---
sourceDocument: Yokohama IT Operations Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/yokohama/it-operations-management

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama IT Operations Management

ft:clusterId :

    - itom

bundleId :

    - itom

workflow :

    - Technology


---

# Linux

# Linux discovery {#ariaid-title1}

* Release version: Yokohama
* 
* Updated January 30, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 7 minutes to read

Discovery and Service Mapping applications use probes and patterns to discover and map information about Linux computers and servers. The information is populated in the CMDB. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.

## Supportability details {#r_DataCollDiscoLinuxComputers__section_mrm_5sy_syb}

The Linux server pattern can discover only English-based Linux.

Supported Linux operating systems
:
    For IPv4 discovery:

    * Red Hat
    * Oracle
    * Fedora
    * Debian
    * SUSE
    * CentOS
    * Ubuntu
    * Alpine Linux (starting from Visibility Content version 6.30.0)\*
    {#r_DataCollDiscoLinuxComputers__ul_uf4_1rw_cz}\* Operating System and OS Version only

    For IPv6 discovery:

    * CentOS 7
    * Ubuntu 20
    {#r_DataCollDiscoLinuxComputers__ul_yxd_dfc_35b}

    The following operating systems or devices haven't been verified for IPv6 discovery:

    * Red Hat cluster
    * Oracle Clusterware
    * Linux Pacemaker cluster
    * Network storage
    {#r_DataCollDiscoLinuxComputers__ul_r4x_mdc_35b}

## Classifier, probes, and pattern {#r_DataCollDiscoLinuxComputers__section_hx5_tmf_nbb}

{#r_DataCollDiscoLinuxComputers__table_nww_wmf_nbb__entry__3}

| Classifier | Probes | Pattern |
|-|-|-|
| Linux (Unix classification) | * Horizontal discovery probe: Launches patterns * Linux - Installed Software\^ * Unix - ADM\^ * Linux - Identity\* * Linux - CPU\* * Linux - Distribution\* * Linux - Find FQDN\* * Linux - Memory\* * Linux - Memory Modules\* * Linux - Network ARP Tables\* * Linux - Storage\* * Linux - Amazon EC2\* * Unix - OS Uptime\* * UNIX - OS Filesystems\* * UNIX - Find FQDN\* * Unix - ADM Enhanced\* {#r_DataCollDiscoLinuxComputers__ul_lxj_zlr_rz} | Linux Server |
[ ]

{#r_DataCollDiscoLinuxComputers__table_nww_wmf_nbb}

\*These probes aren't active on the classifier, as Discovery uses patterns by default for these discoveries.

\^These probes remain active by default, even when Discovery uses pattern discovery.

To use patterns, verify that the correct pattern is specified in the horizontal pattern probe on the classifier. See [Add the Horizontal Pattern probe to a classifier](https://servicenow-prod.fluidtopics.net/F1AaGd2A7GKs7d9ZAQQp5w#t_AddHorizontalPatternProbe "To use a pattern for the identification and exploration phases of horizontal discovery, you must add the Horizontal Pattern probe to the classifiers for the CIs are you trying to discover.") for instructions.

## Request new or enhanced Patterns on the ServiceNow® Store {#r_DataCollDiscoLinuxComputers__section_bzr_dqf_jfc}

Visit the [ServiceNow Store](https://store.servicenow.com/sn_appstore_store.do#!/store/application/06a71b1367e4130051c9027e2685ef1e/1.6.0?referer=/store/search?listingtype=allintegrations%253Bancillary_app%253Bcertified_apps%253Bcontent%253Bindustry_solution%253Boem%253Butility%253Btemplate&q=Patterns&sl=sh) to view all the available updates and for information about submitting requests to the store. For cumulative release notes information for all released apps, see the [ServiceNow Store version history release notes](https://www.servicenow.com/docs/r/store-release-notes/sn-store-release-notes.html).{#r_DataCollDiscoLinuxComputers__p_d21_nfg_h1c}

## Requirements for Linux discovery {#r_DataCollDiscoLinuxComputers__section_fgs_dqf_jfc}

Before running a discovery, you must verify that all the required configurations are complete.

Verify the plugins installation and activation
:
    * [Plugins or applications installed with ITOM Visibility](https://servicenow-prod.fluidtopics.net/dgLPeaSg4KmSaaHdM52~gA "Tables that list the plugins or applications that are installed with ITOM Visibility applications. When you update your application, any newly required application dependencies are installed.")
    * [Install Discovery and Service Mapping Patterns](https://servicenow-prod.fluidtopics.net/4KmHJaegA_VkfbWKT536DQ "You can install the Discovery and Service Mapping Patterns application (sn_itom_pattern) if you have the admin role.")
    * [Install Visibility Content](https://servicenow-prod.fluidtopics.net/OMSn0ziSzYg5__LjZid3Xg "You can install the Visibility Content application (sn_pattern_design) if you have the admin role.")
    {#r_DataCollDiscoLinuxComputers__ul_cjy_gsf_jfc}

Verify the required credentials configuration

:   Configure the credentials by the required SSH permissions. Discovering sensitive Linux data may require a user with appropriate sudo privileges to run the sudo commands. To configure the required sudo privileges, modify the /etc/sudoers file to include the
    commands that Discovery needs. For /etc/sudoers line examples for each command, see [Privileged SSH commands for probe-based discovery](https://servicenow-prod.fluidtopics.net/9zRLtV44HUO12jMk5mJ1Rw "These tables display the SSH commands run by Discovery probes during horizontal discovery. These SSH commands require elevated privileges to run.").

    For more information about the commands that require a user with elevated rights, refer to the following documents.

    * [Commands that require root privileges for Discovery, Orchestration, and Integration Hub](https://www.servicenow.com/docs/access?context=r_SSHCredentialsForm&version=yokohama&pubname=yokohama-platform-security&ft:locale=en-US).
    * For a list of privileged commands that you need for Discovery
      and Service Mapping, see [Service Mapping commands requiring a privileged user](https://servicenow-prod.fluidtopics.net/KmX~uDsV3RoqnUbrW~2SFA "Service Mapping uses commands requiring elevated rights to discover and map Unix-based hosts in your organization. In addition to configuring necessary credentials, configure servers in your organization to allow Service Mapping to run these commands with elevated rights."). This list
      includes commands that require elevated rights to discover and map Unix-based hosts in
      your organization.

    * [MID Server privileged commands](https://www.servicenow.com/docs/access?context=c_PrivilegedCommandsForMIDServer&version=yokohama&pubname=yokohama-servicenow-platform&ft:locale=en-US)
    * [View Patterns commands through the Discovery Patterns module](https://servicenow-prod.fluidtopics.net/eouL4CSH9SmIxBXfakMpaw "View all the commands required for an infrastructure or application pattern to verify you have sufficient permissions to run discovery.")
    * [Validate commands used in pattern-based discovery](https://servicenow-prod.fluidtopics.net/tJclIOdpx59diE4aaqewew "Validate pattern commands to verify that the MID Server can successfully run them. Typically, commands might fail if you haven't configured the credentials necessary to run these commands on your ServiceNow instance. Another common reason of command failure is that the IP addresses used for discovery aren’t reachable.")
    {#r_DataCollDiscoLinuxComputers__ul_ghz_ztf_jfc}

    SSH private key credentials are preferable over SSH password credentials for security reasons.

Verify the MID Server configuration
:   For detailed information, see:

    * [Test MID Server connectivity](https://www.servicenow.com/docs/access?context=t_ValidateNetworkConnectivity&version=yokohama&pubname=yokohama-servicenow-platform&ft:locale=en-US)
    * [MID Server properties](https://www.servicenow.com/docs/access?context=r_MIDServerProperties&version=yokohama&pubname=yokohama-servicenow-platform&ft:locale=en-US)
    {#r_DataCollDiscoLinuxComputers__ul_htq_tzv_jfc}

Verify the configuration of the discovery schedule

:   For information on creating a discovery schedule, see [Schedule a horizontal discovery](https://servicenow-prod.fluidtopics.net/CIQEq9XeYjrEAd3sKWHEVg "A discovery schedule determines what horizontal discovery searches for, when it runs, and which MID Servers are used. Create a discovery schedule for your local environment or a schedule for discovering the resources in your cloud service account.").

    Defining IP ranges ensures that only the specified network adapters and their primary IP addresses are used during Linux discovery. You can configure Quick Ranges by entering comma-separated IPv4 address ranges or single IPv6 address.

    Alternatively, you can use the network_adapter_exclusion_list property to limit Linux discovery to specific network adapters and their primary IP addresses. For more information, see [Omit network adapter secondary IP addresses in Linux discovery](https://servicenow-prod.fluidtopics.net/bwhYFw6F6tqC2g11Z1I9uA "Limit Linux discovery to specific network adapters and their primary IP addresses to improve performance by ignoring secondary IP addresses.").

(Optional) Populate Virtual Machine Object field in Hardware \[cmdb_ci_hardware\] table
:   Starting with Discovery and Service Mapping Patterns version 1.30.2, you can improve query performance by populating the Virtual Machine Object field in the Hardware \[cmdb_ci_hardware\] table. For more information, see [Improved query performance with direct field population in CI tables](https://servicenow-prod.fluidtopics.net/H_wfVmrRA2K_BT9VRkb6iQ "The Populate Service Account and LDC IN CMDB scheduled job populates the Service Account and Logical Datacenter fields in cloud configuration item (CI) tables, and the Virtual Machine Object field in the Hardware [cmdb_ci_hardware] table. This direct population reduces query complexity and improves query performance.").

Set the preferred IP address version for network adapter discovery
:   Starting with Visibility Content version 6.32.0, if your network adapters support both IPv4 and IPv6, the IPv4 address is populated by default in the IP address \[ip_address\] field on the Network Adapter
    \[cmdb_ci_network_adapter\] table. To control which IP version is populated, see [Set the preferred IP version for network adapter discovery](https://servicenow-prod.fluidtopics.net/krs8qXa6h3b1PLhkYEnKqA "Control which IP version Discovery populates on a Network Adapter CI during Linux, Windows, and Solaris discovery.").

## Data collected

The Linux classifier triggers probes that perform the discovery. Several probes are launched during the discovery. See the classifier for a list of the trigger probes.  
Note:  
See the knowledge article [KB0687582](https://support.servicenow.com/kb_view.do?sysparm_article=KB0687582) for information on model_id and manufacturer.
{#r_DataCollDiscoLinuxComputers__table_DiscoveryDataForLinux__entry__4}

| Label | Table Name | Field Name | Source |
|-|-|-|-|
| Operating System | cmdb_ci_linux_server | os | uname -a |
| OS Version | cmdb_ci_computer | os_version | uname -a or cat /etc/\*release |
| Short description | cmdb_ci_linux_server | short_description | uname -a |
| Name | cmdb_ci_linux_server | name | DNS, NBT |
| Hostname | cmdb_ci_linux_server | host_name | DNS, NBT |
| DNS domain | cmdb_ci_linux_server | dns_domain | DNS |
| Start date | cmdb_ci_linux_server | start_date | uptime |
| Manufacturer | cmdb_ci_computer | manufacturer | dmidecode |
| Serial number | cmdb_ci_computer | serial_number | dmidecode |
| CPU type | cmdb_ci_linux_server | cpu_type | /proc/cpuinfo |
| CPU speed (MHz) | cmdb_ci_linux_server | cpu_speed | /proc/cpuinfo |
| CPU count | cmdb_ci_linux_server | cpu_count | /proc/cpuinfo |
| CPU core count | cmdb_ci_computer | cpu_core_count | /proc/cpuinfo |
| CPU core thread | cmdb_ci_computer | cpu_core_thread | /proc/cpuinfo |
| CPU manufacturer | cmdb_ci_linux_server | cpu_manufacturer | /proc/cpuinfo |
| Model number | cmdb_ci_computer | model_number | dmidecode |
| Model ID | cmdb_ci_computer | model_id | dmidecode |
| RAM (MB) | cmdb_ci_linux_server | ram | meminfo |
| Disk space (GB)\* | cmdb_ci_linux_server | disk_space | /proc/ide, /proc/scsi, /var/log/dmesg |
| Type | cmdb_ci_disk | type | /proc/ide, /proc/scsi, /var/log/dmesg |
| Model ID | cmdb_ci_disk | model_id | /proc/ide, /proc/scsi, /var/log/dmesg |
| Disk space (GB) | cmdb_ci_disk | disk_space | /proc/ide, /proc/scsi, /var/log/dmesg |
| Name | cmdb_ci_disk | name | /proc/ide, /proc/scsi, /var/log/dmesg |
| Name | cmdb_ci_file_system | name | df |
| Capacity (MB) | cmdb_ci_file_system | capacity | df |
| Free Space Bytes (MB) | cmdb_ci_file_system | free_space_bytes | df |
| Mount point | cmdb_ci_file_system | mount_point | df |
| Name | cmdb_running_process | name | ps |
| Command | cmdb_running_process | command | ps |
| Type | cmdb_running_process | type | ps |
| PID | cmdb_running_process | pid | ps |
| Parameters | cmdb_running_process | parameters | ps |
| Name | cmdb_ci_network_adapter | name | ifconfig or ip address show |
| IP address\*\* | cmdb_ci_network_adapter | ip_address | ifconfig or ip address show |
| MAC address | cmdb_ci_network_adapter | mac_address | ifconfig or ip address show |
| Netmask | cmdb_ci_network_adapter | netmask | ifconfig or ip address show |
| Default gateway | cmdb_ci_hardware | default_gateway | route |
[ ]

{#r_DataCollDiscoLinuxComputers__table_DiscoveryDataForLinux}\* The value in the disk_space field is an aggregation of the total capacity (to include used space) for all non-removable disks, including both directly attached and SAN storage.

\*\* Starting with Visibility Content version 6.32.0, for network adapters that support both IPv4 and IPv6, the IPv4 address is populated by default. Before this release, the populated value was selected randomly. To control which IP version is populated, see [Set the preferred IP version for network adapter discovery](https://servicenow-prod.fluidtopics.net/krs8qXa6h3b1PLhkYEnKqA "Control which IP version Discovery populates on a Network Adapter CI during Linux, Windows, and Solaris discovery.").  
Note:  
Make sure to define unique serial numbers for the RAMs on the Linux server. Discovery also identifies and classifies information about Linux KVM. Discovery identifies Linux kernel-based virtual machines (KVM) when the process classifier detects libvirtd running on a Linux server. The classification triggers the creation of a cmdb_ci_kvm record and launches the SSH Command probes to explore the Linux server with virsh, lbvert utility, and virtual machine configuration data.

Discovery creates a \[cmdb_ci_kvm_instance\] record for each virtual machine on the server, and then matches the \[cmdb_ci_kvm_instance\] record to a corresponding \[cmdb_ci_computer\] record using the MAC addresses
of installed network adapters.  
{#r_DataCollDiscoLinuxComputers__table_rb4_mlk_tbb__entry__4}

| Table name | Extends | Description | Source |
|-|-|-|-|
| cmdb_ci_kvm | cmdb_ci_vm | A hypervisor that manages kernel-based virtual machines (KVMs) | Process classifier detects libvirtd running on Linux servers |
| cmdb_ci_kvm_vm_instance | cmdb_ci_vm_instance | A virtual machine instance on this hypervisor | virsh list-all and dumpxml command |
| cmdb_ci_kvm_object | cmdb_ci_vm_object | An object connected to a virtual machine instance | \<network\>, \<storage pool\>, and \<storage volume\> elements from the dumpxml command |
| cmdb_kvm_device | Not applicable | A device connected to a virtual machine instance | \<devices\> element from the dumpxml command |
[Table 1. Tables used by Discovery on Linux KVM]

{#r_DataCollDiscoLinuxComputers__table_rb4_mlk_tbb}  
{#r_DataCollDiscoLinuxComputers__table_edq_nlk_tbb__entry__4}

| Label | Table name | Field name | Source |
|-|-|-|-|
| Linux Host | cmdb_ci_kvm | linux_host | Reference to the cmdb_ci_linux_server that is running this virtual machine |
| Details | cmdb_ci_kvm | details_xml | dumpxml |
| Object ID | cmdb_ci_kvm_vm_instance | object_id | virsh dumpxml |
| State | cmdb_ci_kvm_vm_instance | state | virsh list-all |
| CPUs | cmdb_ci_kvm_vm_instance | cpus | virsh dumpxml |
| Memory | cmdb_ci_kvm_vm_instance | memory | virsh dumpxml |
| Disks | cmdb_ci_kvm_vm_instance | disks | virsh dumpxml |
| Disks size | cmdb_ci_kvm_vm_instance | disks_size | virsh domblkinfo |
| Network adapters | cmdb_ci_kvm_vm_instance | nics | virsh dumpxml |
| Name | cmdb_ci_kvm_vm_instance | name | virsh dumpxml |
| Short description | cmdb_ci_kvm_vm_instance | short_description | virsh desc |
| Details | cmdb_ci_kvm_object | details_xml | XML element from dumpxml |
| KVM instance | cmdb_kvm_device | kvm_instance | Reference to cmdb_ci_kvm_instance |
| Device | cmdb_kvm_device | device | disk, controller, interface, and so on |
| Type | cmdb_kvm_device | type | depends on the device |
| Details | cmdb_kvm_device | details_xml | XML element from dumpxml |
[Table 2. Data collected by Discovery on Linux KVM]

{#r_DataCollDiscoLinuxComputers__table_edq_nlk_tbb}  
{#r_DataCollDiscoLinuxComputers__table_qwp_4lk_tbb__entry__3}

| Relationship | Parent table | Child table |
|-|-|-|
| Registered On::Has Registered | KVM \[cmdb_ci_kvm\] | KVM Virtual Machine instance \[cmdb_ci_kvm_vm_instance\] |
| Provided By::Provides | KVM \[cmdb_ci_kvm\] | Network \[cmdb_ci_kvm_network\] |
| Defines resource for::Gets resources from | KVM \[cmdb_ci_kvm\] | Storage Pool \[cmdb_ci_kvm_storage_pool\] |
| Connected By::Connects | KVM Virtual Machine instance \[cmdb_ci_kvm_vm_instance\] | Network \[cmdb_ci_kvm_network\] |
| Instantiated By::Instantiates | KVM Virtual Machine instance \[cmdb_ci_kvm_vm_instance\] | Computer \[cmdb_ci_computer\] |
| Virtualized By::Virtualizes | Computer \[cmdb_ci_computer\] | KVM \[cmdb_ci_kvm\] |
| Provides storage for::Stored on | Storage Pool \[cmdb_ci_kvm_storage_pool\] | KVM Virtual Machine instance \[cmdb_ci_kvm_vm_instance\] |
[Table 3. Data collected by Discovery on KVM Relationship]

{#r_DataCollDiscoLinuxComputers__table_qwp_4lk_tbb}
**Related topics**   

* [Linux discovery fails with "Cannot connect, status is SSH_CONNECTION_FAILURE. Could not agree on signature algorithm Client (KB1425502)](https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB1425502)
* [Linux discovery fails in Unix Classification with the error - Name of unclassified CI is 'servername' (KB0860486)](https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB0860486)
* [Linux discovery error "rbash: PATH: readonly variable Exit status: 1" (KB0866860)](https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB0866860)

