---
sourceDocument: Australia Operational Technology Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/operational-technology

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Operational Technology Management

ft:clusterId :

    - optm

bundleId :

    - optm

workflow :

    - Technology


---

# Create an Auto Query

# Create an Auto Query {#ariaid-title1}

Release version: Australia  
Updated March 12, 2026  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 4 minutes to read  
Create an Auto Query that you can run on demand for different Discovery Console for OT Assets.

## Before you begin

Role required: admin

## Procedure

1. Navigate to Assets \> Auto Query.
2. Select the add icon ![]().
3. For the Identification section, use the automatically provided name or create your own name.  
   Note:  
   If you use an IP address that is already in the system as the new Asset identification, you receive an error message.  

   Be sure to use an IP address that is not in the system already.
4. Select Next.
5. In the Assets section, choose from Assets and Targets.  
   The available Assets are:
   * Existing Assets
   * New Assets Only
   * Incremental
   * Asset Discovery
   * Asset Discovery \& Query

   {#add-auto-query-console__ul_j2v_znp_jhc}The default Asset selection is Existing Assets.

   When Existing Assets is selected for a query, the query uses the asset's IP address and Network Zone as its unique identifier.
   This allows the asset's IP address to exist across multiple Network Zones.

   <br />

6. Targets refers to Sensors and Collector.  
   The available Targets are:
   * All Sensors
   * Specific Sensors
   * Auto Targeting

   {#add-auto-query-console__ul_rkw_mbv_g3c}The default Targets selection is All Sensors. All Sensors uses all available Sensors and Collectors for the query. Specific Sensors uses only the selected Sensor and Collectors for the query. Auto Targeting tries to intelligently assign targets to Sensors and Collectors based on the query. It helps manage complex deployments.
7. Select Next
8. In the Filters section, select the filters as needed.  
   These filters help with the query selections. Filters include the following categories.  
   Note:  
   Some options in this section are only visible when the Assets selection is set to Existing Assets or Incremental. When the selection is Asset Discovery or Asset Discovery \& Query, a few options are inactive.
   * Sites

     Site rules override global behavior when the Site filter is selected. If no site rules matches the Asset, the query skips the Asset.  
     Note:  
     The Console automatically generates a default site. This is in case no Sites have been previously created. You can select the Console-generated site when using the Sites filter to select specific sites.

     <br />

   * Ports
   * Ethernet Vendors
   * Brands
   * Inbound Protocols
   * Outbound Protocols
   * Network
   * Ignore Networks  
     Note:  
     The Ignore Networks filter allows you to select an IP range or individual IP addresses to ignore during the query.  

   * Hostnames  
     The Hostnames filter uses the hostname of the Asset and Targets the Asset based on the specified hostname information. To use this filter, select No Filter (default selection) or one of these options:
     * Empty/Null: Queries Assets where the Hostname field is empty or null.
     * Exact: Matches Assets whose Hostname equals any of the values you add. There is a field to type in a Hostname. All hostnames are included in this query unless you add at least one value.
     * Contains: Matches Assets whose Hostname contains any of the substrings you add. There is a field for adding a value. All hostnames are included in this query unless you add at least one value.

     {#add-auto-query-console__ul_hbg_1mk_jhc}  

   {#add-auto-query-console__ul_qfv_rvl_23c}
9. Choose a filter and then select Next.
10. In the Query Types section, select the applicable query types as needed.  
    * The Simplified query types are a small list of easy-to-understand queries that should cover most possible scenarios. Most users start with this type of query.  

      Note:  
      The simplified Auto Query type Full Page Extraction updates the query to perform a full extraction of your Target landing page. That means, this type of query includes both the screenshot and the HTML information.
    * The Advanced query types are a list of all available advanced auto queries. As some of these queries can be riskier, require more technically complicated to understand, or specific to certain devices; these queries are recommended only for advanced users.

    {#add-auto-query-console__ul_mms_rz3_lgc}  

    Some recently added Advanced Query types include but aren't limited to:
    * MelSecQ - Query the Mitsubishi MELSEC-Q Series
    * Moxa - Query to read the Moxa ICS setting
    * IPC-UA Deep - Retrieve info from an OPC-UA target
    * ProfiNet DCE/RPC EPM - Performs ProfiNet DCE/RPC EPM lookup requests
    * ProfiNet DCP - PLC protocol often used for communicating with Siemens devices; this protocol is newer than S7. NOTE: Since this is a layer 2 scan it may return more results than selected.
    * SSL/TLS Certificate - Query server to retrieve information about served SSL/TLS certificates
    * WMI - Query Windows OS devices using Windows
    {#add-auto-query-console__ul_z4k_zns_tjc}
11. **Optional:** You can set up the Auto Query scan to include all open ports.  
    To do this, select both or either the UDP Port Enumeration and / or TCP Port Enumeration (highlighted in the previous image) from the Advanced Query Types. Each scan determines all open ports for their two respective protocols.  
    Note:  
    For these query types to be available, verify your ScanScripts.json driver is up to date; if not, upload the latest version of this driver. For information, see [Edit the Query Driver on Metadata tab](https://servicenow-prod.fluidtopics.net/mzfhft1A7qlcbTRcS9TuGQ "Edit the Query Driver on Metadata tab. The Query Driver section enables you to import or download query drivers and control the speed of Auto Queries.").
12. Select Next
13. **Optional:** In the Classification section, select from the following.  

    <br />

    * Brand based on MAC address: Assigns brand based on MAC address range match.
    * Brand based on OCR words: Attempts to assign brands based on strings extracted by the OC. Fuzzy word search is supported.
    * Console Hostname Look up: Attempts to determine an Asset's hostname based on its IP address.
    * Location: Sets a label and the location field with Site name.
    * Unknown: Marks the Asset brand and category Unknown.
    {#add-auto-query-console__ul_tr4_2kh_shc}
14. Select Next.
15. In the Confirmation section, set the schedule, recursion, and duration.  

    <br />

16. Select Next.
17. Select the Create Auto Query button.
{#add-auto-query-console__steps_g1j_fgj_42c}

## Result

The query is added to the Auto Query page.

