The Service Graph Connector for AWS enables customers to seamlessly and securely bring their AWS data into ServiceNow CMDB. The integration uses AWS native technologies and AWS security best practices to enable teams to connect the cloud data within their ServiceNow workflows. The Service Graph Connector for AWS relies on cloud formation templates, S3 buckets, AWS Config, and AWS SSM, enabling customers to set up the connector once and then scale as they bring in more accounts, services, and more data types – securely, easily, and with complete control, with minimal access and credential requirements. Service Graph Connectors help you get your AWS data into ServiceNow CMDB to drive business outcomes faster.
Key use cases:
- Visibility into cloud resources, relationships, and state in near real-time
- Deep discovery of applications for ITAM/SAM outcomes
- Governance and compliance outcomes
- Simplified onboarding experience
- Minimal credentials requirement
- Coverage for multiple AWS accounts across the organization
- Automatic incorporation of new account or region addition
- No MID Server required (can be optionally used if needed)
- Near real-time discovery of changes
New
- Instance Metadata Service Version 2 (IMDS v2) is supported for the discovery of Kubernetes resources.
- The primary IP address is populated in the imported Server records.
- Imported AWS compute resources include operating system domain details.
- RDS allocated storage capacity information for AWS RDS database resources is populated in the cloud database table.
- The lookback time window isn’t applied when processing service accounts.
- Amazon FSx file system resources are discovered and imported into the CMDB.
Changed
- The response status (Status field) of the AWS account API is now mapped to the new account state (State field).
Fixed
- Resolved the issue with the aws_lookback_time_in_days connection property. Imports now follow the configured lookback window. (PRB2035571)
- The aws_lookback_time_in_days connection property is now updated only after a full scheduled data import. (PRB2060818)
- Resolved the issue where the ListAccounts API call didn’t handle the deprecation of the Status field, which could cause account imports to fail. (PRB2072899)
- The Is Virtual attribute is populated in the Server records created by Get Inventory imports. (PRB2032947)
- The AWS organization is set as the parent for the Amazon Redshift cluster records that are created by the scheduled import. (PRB2057788)
- Version data is populated for the operating system record in the Software Installation table. (PRB2067866)
- Resolved the issue where the EKS Cluster data source returned an error when the enableDbConfigLoad property is set to true. (PRB2057785)
- Flow execution contexts are created for Get Inventory imports. (PRB2063614)
- The CloudFormation templates (CFT) used by the connector are updated to the latest versions available in SGC Central. (PRB2071071)
- Resolved the issue where duplicate server records were created because the GetS3Object transform overwrote the Name field. (PRB2071695)
- Resolved the issue where the isLastImport function in AwsRemovalUtil only checked whether schedule imports were queued. The final import is now detected correctly. (PRB2060827)
- Resolved the issue where the EKS ETL transformation failed for pod payloads that contained no volume mounts. Such payloads are now transformed successfully. (PRB2030530)
- Server records aren’t created for AWS Systems Manager (SSM) managed instances. (PRB2032936)
- Resolved the issue where an EKS full schedule import didn’t import EKS data when the sn_aws_integ.eks_document_processing_time property is set to 100. (PRB2071475)
- The deprecated Status field is removed from the ETL mapping for the SG-AWS-Service-Account data source. (PRB2039925)
Dependencies
- Integration Commons for CMDB
- CMDB CI Class Models
- Discovery and Service Mapping Patterns
- IntegrationHub Datastream action
- Discovery Core
Usage of this Service Graph Connector requires a subscription to Subscription Unit based IT Operations Management (ITOM) Visibility or ITOM Discovery application. Managed IT Resources (as defined in Section 1.1 of the ServiceNow Subscription Unit Overview - https://www.servicenow.com/content/dam/servicenow-assets/public/en-us/doc-type/legal/servicenow-subscription-unit-overview.pdf) created or modified in the CMDB by this Service Graph Connector, but not yet managed by ITOM Visibility or ITOM Discovery, will increase Subscription Unit consumption within that application. Customers should review their current Subscription Unit consumption within ITOM Visibility or ITOM Discovery to ensure available capacity.