Setup Overview (SaaS Agent for Cloud Only Customers)

Contents of this Page

  1. Intended Audience

  2. Topology Diagram

  3. Step-by-Step Guide and Required SMEs

  4. Explanation of Solution Components (including links to detailed setup instructions)


Intended Audience

  • This page is for customers adopting the CI Sync SaaS Agent. The SaaS Agent is designed for cloud-to-cloud (i.e. read from a cloud source and sync to a cloud CMDB).

  • While the SaaS Agent can be run in parallel with the CI Sync On-Prem Agent, this page is for customers solely adopting the CI Sync SaaS Agent.

Topology Diagram

The numbered bubbles in the diagram refer to the solution components overview table further down this page (See Overview of Solution Components further below)

CI Sync SaaS Agent (only) to SN - High Level Topology (inc Step Bubbles).png

Step-by-Step Guide and Required SMEs

Phase

Step #

Additional Details

Link

Required SMEs

Estimated Time to Complete

Initial Setup

Step 1

Read the General Overview

Review the Pre-Installation Checklist

Here

Here

Project Manager

CI Sync Admin

ServiceNow Admin

10 minutes

Step 2

Enrol the CI Sync SaaS application into Entra ID

Here

AAD/Entra Admin

5 minutes

Step 3

Configure ServiceNow to be ready for CI Sync

Here

ServiceNow Admin

5 minutes

Step 4

Add your ServiceNow destination connection in the CI SynC UI

Here

CI Sync Admin

5 minutes

Step 5

Create Credentials in Source Systems and Add the Source System to CI Sync

Here

Source System Admins

CI Sync Admin

(Potentially) ServiceNow Admin

10 minutes per source system


Synchronization Testing Phase

Step 6

Run your first synchronization test into your Non-Prod ServiceNow using a small set of asset types (e.g. printers, or servers or switches to start with).

In addition to reading the instructions link, Syncfish highly recommend reading the following page before your first sync.

FAQ - What are the Top Tips when first synchronizing data to my non-PROD CMDB?

Run additional synchronization tests into your Non-Prod ServiceNow and include more asset types in the scope of the sync jobs.

Here

CI Sync Admin

Source System admin/s - One or more of the following:

  • ServiceNow Admin

  • ServiceNow platform owner

  • CMDB Manager

  • IT Asset manager

60 - 90 minutes


CMDB Automation Maturity Phase


Start synchronizing into your Production ServiceNow with a small set of asset types.

Progressively sync additional asset types based on your organisational change management approach.

This phase is best thought of as a maturity journey where your newly automated CMDB underpins improvements to key business processes.

N/A

Project Manager

CI Sync Admin

ServiceNow Admin

ServiceNow platform owner

CMDB Manager

IT Asset manager

This timeframe depends on each customer’s own CMDB Automation adoption plan

Overview of Solution Components

Each of the high level steps reference the CI Sync Detailed Setup Instructions. After reading the High Level Steps below we recommend visiting the Detailed Setup Instructions (for cloud agent only customers) Overview page here General Overview and Pre-Read Information page here S1 - Pre-Setup Information.

#

Component

High Level Supporting Notes

1

Enterprise Application object in Entra ID

  1. The CI Sync SaaS setup process requires you to create an Enterprise Application object in your Entra ID.

    1. This object controls authentication of your users to the CI Sync Web UI (of your customer specific CI Sync instance).

  2. You will need to grant one/two users (those people who need to schedule sync jobs) to the Enterprise Application.

  3. Full details of the above are described in S2 - Enroll your CI Sync SaaS Instance to Entra ID of the Detailed Setup Instructions.

2

Cloud Source Systems
(data sources for the CI Sync SaaS Agent)

Each source system has it’s own unique requirements for authentication and API/data access.

Your SME/Admin of each source system needs to create a credential for the CI Sync SaaS Agent and perform any other configuration in the source system itself.

Syncfish provide setup instructions for each source system within S5 - Add One/More Source Systems to CI Sync. For example:

    1. For AWS: Add AWS to SaaS Agent

    2. For Azure: Add Azure to SaaS Agent

    3. For GCP: Add GCP to SaaS Agent

    4. For Lansweeper Cloud:Add Lansweeper Cloud to SaaS Agent

    5. For Cisco Meraki as a data source: Add Cisco Meraki to SaaS Agent

    6. For InTune as a data source: Add InTune to SaaS Agent

    7. For Jamf as a data source: Add Jamf to SaaS Agent

    8. For SentinelOne as a data source: Add SentinelOne to SaaS Agent

    9. For Microsoft 365 as a data source: Add Microsoft 365 to SaaS Agent

    10. and so on.

3

DEV/TEST ServiceNow

  1. You will need to create a user account (web service account only) for your customer specific CI Sync instance to use for authentication.  The user/web service account can use Basic Auth or OAuth.

  2. Syncfish provide a list of OOTB roles to be assigned to the account.  These are least privileged roles that allow read/write to CMDB tables and several other reference tables.

  3. For performance reasons Syncfish recommend two settings are made in ServiceNow (an API timeout value is increased, and a dictionary value is set on the CMDB). 

  4. Full details of the above are described in S3 - Configure ServiceNow for CI Sync of the Detailed Setup Instructions.

4

CI Sync Web UI
(to add ServiceNow as a destination, and add cloud data sources for the CI Sync SaaS Agent)

  1. Firstly, you will add a Destination Connection (i.e. to your ServiceNow) in your CI Sync SaaS instance using the CI Sync Web UI. 

    1. See S4 - Add ServiceNow as a Destination for CI Sync of the Detailed Setup Instructions.

  2. Next, you will add each cloud source (e.g. AWS, Azure, etc) as a source connection using the CI Sync Web UI. VisitS5 - Add One/More Source Systems to CI Sync. That page contains an index of each supported source system. For example:For AWS: Add AWS to SaaS Agent

    1. For Azure: Add Azure to SaaS Agent

    2. For GCP: Add GCP to SaaS Agent

    3. For Lansweeper Cloud:Add Lansweeper Cloud to SaaS Agent

    4. For Cisco Meraki as a data source: Add Cisco Meraki to SaaS Agent

    5. For InTune as a data source: Add InTune to SaaS Agent

    6. For Jamf as a data source: Add Jamf to SaaS Agent

    7. For SentinelOne as a data source: Add SentinelOne to SaaS Agent

    8. For Microsoft 365 as a data source: Add Microsoft 365 to SaaS Agent

    9. and so on.

5

CI Sync SaaS

You then do the following using your Non-Production ServiceNow Instance (e.g. ServiceNow DEV or TEST)

  1. See Run a Small Initial Sync Job (then run more) of the Detailed Setup Instructions.

  2. You will assess the resulting data in your non-Production ServiceNow instance.

  3. Once you are satisfied your non-production results/data is satisfactory you will progress to Production (see #6 below).

6

PROD ServiceNow

The transition to synchronization into your Production ServiceNow instance is very simple:

  1. You repeat the activities mentioned in item #3 above.

    1. Add a User Account (with the relevant roles).

    2. Check the REST API timeout setting and check the CMDB dictionary setting.

  2. You repeat the activities mentioned in item #4 above.

    1. Add a Destination Connection (i.e. to your Production ServiceNow) in your CI Sync SaaS instance using the CI Sync Web UI. 

    2. Run your first Sync job (a small one to start with), review the results/data and then run additional sync jobs.

Important Information about Non-Production vs Production Synchronization

Before sync’ing to production we recommend you inform the Syncfish Team. This ensures Syncfish are aware in case you need extra assistance and also means Syncfish can advise how to check whether any specific CI Sync configuration settings need to be promoted from your CI Sync Test Config to your CI Sync Prod Config.