}
* **[Shazzam probe, port probes, and protocols](https://www.servicenow.com/docs/T56zqJiSChinIMzyhJBkvQ)**   
  Port scanning is the first step in the discovery process. The Shazzam probe performs port scanning, regardless of whether you use patterns for horizontal discovery. The following table lists the known ports and protocols used by Discovery.
* **[Configure Shazzam probe](https://www.servicenow.com/docs/byjpLAAKvoBPJb8VIYpz7Q#t_ConfigureTheShazzamProbe)**   
  When you run Discovery, the Shazzam probe finds your active network devices by scanning specified ports on specified IP address ranges. If the list of IP ranges being scanned is large, you can configure the Shazzam payload for JSON encoding to reduce its size.

*[\>]: and then


