Using push-based Discovery and SAM together
Summarize
Summary of Using push-based Discovery and SAM together
The Agent Client Collector for Visibility Content (ACC-VC) integrates push-based Discovery with Software Asset Management (SAM) to optimize software data collection. This combination supports SAM basic metering and SAM total usage metrics on Windows and macOS systems, enabling accurate tracking of installed software usage and edition details.
Show less
Key Features
- Software Usage Data Collection: ACC-VC gathers last accessed time and usage data, storing it in the
sampswusagetable to support SAM metering. - Domain Separation: Usage records are domain separated based on the MID Server domain, facilitating correct user mapping in multi-domain environments.
- Duplicate Record Management: Uses a consistent discovery source ("ServiceNow") across push-based and horizontal IP-based Discovery to avoid duplicate software installation records.
- SAM Basic Metering: Requires registry read permissions for the servicenow user to access the Windows UserAssist table and specific registry updates to enable accurate data collection.
- SAM Total Usage Metrics: Requires manual deployment of the osqueryd daemon service on Windows to collect total usage time and count, with scheduled queries and logging configured via osquery flags and configuration files.
- Software Edition Visibility: Supported from ACC-VC version 2.3.0 for Adobe Acrobat and MS SQL Server, with edition details displayed in the
cmdbsamswinstalltable. - Non-Osqueryd Data Collection Option: Allows data collection without deploying osqueryd by configuring agent permissions and enabling a system property, improving efficiency for environments using ACC agents version 4.1.0 or later.
Requirements and Configuration
- SAM plugin (
com.snc.samp) must be enabled. - System property
snaccviscontent.persistsamusagemetricsset totrueto enable SAM usage metric persistence. - Windows registry permissions must be configured to allow the servicenow user READ access to the UserAssist key for each user.
- For total usage metrics, osqueryd must be installed and configured with the appropriate service flags and scheduled queries using provided PowerShell scripts.
- Local System account is required for the ACC service on Windows when using non-osqueryd data collection.
Practical Benefits for ServiceNow Customers
- Improved accuracy in software usage tracking supports better license compliance and optimization.
- Domain-aware usage data helps map software consumption to correct users in complex organizational structures.
- Automated collection of software edition information enhances asset detail visibility for effective management.
- Flexible deployment options (osqueryd or non-osqueryd) allow customers to tailor data collection to their environment and operational preferences.
Next Steps
- Ensure SAM plugin activation and system properties are correctly configured.
- Configure registry permissions and deploy osqueryd on Windows hosts as needed.
- Use provided scripts and configuration guidance to install and manage osqueryd for SAM total usage metrics.
- Consider enabling non-osqueryd data collection if agent versions and permissions meet requirements for an efficient alternative.
- Review related knowledge base articles for detailed setup and troubleshooting.
Agent Client Collector for Visibility Content (ACC-VC) collects installed software data for use cases for Software Asset Management (SAM), when the SAM plugin is installed. Using push-based Discovery and SAM together can help optimize software data collection with SAM basic metering and SAM total usage metrics.
ACC-VC can capture the last accessed time for the software or applications that are installed on the target via push-based Discovery. This information along with the target CI reference, is added to the Software Update [samp_sw_usage] table.
SAM Basic metering and SAM total usage metrics are supported for both Windows and macOS.
The software usage records are domain separated. The records are populated with the domain of the MID Server that is used for the agent-based Discovery for the target.
When using ACC-VC to discover MSSQL components, run Discovery as a local system user.
Requirements
- SAM basic metering and SAM total usage metrics
-
For SAM basic metering and SAM total usage metrics, the non-privileged servicenow user (which the agent service logs on as) must be configured with READ only access in the registry. This access allows for successful execution of the OSQuery against the UserAssist table to be successful. Go to regedit and allow the servicenow user to read UserAssist for a user account on the device (for example: HKEY_USERS\SID...\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist for every user in HKEY_USERS).Note:The UserAssist key does not inherit permissions from the HKEY_USERS\SID... parent key. Therefore, you must navigate to the UserAssist key and add permission directly on the key.To apply SAM basic metering or SAM total usage metrics, you need the following:
- SAM plugin (com.snc.samp) enabled
- System property [sn_acc_vis_content.persist_sam_usage_metrics] set to true. See System properties for more details.
- Write permissions enabled for the log folder in the ACC install directory.
For details on SAM metering setup with the Agent Client Collector, see the Knowledge Base article KB1642676.
- Software edition information
- To retrieve software edition information, you need the SAM plugin (com.snc.samp) enabled.
SAM basic metering
- Name: Start_TrackProgs
- Base: Hexadecimal
- Value:1
- Name: Start_TrackProgsBase
- Base: Hexadecimal
- Value:1
For the list of software in the payload, query the Software Discovery Model [cmdb_sam_sw_discovery_model] table to fetch the corresponding product and publisher. Once the product is fetched, check if the reclamation rule is enabled for that product to persist the last usage information in the Software Usage [samp_sw_usage] table. See the flowchart for details.
- True: SAM usage is stored for all licensable software (with or without defined reclamation rules), and for any non-licensable software that has a reclamation rule defined.
- False: Store SAM usage according to defined reclamation rules.
- WinZip
- Google Chrome
- Sublime Text
- Notepad++
- Autodesk
- Microsoft Office 365
- Tableau
SAM total usage metrics
SAM total usage metrics allows you to measure total usage time and total usage count on any application that has a software reclamation rule enabled.
Osquery provides a daemon executable which can run as a service, called Osqueryd. Osqueryd needs to be manually deployed for SAM total usage metrics to work properly. Each Osqueryd deployment requires the osquery.conf file, optional external packs, and initialization flags (configured in osquery.flags file) provided when starting the service. In return, the daemon service runs scheduled queries on the host and logs it into a local file system.
Domain information can be collected during the data collection. This can help large organizations with multiple employee directories map software to the correct user. Currently, this is supported for Windows only. To map the software usage/assigned_to with the correct user in a domain separated environment, use the system property [sn_acc_vis_content.column_name_for_user_mapping] with a valid field name. By default, the value of this system property is empty which means it only validates the username and not the domain. You can use either of the following formats to validate username and domain: username@domain or domain\username.
Using the list of processes, you can perform SAM normalization to map the processes for the relevant installed software records. This provides flexibility since installed software names and processes are not usually the same. For the list of processes in the payload, query the Software Discovery Model [cmdb_sam_sw_discovery_model] table and Software Product [samp_sw_product] table to fetch the corresponding product and publisher. Once the product is fetched, check if the reclamation rule is enabled for that product to persist the total usage time in the Software Usage [samp_sw_usage] table. See the flowchart for details.
# Install latest osquery
$msi = "osquery-5.7.0.msi"
$url = "https://pkg.osquery.io/windows/$msi"
$dst = "$PSScriptRoot\$msi"
Invoke-WebRequest -Uri $url -OutFile $dst
# msiexec /i "$dst" /quiet /qn /norestart
Start-Process msiexec.exe -Wait "/i $dst /quiet /qn /norestart"
# Configure osqueryd service
$flags = "--logger_rotate=true
--logger_rotate_size=26214400
--logger_rotate_max_files=1
--watchdog_level=-1
--config_path=C:\Program Files\osquery\osquery-sam.conf"
Set-Content -Path 'C:\Program Files\osquery\osquery.flags.default' -Value "$flags"
$conf = @'
{
"options": {
"config_plugin": "filesystem",
"logger_plugin": "filesystem",
"utc": "true"
},
"schedule": {
"sam_process_info": {
"query": "SELECT name, pid, elapsed_time, start_time, user_time, system_time, username FROM processes p JOIN users u ON u.uid = p.uid WHERE p.elapsed_time != -1 AND u.type != 'special';",
"snapshot" : true,
"interval": 300
},
"system_info": {
"query": "SELECT hostname, cpu_brand, physical_memory FROM system_info;",
"interval": 3600
}
},
"decorators": {
"load": [
"SELECT uuid AS host_uuid FROM system_info;",
"SELECT user AS username FROM logged_in_users ORDER BY time DESC LIMIT 1;"
]
},
"packs": {
}
}
'@
Set-Content -Path 'C:\Program Files\osquery\osquery-sam.conf' -Value "$conf"
cd 'C:\Program Files\osquery'
.\manage-osqueryd.ps1 -uninstall
.\manage-osqueryd.ps1 -install
Restart-Service osqueryd
For details on Windows and macOS see Configure Osqueryd schedule for SAM total usage metrics and Configure Osqueryd logs for SAM total usage metrics.
Collecting SAM metrics without osqueryd
Optionally, you can enhance efficiency by using non-osqueryd data collection when using push-based Discovery and Software Asset Management (SAM) together. When non-osqueryd data collection is invoked, data collection is automatically performed on all available agents, instead of invoking osqueryd on each agent individually.
- Ensure that the following permissions are configured for the relevant OS:
- Windows: The ACC service must run as the Local System account. Set the ACC service's Log On As value to Local System.
- macOS: The servicenow user must be able to run osqueryi without a password. For information about servicenow user permissions for osqueryi, see .
- On the System Properties page (), set the sn_acc_vis_content.enable_sam_collection_without_osqueryd property to true.Note:Enable this property only when all agents are version 4.1.0 or later.
Software edition information
Starting in ACC-VC version 2.3.0, edition information is supported for Adobe Acrobat and MS SQL server. With this feature, SAM admins can get clear visibility into the editions of their installed software. Osquery commands are used to fetch the edition information which then shows in the Software Installation [cmdb_sam_sw_install] table in the Edition Override column. For more details, see the support KB: https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB0721360