---
sourceDocument: Yokohama IT Operations Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/yokohama/it-operations-management

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama IT Operations Management

ft:clusterId :

    - itom

bundleId :

    - itom

workflow :

    - Technology


---

# Exploring Agent Client Collector Framework

# Exploring Agent Client Collector Framework {#ariaid-title1}

* Release version: Yokohama
* 
* Updated January 30, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 3 minutes to read

Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Exploring Agent Client Collector Framework

The Agent Client Collector Framework (ACC-F) is a ServiceNow solution designed to monitor the performance and health of infrastructure components by deploying agents on servers and devices.
These agents collect critical system metrics and events, transmitting this data securely through a MID Server to the ServiceNow instance.
The framework stores and associates the data with Configuration Items (CIs) in the CMDB, enabling proactive management, troubleshooting, and optimization of infrastructure.
Show full answer Show less  

## Key Features

* **Agent Deployment and Data Collection:** Agents run predefined scripts or checks on Windows, Linux, and macOS devices to gather metrics such as CPU usage, memory, disk space, network activity, error logs, and alerts.
* **Secure Data Transmission:** Data flows securely through a dedicated MID Server acting as a communication bridge between infrastructure and ServiceNow.
* **Data Storage and Association:** Collected data is stored in ServiceNow and linked to corresponding CIs for effective tracking and reporting within the CMDB.
* **Analysis and Automation:** The framework analyzes data for monitoring and troubleshooting, triggering alerts and remediation actions such as running corrective scripts or notifying teams.
* **Plugins and Customization:** Extend monitoring capabilities with plugins that perform specialized checks and trigger events based on defined conditions, providing scalable and customizable infrastructure monitoring.
* **Secure Parameters:** Sensitive data used during check execution is securely passed via standard input, preventing exposure in logs or command lines.
* **Configuration Data Files:** Dynamic instance data is stored and used by checks to ensure accurate execution.
* **Comprehensive Logging:** ACC logs provide insights into agent performance and issues, facilitating troubleshooting and improving agent effectiveness.
* **API Integration:** The ACC API enables automation by executing queries on agents and processing results to streamline system monitoring and management.
* **Health Instance Scan Suite:** Built-in checks detect anomalies in the ACC instance to maintain health and performance proactively.
* **Domain Separation Support:** Allows logical separation of data and administrative control, ensuring data visibility and access can be managed appropriately across domains.

## Benefits for ServiceNow Customers

* **Improved Operational Efficiency:** Automated, continuous monitoring of system health and performance reduces manual effort and speeds incident triage.
* **Comprehensive Visibility:** Enables tracking of server inventory, software usage, and devices even in isolated or air-gapped environments with minimal network impact.
* **Proactive Issue Resolution:** Early detection and automated remediation actions minimize downtime and prevent user impact.
* **Enhanced Security and Compliance:** Secure handling of sensitive parameters and controlled domain separation support organizational security policies.
* **Scalable and Customizable:** Use of plugins and configuration files allows tailored monitoring to meet evolving infrastructure needs.
* **Integration with ITSM and Security Processes:** Live CI data access and remote actions support incident management and security response workflows.

## Practical Application

ServiceNow customers can deploy ACC-F agents on key infrastructure devices to gain continuous insights into system performance and health. By leveraging the framework's data collection, analysis, and automation features, organizations can enhance IT asset discovery, improve incident response times, and maintain reliable service operations. The framework's support for domain separation and secure parameter handling aligns it with enterprise security and governance requirements.  
The Agent Client Collector Framework (ACC-F) is a powerful solution for monitoring the performance and health of infrastructure components by using agents installed on servers and devices. It collects and
sends critical system data to ServiceNow for analysis, enabling proactive management and troubleshooting of Configuration Items (CIs).

## Agent Client Collector Framework overview {#exploring-agent-client-collector-framework__section_hxc_24k_lzb}

The Agent Client Collector Framework enables organizations to monitor and manage the health of their infrastructure through agents installed on key systems. These agents execute predefined
commands on the machines they are installed on, sending the resulting data back to the ServiceNow® instance via a dedicated MID Server. The framework enables seamless management of both the Agent Client Collector and MID Server, storing event data and performance metrics in the appropriate database. By providing insights into CI performance, ACC-F helps organizations identify and resolve issues
quickly, improving operational efficiency and system reliability.

## Agent Client Collector Framework workflow {#exploring-agent-client-collector-framework__section_ixc_24k_lzb}

The following illustration describes the layout and data flow within the Agent Client Collector Framework application.
Figure 1. Collecting and distributing data with ACC-F  
1. Agent installation: The agent is installed on infrastructure components, such as servers, devices, and network equipment. These agents are responsible for executing system commands and gathering performance data from the host machine. ACC-F is deployed on the customer's ServiceNow® instance.
2. Data collection: The agent runs predefined scripts or queries (checks) on the infrastructure components to collect various system metrics and events. This includes performance data such as CPU usage, memory utilization, disk space, and network activity. The agent also collects error logs and system alerts.
3. MID Server communication: The agent sends the collected data to the ServiceNow instance through a dedicated MID Server. The MID Server acts as a secure communication bridge between the infrastructure and the ServiceNow platform, ensuring data is transmitted reliably and securely.
4. Data Storage: Upon receiving the data, the ServiceNow instance stores the events and performance metrics in the relevant database. This data is then associated with the respective Configuration Items (CIs) within the ServiceNow CMDB Configuration Management Database (CMDB), enabling efficient tracking and reporting.
5. Data Analysis and Reporting: The collected data is analyzed within the ServiceNow instance, where it is used for monitoring, troubleshooting, and reporting purposes. This analysis helps identify potential issues or areas of improvement, triggering alerts or actions to resolve problems proactively.
6. Feedback Loop: Based on the analysis, the system can trigger remediation actions, such as running corrective scripts, reconfiguring settings, or notifying responsible teams for further investigation. The feedback is looped back into the system, allowing for continuous monitoring and optimization.
{#exploring-agent-client-collector-framework__ol_w1h_wpf_2cc}

## Agent Client Collector Framework benefits {#exploring-agent-client-collector-framework__section_lxc_24k_lzb}

Agent Client Collector Framework provides data to other Agent Client Collector components.
{#exploring-agent-client-collector-framework__table_mxc_24k_lzb__entry__3}

| Benefit | Feature | Users |
|-|-|-|
| Monitor your system's health, performance, and availability through automated collection of events and metrics, leveraging automated configurations. | [Agent Client Collector Monitoring](https://servicenow-prod.fluidtopics.net/PBwCUG8gQlCWksLnNdTV3Q "Agent Client Collector Monitoring enables you to monitor your service availability, examine the health and performance of your environment, and ensure that your infrastructure and its applications are running properly.") | NOC User, Event Management administrator |
| Track server inventory, software installations and usage continuously with non-admin access and minimal network communication. | [Agent Client Collector for Visibility Content](https://servicenow-prod.fluidtopics.net/uQErvRgVvo2nORIFqEJcSA "Agent Client Collector for Visibility Content (ACC-VC) is a ServiceNow Agent installed on your Windows, Linux, or macOS endpoint devices to collect host data.") | CMDB/Discovery administrator |
| Gather detailed inventory data of devices not connected to your network or running in isolated environments (air-gapped). | [Agent Client Collector Framework Air Gapped Configuration Item Management Solution](https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB1585753) | CMDB/Discovery administrator |
| Minimize triage time of incidents by direct access of live device details and interactions to remediate. | [View live CI data with Agent Client Collector](https://servicenow-prod.fluidtopics.net/ax1_KucIX_GSssOZk9JJ_Q "View live data for incident-related CIs through Agent Client Collector for information that can help resolve the incidents.") | ITSM user |
| Trigger remote actions against managed devices, without additional credential or network communication. | [Agent Client Collector Security Incident Response](https://servicenow-prod.fluidtopics.net/MoiKC_9nntxnYvpL7tRG~g "Agent Client Collector Security Incident Response (ACC-SIR) enables you to automate security incident enrichment data collection and response actions using the Agent Client Collector. This functionality is measured by the Security Operations Security Incident Response (SIR).") | Automation expert |
| Stream log data into your instance to predict problems and solve them before they happen, to minimize user impact. | [Agent Client Collector Log Analytics](https://servicenow-prod.fluidtopics.net/SuAKpX6~2tbaSzdG4PW6ng "Agent Client Collector Log Analytics (ACC-L) enables you to stream log data from Linux and Windows hosts to a ServiceNow instance, using the Agent Client Collector.") | Agent Client Collector administrator |
[ ]

{#exploring-agent-client-collector-framework__table_mxc_24k_lzb}
* **[Agent Client Collector Framework use case](https://servicenow-prod.fluidtopics.net/~4wQehcYtNyONP3BCUgNIw)**   
  The Agent Client Collector Framework use case demonstrates how a financial organization can use Agent Client Collector Framework to assist in IT asset discovery.
* **[Agent Client Collector architecture](https://servicenow-prod.fluidtopics.net/3Fta4Y2~KaGvDc_hadlosw)**   
  The Agent Client Collector is a ServiceNow agent installed on your Windows, Linux, and macOS devices to monitor your company's infrastructure and installed applications.
* **[Agent Client Collector plugins](https://servicenow-prod.fluidtopics.net/PKiJ_p74aiOF7VS66QHuhg)**   
  An Agent Client Collector plugin is a script or group of scripts that extend the Agent Client Collector's capabilities. Plugins enhance monitoring by collecting metrics, performing specialized checks, and triggering events based on conditions, like monitoring an application's queue size when it reaches 60% or 80%. Plugins ensure scalable, customizable monitoring to adapt to evolving infrastructure or application needs.
* **[Verify data collection in Agent Client Collector](https://servicenow-prod.fluidtopics.net/mJlxgBo3gG5Cy2TftZur2A)**   
  Collect data by gathering essential information from an agent's host system before executing any checks or policies. This process ensures that the Agent Client Collector has accurate and up-to-date data on the infrastructure, processes, and applications running on the host.
* **[Checks and policies](https://servicenow-prod.fluidtopics.net/ft6B1g3pkBxbL537XUnCNg)**   
  A check is a combination of a command and its configuration. The check is executed on the Agent Client Collector's devices to gather data from those devices.
* **[Secure parameters in the Agent Client Collector](https://servicenow-prod.fluidtopics.net/dBUboHugQQSuyJevUXOVcQ)**   
  Secure parameters in the Agent Client Collector (ACC) refers to securely passing sensitive data, such as user names, passwords, and API keys, during check execution, without exposing the sensitive data in the command line. Parameters are passed to the script through standard input (STDIN), hiding them from logs or any process that might capture command-line arguments.
* **[Agent Client Collector configuration data files](https://servicenow-prod.fluidtopics.net/U9hdznY3y7S0GBH0RSjMYw)**   
  Configuration data files store dynamic instance data, such as virtual machine details, that check definitions use during execution. This ensures that checks are executed with up-to-date and accurate information about the instance being monitored.
* **[Agent Client Collector logs](https://servicenow-prod.fluidtopics.net/ly0ncmIUFJSntF~3mB2YBQ)**   
  Agent Client Collector (ACC) logs play a critical role in monitoring the activity and performance of the agent. Logs offer valuable feedback that helps identify potential issues, especially when the agent's performance is suboptimal. By providing insights into areas of concern, these logs are essential for troubleshooting and resolving issues, ultimately improving the overall effectiveness of the agent.
* **[Agent Client Collector API](https://servicenow-prod.fluidtopics.net/dujJH76UqE7ty7hho59ATQ)**   
  Use the Agent Client Collector (ACC) API to create a flow that executes an `osquery` command on agents and processes the results. By leveraging the ACC API, you can automate the querying of agent data and streamline the processing of results, making it easier to monitor and manage system performance.
* **[Agent Client Collector health instance scan suite](https://servicenow-prod.fluidtopics.net/NOEUnFsGz4OYmL9hY4d7pw)**   
  The Agent Client Collector (ACC) health instance scan suite consists of checks that detect anomalies and other issues that might occur on your instance. These checks ensure the overall health and performance of the ACC, proactively identifying potential problems before they impact system operations.
* **[Domain separation and Agent Client Collector](https://servicenow-prod.fluidtopics.net/x5LQOCmTju9rL_M1K5oEwA)**   
  Domain separation is supported for Agent Client Collector (ACC). Domain separation enables you to separate data, processes, and administrative tasks into logical groupings called domains. You can control several aspects of this separation, including which users can see and access data.

