Skip to content
Release: Australia · Updated: 2026-05-27 · Official documentation · View source

Configure observability agents for Now Assist

Configure observability agents for third-party application performance monitoring (APM) or network performance monitoring (NPM) vendors. These agents are invoked by the analyze alert impact agentic workflow. You must configure connections to those vendors before they can be invoked.

Important: This AI agent is turned on by default. For more information, see Now Assist skills, agents, and agentic workflows on by default.

After you configure the agent(s), they can surface information from alerts generated by third-party systems to help you investigate alerts and incidents in the Service Operations Workspace.

Connections to vendors use MCP when possible, otherwise they use an API connection. You need connection and credential information to complete the connection process as shown in the following tables.

Note: These agents are different from the data sources used in the Service Observability dashboards.

Before you begin

Before configuring the integration agents, you must do the following:

Role required: connection_admin and credential_admin

AWS CloudWatch MCP

Connection informationValue
Agent nameAWS CloudWatch MCP Server Agent
Overview of data returnedAlarm details, metric trend analysis, CloudWatch logs \(anomalies, error patterns, log insights queries\), CMDB resource context, correlated service metrics, and root cause analysis with recommended next steps
Credential & Connection Alias nameAWS CloudWatch MCP server
Connection typeMCP
Returned data typeAPM
Connection URL

https://your-mcp-server-host/mcp

This assumes you have deployed the CloudWatch MCP server using a MID Server instead of a publicly exposed EC2 instance. For more information about deploying the MCP server, see the AWS CloudWatch MCP Server — MID Server Deployment Guide [KB3030674] article in the Now Support Knowledge Base.

Required credentials- AWS access key ID - AWS secret access key
Required scopeAWS IAM permissions: - `cloudwatch:Describe*` - `cloudwatch:Get*` - `cloudwatch:List*` - `logs:Describe*` - `logs:Get*` - `logs:StartQuery` - `logs:StopQuery` - `logs:GetQueryResults`

AWS CloudWatch API

Connection informationValue
Agent nameAWS CloudWatch API Agent
Overview of data returnedAlarm details, metric trend analysis, CloudWatch logs \(anomalies, error patterns, log insights queries\), CMDB resource context, correlated service metrics, and root cause analysis with recommended next steps
Credential & Connection Alias nameAWS CloudWatch API Credentials
Connection typeAPI \(MCP fallback mechanism\)
Returned data typeAPM
Connection URLN/A
Credential typeAWS Credentials
Authentication algorithmAWS CloudWatch Algorithm
Required credentials- AWS access key ID - AWS secret access key
Required scopeAWS IAM permissions: - `cloudwatch:Describe*` - `cloudwatch:Get*` - `cloudwatch:List*` - `logs:Describe*` - `logs:Get*` - `logs:StartQuery` - `logs:StopQuery` - `logs:GetQueryResults`

Datadog

Connection informationValue
Agent nameDatadog APM MCP Server Agent
Overview of data returnedService health, distributed traces, triggered monitors, log analysis, incidents, SLO compliance, deployment events, and service dependencies
Credential & Connection Alias nameDatadog APM MCP Connection
Connection typeMCP
Returned data typeAPM
Connection URL`https://mcp.datadoghq.com/api/unstable/mcp-server/mcp?toolsets=core,alerting,apm,error-tracking`
Required credentials- Datadog API key - Datadog application key
Required scopeN/A

Dynatrace

Kentik

Connection informationValue
Agent nameDynatrace MCP Server Agent
Overview of data returnedInsights about logs, topology, recent changes, root causes, impacted entities, and environments.
Credential & Connection Alias nameDynatrace MCP server
Connection typeMCP
Returned data typeAPM
Connection URLURL of your Dynatrace instance. Dynatrace URLs follow this format: `https://.apps.dynatrace.com/platform-reserved/mcp-gateway/v0.1/servers/dynatrace-mcp/mcp`
Required credentialsPlatform token \(must be prefixed with `Bearer`\). For example, `Bearer dt0s01.STABCDEF12345.G3HIJKLMNOP`.
Required scopeIAM policy and group assignment that allows the following scopes: - `davis-copilot:nl2dql:execute` - `davis-copilot:dql2nl:execute` - `davis-copilot:conversations:execute` - `davis:analyzers:read` - `davis:analyzers:execute` - `mcp-gateway:servers:invoke` - `mcp-gateway:servers:read` - `storage:buckets:read` - `storage:logs:read` - `storage:events:read` - `storage:security.events:read` - `storage:metrics:read` - `storage:bizevents:read` - `storage:spans:read` - `storage:entities:read` - `storage:smartscape:read` - `storage:system:read`
Required Dynatrace Intelligence settings- Enable generative AI - Enable document suggestions - Enable environment-aware queries

New Relic

Connection informationValue
Agent nameKentik analysis AI agent
Overview of data returnedService network performance, connectivity, DDOS attacks, and anomalies
Credential & Connection Alias nameKentik analysis AI agent
Connection typeAPI
Returned data typeAPM
Connection URLURL of your Kentik instance. Kentik URLs follow this format: `https://.api.kentik.com`
Required credentials- User email - API token
Required scopeCan view devices
Connection informationValue
Agent nameNew Relic MCP Server Agent
Overview of data returnedService and user impact, root cause theories, and responsible teams.
Credential & Connection Alias nameNew Relic MCP Connection
Connection typeMCP
Returned data typeAPM
Connection URL`https://mcp.newrelic.com/mcp/`
Required credentialsAPI key \(also known as "User Key"\) Header name: `api-key`
Required scopeN/A

Prometheus

SolarWinds

Connection informationValue
Agent namePrometheus API Agent
Overview of data returnedPromQL metric queries \(CPU, memory, disk, network\), active alerts, alert rule definitions, and scrape target health
Credential & Connection Alias namePrometheus connection
Connection typeAPI
Returned data typeAPM
Connection URL`https://`
Required credentials- MID Server Prometheus is installed on - User name \(for outbound connection\) - Password \(for outbound connection\)
Required scopeN/A

Splunk

Connection informationValue
Agent nameSolarWinds analysis AI agent
Overview of data returnedOn-premises data from SolarWinds Orion: node health/status, CPU/memory, packet loss/latency, interface utilization/errors/discards, active alerts/history, affected entities/services, and trend/baseline metrics used for root-cause investigation
Credential & Connection Alias nameSolarWinds AI Agent
Connection typeAPI
Returned data typeNPM
Connection URL`https://`
Required credentials- MID Server SolarWinds is installed on - User name - Password
Required scopeSolarWinds Orion API/SWQL read access \(NPM/APM\) via MID Server

ThousandEyes

Connection informationValue
Agent nameSplunk MCP Server Agent
Overview of data returnedSPL query results from Splunk indexes, index/sourcetype metadata, and structured investigation findings including affected entities, root cause analysis, and recommended actions
Credential & Connection Alias nameSplunk MCP Connection
Connection typeMCP
Returned data typeAPM
Connection URL`https://.splunkcloud.com`
Required credentialsSplunk MCP token
Required scopeFor Splunk token generation: - `mcp_user` role \(or any role with `mcp_tool_execute`\) required for all MCP tool calls - Search capability and read access to the relevant indexes for running queries - Knowledge object read permissions for Get Knowledge Objects - Token must be generated using the Splunk MCP Server app with `audience = mcp` \(not a standard Splunk API token\)
Connection informationValue
Agent nameThousandEyes MCP Server Agent
Overview of data returnedTest configuration and status, aggregated metrics (response time, packet loss, latency, jitter, throughput, availability), metric anomalies with deviation analysis, network events and routing changes, ISP/network outages with provider and ASN details, hop-by-hop path visualization, and root cause analysis with ranked probable causes and recommended next steps
Credential & Connection Alias nameThousandEyes MCP Connection
Connection typeMCP
Returned data typeNPM
Connection URLhttps://api.thousandeyes.com/mcp
Required credentialsAPI key prefixed with Bearer. For example, Bearer <api-key>.
Required scopeThousandEyes API access with permissions to read tests, metrics, anomalies, events, outages, and path visualization data

Procedure

  1. Navigate to All > sys_alias.LIST.
  2. Search for and select the vendor's connection name as shown in the preceding tables.
  3. Select Create New Connection & Credential.
  4. Fill in the form, using the information in the preceding tables.
  5. Select Create.

    Your connection appears in the Connections tab.

The agents are now ready to be used by the analyze alert impact agentic workflow

Parent Topic:Configure Now Assist for ITOM

sndocs is an independent community mirror and is not affiliated with or endorsed by ServiceNow.

ServiceNow, the ServiceNow logo, Now, and other ServiceNow marks are trademarks and/or registered trademarks of ServiceNow, Inc., in the United States and/or other countries. Other company and product names may be trademarks of the respective companies with which they are associated.

© 2026 ServiceNow, Inc. All rights reserved.

Documentation content is redistributed under the Apache License 2.0 from the ServiceNowDocs repository.