The Service Graph Connector for AWS enables customers to seamlessly and securely bring their AWS data into ServiceNow CMDB. The integration uses AWS native technologies and AWS security best practices to enable teams to connect the cloud data within their ServiceNow workflows. The Service Graph Connector for AWS relies on cloud formation templates, S3 buckets, AWS Config, and AWS SSM, enabling customers to set up the connector once and then scale as they bring in more accounts, services, and more data types – securely, easily, and with complete control, with minimal access and credential requirements. Service Graph Connectors help you get your AWS data into ServiceNow CMDB to drive business outcomes faster.
Key use cases:
- Visibility into cloud resources, relationships, and state in near real-time
- Deep discovery of applications for ITAM/SAM outcomes
- Governance and compliance outcomes
- Simplified onboarding experience
- Minimal credentials requirement
- Coverage for multiple AWS accounts across the organization
- Automatic incorporation of new account or region addition
- No MID Server required (can be optionally used if needed)
- Near real-time discovery of changes
Changed:
- The SG-AWS-RunPowerShellScript data source now uses Get-CimInstance commands instead of WMIC for Windows Server 2025 discovery.
- Resource type-based parallelism is used instead of account-based for parallel loading, improving performance for large-scale environments.
Fixed:
- The CreateServiceNowUser.yml file loads in AWS cloud discovery without script errors.
- The SG-AWS-Organization pattern correctly retrieves Organization Account details.
- The AWS-Tags data source handles large datasets.
- EC2 to Storage Volume relationships are populated correctly in the CMDB.
- The performance of generic resource import is improved for large data loads.
- SSM-GetS3Object data collection enables consistent Running Processes refresh on servers.
- The SG-AWS-EKS-FULL scheduled import job loads all EKS data without transformation errors.
- Server name is updated when EC2 privateDnsName value changes.
- The SG-AWS-EKS-FULL job loads EKS data without the "String object would exceed maximum permitted size" error.
- Service Account is retired correctly during record removal.
- SgGetInventoryDataSourceUtils definition is now available.
- The Image-Id datasource no longer has cross-account access by assuming roles.
- Service Account credential mapping is removed.
- The performance of the SendCommand datasource is improved.
Dependencies
- Integration Commons for CMDB
- CMDB CI Class Models
- Discovery and Service Mapping Patterns
- IntegrationHub Datastream action
- Discovery Core