---
sourceDocument: Yokohama IT Operations Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/yokohama/it-operations-management

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama IT Operations Management

ft:clusterId :

    - itom

bundleId :

    - itom

workflow :

    - Technology


---

# Create a Discovery behavior

# Create a Discovery behavior {#ariaid-title1}

* Release version: Yokohama
* 
* Updated January 30, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read

Create a Discovery behavior to determine which probes Shazzam launches and which MID Server is used.{#create-disco-behavior__ph_discovery-behavior-intro}

## Before you begin

Role required: discovery_admin

## Procedure

1. Navigate to AllDiscovery DefinitionBehavior and click New.
2. Enter a name.
3. Right-click the form header and select Save.  
4. In the Discovery Functionality related list, click New.  
   Discovery Functionality defines what each MID Server in this behavior must do, specifically which protocols to detect.
5. Fill out the form fields:  
   {#create-disco-behavior__table_lzj_wlf_wbb__entry__2}

   | Field | Description |
   |-|-|
   | Phase | Enter an integer that represents an arbitrary phase. The phase is used to group one or more functionalities together. All the functionalities within a specified phase are executed together, and all phases are executed in numerical order. All functionalities in a behavior can have the same phase. The Shazzam probe runs once for each phase in a behavior, which makes fewer phases desirable. Run multiple phases for behaviors only when devices in the network are running multiple protocols, such as SSH and SNMP. In that example, set one phase for the SSH scan and another phase for the SNMP scan. |
   | Active | Keep this option selected to apply the discovery functionality. |
   | Functionality definition | Click the lookup icon, and then select a pre-configured functionality that defines the protocol or list of protocols that each MID Server scans. |
   | Match criteria | Define criteria here for Windows MID Servers. |
   | MID Servers | Select one or more MID Servers to perform this functionality for the following Discovery types: * IP Scan * CI Scan {#create-disco-behavior__ul_l42_gs2_vp} Discovery automatically balances the load when multiple MID Servers are selected. |
   [ ]

   {#create-disco-behavior__table_lzj_wlf_wbb}
6. Right-click the form header and select Save.
7. To add criteria that the functionality must meet in order to be triggered, click New in the Functionality Criteria related list, fill out the form fields, and then click Submit.  
   {#create-disco-behavior__table_f1v_ts2_vp__entry__2}

   | Field | Input Value |
   |-|-|
   | Name | The name in the criteria is the variable that passes the following information: * <kbd class="ph userinput">mid_server</kbd>: MID Server that processes the results from the Shazzam probe. * <kbd class="ph userinput">win_domain</kbd>: Windows domain of the target device. {#create-disco-behavior__ul_sfd_zt2_vp} |
   | Operator | Select a logical operator. |
   | Value | Enter the actual name of the MID Server (<kbd class="ph userinput">mid_server</kbd>) or domain (<kbd class="ph userinput">win_domain</kbd>) to pass to Discovery for this criteria. This field can also have a value of <kbd class="ph userinput">mid_domain</kbd>, which defines the Windows domain of the MID Server that is processing the Shazzam results. |
   [ ]

   {#create-disco-behavior__table_f1v_ts2_vp}  
   Note:  
   Functionality criteria are required for Windows MID Servers only, and only when the behavior controls Discovery across multiple domains. When the instance launches the Shazzam probe for a Discovery in which a behavior defines multiple MID Servers to scan multiple domains, the functionality criteria determine which MID Server process the results of the probe.

   The following graphic shows an example of functionality criteria.

## What to do next

[Schedule a horizontal discovery](https://servicenow-prod.fluidtopics.net/CIQEq9XeYjrEAd3sKWHEVg "A discovery schedule determines what horizontal discovery searches for, when it runs, and which MID Servers are used. Create a discovery schedule for your local environment or a schedule for discovering the resources in your cloud service account.") of type Configuration Item, and select Use Behavior for the MID Server selection method.
**Related tasks**   

* [Set up a load balancing behavior](https://servicenow-prod.fluidtopics.net/EC0UygqHQWz4LolebKhI1A "When multiple MID Servers are configured to scan the same protocol, you can set up load balancing behavior to automatically balance the work between MID Servers.")
* [Access an ACL-protected SNMP device](https://servicenow-prod.fluidtopics.net/lsAWzmnqubUeNotoloE9Ew "Access an SNMP device protected by an ACL using a Discovery behavior.")  
**Related reference**   

* [Examples of Discovery behavior functionalities](https://servicenow-prod.fluidtopics.net/Tj16lpfCRzAFWxaWpvp8EQ "This example of a Discovery behavior requires three functionalities for the behavior.")

*[\>]: and then


