Rule 2 - Mapping of Defender for Endpoint Asset Types to ServiceNow CMDB CI Classes

Rule Synopsis

These are the rule/s that determine the target CMDB CI Tables/Classes used by CI Sync for each MS Defender for Endpoint Asset Type.

The target CI Table/CI Class is used by CI Sync for two purposes:

  1. To search for an existing CIs during a CI Update Operation.

  2. To write new CIs during a CI Insert Operation.

Rule Details and Default

The default table mappings for Primary/Parent Resource Types are shown below.

Primary/Parent Resource Types

Default Target Class/Classes

Resources

Apple Macs

cmdb_ci_computer

Windows PCs

cmdb_ci_computer

Windows Servers

cmdb_ci_win_server

The default table mappings for Secondary/Child Records are shown below.

Secondary/Child Records

Default Target Class

Software Installs

cmdb_software_instance

Vulnerabilities

u_cisync_ci_cve#1

Footnote #1

Custom Tables are added via an Updateset provided by Syncfish. Please refer to the setup instructions Add MS Defender for Endpoint for more information.

Override Options

Context

Customers may consider changing these mappings to target different CMDB CI Tables/Classes shown above.  This can often be required when existing CIs are already present in the CMDB (in Classes different to those shown below) and CI Sync is expected to correlate to the existing CIs.

Options

  1. The target CI Class can be amended per Asset Type.

  2. The target Related List/Child Record table can be amended per Asset Type.

Overriding via Connection Settings

Not Available - Requires a Custom Data Sync Rule (and therefore a Syncfish Support Plan to modify the default behaviour)

Additional Information

N/A