Skip to content
snflows

IT Service & Operations · IT Operations Management (ITOM)

Discovery

View on map ⤴

Implementation path

Required dependenciesCMDB Foundation
● This moduleDiscovery
Required by these capabilitiesService Mapping
Commonly implemented afterwardEvent Management

Capability comparison

Discovery and Event Management

Discovery populates the CMDB with what you have and how it connects. Event Management turns monitoring noise into actionable alerts, using that CMDB context to bind events to the right infrastructure.

Discovery provides

  • Automated discovery of servers, network devices, cloud resources, and applications
  • Population and ongoing refresh of the CMDB with discovered infrastructure and relationships
  • IP-based and credential-based scanning across on-prem, cloud, and hybrid environments
  • Service Mapping integration to connect infrastructure to business services
  • Discovery schedules, probes, sensors, and patterns for comprehensive coverage

Event Management provides

  • Ingestion and normalization of monitoring events from supported connectors, APIs, listeners, and configured sources
  • Event correlation and deduplication that groups related events into actionable alerts
  • CI binding when identification and binding rules find a matching configuration item
  • Alert-to-incident automation that creates and routes incidents from critical alerts
  • Additional grouping, analytics, and AIOps capabilities when the required applications are installed and configured

Consider it when

  • Discovery is already populating the CMDB, but monitoring events are still manually triaged or siloed in individual tools.
  • The operations team needs automated alert correlation, deduplication, and incident creation to reduce noise and response time.
  • Leadership wants configured grouping, analytics, or AIOps capabilities on top of monitoring data.
  • Do not treat Event Management as dependent on Discovery completion - adopt it when monitoring volume, tool sprawl, or alert fatigue demands systematic event handling.
Where the capabilities overlap
  • Both operate in the ITOM space and feed the same operational workflows, but Discovery answers 'what do we have?' while Event Management answers 'what is happening to it right now?'
  • Both can produce CMDB-aware operational data: Discovery uses supported infrastructure, cloud, API, and pattern-based discovery methods, while Event Management processes configured event streams.
Sources

Discovery and Event Management can be adopted independently. The sequence shown is practical implementation guidance, not an installation prerequisite.

What it is (plain English)

Automated scanning that finds the servers, applications, network devices, and cloud resources running in your environment and keeps the CMDB populated and current - without anyone maintaining a spreadsheet. It's how a CMDB stays trustworthy at scale.

Problems it solves

  • A CMDB that goes stale the moment it's built because updates are manual.
  • No reliable picture of what's actually running, especially in the cloud.
  • Change and incident impact analysis undermined by inaccurate CI data.

What must exist first

CMDB Foundation - Discovery fills and maintains the CMDB, so the CMDB structure (and CSDM alignment) should be established first.

What the customer needs to provide

  • Network access and credentials for the systems to be scanned (a major coordination item with security/infra teams).
  • MID Server hosts (the on-prem agents Discovery runs through) and firewall arrangements.
  • Cloud account access for cloud discovery (AWS/Azure/GCP).
  • Scope decisions: which network ranges and CI classes to discover first.

Where it can go next

Service Mapping builds business-service maps on discovered data; Event Management correlates alerts against discovered CIs; accurate CIs sharpen Change Management risk and Incident Management impact analysis.