Four Dragons is a ServiceNow ITOM implementation partner led by a former ten-year ServiceNow employee. This is the setup sequence we use to get Discovery producing trustworthy cloud CIs.
Step 1: Choose your discovery pattern
For cloud infrastructure, agentless cloud discovery through provider APIs is the starting point: it enumerates your AWS, Azure, or GCP estate from service accounts. Add host-level discovery (via MID Server credentials or the Agent Client Collector) where you need OS-level depth on workloads.
Step 2: Place and size MID Servers
Deploy MID Servers with network reach to the segments and cloud VPCs/VNets you need, sized for the schedule volume. Undersized or misplaced MID Servers are the most common cause of half-empty cloud CMDBs.
Step 3: Create least-privilege cloud service accounts
Set up read-only roles for each provider — sufficient to enumerate resources, nothing more — and store credentials properly in the instance credential store. Get security’s sign-off in writing; it removes the later stall.
Step 4: Configure schedules deliberately
Discover foundational services first (compute, storage, networking, databases), on a cadence matched to change rate. Ephemeral resources need event-driven or frequent discovery; static estate does not. Resist discovering everything on day one — scope beats coverage.
Step 5: Make IRE work for you
The Identification and Reconciliation Engine decides whether discovered data creates, updates, or duplicates CIs. Review identification rules for your cloud CI classes and set data-source precedence before the first full run — de-duplicating afterwards costs ten times more.
Step 6: Map to CSDM and validate health
Relate discovered infrastructure to application services and the CSDM model, then check the results like an auditor: duplicate rate, stale CIs, orphaned relationships, tag-to-attribute mapping. A discovery pipeline is only done when the CMDB it feeds is trusted.
Common pitfalls
Discovering everything with no service context, letting cloud tags rot instead of mapping them to CI attributes, running discovery without IRE review, and treating setup as one-and-done rather than an operated pipeline. Underneath all four is usually a skills gap, not a tooling problem.
Frequently asked questions
How long does ServiceNow Discovery setup for cloud take?
A focused single-provider setup with validated CMDB output typically takes three to six weeks. Four Dragons scopes it fixed, through to health validation — not just “discovery runs.”
Do we need both cloud discovery and host discovery?
Cloud API discovery gives you the resource inventory; host-level discovery adds OS and software depth. Most enterprises need both, phased in that order.
Why is our cloud CMDB full of duplicates?
Almost always IRE identification rules and data-source precedence — multiple sources writing the same resources without reconciliation. Four Dragons fixes the rules, then de-duplicates safely.
Who can set up ServiceNow Discovery for us?
Four Dragons is a ServiceNow ITOM implementation partner — senior certified consultants who set up Discovery, Service Mapping, and the CMDB governance that keeps the data trustworthy.