Create an AI connection for Amazon
Create an AI connection for Amazon in AI Control Tower using the AI Service Graph Connector for Amazon.
Before you begin
Role required: sn_ai_disc.discovery_admin and sn_cmdb_int_util.sgc_admin
Procedure
- Navigate to Al Control Tower > Configurations > AI connections.
- Click Add.
- Select AWS from all the available connectors.
-
Click Create connection.
Note:The Review the setup instructions page appears and verifies to follow all the prerequisites.
-
Select Download basic scripts.
Note:Download the basic scripts and select the check box.
-
Select Continue.
Setup page appears.
- Select Source systems.
-
Choose the AWS services that you want to integrate with ServiceNow.
- Amazon Bedrock
- Amazon Bedrock AgentCore
- Amazon SageMaker
- Select Submit.
-
Configure Amazon Bedrock
- Enter the Connection Name
- Enter the Access Key ID
-
Enter the Secret Access Key
The Access keys are long-term credentials for an IAM user or the AWS account root user. Access keys consist of two parts: an access key ID and a secret access key. For detailed information, see how to get access and secret key
-
Enter the AWS Region.
Note:The region information is available in the navigation bar of the AWS management console.
-
Enter the Management Account ID
Note:The Management Account ID applies in two scenarios:
- Your IAM user is created in a Designated Member account.
- You need Organizational-level access.
-
Enter the Standalone Account ID
Note:This step is optional. Provide a single account ID to test discovery against that account before enabling full Organization discovery.
-
Enter the STS Assume Role
The role assumed for discovery.
- Select Update and test connection
- Select Continue
-
Configure Bedrock import schedule
- Open a parent schedule import
- Select the Active check box
-
Select Run according to your preference
Note:This is an optional step as the schedule imports run according to the schedule.
-
Configure CloudWatch logs forBedrock
- Enter the Connection Name.
- Enter the Access Key.
- Enter the Secret Key.
- Enter the AWS Region.
- Enter the Log Group Names.
- Select Create and test connection.
- Select Continue.
-
Configure CloudWatch logs import schedule for Bedrock
- Open a parent schedule import.
- Select the Active check box.
-
Select Execute Now.
Note:This is an optional step as the schedule imports run according to the schedule.
- Select Continue.
-
Configure SageMaker
- Enter the Connection Name
- Enter the Access Key ID
- Enter the Secret Access Key
- Enter the AWS Region
- Select Create and test connection
- Select Continue
-
Configure SageMaker import schedule
- Open a parent schedule import
- Select the Active check box
- Select Run according to your preference
-
Select Execute Now
Note:This is an optional step as the schedule imports run according to the schedule
- Select Continue
-
Configure CloudWatch monitoring for SageMaker
- Enter the Connection Name
- Enter the Access Key
- Enter the Secret Key
- Enter the AWS Region
- Select Create and test connection
- Select Continue
-
Configure CloudWatch monitoring import schedules for SageMaker
- Open a parent schedule import
- Select Active check box
- Select Run according to your preference
-
Select Execute Now
Note:This is an optional step as the schedule imports run according to the schedule
- Select Continue.
Result
The AI connection for AWS is created and configured.