Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Windows discovery

Discovery identifies and classifies information about Windows computers that use IPv4 addresses, IPv6 addresses, or both.

Note: For information on Probe to Pattern migration see the knowledge article KB0694477.

Note: admin$ share access is required for Windows discovery from Madrid P3 and later. A Remote Access role must be configured in the target Windows Server to enable connectivity with ServiceNow Discovery.

Supported Windows versions

For IPv4 discovery:

  • Windows Workstation 7, 8, 10
  • Windows Server versions:
    • 2008
    • 2008R2
    • 2012R2
    • 2016
    • 2019
    • 2022
    • 2025

For IPv6 discovery:

  • Windows 2019 (10.0.17763)
  • Windows Server 2016
  • Windows Desktop 10
  • Windows 2019 Datacenter

Note: For fiber channel discovery on a Windows 2008 host, the Microsoft Fibre Channel Information Tool (fcinfo.exe) must be installed on that machine. The fcinfo executable should be available on the environment path. The Microsoft Fibre Channel Information Tool tool is available for download at http://www.microsoft.com.

IPv6 supportability limitations

The following device types haven’t been verified for IPv6 discovery:

  • Printers
  • Network Storage (NFS, CIFS, NAS, FC, ISCSI)
  • Azure virtual machines (IPv6 native mode isn’t supported by Microsoft)

Requirements

  • Verify PowerShell support

    ServiceNow now supports PowerShell 3.0 up to 5.1.

  • Configure Windows credentials

    For more information, see Windows credentials.

  • Verify user access

    Verify that the user configured for the credential has the following permissions:

    • Local admin access to the Windows machine.
    • Access to the WMI service to the current namespace and subnamespaces.
    • Access to the PowerShell service.
    • Membership in the Distributed COM Users local security group.
    • (Optional) Populate Virtual Machine Object field in Hardware [cmdb_ci_hardware] table

    Starting with Discovery and Service Mapping Patterns version 1.30.2, you can improve query performance by populating the Virtual Machine Object field in the Hardware [cmdb_ci_hardware] table. For more information, see Improved query performance with direct field population in CI tables.

  • Set the preferred IP address version for network adapter discovery

    Starting with Visibility Content version 6.32.0, if your network adapters support both IPv4 and IPv6, the IPv4 address is populated by default in the IP address [ip_address] field on the Network Adapter [cmdb_ci_network_adapter] table. To control which IP version is populated, see Set the preferred IP version for network adapter discovery.

Classifiers, probes, and patterns

ClassifiersProbesPatterns
- Windows - Windows 2008 Server - Windows 2012 Server - Windows 2016 Server - Windows 2025 Server- Horizontal discovery probe: Launches patterns - WMIRunner-Windows - Installed Software^ - MultiProbe-Windows - ADM^ - Windows - Identity\* - Windows - Network ARP Table\* - Windows - Network NDP Table\* - Windows - OS Information\* - Windows - Cluster\* - Windows - CPU/Memory\* - Windows - Installed Software\* - Windows - Printers\* - Windows - Storage 2008\* - Windows - Storage 2012\* - Windows - Amazon EC2\* - Windows - Azure\* - DNS\* - SNMP - Routing\*- Windows OS - Server - Windows OS - Desktops
Windows 2019 ServerN/AWindows OS - Server

*These probes aren't active on the classifier, as Discovery uses patterns by default for these discoveries.

^These probes remain active by default, even when Discovery uses pattern discovery.

To use patterns, verify that the correct pattern is specified in the horizontal pattern probe on the classifier. See Add the Horizontal Pattern probe to a classifier for instructions.

Data collected

Note: See the knowledge article KB0687582 for information on model_id and manufacturer.

LabelTable nameField nameSource
Assigned tocmdb_ci_win_serverassigned_towmi
Chassis typecmdb_ci_win_serverchassis_typewmi
Commandcmdb_running_processcommandwmi
Connects tocmdb_running_processconnects_towmi
CPU core count*cmdb_ci_computercpu_core_countwmi
CPU core thread*cmdb_ci_computercpu_core_threadwmi
CPU count*cmdb_ci_computercpu_countwmi
CPU manufacturercmdb_ci_computercpu_manufacturerwmi
CPU namecmdb_ci_computercpu_namewmi
CPU speed (MHz)cmdb_ci_computercpu_speedwmi
Default gatewaycmdb_ci_win_serverdefault_gatewaywmi
Descriptioncmdb_ci_diskshort_descriptionwmi
Disk space (GB)cmdb_ci_computerdisk_spacewmi
Disk space (GB)cmdb_ci_diskdisk_spacewmi
DHCP enabledcmdb_ci_network_adapterdhcp_enabledwmi
DNS domaincmdb_ci_win_serverdns_domainDNS
Free space (GB)cmdb_ci_file_systemfree_spacewmi
Hostnamecmdb_ci_win_serverhost_nameDNS, NBT
IP address***cmdb_ci_network_adapterip_addresswmi
Listening oncmdb_running_processlistening_onwmi
MAC addresscmdb_ci_network_adaptermac_addresswmi
Manufacturercmdb_ci_win_servermanufacturerwmi
Model IDcmdb_cimodel_idwmi
Namecmdb_ci_win_servernameDNS, NBT
Namecmdb_ci_disknamewmi
Namecmdb_running_processnamewmi
Namecmdb_ci_network_adapternamewmi
Netmaskcmdb_ci_network_adapternetmaskwmi
Operating Systemcmdb_ci_computeroswmi
OS domaincmdb_ci_computeros_domainNBT
OS service packcmdb_ci_computeros_service_packwmi
OS versioncmdb_ci_computeros_versionwmi
Parameterscmdb_running_processparameterswmi
PIDcmdb_running_processpidwmi
RAM (MB)cmdb_ci_computerramwmi
Serial numbercmdb_ci_win_serverserial_numberwmi
Short descriptioncmdb_ci_win_servershort_descriptionwmi
Typecmdb_ci_disktypewmi

* Core counts and threads per core might not be accurate, due to issues with Microsoft reporting.

** The value in the disk_space field is an aggregation of the total capacity (to include used space) for all non-removable disks, including both directly attached and SAN storage.

*** Starting with Visibility Content version 6.32.0, for network adapters that support both IPv4 and IPv6, the IPv4 address is populated by default. Before this release, the populated value was selected randomly. To control which IP version is populated, see Set the preferred IP version for network adapter discovery.

The Windows registry

Discovery can find software that has been installed on a Windows machine by looking at the Windows Registry. Discovery can find the following attributes of discovered software:

  • Product Name: Combination of name and version, such as Windows Imaging Component 3.0.
  • Name: Name of the product only without the version.
  • Version: Version of the product.
  • Uninstall String: Path to the uninstaller, such as C:\Program Files\Notepad++\uninstall.exe.
  • Part of: Update for which this registry is a part, such as Windows Internet Explorer 8 - Software U.
  • Install Date: The date the software was installed. The Windows - Installed Software sensor appends a timestamp of 00:00:00 to the install_date retrieved from the registry. The installation time of all Windows software is independent of the time zone and is set to midnight of the day it was installed. For example, an install date of 2.19.2017 in the Windows registry appears as 2.19.2017 00:00:00 in the CMDB.
  • Installed on: The name of the asset on which the software is installed.

  • Windows server cluster discovery
    Discovery establishes the relationships between a Windows server cluster and its nodes.

Parent Topic:Operating systems discovery

Related topics

Windows probes and permissions