---
sourceDocument: Australia IT Operations Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/de-DE/it-operations-management

 Release :

    - australia

ft:locale :

    - de-DE

ft:publication_title :

    - Australia IT Operations Management

ft:clusterId :

    - itom

bundleId :

    - itom

workflow :

    - Technology


---

# Discovery for AWS

# Discovery for AWS {#ariaid-title1}

* Freigeben Version: Australia
* 
* Aktualisiert 12. März 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 3 Minuten Lesedauer

Amazon Web Services (AWS) cloud discovery enables visibility to your AWS cloud resources, to populate and update the Configuration Management Database (CMDB). Visibility into AWS supports business outcomes such as cloud transformation and optimizing efficiency for operations (ITOM/ITSM/AIOps).

## What is AWS cloud discovery {#understanding-aws-discovery__section_xjy_34q_mhc}

AWS cloud discovery is an automated process that continuously identifies and maps AWS resources and populates the data in the Configuration Management Database (CMDB).

AWS discovery can be performed by a combination of approaches such as agent-based or agentless, cloud APIs for metadata discovery, or IPs for OS-level discovery. The visibility can be
provided near real time (using event-based discovery for example) or by timed discovery schedules.

The Discovery and Service Mapping apps perform discovery by methods refereed to as horizontal discovery and top‑down mapping. Horizontal discovery identifies configuration items (CIs) without dependency mapping.
Top‑down service mapping identifies application dependencies, connection paths, and service impact.

## Key outcomes and business value {#understanding-aws-discovery__section_icp_5vx_1hc}

AWS discovery facilitates several vital business outcomes by populating the CMDB with essential cloud data:

* Regulatory compliance enabled by the data support. Visibility can promote alignment with compliance frameworks such as the Mutual Recognition Agreement (MRA) or Digital Operational Resilience Act (DORA).
* Software asset management (SAM) enabled by visibility into cloud software deployments.
* Financial operations(FinOps) enabled by comprehensive visibility into AWS resources and their usage,
* Security operations(SecOps) enabled by continuous visibility into cloud resources and their configurations.
* Certificate management enabled by the discovery of certificates, their expiry, and usage.
* Artificial intelligence for IT operations (AIOps) enabled by Identifying and mapping all cloud resources, and their configurations.
{#understanding-aws-discovery__ul_a2s_gvx_1hc}

## AWS discovery approaches {#understanding-aws-discovery__section_s3n_svx_1hc}

There are several approaches for discovering AWS environments.

1. Cloud metadata discovery: Provides a high-level view of the AWS cloud infrastructure.
2. Cloud OS-Level discovery: Provides a deeper level of discovery that indicates the state of the AWS cloud resources, such as installed software, active services, running processes, and system configurations.
3. Event‑driven cloud discovery: Tracks changes in the life-cycle state or the configuration of AWS cloud resources. For more information, see [AWS events-driven discovery](https://servicenow-prod.fluidtopics.net/wLyaKKWolkmvMCS7STyfmg "The Amazon Web Services (AWS) Config service can raise events for any changes in the life-cycle state or the configuration of a cloud resource. The ServiceNow event-driven discovery uses the events to auto-update the latest resource information in the Configuration Management Database (CMDB).")
4. Collecting data with AWS Systems Manager: Provides a streamlined, agent-based approach to discovering Amazon Elastic Compute Cloud (EC2). For more information, see [AWS SSM discovery](https://servicenow-prod.fluidtopics.net/MAxESvhFyCY2kynR6WI3hA "AWS Systems Manager (SSM) Agent discovery introduces a streamlined, agent-based approach to discovering Amazon Elastic Compute Cloud (EC2) using AWS SSM. This integration enhances Discovery by leveraging SSM agents to reduce dependency on traditional MID Server configurations, simplify credential management, and improve scalability across multi-region environments.")
5. Collecting data with Agent Client Collector (ACC-VC): Performs horizontal IP-based discovery for OS-related attributes such as system configurations, network interfaces, and running process. For more information, see [Agent Client Collector Discovery](https://servicenow-prod.fluidtopics.net/CHtEnCuw8bYe90Ip8K46sQ "Discover CIs in your environment by using Agent Client Collector for Visibility - Content (ACC-VC) Discovery. ACC-VC works with both horizontal IP-based Discovery, and you can also use push-based Discovery.").
6. Collecting data with Service Graph Connectors: Imports and integrates AWS data into CMDB and non-CMDB tables. Specializes in collecting the data for AWS Organizations. For more information, see [AWS discovery solutions comparison](https://servicenow-prod.fluidtopics.net/lC0JBmi_av93E2RC3gpdCg "ITOM Visibility applications discover a variety of AWS resources and populate the relevant configuration item (CI) classes in the Configuration Management Database (CMDB) with their attributes.") and [Service Graph Connector for AWS](https://www.servicenow.com/docs/access?context=cmdb-integration-aws-sg&version=australia&pubname=australia-servicenow-platform&ft:locale=en-US).
{#understanding-aws-discovery__ol_cmv_mmk_khc}

For comparison of AWS cloud discovery methods and requirements, see [AWS cloud discovery methods and use cases](https://servicenow-prod.fluidtopics.net/5SetQY7Cg90T~no0PrwLew "Comparison of use cases and requirements for cloud discovery methods in AWS.")

## How to perform AWS cloud discovery {#understanding-aws-discovery__section_uh2_dpq_mhc}

Multiple ITOM Visibility apps can collect (or discover) your data, visualize it, and help you monitor your AWS resources.

* [Discovery Admin Workspace](https://servicenow-prod.fluidtopics.net/9ZgOY7Wx_FgGtt4xf_biDg "The Discovery Admin Workspace serves as a central location for monitoring, tracking, and completing discovery-related tasks. Experience a streamlined discovery process and greater efficiency with the integration of schedules, diagnostics, tuning, anomaly detection, and more within this single workspace.")
* [Discovery for Amazon Elastic Kubernetes Service (EKS)](https://servicenow-prod.fluidtopics.net/DxwB0lAeof0qBgmSxIZ~yg "The ServiceNow ITOM Visibility finds Kubernetes and OpenShift components using patterns and creates application services containing them. Discovery also finds Kubernetes events and frequently updates the CMDB to reflect the dynamic Kubernetes environment.")
* [Service Mapping](https://servicenow-prod.fluidtopics.net/tvx92LEagZz6tjwRzVmQgg "Service Mapping in cloud environments provides critical visibility into application dependencies and connections. By identifying how different application components interact within IaaS and PaaS environments, your organization can gain better insight into its application services and improve overall service management.")
* [Discovery and Service Mapping Patterns](https://servicenow-prod.fluidtopics.net/VRVjHOLBToHiwjz2ZRkbUg "Discovery and Service Mapping Patterns uses patterns to discover components of the Amazon AWS Cloud deployment during horizontal discovery. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.")
* [Certificate Inventory and Management](https://servicenow-prod.fluidtopics.net/2OfTv01DTIUbowY6kgvY_A "Cloud Discovery uses Patterns to discover certificate data that the Amazon AWS Cloud Certificate Manager (ACM) manages. Discovering this data requires installing and updating Discovery and Service Mapping Patterns and Certificate Inventory and Management.")
{#understanding-aws-discovery__ul_qzt_gqq_mhc}

Enabling Discovery or other Visibility solutions to access your AWS infrastructure depends on roles and permissions configured both in AWS and in ServiceNow AI Platform. The discovery process requires configuration within AWS, like setting up Identity and Access Management roles.  
{#understanding-aws-discovery__table_ajm_35s_ghc__entry__2}

| AWS Users | Discovery permissions |
|-|-|
| AWS Organizations with master and member accounts | Access is based on the IAM roles defined for the master and member accounts. |
| AWS account root user | Has complete access to all AWS services and resources in the account. |
| IAM users/IAM user group | Has access to specific resources and services based on IAM roles or temporary access based on assumed roles. |
[Tabelle : 1. AWS user discovery permissions]

{#understanding-aws-discovery__table_ajm_35s_ghc} For more information, see [Access to cloud environments for ITOM products](https://servicenow-prod.fluidtopics.net/BUydLGViOBChmi5JKOzBGw "If your organization deploys IT assets on the cloud, ITOM products must access your cloud environment to collect information about the IT infrastructure.")  
In the ServiceNow AI Platform side, there are user configurations needed if you choose to use Discovery.

* You must configure the discovery_admin role for a user, to be able to run the discovery. For more information, see [Managing roles](https://www.servicenow.com/docs/access?context=ua-creating-roles&version=australia&pubname=australia-platform-administration&ft:locale=en-US)
* Discovery runs commands and API queries to access and discover your AWS infrastructure. Before starting to configure Discovery roles and permissions, review the Cloud discovery spreadsheet and verify the REST API permissions.

{#understanding-aws-discovery__ul_vym_w5g_lhc}

## Verify the REST API Permissions {#understanding-aws-discovery__id_wxp_lh3_chc}

Download the [Cloud Discovery patterns spreadsheet](https://downloads.docs.servicenow.com/resource/enus/api/servicenow-discovery-patterns-api-details.xlsx) so you can grant user permissions required for running the Discovery patterns. In addition to permissions, the spreadsheet also includes useful information such as pattern names, types, CI Classes, and links to vendor documentation. New patterns are available
quarterly, so check periodically to be sure you have the latest version of the spreadsheet.{#understanding-aws-discovery__cloud-discovery-api-paragraph}

