Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Data mapping for Service Graph Connector for AWS

Data from the AWS data sources is mapped and transformed into the ServiceNow CMDB Configuration Item (CI) class definitions using the Robust Transform Engine (RTE). Data is inserted into the ServiceNow® CMDB using the Identification and Reconciliation Engine (IRE).

Data mapping for AWS

Data from the AWS data sources is mapped and transformed into the ServiceNow CMDB Configuration Item (CI) class definitions using the Robust Transform Engine (RTE). Data is inserted into the ServiceNow CMDB using the Identification and Reconciliation Engine (IRE).

Note: If the Use last run datetime field for an AWS data source in the Data Source [sys_data_source] table is empty, the connector imports all available initial data. If the Use last run datetime field includes a date stamp, the connector imports incremental data that has been newly added since the previous run.

The following table lists the import schedule order, the data sources and import schedules of the same name, the staging tables, the target tables as CMDB CI classes, the import schedule requirement type, and the import schedule dependencies for AWS.

OrderName\(data source or import schedule\)Staging tableCMDB CI classesImport schedule requirement typeImport schedule dependencies
1SG-AWS-OrganizationSG-AWS-Organization \[sn\_aws\_integ\_sg\_aws\_organization\]Cloud OrganizationsRequiredNone
2SG-AWS-Org-UnitsSG-AWS-Org-Units \[sn\_aws\_integ\_sg\_aws\_org\_units\]AWS Organizational UnitOptionalSG-AWS-Organization
3SG-AWS-Service-AccountSG-AWS-Service-Account \[sn\_aws\_integ\_sg\_aws\_service\_account\]Cloud Service Account Cloud Organizations Key ValueRequiredSG-AWS-Organization
4SG-AWS-Service-Account-TagsSG-AWS-Service-Account-Tags \[sn\_aws\_integ\_sg\_aws\_service\_account\_tags\]Cloud Service Account Key ValueOptionalSG-AWS-Organization SG-AWS-Service-Account
5SG-AWS-Org-Unit-AccountsSG-AWS-Org-Unit-Accounts \[sn\_aws\_integ\_sg\_aws\_org\_unit\_accounts\]Cloud Service AccountOptionalSG-AWS-Organization SG-AWS-Service-Account
6SG-AWS-DatacentersSG-AWS-Datacenters \[sn\_aws\_integ\_sg\_aws\_datacenters\]Cloud Service Account AWS DatacenterRequiredSG-AWS-Organization SG-AWS-Service-Account
7SG-AWS-VPCSG-AWS-VPC \[sn\_aws\_integ\_sg\_aws\_vpc\]Cloud Service Account Cloud Network AWS Datacenter Key Value SG-AWS Extension AttributesRequiredSG-AWS-Organization SG-AWS-Service-Account SG-AWS-Datacenters
8SG-AWS-SubnetsSG-AWS-Subnets \[sn\_aws\_integ\_sg\_aws\_subnets\]Availability Zone Cloud Network Cloud Subnet AWS Datacenter Key Value SG-AWS Extension AttributesRequiredSG-AWS-Organization SG-AWS-Service-Account SG-AWS-Datacenters SG-AWS-VPC
9SG-AWS-Network-InterfaceSG-AWS-Network-Interface \[sn\_aws\_integ\_sg\_aws\_network\_interface\]Cloud Network Cloud Subnet Cloud Mgmt Network Interface AWS Datacenter Key Value SG-AWS Extension AttributesRequired for a virtual machine \(VM\) instanceSG-AWS-Organization SG-AWS-Service-Account SG-AWS-Datacenters SG-AWS-VPC
10SG-AWS-Security-GroupSG-AWS-Security-Group \[sn\_aws\_integ\_sg\_aws\_security\_group\]Cloud Network Compute Security Group AWS Datacenter Key Value SG-AWS Extension AttributesRequired for a VM instanceSG-AWS-Organization SG-AWS-Service-Account SG-AWS-Datacenters SG-AWS-VPC
11SG-AWS-Storage-VolumeSG-AWS-Storage-Volume \[sn\_aws\_integ\_sg\_aws\_storage\_volume\]Storage VolumeStorage Volume Snapshot AWS Datacenter Key Value SG-AWS Extension AttributesRequired for a VM instanceSG-AWS-Organization SG-AWS-Service-Account SG-AWS-Datacenters SG-AWS-VPC
12SG-AWS-Image-PrivateSG-AWS-Image \[sn\_aws\_integ\_sg\_aws\_image\]ImageRequired for a VM instanceSG-AWS-Organization SG-AWS-Service-Account SG-AWS-Datacenters SG-AWS-VPC
13SG-AWS-Image-IdSG-AWS-Image-Id \[sn\_aws\_integ\_sg\_aws\_image\_id\]ImageRequired for a VM instanceSG-AWS-Organization SG-AWS-Service-Account SG-AWS-Datacenters SG-AWS-VPC
14SG-AWS-Hardware-TypeSG-AWS-Hardware-Type \[sn\_aws\_integ\_sg\_aws\_hardware\_type\]Hardware Type AWS DatacenterRequired for a VM instanceSG-AWS-Organization SG-AWS-Service-Account SG-AWS-Datacenters SG-AWS-VPC
15SG-AWS-EC2SG-AWS-EC2 \[sn\_aws\_integ\_sg\_aws\_ec2\]Virtual Machine Instance The following CIs are populated when populating the Virtual Machine Instance CI:Server VNIC Endpoint Storage Mapping Block Endpoint IP Address Network Adapter Key ValueOptionalSG-AWS-Organization SG-AWS-Service-Account SG-AWS-Datacenters SG-AWS-VPC SG-AWS-Subnets SG-AWS-Network-Interface SG-AWS-Hardware-Type SG-AWS-Security-Group SG-AWS-Storage-Volume SG-AWS-Image-Private SG-AWS-Image-Id
16SG-AWS-ELB-V1SG-AWS-ELB-V1 \[sn\_aws\_integ\_sg\_aws\_elb\_v1\]Cloud Load Balancer Compute Security Group Availability Zone AWS Datacenter Key Value SG-AWS Extension AttributesOptionalSG-AWS-Organization SG-AWS-Service-Account SG-AWS-Datacenters
17SG-AWS-ELB-V2SG-AWS-ELB-V2 \[sn\_aws\_integ\_sg\_aws\_elb\_v2\]Cloud Load Balancer Compute Security Group Availability Zone AWS Datacenter Key Value SG-AWS Extension AttributesOptionalSG-AWS-Organization SG-AWS-Service-Account SG-AWS-Datacenters
18SG-AWS-RDSSG-AWS-RDS \[sn\_aws\_integ\_sg\_aws\_rds\]Cloud DataBase AWS Datacenter Key Value SG-AWS Extension AttributesOptionalSG-AWS-Organization SG-AWS-Service-Account SG-AWS-Datacenters
19SG-AWS-API-GatewaySG-AWS-API-Gateway \[sn\_aws\_integ\_sg\_aws\_api\_gateway\]

Cloud Gateway [cmdb_ci_cloud_gateway]

AWS Datacenter

Key Value

SG-AWS Extension Attributes

OptionalSG-AWS-Organization SG-AWS-Service-Account SG-AWS-Datacenters
20SG-AWS-LambdaSG-AWS-Lambda \[sn\_aws\_integ\_sg\_aws\_lambda\]Cloud FunctionOptionalSG-AWS-Organization SG-AWS-Service-Account SG-AWS-Datacenters
21SG-AWS-S3SG-AWS-S3 \[sn\_aws\_integ\_sg\_aws\_s3\]Cloud Object StorageOptionalSG-AWS-Organization SG-AWS-Service-Account SG-AWS-Datacenters
22SG-AWS-DynamoDbSG-AWS-DynamoDb \[sn\_aws\_integ\_sg\_aws\_dynamodb\]DynamoDB Table AWS Datacenter Key Value SG-AWS Extension AttributesOptionalSG-AWS-Organization SG-AWS-Service-Account SG-AWS-Datacenters
23SG-AWS-Software-InventorySG-AWS-Software-Inventory \[sn\_aws\_integ\_sg\_aws\_software\_inventory\]SG-AWS-Software-Staging \[sn\_aws\_integ\_sg\_aws\_temp\_software\_staging\]When the Software Asset Management \(SAM\) application isn't installed: Software Packages Software Instance Server When the SAM application is installed: Software Installation ServerOptionalSG-AWS-Organization SG-AWS-Service-Account SG-AWS-Datacenters SG-AWS-VPC SG-AWS-Subnets SG-AWS-Network-Interface SG-AWS-Hardware-Type SG-AWS-Security-Group SG-AWS-Storage-Volume SG-AWS-Image-Private SG-AWS-Image-Id SG-AWS-EC2
24SG-AWS-Software-RemoveSG-AWS-Software-Remove \[sn\_aws\_integ\_sg\_aws\_software\_remove\]NoneOptionalSG-AWS-Organization SG-AWS-Service-Account SG-AWS-Datacenters SG-AWS-VPC SG-AWS-Subnets SG-AWS-Network-Interface SG-AWS-Hardware-Type SG-AWS-Security-Group SG-AWS-Storage-Volume SG-AWS-Image-Private SG-AWS-Image-Id SG-AWS-EC2 SG-AWS-Software-Inventory
25SG-AWS-SSM-SendCommandSG-AWS-SSM-SendCommand \[sn\_aws\_integ\_sg\_aws\_ssm\_sendcommand\]Application Running Process \[cmdb\_running\_process\] TCP Connections \[cmdb\_tcp\]OptionalSG-AWS-Organization SG-AWS-Service-Account SG-AWS-Datacenters SG-AWS-VPC SG-AWS-Subnets SG-AWS-Network-Interface SG-AWS-Security-Group SG-AWS-Storage-Volume SG-AWS-Image-Private SG-AWS-Image-Id SG-AWS-EC2
26SG-AWS-TagsSG-AWS-Tags \[sn\_aws\_integ\_sg\_aws\_tags\]DynamoDB Table Cloud Load Balancer Cloud Function Key ValueOptionalSG-AWS-Organization SG-AWS-Service-Account SG-AWS-Datacenters SG-AWS-ELB-V1 SG-AWS-ELB-V2 SG-AWS-DynamoDb SG-AWS-Lambda
27SG-AWS-VM-Hw-ConsolidationSG-AWS-VM-Hw-Consolidation \[sn\_aws\_integ\_sg\_aws\_vm\_hw\_consolidation\]Virtual Machine Instance ServerOptionalSG-AWS-Organization SG-AWS-Service-Account SG-AWS-Datacenters SG-AWS-VPC SG-AWS-Subnets SG-AWS-Network-Interface SG-AWS-Security-Group SG-AWS-Storage-Volume SG-AWS-Image-Private SG-AWS-Image-Id SG-AWS-EC2 SG-AWS-Hardware-Type
28SG-AWS-EKS-ClusterSG-AWS-EKS-Cluster \[sn\_aws\_integ\_sg\_aws\_eks\_cluster\]Kubernetes Cluster AWS Datacenter Key Value SG-AWS Extension AttributesOptionalSG-AWS-Organization SG-AWS-Service-Account SG-AWS-Datacenters SG-AWS-VPC SG-AWS-Subnets SG-AWS-Network-Interface SG-AWS-Security-Group SG-AWS-Storage-Volume SG-AWS-Image-Private SG-AWS-Image-Id SG-AWS-EC2 SG-AWS-Hardware-Type SG-AWS-VM-Hw-Consolidation
29SG-AWS-EKS-Cluster-2SG-AWS-EKS-Cluster-2 \[sn\_aws\_integ\_sg\_aws\_eks\_cluster\_2\]Kubernetes Cluster AWS Datacenter Key Value SG-AWS Extension AttributesOptionalSG-AWS-Organization SG-AWS-Service-Account SG-AWS-Datacenters SG-AWS-VPC SG-AWS-Subnets SG-AWS-Network-Interface SG-AWS-Security-Group SG-AWS-Storage-Volume SG-AWS-Image-Private SG-AWS-Image-Id SG-AWS-EC2 SG-AWS-Hardware-Type SG-AWS-VM-Hw-Consolidation SG-AWS-EKS-Cluster
30SG-AWS-EKS-FULLSG-AWS-EKS-FULL \[sn\_aws\_integ\_sg\_aws\_eks\_full\]Kubernetes Cluster Server Kubernetes Namespace Kubernetes Node Kubernetes Service Kubernetes Pod Docker Container Docker Image Kubernetes Volume Kubernetes Deployment Kubernetes DaemonSet Kubernetes ReplicaSetOptionalSG-AWS-Organization SG-AWS-Service-Account SG-AWS-Datacenters SG-AWS-VPC SG-AWS-Subnets SG-AWS-Network-Interface SG-AWS-Security-Group SG-AWS-Storage-Volume SG-AWS-Image-Private SG-AWS-Image-Id SG-AWS-EC2 SG-AWS-Hardware-Type SG-AWS-VM-Hw-Consolidation SG-AWS-EKS-Cluster SG-AWS-EKS-Cluster-2
31SG-AWS-Generic-ResourcesSG-AWS-Generic-Resources \[sn\_aws\_integ\_sg\_aws\_generic\_resources\]Cloud Resource SG-AWS Extension AttributesOptionalSG-AWS-Organization
32SG-AWS-Redshift-ClusterSG-AWS-Redshift-Cluster \[sn\_aws\_integ\_sg\_aws\_redshift\_cluster\]Amazon RedshiftOptionalSG-AWS-Organization SG-AWS-Service-Account SG-AWS-Datacenters
33SG-AWS-Get-InventorySG-AWS-Get-Inventory \[sn\_aws\_integ\_sg\_aws\_get\_inventory\]ServerRequiredSG-AWS-Organization SG-AWS-Service-Account SG-AWS-Datacenters
34SG-AWS-GenericTagsSG-AWS-GenericTags \[sn\_aws\_integ\_sg\_aws\_generictags\]Cloud Resource Key ValueOptionalSG-AWS-Organization SG-AWS-Generic-Resources
35SG-AWS-SendCommandSG-AWS-SendCommand \[sn\_aws\_integ\_sg\_aws\_ssm\_sendcommand\]NoneNote: The SG-AWS-SendCommand data source doesn't have target CMDB CI classes. This data source populates the data into the sn_aws_integ_sg_aws_ssm_sendcommand staging table, but the import records aren't transformed, and the import sets remain in pending state.OptionalSG-AWS-Organization SG-AWS-Service-Account SG-AWS-Datacenters SG-AWS-VPC SG-AWS-Subnets SG-AWS-Network-Interface SG-AWS-Security-Group SG-AWS-Storage-Volume SG-AWS-Image-Private SG-AWS-Image-Id SG-AWS-EC2
36SG-AWS-SSM-GetS3ObjectSG-AWS-SSM-GetS3Object \[sn\_aws\_integ\_sg\_aws\_ssm\_gets3object\]Server Running Process \[cmdb\_running\_process\] TCP Connections \[cmdb\_tcp\]OptionalSG-AWS-Organization SG-AWS-Service-Account SG-AWS-Datacenters SG-AWS-VPC SG-AWS-Subnets SG-AWS-Network-Interface SG-AWS-Security-Group SG-AWS-Storage-Volume SG-AWS-Image-Private SG-AWS-Image-Id SG-AWS-EC2 SG-AWS-SendCommand
37SG-AWS-Autoscaling-Group​SG-AWS-Autoscaling-Group​ \[sn\_aws\_integ\_sg\_aws\_autoscaling\_group\]Instance Scale SetOptionalSG-AWS-Organization SG-AWS-Service-Account SG-AWS-Datacenters

For more information on where data is saved when pulling data from AWS, see CMDB classes targeted in Service Graph Connector for AWS and Supported AWS resource types.

You can use the IntegrationHub ETL app to view the data maps. See IntegrationHub ETL for more information.

For more information about how CI information is pulled from AWS, see the Service Graph Connector for AWS - Functional Spec and CI article on the ServiceNow Community site.

Additional information about AWS data sources:

  • The SG-AWS-Generic-Resources data source imports data for generic resources that aren't tracked by other data sources. The connector uses the Service Graph Resource Inclusion Whitelist [sn_cmdb_int_util_service_graph_resource_inclusion_whitelist] table to differentiate between generic and other supported resource types.

    The connector first populates all supported resources in the Service Graph Resource Inclusion Whitelist [sn_cmdb_int_util_service_graph_resource_inclusion_whitelist] table. These resources, categorized under their respective supported resource types, have specific data sources designated for ingestion within the connector. When the SG-AWS-Generic-Resources data source is executed and retrieves unsupported resource types, they are added to the Service Graph Resource Inclusion Whitelist [sn_cmdb_int_util_service_graph_resource_inclusion_whitelist] table and categorized as generic.

  • In Service Graph Connector for AWS version 2.13.0 and later, parallel loading is enabled for SG-AWS-Generic-Resources data source if the AWS Config aggregator is used for discovery. Partitions are created for the SG-AWS-Generic-Resources data source based on the Resource Types in the Service Graph Resource Inclusion Whitelist [sn_cmdb_int_util_service_graph_resource_inclusion_whitelist] table. Additionally, delete jobs aren't created for a full data load.

    If the AWS Config aggregator isn't used for discovery, API calls are made to multiple accounts and the Partition info field is populated with Account and Region details.

  • To import global generic resources such as IAM user and IAM group, specify a standard AWS region that has Config enabled with includeGlobalResourceTypes set to true by updating the value of the sn_aws_integ.global_generic_resource_region system property for the SG-AWS-Generic-Resources data source.

    If an aggregator is configured, and the sn_aws_integ.global_generic_resource_region value is not specified, the aggregator region is assigned as the value of this system property for importing global generic resources.

  • If the AWS Systems Manager (SSM) service isn't enabled, the connector populates the server records in the Server [cmdb_ci_server] class. If the AWS SSM service is enabled, then based on the platform type obtained through the SSM service, the server records are populated in either the Linux Server [cmdb_ci_linux_server] class or the Windows Server [cmdb_ci_win_server] class. The Server [cmdb_ci_server] class is the parent class of the Linux Server [cmdb_ci_linux_server] and the Windows Server [cmdb_ci_win_server] classes.

  • All labels associated with an AWS resource are added to the Key Value [cmdb_key_value] table.

    Note: You can use the CMDB Data Manager to delete tag data from retired CIs in the Key Value [cmdb_key_value] table based on conditions like retention time and discovery source. A scheduled job runs the policy, which can be configured to execute during off-peak hours.

  • The basic information about an AWS resource is stored in the SG-AWS Extension Attributes [sn_aws_extension_attributes] table.

  • In Service Graph Connector for AWS version 2.10.0 and later, the SG-AWS-Get-Inventory data source runs before the SG-AWS-EC2 data source and creates a Server [cmdb_ci_server] CI with the host name mapped to the Name attribute, instead of being mapped to the VM name.
  • The SG-AWS-GenericTags data source imports tag data only for generic resources that have an ARN key. You can use the SG-AWS Extension Attributes [sn_aws_extension_attributes] table to verify which generic resources have an ARN key.

    Note: The SG-AWS-GenericTags data source doesn't import tag data for Amazon CloudFront resources.

  • The AWS configuration data for each connection is stored in the SG AWS Application Properties [sn_aws_integ_sg_aws_application_properties] table.

  • When you run the diagnostic test, the data is loaded in the following tables:
    • SG AWS Diagnostic Details [sn_aws_integ_sg_aws_diagnostic_details]
    • SG-AWS Diagnostic Summary [sn_aws_integ_sg_aws_diagnostic_summary]
    • SG AWS Diagnostic Summary Notes [sn_aws_integ_sg_aws_diagnostic_summary_notes]
  • In Service Graph Connector for AWS version 2.13.0 and later, the SG-AWS-Image-Id data source doesn't access cross-account records during lookup.

CMDB classes targeted in Service Graph Connector for AWS

Service Graph Connector for AWS properties