Coordination of partial configuration items

By employing a method of secondary coordination and machine learning model prediction of missing attributes, the problem of some configuration items not being identified was solved, achieving efficient configuration item coordination and identification, and improving identification efficiency and memory utilization.

CN122122881APending Publication Date: 2026-05-29SERVICENOW INC
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
SERVICENOW INC
Filing Date
2024-09-19
Publication Date
2026-05-29

AI Technical Summary

Technical Problem

Existing technologies have the problem that some configuration items are not fully identified when identifying computer hardware and software components on the network, which makes these attributes unusable. At the same time, existing methods for disambiguation are inefficient and memory-intensive.

Method used

Through a secondary coordination process, missing attributes are predicted using different discovery data sources or machine learning models. Combined with streaming or pipeline methods, some configuration items are coordinated efficiently, reducing reliance on main memory.

Benefits of technology

It achieves effective coordination of some configuration items, improves recognition efficiency and memory utilization, and ensures that configuration items can be used by other applications.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122122881A_ABST
    Figure CN122122881A_ABST
Patent Text Reader

Abstract

Example embodiments can involve determining a configuration item identification failure, where the configuration item represents computing hardware or software associated with a network; based on the configuration item identification failure, performing a reconciliation process, where the reconciliation process modifies an attribute of the configuration item; determining that the modified configuration item passes identification; and writing the modified configuration item to a database.
Need to check novelty before this filing date? Find Prior Art

Description

Cross-references to related applications

[0001] This application claims priority to U.S. Patent Application No. 18 / 387,272, filed November 6, 2023, which is incorporated herein by reference in its entirety. Background Technology

[0002] Discovery refers to a series of processes used to identify computer hardware and software components deployed on one or more networks and store representations of these components as configuration items. In some scenarios, the identification process often fails in one of several ways, resulting in the discovery process not fully identifying a particular component. Therefore, a large portion of configuration items may remain in a partial state with missing attributes, limiting or preventing other applications from using these attributes. Furthermore, techniques used to eliminate such partial configuration item ambiguities are memory-intensive, inefficient, and often ineffective. Summary of the Invention

[0003] The various implementations disclosed in this paper include solutions to these technical problems and other potential technical issues. Specifically, secondary reconciliation can be performed on partial configuration items to determine their missing attributes. This secondary reconciliation may involve performing another set of discovery operations using different discovery data sources or different discovery configurations. Alternatively or additionally, trained machine learning models or generative artificial intelligence (AI) models can be employed to predict missing attributes without an additional discovery process. This allows at least some partial configuration items to be reconciled and made available for use by other applications. Furthermore, secondary reconciliation can be performed in an efficient streaming or pipelined manner, using only a limited amount of main memory when reconciling partial configuration items.

[0004] Therefore, the first example embodiment may involve: determining that a configuration item identification fails, wherein the configuration item represents computing hardware or software associated with the network; based on the configuration item identification failure, performing a coordination process, wherein the coordination process modifies the attributes of the configuration item; determining that the modified configuration item passes identification; and writing the modified configuration item to a database.

[0005] The third example embodiment may relate to a non-transitory computer-readable medium having stored program instructions thereon that, when executed by a computing system, cause the computing system to perform operations according to the first example embodiment.

[0006] In a fourth example embodiment, the computing system may include at least one processor, as well as memory and program instructions. The program instructions may be stored in memory and, when executed by the at least one processor, cause the computing system to perform operations according to the first example embodiment.

[0007] In the fifth example embodiment, the system may include various means for performing each operation of the first example embodiment.

[0008] By reading the following detailed description and appropriately referring to the accompanying drawings, those skilled in the art will understand these and other embodiments, aspects, advantages, and alternatives. Furthermore, the content of this invention, as well as the other descriptions and drawings provided herein, are intended to illustrate the embodiments by way of example only, and therefore various modifications are possible. For example, structural elements and process steps may be rearranged, combined, distributed, eliminated, or otherwise altered while remaining within the scope of the claimed embodiments. Attached Figure Description

[0009] Figure 1 A schematic diagram of a computing device according to an exemplary embodiment is shown.

[0010] Figure 2 A schematic diagram of a server device cluster according to an exemplary embodiment is shown.

[0011] Figure 3 A remote network management architecture according to an exemplary embodiment is described.

[0012] Figure 4 A communication environment involving a remote network management architecture, according to an exemplary embodiment, is described.

[0013] Figure 5 Another communication environment involving a remote network management architecture, according to an exemplary embodiment, is described.

[0014] Figure 6 Operations related to identification and coordination according to an example embodiment are described.

[0015] Figure 7 It is a JavaScript object notation (JSON) representation of the configuration item according to the example embodiment.

[0016] Figure 8 The use of a secondary coordination application according to an example embodiment is described.

[0017] Figure 9 The compilation of training data for a machine learning model that can be used with a discovery process is described according to an example embodiment.

[0018] Figure 10 The training and use of a generative AI model, which can be used with a discovery process, according to an example embodiment, are described.

[0019] Figure 11A memory-efficient streaming process for processing partial configuration items, according to an example embodiment, is described.

[0020] Figure 12 This is a flowchart based on an example embodiment. Detailed Implementation

[0021] This document describes example methods, devices, and systems. It should be understood that the terms "example" and "illustrative" as used herein mean "serving as an example, instance, or illustration." Unless otherwise stated, any embodiment or feature described herein as "example" or "exemplary" is not necessarily to be construed as preferred or advantageous over other embodiments or features. Therefore, other embodiments may be used and other modifications may be made without departing from the scope of the subject matter presented herein.

[0022] Therefore, the exemplary embodiments described herein are not intended to be limiting. It will be readily understood that the aspects of this disclosure, as generally described herein and illustrated in the accompanying drawings, can be arranged, substituted, combined, separated, and designed in a variety of different configurations. For example, features can be separated into “client” and “server” components in various ways.

[0023] Furthermore, unless the context otherwise suggests, the features illustrated in each figure can be used in combination with each other. Therefore, these figures should generally be considered as aspects of one or more overall embodiments, and it should be understood that not all illustrated features are necessary for every embodiment.

[0024] Furthermore, any enumeration of elements, blocks, or steps in this specification or claims is for clarity purposes. Therefore, such enumeration should not be construed as requiring or implying that these elements, blocks, or steps follow a particular arrangement or are performed in a particular order.

[0025] I. introduction

[0026] Large enterprises are complex entities with many interconnected operations. Some of these operations are spread throughout the enterprise, such as human resources (HR), supply chain, information technology (IT), and finance. However, each enterprise also has its own unique operations that provide key capabilities and / or create competitive advantage.

[0027] To support widespread implementation, businesses typically use off-the-shelf software applications, such as Customer Relationship Management (CRM) and Human Capital Management (HCM) packages. However, they may also need to customize software applications to meet their unique needs. Large enterprises often have dozens or hundreds of such custom software applications. Nevertheless, the advantages provided in the embodiments described herein are not limited to large enterprises and can be applied to businesses of any size or any other type of organization.

[0028] Many of these software applications are developed by various departments within an enterprise. These applications range from simple spreadsheets to custom software tools and databases. However, the proliferation of siloed, custom software applications has many drawbacks. It negatively impacts an enterprise's ability to operate and expand its business, innovate, and meet regulatory requirements. Enterprises may find it difficult to integrate, streamline, and improve their operations due to the lack of a single system unifying their subsystems and data.

[0029] To efficiently create custom applications, businesses will benefit from remotely hosted application platforms that eliminate unnecessary development complexity. The goal of such platforms is to reduce time-consuming and repetitive application development tasks, allowing software engineers and other personnel to focus on developing unique, high-value features.

[0030] To achieve this goal, the concept of Application Platform as a Service (aPaaS) has been introduced to intelligently automate workflows across the entire enterprise. aPaaS systems are remotely hosted away from the enterprise but can be accessed through secure connections to access data, applications, and services within the enterprise. Such aPaaS systems can possess many advantageous capabilities and features. These advantages and features can potentially improve an enterprise's operations and workflows in IT, HR, CRM, customer service, application development, and security. Nevertheless, the embodiments described herein are not limited to enterprise applications or environments and can be applied more broadly.

[0031] aPaaS systems can support the development and execution of Model-View-Controller (MVC) applications. MVC applications divide their functionality into three interconnected parts (model, view, and controller) to isolate the way information is represented from how it is presented to the user, thereby enabling efficient code reuse and parallel development. Such applications can be web-based and provide create, read, update, and delete (CRUD) functionality. This allows new applications to be built on common application infrastructures. In some cases, applications with different structures from MVC can be used, such as those employing unidirectional data flow.

[0032] aPaaS systems can support standardized application components, such as standardized sets of widgets for graphical user interface (GUI) development. In this way, applications built using an aPaaS system share a common look and feel. Other software components and modules can also be standardized. In some cases, this look and feel can be branded or skinned using a company's custom identity (logo) and / or color scheme.

[0033] aPaaS systems support the ability to configure application behavior using metadata. This allows application behavior to be quickly adjusted to meet specific needs. This approach reduces development time and increases flexibility. Furthermore, aPaaS systems support GUI tools that facilitate metadata creation and management, thereby reducing errors in metadata.

[0034] aPaaS systems can support clearly defined interfaces between applications, allowing software developers to avoid unwanted inter-application dependencies. Therefore, aPaaS systems can implement a service layer where persistent state information and other data are stored.

[0035] aPaaS systems can support a rich set of integration features, enabling applications on top of them to interact with legacy and third-party applications. For example, an aPaaS system can support a custom employee onboarding system that integrates with legacy HR, IT, and accounting systems.

[0036] aPaaS systems can support enterprise-level security. Furthermore, because aPaaS systems may be remotely hosted, they should also employ security procedures when interacting with systems within the enterprise or with third-party networks and services hosted outside the enterprise. For example, an aPaaS system can be configured to share data between the enterprise and other parties to detect and identify common security threats.

[0037] aPaaS systems may have other features, functionalities, and advantages. This description is for illustrative purposes only and is not intended to be limiting.

[0038] As an example of the aPaaS development process, software developers might be assigned to create a new application using an aPaaS system. First, the developer can define a data model, specifying the types of data the application uses and the relationships between them. Then, the developer inputs (e.g., uploads) the data model through the aPaaS system's GUI. The aPaaS system automatically creates all the corresponding database tables, fields, and relationships, which can then be accessed through an object-oriented service layer.

[0039] Furthermore, aPaaS systems can also build fully functional applications with client-side interfaces and server-side CRUD logic. The resulting applications can serve as a foundation for further user development. Advantageously, developers do not need to spend a significant amount of time on basic application functionality. Additionally, since the application may be web-based, it can be accessed from any internet-enabled client device. Alternatively or additionally, for example, when internet service is unavailable, a local copy of the application may be accessible.

[0040] aPaaS systems also support a rich set of predefined features that can be added to applications. These features include support for search, email, templating, workflow design, reporting, analytics, social media, scripting, mobile-friendly output, and custom GUIs.

[0041] Such aPaaS systems can present a GUI in multiple ways. For example, the server device of an aPaaS system can use a combination of Hypertext Markup Language (HTML) and JavaScript® to generate a representation of the GUI. JavaScript® can include client-side executable code, server-side executable code, or both. The server device can transmit this representation to the client device or otherwise provide it to the client device so that the client device can display it on the screen according to its locally defined look and feel. Alternatively, the GUI can be presented in other forms, such as an intermediate form (e.g., JavaScript® bytecode) from which the client device directly generates graphical output. Other possibilities also exist.

[0042] Furthermore, user interactions with GUI elements (such as buttons, menus, tabs, sliders, checkboxes, toggle switches, etc.) can be described as “selecting,” “activating,” or “actuating” them. These terms can be used regardless of whether the interaction with these GUI elements is via a keyboard, pointing device, touchscreen, or other mechanism.

[0043] The aPaaS architecture is particularly powerful when integrated with and used to manage enterprise networks. The following examples describe the architectural and functional aspects of an example aPaaS system, as well as its features and benefits.

[0044] II. Example computing devices and cloud-based computing environments

[0045] Figure 1This is a simplified block diagram illustrating computing device 100, showing some components that may be included in a computing device configured to operate according to embodiments herein. Computing device 100 may be a client device (e.g., a device actively operated by a user), a server device (e.g., a device providing computing services to client devices), or some other type of computing platform. Some server devices may sometimes operate as client devices to perform specific operations, and some client devices may contain server functionality.

[0046] In this example, computing device 100 includes a processor 102, a memory 104, a network interface 106, and an input / output unit 108, all of which may be coupled via a system bus 110 or a similar mechanism. In some embodiments, computing device 100 may include other components and / or peripheral devices (e.g., removable memory, printer, etc.).

[0047] Processor 102 can be one or more of any type of computer processing element, such as a central processing unit (CPU), a coprocessor (e.g., a math, graphics, or cryptographic coprocessor), a digital signal processor (DSP), a network processor, and / or an integrated circuit or controller that performs processor operations. In some cases, processor 102 can be one or more single-core processors. In other cases, processor 102 can be one or more multi-core processors with multiple independent processing units. Processor 102 may also include register memory for temporarily storing instructions being executed and related data, and cache memory for temporarily storing recently used instructions and data.

[0048] Memory 104 can be any form of computer-usable memory, including but not limited to random access memory (RAM), read-only memory (ROM), and non-volatile memory (e.g., flash memory, hard disk drive, solid-state drive, optical disc (CD), digital video disc (DVD), and / or magnetic tape storage). Therefore, memory 104 represents both a main memory unit and a long-term storage device. Other types of memory may include biological memory.

[0049] Memory 104 may store program instructions and / or data operable thereto. As an example, memory 104 may store such program instructions on a non-transitory computer-readable medium such that the instructions are executable by processor 102 to perform any method, process, or operation disclosed in this specification or the accompanying drawings.

[0050] like Figure 1As shown, memory 104 may include firmware 104A, kernel 104B, and / or application 104C. Firmware 104A may be some or all of the program code used to boot or otherwise initialize computing device 100. Kernel 104B may be an operating system, including modules for memory management, process scheduling and management, input / output, and communication. Kernel 104B may also include a device driver that allows the operating system to communicate with the hardware modules of computing device 100, such as memory units, network interfaces, ports, and buses. Application 104C may be one or more user-space software programs, such as a web browser or email client, and any software libraries used by these programs. Memory 104 may also store data used by these programs and other programs and applications.

[0051] Network interface 106 may take the form of one or more wired interfaces, such as Ethernet (e.g., Fast Ethernet, Gigabit Ethernet, etc.). Network interface 106 may also support communication via one or more non-Ethernet media (such as coaxial cable or power line) or via wide area media (such as Synchronous Optical Networking (SONET) or Digital Subscriber Line (DSL) technologies). Network interface 106 may also take the form of one or more wireless interfaces, such as IEEE 802.11 (Wi-Fi), BLUETOOTH® (Bluetooth), Global Positioning System (GPS), or wide area wireless interfaces. However, other forms of physical layer interfaces and other types of standard or proprietary communication protocols may also be used on network interface 106. Furthermore, network interface 106 may include multiple physical interfaces. For example, some embodiments of computing device 100 may include Ethernet, BLUETOOTH®, and Wi-Fi interfaces.

[0052] Input / output unit 108 facilitates interaction between the user and peripheral devices and computing device 100. Input / output unit 108 may include one or more types of input devices, such as a keyboard, mouse, touchscreen, etc. Similarly, input / output unit 108 may include one or more types of output devices, such as a screen, monitor, printer, and / or one or more light-emitting diodes (LEDs). Additionally or alternatively, computing device 100 may communicate with other devices using, for example, a Universal Serial Bus (USB) or High-Definition Multimedia Interface (HDMI) port interface.

[0053] In some embodiments, one or more computing devices, such as computing device 100, may be deployed to support an aPaaS architecture. The actual physical location, connectivity, and configuration of these computing devices may be unknown and / or insignificant to the client devices. Therefore, these computing devices may be referred to as “cloud-based” devices, which may be hosted in various remote data center locations.

[0054] Figure 2 A cloud-based server cluster 200 according to an exemplary embodiment is depicted. Figure 2 In this system, the operation of computing devices (e.g., computing device 100) can be distributed among server devices 202, data storage devices 204, and routers 206, all of which can be connected via a local cluster network 208. The number of server devices 202, data storage devices 204, and routers 206 in the server cluster 200 may depend on the computing tasks and / or applications assigned to the server cluster 200.

[0055] For example, server device 202 can be configured to perform various computing tasks of computing device 100. Therefore, computing tasks can be distributed across one or more server devices 202. Such task distribution can reduce the total time to complete these tasks and return results to the extent that these computing tasks can be executed in parallel. For simplicity, both server cluster 200 and individual server devices 202 can be referred to as "server devices." It should be understood that this naming convention indicates that server device operation may involve one or more different server devices, data storage devices, and cluster routers.

[0056] Data storage device 204 may be a data storage array, including a drive array controller configured to manage read and write access to a group of hard disk drives and / or solid-state drives. The drive array controller may also be configured, individually or in conjunction with server device 202, to manage backups or redundant copies of data stored in data storage device 204 to prevent drive failures or other types of failures that could prevent one or more server devices 202 from accessing units of data storage device 204. Other types of storage may be used in addition to drives.

[0057] Router 206 may include network devices configured to provide internal and external communication for server cluster 200. For example, router 206 may include one or more packet switching and / or routing devices (including switches and / or gateways) configured to provide (i) network communication between server device 202 and data storage device 204 via local cluster network 208, and / or (ii) network communication between server cluster 200 and other devices via communication link 210 to network 212.

[0058] In addition, the configuration of router 206 may be based at least in part on the data communication requirements of server device 202 and data storage device 204, the latency and throughput of local cluster network 208, the latency, throughput and cost of communication link 210, and / or other factors that may contribute to the cost, speed, fault tolerance, resilience, efficiency and / or other design goals of the system architecture.

[0059] As a possible example, data storage device 204 may include any form of database, such as a Structured Query Language (SQL) database. Information in such a database can be stored using various types of data structures, including but not limited to tables, arrays, lists, trees, and tuples. Furthermore, any database in data storage device 204 may be monolithic or distributed across multiple physical devices.

[0060] Server device 202 can be configured to send data to and receive data from data storage device 204. This transmission and retrieval can take the form of SQL queries or other types of database queries and the output of these queries. Additional text, images, video, and / or audio may also be included. Furthermore, server device 202 can organize the received data into web pages or web application representations. These representations can take the form of markup languages ​​such as HTML, Extensible Markup Language (XML), or other standardized or proprietary formats. Additionally, server device 202 may have the ability to execute various types of computer scripting languages ​​such as, but not limited to, Perl, Python, PHP Hypertext Preprocessor (PHP), Active Server Pages (ASP), JavaScript®, etc. Computer program code written in these languages ​​can facilitate the delivery of web pages to client devices and the interaction between client devices and web pages. Alternatively or additionally, JAVA® can be used to facilitate the generation of web pages and / or the provision of web application functionality.

[0061] III. Example Remote Network Management Architecture

[0062] Figure 3 A remote network management architecture according to an exemplary embodiment is depicted. The architecture includes three main components: a managed network 300, a remote network management platform 320, and a public cloud network 340, all of which are connected via the Internet 350.

[0063] A. Managed network

[0064] For example, managed network 300 can be an enterprise network used by entities for computing and communication tasks as well as for data storage. Therefore, managed network 300 can include client device 302, server device 304, router 306, virtual machine 308, firewall 310, and / or proxy server 312. Client device 302 can be implemented by computing device 100, server device 304 can be implemented by computing device 100 or server cluster 200, and router 306 can be any type of router, switch, or gateway.

[0065] Virtual machine 308 can be implemented by one or more computing devices 100 or server clusters 200. Typically, a virtual machine is a simulation of a computing system and mimics the functionality of a physical computer (e.g., processor, memory, and communication resources). A single physical computing system, such as server cluster 200, can support up to thousands of independent virtual machines. In some embodiments, virtual machine 308 can be managed by a centralized server device or application that facilitates the allocation of physical computing resources to independent virtual machines and facilitates performance and error reporting. Enterprises typically use virtual machines to efficiently allocate computing resources on demand. Vendors of virtualized computing systems include VMware® and Microsoft®.

[0066] Firewall 310 can be one or more dedicated routers or server devices that protect managed network 300 from unauthorized access attempts to devices, applications, and services within managed network 300, while allowing authorized communication originating from managed network 300. Firewall 310 may also provide intrusion detection, web filtering, virus scanning, application-layer gatewaying, and other applications or services. Figure 3 In some embodiments not shown, the managed network 300 may include one or more virtual private network (VPN) gateways through which the managed network 300 communicates with a remote network management platform 320 (see below).

[0067] The managed network 300 may also include one or more proxy servers 312. Embodiments of the proxy server 312 may be server applications that facilitate communication and data movement between the managed network 300, the remote network management platform 320, and the public cloud network 340. Specifically, the proxy server 312 may be able to establish and maintain secure communication sessions with one or more computing instances of the remote network management platform 320. Through such sessions, the remote network management platform 320 may be able to discover and manage architectural and configuration aspects of the managed network 300 and its components.

[0068] With the assistance of proxy server 312, remote network management platform 320 may also be able to discover and manage aspects of the public cloud network 340 used by managed network 300. Although Figure 3Not shown, but one or more proxy servers 312 can be deployed in any public cloud network 340 to facilitate such discovery and management.

[0069] Firewalls, such as firewall 310, typically reject all incoming communication sessions via the Internet 350 unless such sessions ultimately originate behind the firewall (i.e., from devices on the managed network 300) or the firewall is explicitly configured to support such sessions. By placing a proxy server 312 behind firewall 310 (e.g., within the managed network 300 and protected by firewall 310), proxy server 312 may be able to pass through firewall 310. Therefore, firewall 310 may not need to be specifically configured to support sessions originating from remote network management platform 320, thereby avoiding potential security risks to the managed network 300.

[0070] In some cases, a managed network 300 may consist of a small number of devices and a limited number of networks. In other deployments, a managed network 300 may span multiple physical locations and contain hundreds of networks and hundreds of thousands of devices. Therefore, Figure 3 The architecture described in the text can be scaled up or down by orders of magnitude.

[0071] Furthermore, depending on the size, architecture, and connectivity of the managed network 300, a varying number of proxy servers 312 may be deployed within it. For example, each proxy server 312 may be responsible for communication between a portion of the managed network 300 and the remote network management platform 320. Alternatively or additionally, a set of two or more proxy servers may be allocated to this portion of the managed network 300 for load balancing, redundancy, and / or high availability purposes.

[0072] B. Remote Network Management Platform

[0073] The remote network management platform 320 is a hosted environment that provides aPaaS services to users, particularly the operators of the managed network 300. These services can take the form of a web-based portal, for example, using the aforementioned web-based technologies. Therefore, users can securely access the remote network management platform 320 from, for example, client device 302 or possibly from client devices outside the managed network 300. Through these web-based portals, users can design, test, and deploy applications, generate reports, view analytics, and perform other tasks. The remote network management platform 320 can also be referred to as a multi-application platform.

[0074] like Figure 3As shown, the remote network management platform 320 includes four compute instances 322, 324, 326, and 328. Each of these compute instances can represent one or more server nodes and / or one or more database nodes running a dedicated copy of aPaaS software. The arrangement of server and database nodes on physical server equipment and / or virtual machines can be flexible and can vary based on enterprise needs. These nodes can be combined to provide a collection of web portals, services, and applications (e.g., a fully functional aPaaS system) available to a specific enterprise. In some cases, a single enterprise may use multiple compute instances.

[0075] For example, managed network 300 can be an enterprise customer of remote network management platform 320 and can use compute instances 322, 324, and 326. The reason for providing multiple compute instances to a customer is that the customer may want to independently develop, test, and deploy their applications and services. Therefore, compute instance 322 can be dedicated to application development related to managed network 300, compute instance 324 can be dedicated to testing these applications, and compute instance 326 can be dedicated to the live execution of tested applications and services. Compute instances can also be referred to as managed instances, remote instances, customer instances, or other names. Any application deployed to a compute instance can be a scoped application because its access to the database within the compute instance can be limited to certain elements (e.g., one or more specific database tables or specific rows in one or more database tables).

[0076] For clarity, the contents of this document will collectively refer to the application nodes, database nodes, the aPaaS software running on them, and the underlying hardware deployment as "computation instances." It should be noted that users may commonly refer to the graphical user interface provided as an "instance." However, unless otherwise defined herein, a "computation instance" is a computing system deployed within a remote network management platform 320.

[0077] The multi-instance architecture of the Remote Network Management Platform 320 contrasts with traditional multi-tenant architectures, offering several advantages. In a multi-tenant architecture, data from different customers (e.g., enterprises) is mixed in a single database. While these customers' data is separated from each other, this separation is enforced by the software operating the single database. Therefore, security vulnerabilities in this system can affect the data of all customers, increasing additional risk, especially for entities regulated by government, healthcare, and / or finance. Furthermore, any database operation affecting one customer can potentially affect all customers sharing that database. Thus, if an outage occurs due to hardware or software errors, this outage will affect all such customers. Similarly, if a database is upgraded to meet the needs of one customer, the database will be unavailable to all customers during the upgrade process. Typically, such maintenance windows will be long due to the size of the shared database.

[0078] In contrast, a multi-instance architecture provides each customer with their own database within a dedicated compute instance. This prevents the mixing of customer data and allows for independent management of each instance. For example, if one customer's instance goes down due to a bug or upgrade, other compute instances are unaffected. Because the database contains only one customer's data, maintenance downtime is limited. Furthermore, the simpler design of a multi-instance architecture allows for the deployment of redundant copies of each customer's database and instance in a geographically distributed manner. This contributes to high availability, where a live version of the customer instance can be moved when a failure is detected or maintenance is in progress.

[0079] In some embodiments, the remote network management platform 320 may include one or more central instances controlled by the entity operating the platform. Similar to compute instances, central instances may include a number of application and database nodes deployed on a number of physical server devices or virtual machines. Such central instances can serve as a specific configuration for compute instances and a data repository that can be shared among at least some of the compute instances. For example, definitions of common security threats that may occur on compute instances, software packages typically found on compute instances, and / or application stores for applications that can be deployed to compute instances may reside in the central instance. Compute instances can communicate with the central instance to obtain this data through well-defined interfaces.

[0080] To effectively support multiple compute instances, the remote network management platform 320 can implement multiple such instances on a single hardware platform. For example, when an aPaaS system is implemented on a server cluster, such as server cluster 200, the aPaaS system can operate virtual machines that allocate varying amounts of compute, storage, and communication resources to the instances. However, full virtualization of server cluster 200 may not be necessary, and other mechanisms can be used to decouple the instances. In some examples, each instance on server cluster 200 may have a dedicated account and one or more dedicated databases. Alternatively, compute instances, such as compute instance 322, can span multiple physical devices.

[0081] In some cases, a single server cluster of the remote network management platform 320 can support multiple independent enterprises. Furthermore, as described below, the remote network management platform 320 may include multiple server clusters deployed in geographically dispersed data centers to facilitate load balancing, redundancy, and / or high availability.

[0082] C. Public cloud network

[0083] Public cloud network 340 can be remote server devices (e.g., multiple server clusters such as server cluster 200) that can be used for outsourced computing, data storage, communication, and service hosting operations. These servers can be virtualized (i.e., the servers can be virtual machines). Examples of public cloud network 340 include Amazon AWS cloud, Microsoft Azure cloud (Azure), Google Cloud Platform (GCP), and IBM Cloud Platform. Similar to remote network management platform 320, multiple server clusters supporting public cloud network 340 can be deployed in geographically dispersed locations for load balancing, redundancy, and / or high availability purposes.

[0084] The managed network 300 can use one or more public cloud networks 340 to deploy applications and services to its clients and customers. For example, if the managed network 300 provides an online music streaming service, the public cloud network 340 can store music files and provide a web interface and streaming functionality. In this way, the enterprise using the managed network 300 does not need to build and maintain its own servers for these operations.

[0085] The remote network management platform 320 may include modules integrated with the public cloud network 340 to expose its virtual machines and managed services to the managed network 300. These modules allow users to request virtual resources, discover allocated resources, and provide flexible reporting to the public cloud network 340. To establish this functionality, a user from the managed network 300 may first create an account in the public cloud network 340 and request a relevant set of resources. The user can then input their account information into the appropriate modules of the remote network management platform 320. These modules can then automatically discover manageable resources within the account and provide reports related to usage, performance, and billing.

[0086] D. Communication support and other operations

[0087] Internet 350 can represent a portion of the global Internet. However, Internet 350 can alternatively represent different types of networks, such as private wide area or local area packet-switched networks.

[0088] Figure 4 The communication environment between the managed network 300 and the computing instance 322 is also illustrated, and additional features and alternative embodiments are described. Figure 4 In this system, compute instance 322 is replicated, either wholly or partially, across data centers 400A and 400B. These data centers may be geographically distant from each other, located in different cities or countries. Each data center includes support equipment that facilitates communication with the managed network 300 and remote users.

[0089] In data center 400A, network traffic to and from external devices flows either through VPN gateway 402A or firewall 404A. VPN gateway 402A can establish a peering connection with VPN gateway 412 of managed network 300 via security protocols such as Internet Protocol Security (IPSEC) or Transport Layer Security (TLS). Firewall 404A can be configured to allow access from authorized users (e.g., user 414 and remote user 416) and deny access from unauthorized users. Through firewall 404A, these users can access compute instance 322 and potentially other compute instances. Load balancer 406A can be used to distribute traffic among one or more physical or virtual server devices hosting compute instance 322. Load balancer 406A can simplify user access by hiding the internal configuration of data center 400A (e.g., compute instance 322) from client devices. For example, if compute instance 322 includes multiple physical or virtual compute devices that share access to multiple databases, load balancer 406A can distribute network traffic and processing tasks across these compute devices and databases so that no one compute device or database is significantly busier than the others. In some embodiments, compute instance 322 may include VPN gateway 402A, firewall 404A, and load balancer 406A.

[0090] Data center 400B may include components from its own version of data center 400A. Therefore, VPN gateway 402B, firewall 404B, and load balancer 406B can perform the same or similar operations as VPN gateway 402A, firewall 404A, and load balancer 406A, respectively. Furthermore, compute instance 322 can coexist in both data centers 400A and 400B through real-time or near real-time database replication and / or other operations.

[0091] Figure 4 The data centers 400A and 400B shown can promote redundancy and high availability. Figure 4 In this configuration, data center 400A is active, and data center 400B is passive. Therefore, data center 400A is serving all traffic entering and leaving managed network 300, while the version of compute instance 322 in data center 400B is being updated in near real-time. Other configurations are also supported, such as both data centers being active.

[0092] If data center 400A fails in some way or otherwise becomes unavailable to users, data center 400B can take over as an active data center. For example, the Domain Name System (DNS) server that associates the domain name of compute instance 322 with one or more Internet Protocol (IP) addresses of data center 400A can reassociate that domain name with one or more IP addresses of data center 400B. After this reassociation is complete (which may take less than a second or a few seconds), users can access compute instance 322 through data center 400B.

[0093] Figure 4 Possible configurations for the managed network 300 are also shown. As described above, proxy server 312 and user 414 can access compute instance 322 through firewall 310. Proxy server 312 can also access configuration item 410. Figure 4 In this context, configuration item 410 can refer to any or all of client device 302, server device 304, router 306, and virtual machine 308, any of their components, any applications or services running on them, and the relationships between devices, components, applications, and services. Therefore, the term "configuration item" can be an abbreviation for any physical or virtual device, or any application or service that can be remotely discovered or managed by compute instance 322, or an abbreviation for the relationships between discovered devices, applications, and services. Configuration items can be represented in the configuration management database (CMDB) of compute instance 322.

[0094] When stored or transmitted, a configuration item can be a list of attributes that characterize the hardware or software it represents. These attributes may include manufacturer, supplier, location, owner, unique identifier, description, network address, operating status, serial number, last update time, and so on. The category of a configuration item can determine which subset of attributes exists for that configuration item (for example, software configuration items and hardware configuration items may have different lists of attributes).

[0095] As described above, VPN gateway 412 can provide a dedicated VPN to VPN gateway 402A. Such a VPN can be helpful when there is significant traffic between managed network 300 and compute instance 322, or when security policies otherwise recommend or require the use of a VPN between these sites. In some embodiments, any device in compute instance 322 and / or managed network 300 that communicates directly via VPN is assigned a public IP address. Other devices in compute instance 322 and / or managed network 300 may be assigned private IP addresses (e.g., IP addresses selected from 10.0.0.0–10.255.255.255 or 192.168.0.0–192.168.255.255, abbreviated as subnets 10.0.0.0 / 8 and 192.168.0.0 / 16, respectively). In various alternatives, devices in managed network 300 (e.g., proxy server 312) may communicate directly with one or more data centers using a security protocol such as TLS.

[0096] IV. Example discovery

[0097] To enable the remote network management platform 320 to manage the devices, applications, and services of the managed network 300, the remote network management platform 320 can first determine which devices exist in the managed network 300, their configurations, components, and operational status, as well as the applications and services provided by these devices. The remote network management platform 320 can also determine the relationships between discovered devices, their components, applications, and services. Each device, component, application, and service can be represented as a configuration item. The process of determining configuration items and relationships within the managed network 300 is called discovery and can be facilitated at least in part by the proxy server 312. The representation of configuration items and relationships is stored in a CMDB (Configuration Management Database).

[0098] While this section describes discovery for managed network 300, the same or similar discovery procedures can be used for public cloud network 340. Therefore, in some environments, “discovery” can refer to the discovery of configuration items and relationships on managed network and / or one or more public cloud networks.

[0099] For the purposes of this embodiment, "application" can refer to one or more processes, threads, programs, client software modules, server software modules, or any other software that execute on a device or a set of devices. "Service" can refer to advanced capabilities provided by one or more applications that execute on one or more devices working together. For example, a web service might involve multiple web application server threads executing on one device and accessing information from a database application executing on another device.

[0100] Figure 5It provides a logical representation of how configuration items and relationships are discovered and how related information is stored. For simplicity, the remote network management platform 320, the public cloud network 340, and the Internet 350 are not shown.

[0101] exist Figure 5 In this configuration, CMDB 500, task list 502, and identification and reconciliation engine (IRE) 514 are configured within and / or run within compute instance 322. Task list 502 represents the connection point between compute instance 322 and agent server 312. Task list 502 may be referred to as a queue, or more specifically as an external communication channel (ECC) queue. Task list 502 may represent not only the queue itself, but also any associated processing, such as adding, deleting, and / or manipulating information within the queue.

[0102] As discovery progresses, compute instance 322 can store discovery tasks (jobs) to be executed by agent server 312 in task list 502 until agent server 312 requests these tasks in one or more batches. Adding tasks to task list 502 may trigger or otherwise cause agent server 312 to begin its discovery operation. For example, agent server 312 may poll task list 502 periodically or from time to time, or may otherwise become aware of discovery commands in task list 502. Alternatively or concurrently, discovery may be triggered manually or automatically based on a triggering event (e.g., discovery may automatically begin once a day at a specific time).

[0103] Regardless, computing instance 322 can send these discovery commands to proxy server 312 upon request. For example, proxy server 312 can repeatedly query task list 502, retrieve the next task in the task list, and execute that task until task list 502 is empty or another stopping condition is met. In response to receiving a discovery command, proxy server 312 can query various devices, components, applications, and / or services in managed network 300 (in... Figure 5 For simplicity, these are represented by devices 504, 506, 508, 510, and 512. These devices, components, applications, and / or services can provide responses to the proxy server 312 related to their configuration, operation, and / or status. The proxy server 312 can then provide this discovery information to the task list 502 (i.e., the task list 502 may have an outgoing queue for storing discovery commands until requested by the proxy server 312, and an incoming queue for storing discovery information until it is read).

[0104] IRE 514 can be a software module that removes discovery information from task list 502 and organizes it into configuration items (e.g., representing devices, components, applications, and / or services discovered on managed network 300) and relationships between these configuration items. IRE 514 can then provide these configuration items and relationships to CMDB 500 for storage. The operation of IRE 514 is described in more detail below.

[0105] In this way, the configuration items stored in CMDB 500 represent the environment of the managed network 300. As an example, these configuration items can represent a collection of physical and / or virtual devices (e.g., client devices, server devices, routers, or virtual machines), applications running on the physical and / or virtual devices (e.g., web servers, email servers, databases, or storage arrays), and services involving multiple individual configuration items. Relationships can be pairwise definitions of permutations or dependencies between configuration items.

[0106] To perform discovery in the manner described above, proxy server 312, CMDB 500, and / or one or more credential storage devices may be configured with credentials for the device to be discovered. Credentials may include any type of information required to access the device. These may include user ID / password pairs, certificates, etc. In some embodiments, these credentials may be stored in an encrypted field of CMDB 500. Proxy server 312 may contain a decryption key for the credentials, enabling proxy server 312 to use these credentials to log in or otherwise access the device being discovered.

[0107] There are two general types of discovery: horizontal discovery and vertical discovery (top-down). These will be discussed separately below.

[0108] A. Horizontal discovery

[0109] Horizontal discovery is used to scan managed networks 300 to find devices, components, and / or applications, and then populates the CMDB 500 with configuration items representing these devices, components, and / or applications. Horizontal discovery also creates relationships between configuration items. For example, this could be a "run on" relationship between a configuration item representing a software application and a configuration item representing the server device on which the software application runs. Typically, horizontal discovery is not service-aware and does not create relationships between configuration items based on the services that run within them.

[0110] There are two versions of horizontal discovery. One relies on detectors and sensors, while the other also employs a pattern. Detectors and sensors can be scripts (e.g., written in JavaScript®) that collect and process discovery information about devices and then update the CMDB 500 accordingly. More specifically, detectors explore or investigate devices on the managed network 300, and sensors parse the discovery information returned from the detectors.

[0111] Patterns are also scripts that collect data about one or more devices, process that data, and update the CMDB. Patterns differ from detectors and sensors in that they are written in a specific discovery programming language and used to perform detailed discovery processes on specific devices, components, and / or applications that are typically not reliably discoverable (or not discoverable at all) by more general detectors and sensors. Specifically, a pattern can specify a series of operations that define how to discover devices, components, and / or applications in a particular layout, what credentials to use, and which CMDB tables to populate with the configuration items generated by that discovery.

[0112] Both versions can be performed in four logical phases: scanning, classifying, identifying, and exploring. Similarly,

[0113] Both versions may require specifying one or more IP address ranges on the managed network 300 to which discovery is to be performed. Each stage may involve communication between devices on the managed network 300 and the agent server 312, and communication between the agent server 312 and the task list 502. Some stages may involve storing partial or preliminary configuration items in the CMDB 500, which may be updated in subsequent stages.

[0114] During the scanning phase, proxy server 312 can probe one or more specified IP address ranges for each IP address against open Transmission Control Protocol (TCP) and / or User Datagram Protocol (UDP) ports to determine the typical device type and its operating system. The presence of such open ports at a particular IP address may indicate that a specific application is running on the device assigned to that IP address, which in turn can identify the operating system used by the device. For example, if TCP port 135 is open, the device is likely running the Windows® operating system. Similarly, if TCP port 22 is open, the device is likely running a UNIX® operating system, such as Linux®. If UDP port 161 is open, it may be possible to further identify the device via Simple Network Management Protocol (SNMP). Other possibilities also exist.

[0115] During the classification phase, proxy server 312 can also probe each discovered device to determine its operating system type. The probes for a specific device are based on information about that device collected during the scanning phase. For example, if a device with TCP port 22 open is discovered, a UNIX®-specific probe set can be used. Similarly, if a device with TCP port 135 open is discovered, a WINDOWS®-specific probe set can be used. In either case, a suitable set of tasks can be arranged in task list 502 for proxy server 312 to execute. These tasks may cause proxy server 312 to log in or otherwise access information from the specific device. For example, if TCP port 22 is open, proxy server 312 can be instructed to initiate a Secure Shell (SSH) connection to that specific device and retrieve information about the specific type of operating system running on it from a specific location in the file system. Based on this information, the operating system can be determined. As an example, a UNIX® device with TCP port 22 open can be classified as AIX®, HPUX, LINUX®, MACOS®, or SOLARIS®. This classification information can be stored in CMDB 500 as one or more configuration items.

[0116] During the identification phase, the agent server 312 can determine specific details about the classified device. The detectors used in this phase can be based on information about the specific device collected during the classification phase. For example, if the device is classified as LINUX®, a LINUX®-specific set of detectors can be used. Similarly, if the device is classified as WINDOWS® 10, a WINDOWS® 10-specific set of detectors can be used. As with the classification phase, a suitable set of tasks can be placed in the task list 502 for the agent server 312 to execute. These tasks may cause the agent server 312 to read information from the specific device, such as Basic Input / Output System (BIOS) information, serial number, network interface information, one or more Media Access Control addresses assigned to one or more of these network interfaces, one or more IP addresses used by the specific device, etc. This identification information can be stored in the Configuration Management Database 500 as one or more configuration items along with the relationships between any of these configuration items. This may involve processing the identification information through IRE 514 to avoid generating duplicate configuration items and thus eliminate ambiguity, and / or determining which of the CMDB 500 tables the discovery information should be written to.

[0117] During the exploration phase, agent server 312 can determine more details about the operational status of the classified devices. The detectors used in this phase can be based on information about the specific device collected during the classification and / or identification phases. Similarly, a suitable set of tasks can be arranged in task list 502 for agent server 312 to execute. These tasks allow agent server 312 to read additional information from the specific device, such as processor information, memory information, a list of running processes (software applications), etc. Likewise, the discovered information can be stored in CMDB 500 as one or more configuration items and relationships.

[0118] On some devices, such as switches and routers, level discovery can utilize SNMP. In addition to determining, or alternatively to, a list of running processes or other application-related information, discovery can identify other subnets known to the router and the operational status of the router's network interfaces (e.g., active, inactive, queue length, number of dropped packets, etc.). The IP addresses of these additional subnets can be candidates for other discovery processes. Therefore, level discovery can be performed iteratively or recursively.

[0119] Patterns are used only in the identification and exploration phases (under pattern-based discovery); the scanning and classification phases operate in the same way as when using detectors and sensors. After the classification phase is complete, the pattern detector is designated as the detector to be used during identification. Then, the pattern detector and the pattern it is designated are activated.

[0120] Pattern-based discovery enables the use of programming language patterns to support many features that are unavailable or difficult to achieve using detectors and sensors. For example, pattern-based discovery makes it easier to discover devices, components, and / or applications in public cloud networks, as well as to track profiles. Furthermore, these patterns are more easily customized by users compared to detectors and sensors. Additionally, patterns are more focused on specific devices, components, and / or applications, and therefore may execute faster than the more general methods used by detectors and sensors.

[0121] Once horizontal discovery is complete, configuration entries for each discovered device, component, and / or application are available in CMDB 500. For example, after discovery, the operating system versions, hardware configurations, and network configuration details of client devices, server devices, and routers in the managed network 300, as well as the applications running on them, can be stored as configuration entries. This collected information can be presented to the user in various ways to allow the user to view the hardware composition and operational status of the devices.

[0122] Furthermore, CMDB 500 can include entries regarding relationships between configuration items. More specifically, suppose a server device comprises multiple hardware components (e.g., processor, memory, network interface, storage, and file system) and has several software applications installed on or running on it. Relationships between components and the server device (e.g., "included in") and relationships between software applications and the server device (e.g., "running on") can be represented in CMDB 500 as follows.

[0123] More generally, the relationships between software configuration items installed or executed on hardware configuration items can take various forms, such as "hosted on," "running on," or "dependent on." Therefore, a database application installed on a server device might have a "hosted on" relationship with the server device, indicating that the database application is hosted on that server device. In some embodiments, the server device might have a reciprocal "used" relationship with the database application, indicating that the server device is used by the database application. These relationships can be automatically discovered using the discovery process described above, but they can also be set manually.

[0124] In this way, the remote network management platform 320 can discover and inventory the hardware and software (and possibly other components) deployed on and provided by the managed network 300.

[0125] B. Vertical Discovery

[0126] Vertical discovery is a technique used to find and map configuration items that are part of a whole service, such as a web service. For example, vertical discovery can map a web service by showing the relationships between a web server application, a Linux® server device, and a database that stores the web service's data. Typically, horizontal discovery is run first to find configuration items and the basic relationships between them, and then vertical discovery is run to establish the relationships between the configuration items that make up the service.

[0127] Patterns can be used to discover certain types of services because these patterns can be programmed to find specific hardware and software deployments that match a description of how the service is deployed. Alternatively, traffic analysis (e.g., examining network traffic between devices) can be used to aid vertical discovery. In some cases, service parameters can be manually configured to assist vertical discovery.

[0128] Typically, vertical discovery aims to discover specific types of relationships between devices, components, and / or applications. Some of these relationships can be inferred from configuration files. For example, a web server application's configuration file might reference the IP address and port number of the database it depends on. Vertical discovery patterns can be programmed to find such references and infer relationships from them. Relationships can also be inferred from traffic between devices; for example, if there is a large amount of web traffic (e.g., TCP port 80 or 8080) flowing between a load balancer and the device hosting the web server, a relationship may exist between the load balancer and the web server.

[0129] Relationships discovered through vertical discovery can take various forms. As an example, an email service might include email server software configuration items and database application software configuration items, each installed on different hardware device configuration items. The email service might have a "dependency" relationship with these two software configuration items, while the software configuration items might have a reciprocal "being used" relationship with the email service. Such services may not be fully determined through horizontal discovery processes, but may instead rely on vertical discovery and possibly some degree of manual configuration.

[0130] C. Advantages of discovery

[0131] Regardless of how the discovery information is obtained, it is valuable for the operation of a managed network. Notably, IT personnel can quickly determine where certain software applications are deployed and which configuration items constitute a service. This enables the rapid pinpointing of the root cause of service outages or performance degradation. For example, if two different services are responding slowly intermittently, the CMDB (potentially combined with other activity) can be queried to determine that the root cause is high processor utilization by the database application used by both services. Therefore, IT personnel can focus on the database application rather than wasting time considering the health and performance of other configuration items that make up the service.

[0132] In another example, suppose a database application is running on a server device, and this application is used by the employee onboarding and payroll services. Therefore, if the server device goes down for maintenance, it's obvious that the employee onboarding and payroll services will be affected. Similarly, dependencies and relationships between configuration items can represent the services affected when a specific hardware device fails.

[0133] Typically, configuration items and / or relationships between configuration items can be displayed on a web-based interface in a hierarchical manner. Such configuration items and / or relationships in the CMDB can be modified through this interface.

[0134] In addition, users from the managed network 300 can develop workflows that allow certain coordinated activities to be performed across multiple discovered devices. For example, an IT workflow might allow a user to change a universal administrator password for all discovered LINUX® devices in a single operation.

[0135] IV. CMDB Recognition Rules and Coordination

[0136] CMDBs, such as CMDB 500, provide a repository of configuration items and relationships. When properly configured, they can play a critical role in applications deployed within compute instances or in higher-level applications involving compute instances. These applications may involve enterprise IT service management, operations management, asset management, configuration management, compliance, and more.

[0137] For example, IT service management applications might use information in the CMDB to identify applications and services that may be affected by components (such as server equipment) that have failed, crashed, or been overloaded. Similarly, asset management applications might use information in the CMDB to determine which hardware and / or software components (or other types of components, services, or systems) are being used to support specific enterprise applications. Given the importance of the CMDB, it is desirable that the information stored in it be accurate, consistent, and up-to-date.

[0138] A CMDB can be populated in various ways. As mentioned above, the discovery process can automatically store information, including configuration items and relationships, in the CMDB. However, the CMDB can also be populated manually, through configuration files, and third-party data sources, either wholly or partially. Given that multiple data sources may be able to update the CMDB at any time, one data source may overwrite entries from another. Furthermore, two data sources may each create slightly different entries for the same configuration item, resulting in duplicate data in the CMDB. Any of these situations can lead to a decline in the health and usability of the CMDB.

[0139] To mitigate this situation, these data sources may not write configuration items directly to the CMDB. Instead, they can write to the IRE 514's Identification and Coordination Application Programming Interface (API). The IRE 514 can then use a configurable set of identification rules to uniquely identify the configuration items and determine whether and how to write them to the CMDB.

[0140] Typically, an identification rule specifies the set of configuration item attributes that can be used for unique identification. Identification rules can also have priorities, so that rules with higher priorities are considered before rules with lower priorities. Furthermore, rules can be independent, meaning they identify configuration items independently of other configuration items. Alternatively, rules can be dependent, meaning they first use metadata rules to identify dependent configuration items.

[0141] Metadata rules describe which other configuration items are included within a specific configuration item, or on which host a specific configuration item is deployed. For example, a network directory service configuration item might contain a domain controller configuration item, while a web server application configuration item might be hosted on a server device configuration item.

[0142] The goal of each identification rule is to use a combination of attributes that can clearly distinguish a configuration item from all other configuration items and are not expected to change during the lifetime of that configuration item. Some possible attributes for an example server device may include serial number, location, operating system, operating system version, memory capacity, etc. If the attributes specified by the rule cannot uniquely identify the configuration item, multiple components may be represented as the same configuration item in the CMDB. Furthermore, if the attributes specified by the rule change for a particular configuration item, duplicate configuration items may be created.

[0143] Therefore, when a data source provides IRE 514 with information about a configuration item, IRE 514 can attempt to match that information against one or more rules. If a match is found, the configuration item is written to the CMDB, or if the configuration item already exists in the CMDB, it is updated. If no match is found, the configuration item can be retained for further analysis.

[0144] The configuration item reconciliation process can be used to ensure that only authoritative data sources are allowed to overwrite configuration item data in the CMDB. This reconciliation can also be rule-based. For example, a reconciliation rule can specify that a particular data source is authoritative for a specific configuration item type and property set. Then, IRE 514 might only allow this authoritative data source to write to that specific configuration item and can prevent writes from unauthorized data sources. Therefore, the authorized data source becomes the sole source of truth regarding that specific configuration item. In some cases, if an unauthorized data source is creating a configuration item or the property it is writing to is empty, then writing to that configuration item may be allowed from the unauthorized data source.

[0145] Furthermore, multiple data sources may have authority over the same configuration item or its properties. To avoid ambiguity, these data sources can be assigned priorities, which are considered during the writing of the configuration item. For example, a secondary authoritative data source might be able to write to a configuration item's property until the primary authoritative data source writes to that property. Afterward, the secondary authoritative data source can be prevented from writing to that property further.

[0146] In some cases, duplicate configuration items can be detected automatically by IRE 514 or otherwise. These configuration items can be deleted or marked for manual deduplication.

[0147] VI. Some configuration items

[0148] Figure 6 The architecture and operations related to IRE 514 are described in more detail. Managed networks typically employ multiple data sources for discovery purposes. As shown in the figure, these data sources may include horizontal and / or vertical discovery 602, discovery patterns 604, third-party discovery tools 606, CSV files 608, manual data entry 610, and other sources 612.

[0149] Here, horizontal and / or vertical discovery 602 has been described above. Discovery mode 604 has also been described above and is sometimes referred to as a service graph connector. Third-party discovery tools 606 may include any local or remote software application capable of providing configuration items to the IRE 514. In some cases, these tools are configured to discover multiple types of configuration items (e.g., horizontal and / or vertical discovery 602) or specific to certain types of hardware and / or software (e.g., discovery mode 604). The CSV file 608 may be a comma-separate-value file or any other type of file containing structured information, which may be uploaded to the IRE 514 and parsed by it to identify the configuration items within. Manual entry 610 may involve a user entering configuration information into a remote network management platform 320, which the IRE 514 can use to generate configuration items. Other sources 612 could be specific representational state transfer (REST) ​​interfaces that can be used to discover configuration items, event management applications, orchestration applications, import sets (temporary tables containing configuration item data before they are written to CMDB 500), etc.

[0150] Multiple data sources may be necessary because any single data source may not discover all the configuration items used by the managed network. For example, horizontal and / or vertical discovery 602 may fail to identify or fully discover certain hardware units on the managed network. This could be because these units require a custom discovery process (e.g., specific API calls) or because these units are located within a public cloud network. In some cases, discovery mode 604 or a third-party discovery tool 606 may be able to discover the hardware. Alternatively, the configuration items associated with the hardware can be provided in a CSV file 608 or through manual entry 610. Other possibilities exist. In any case, using multiple data sources generally results in a more accurate and complete population of CMDB500.

[0151] In some cases, more than one data source may discover the same configuration item, and IRE 514 can, where possible, reconcile the output of these data sources so that CMDB 500 does not contain multiple entries for the same configuration item. For example, if CSV file 608 contains a configuration item that has already been discovered by horizontal and / or vertical discovery 602, IRE 514 can avoid creating duplicate configuration items and can update existing configuration items in CMDB 500 or discard copies in CSV file 608.

[0152] In some cases, IRE 514 can receive configuration item data from multiple data sources in parallel. This data may include duplicate or conflicting attributes and their values ​​for the same configuration item. IRE 514 is configured to apply its rules to determine the correct interpretation of the configuration item data and how to update CMDB 500 to accurately reflect the identified hardware and software components.

[0153] For the purposes of this description, the term “identification” should be interpreted broadly to include the various processes, steps, checks, and / or rules that IRE 514 can apply to determine whether information from a data source can be written to CMDB 500 as a configuration item and to what extent it can be written to CMDB 500 as a configuration item (including updates to existing configuration items). For example, identification may include one or more of the following processes: (i) using identification rules on certain attributes of an input configuration item (e.g., serial number and / or IP address) to determine whether the configuration item corresponds to an existing configuration item in CMDB 500; (ii) writing information as a new configuration item, or merging attributes of an input configuration item with attributes of an existing configuration item; (iii) standardizing the data in the attributes of the configuration item to ensure that it conforms to the standardized formats and units of measurement used in CMDB 500; (iv) mapping and orchestrating updates to dependencies and associations between configuration items; (v) detecting conflicts between input configuration items and existing configuration items and possibly applying predefined rules to automatically resolve these conflicts, or resolving these conflicts by generating tasks for human review; and / or (vi) maintaining an audit trail of changes made to configuration items in CMDB 500.

[0154] If any of these identification processes fails or cannot be completed for a configuration item, the "identification" of that configuration item may be considered a failure, even if it is partially identified (for example, a configuration item may have a serial number attribute (with a value that uniquely identifies the configuration item), but the configuration item may still fail to be "identified" because it lacks other required attributes or those other attributes are not properly formatted). In some cases, this may result in the input configuration item being stored as a partial configuration item, as described below.

[0155] In some cases, even if a configuration item is complete, it may fail to pass the "recognition" test. For example, the IRE514 rule may require a configuration item to have a known relationship with another configuration item of a specific type. If that relationship does not exist, the configuration item may be considered a partial configuration item even if all its required properties have the correct values.

[0156] For illustrative purposes, this article assumes that the discovered configuration items are provided to IRE 514 in the form of JavaScript Object Notation (JSON) blocks, but other formats (such as XML or CSV files) may also be used. Figure 7 Configuration item 700 is shown as an example, which represents the server device, its network adapter, and its installed software.

[0157] The first configuration item in configuration item 700 is server device 710, which is represented by "ci" and has several attributes. Some of these attributes include manufacturer 712, model_id 714, and serial number 716, as well as IP address 718 and discovery source 720. Discovery source 720 indicates that the discovery source is "ServiceNow Discovery," which may be horizontal and / or vertical discovery 602.

[0158] The second configuration item in configuration item 700 is the network adapter list 730. This list includes one entry, namely network adapter 732. The attributes of this entry include the MAC address, IP address, subnet address, and gateway address assigned to the network adapter.

[0159] The third configuration item in configuration item 700 is the installed software list 740. This list includes two entries, namely installed software 742 and 744. The attributes of these entries include the name and version of the installed software.

[0160] Typically, such a representation of a server device may include more, fewer, or different configuration items, and configuration items may include more, fewer, or different attributes. In some cases, the association between these configuration items (e.g., server device 710 includes network adapter 732, on which software 742 and 744 are installed) can be implied through their grouping. In other cases, these associations may be explicit, where network adapter 732 and the installed software 742 and 744 contain attributes that somehow point to server device 710.

[0161] Back Figure 6As mentioned above, IRE 514 can access a set of configurable identification rules that can be used to uniquely identify configuration items and determine whether and how these items are written to CMDB 500. For example, IRE 514 can be programmed such that a configuration item of type cmdb_ci_server can only be written to CMDB 500 if the manufacturer, model_id, and serial_number attributes of the configuration item are populated (or at least populated with non-null, non-default, non-blank, properly formatted, or "correct" values ​​that match the corresponding predefined format for that attribute). Other types of configuration items may have similar rules requiring certain subsets of their attributes to be populated correctly in order for these configuration items to be stored in CMDB 500.

[0162] If one or more mandatory attributes of a configuration item lack correct values, IRE 514 can write this configuration item to storage device 620. Here, storage device 620 can be a database, database table, or file structure (e.g., one or more JSON files) capable of storing such partial configuration items. Storage device 620 can be volatile or non-volatile memory; therefore, in the latter case, storage device 620 can retain partial configuration items indefinitely. For convenience, an attribute determined to contain anything other than a valid value may be referred to as a "missing attribute," even if the attribute exists and has a value.

[0163] Applying such rules can make CMDB 500 more accurate, complete, and useful. Since CMDB 500 serves as the ground truth for the hardware and software deployed within the network, it is desirable for CMDB 500 to avoid incomplete and potentially duplicated configuration items, as these can lead to confusion about which components are actually deployed in the network. By maintaining partial configuration items in storage device 620, these partial configuration items can be later improved (e.g., by providing another data source with one or more missing attributes) and then moved to CMDB 500.

[0164] In practice, discovery is an imperfect process, and mandatory properties of configuration items may fail to be identified for various reasons. In some cases, hardware or software components may be unable to provide these properties to the data source. In other cases, the data source may fail to correctly represent the content of mandatory properties, for example, by placing this content in the wrong property or by improper formatting. In still other cases, the data source may not be configured to query or request mandatory properties. Other possibilities exist, but typically, the data source is unaware of which properties IRE 514 considers mandatory for which configuration items.

[0165] Regardless of the reason, the number of partial configuration items in storage device 620 will increase over time. For some networks, hundreds of thousands of such partial configuration items may become stuck in a stagnant state until they can be reconciled. This not only prevents these configuration items from being stored in CMDB 500, but also requires tens of megabytes (or more) of capacity to be used by storage device 620. In some real-world environments, the number of partial configuration items has been observed to reach hundreds of thousands, occupying several gigabytes of storage space. Therefore, finding methods to reconcile these partial configuration items can improve system efficiency and performance.

[0166] In many cases, users of the remote network management platform 320 are unaware of the existence of certain configuration items or the storage space they occupy. Furthermore, there may be no user interface to inform users of the existence of these partial configuration items. Therefore, some partial configuration items may persist indefinitely because no action has been taken to coordinate them.

[0167] VII. Secondary coordination architecture

[0168] Figure 8 An architecture 800 for secondary coordination of certain configuration items is described. In addition to the IRE 514, CMDB 500, and storage device 620 described above, architecture 800 includes a secondary coordination application 802, which is configured to perform various aspects of secondary coordination.

[0169] For convenience and organizational purposes, the secondary coordination application 802 may include the ability to operate according to automated coordination 804 or user-assisted coordination 806. Automated coordination 804 may be a process executed by the secondary coordination application 802 on demand, according to a pre-configured schedule, or based on some other triggering condition. For example, automated coordination 804 may be configured to execute daily, weekly, or monthly. The result of automated coordination 804 may be a list of partially coordinated configuration items (e.g., missing attributes have been filled). This list may be submitted to IRE 514 for processing, possibly after user review and approval. User-assisted coordination 806 may be an interactive process executed by the secondary coordination application 802 on demand to guide the user during the secondary coordination process. For example, user-assisted coordination 806 may be executed manually by the user, possibly in response to a notification or reminder to do so.

[0170] In a broad sense, automated coordination 804 can employ one or more of data sources 810, machine learning 812, and / or generative artificial intelligence (AI) 814 to coordinate partial configuration items. User-assisted coordination 806 can employ any of these technologies, as well as manual input 816, to coordinate partial configuration items interactively. Nevertheless, some manual editing of partial configuration items can also be performed in conjunction with automated coordination 804.

[0171] Data source 810 can be any data source discussed above, such as horizontal and / or vertical discovery 602, discovery patterns 604, third-party discovery tools 606, CSV files 608, or some other data source. It is worth noting that there is a distinction between manual input 816 and manual entry 610, as the former aims to correlate secondary coordination, while the latter aims to correlate regular discovery. However, manual input 816 and manual entry 610 can be similar interactive processes that prompt the user to provide information related to configuration items and their attributes.

[0172] Whether using automated coordination 804 or user-assisted coordination 806, the secondary coordination application 802 can read a certain number of partial configuration items from storage device 620, attempt to coordinate at least a portion of these partial configuration items, and then provide the potentially coordinated configuration items to IRE 514. IRE 514, according to its rules, can write the coordinated configuration items as complete configuration items to CMDB 500, and / or write back any still uncoordinated (e.g., still partial) configuration items to storage device 620. In the case of uncoordinated configuration items being written back to storage device 620, one or more attributes of these configuration items may have been updated, but at least one mandatory attribute may still be missing proper population.

[0173] The following sections describe how the secondary coordination application 802 uses data sources 810, machine learning 812, generative AI 814, and / or manual input 816. Nevertheless, the secondary coordination application 802 may be able to use other techniques.

[0174] A. Data source

[0175] Secondary reconciliation applications 802 can employ data sources in various ways, such as secondary discovery, targeted discovery, or re-performing discovery under different configurations. The decision of which of these techniques to use can be pre-configured, made in response to the attribute content of partial configuration items, and / or based on manual instructions. It is worth noting that more than one of these techniques can be used for the same partial configuration item.

[0176] Secondary discovery may involve performing the discovery process using a different data source than the one or more data sources used to generate that part of the configuration items. For example... Figure 7 As shown, the `discovery_source` property indicates the data source used to populate certain configuration items. Therefore, the secondary reconciliation application 802 can read this property and determine that another data source is available.

[0177] For example, suppose the `discovery_source` attribute indicates that horizontal and / or vertical discovery 602 should be used to populate this partial configuration item. Further suppose that a third-party discovery tool 606 is available but not yet used to discover this partial configuration item. Then, a secondary reconciliation application 802 can perform discovery using one or more of the third-party discovery tools 606 with the aim of reconciling (e.g., refining) the partial configuration item.

[0178] In some cases, the secondary coordination application 802 can select such a data source based on the attribute content of certain configuration items. For example, it is known that horizontal and / or vertical discovery 602 may not be able to discover the serial numbers of certain hardware components, but a discovery tool from the component manufacturer can determine such serial numbers. In this case, the secondary coordination application 802 can be configured to select this third-party discovery tool for secondary discovery when these serial numbers are unknown.

[0179] Targeted discovery may involve performing discovery on a specific hardware or software component to potentially obtain more information about that component. This component can be identified by its assigned IP address or some other unique identifier. Targeted discovery may involve the secondary coordination application 802 rerunning discovery from a previously involved data source, or performing discovery using a new data source. For example, configuration items for a hardware component may have already been discovered by the horizontal and / or vertical discovery 602 section. However, changes may have been made to this component, causing the horizontal and / or vertical discovery 602 to successfully complete the discovery. In this case, the secondary coordination application 802 can rerun the horizontal and / or vertical discovery 602 against that specific component to attempt to refine the configuration items.

[0180] Re-performing discovery under different configurations may involve changing the parameters of how discovery is performed using a specific data source, and then performing the discovery again. For example, if discovery using a given data source is performed with a set of unprivileged credentials (e.g., user-level permissions), using those credentials may cause certain properties of configuration items to be unavailable during discovery. However, if discovery is re-performed using the given data source with privileged credentials (e.g., administrator-level permissions), the values ​​of those missing properties may be discoverable.

[0181] Another way to re-execute discovery is to specifically configure the given data source to discover any missing properties. For example, if discovery using a given data source is performed with a default configuration, this configuration might not support discovering all discoverable properties. However, the default configuration might be modifiable, allowing re-execution of discovery using this data source to ensure that at least some missing properties are discoverable.

[0182] Although different, secondary discovery, targeted discovery, and re-execution discovery may overlap to some extent. For example, re-execution discovery may involve performing the discovery on a small number of specific components, such as based on a network subnet or a list of IP addresses.

[0183] B. Machine Learning

[0184] Alternatively or additionally, the secondary reconciliation application 802 may involve using a trained machine learning model to predict the value of the missing attribute. For example, the secondary reconciliation application 802 may provide at least some attributes of a partial configuration item to a trained machine learning model. The model may return a prediction of the missing attribute or indicate that it cannot predict the missing attribute. If a prediction is returned, the value of that attribute can be added to the partial configuration item. The partial configuration item can then be provided to IRE 514 as a potentially reconciled configuration item.

[0185] The training of machine learning models can be based on the prior coordination of some configuration items. Figure 9 The process is described in 900.

[0186] exist Figure 9 In this process, the discovered attributes (e.g., non-missing attributes) of partial configuration item 902 are recorded as attribute 902A. Then, partial configuration item 902 is provided to the secondary reconciliation application 802. As described above, the secondary reconciliation application 802 can discover some missing attributes of partial configuration item 902 and resubmit the partial configuration item 902, whose missing attributes have been filled, as a potentially reconciled configuration item to IRE 514. Assuming the reconciliation is effective and all mandatory attributes exist, the result is a complete configuration item 904. Thus, the completed attributes are written to attribute 904A. Completed attributes are those previously missing but correctly filled through the secondary reconciliation application 802.

[0187] The combination of attributes 902A and 904A can be used as training data entries for a machine learning model. Specifically, attribute 902A can be the input training data, and attribute 904A can be the labeled output (real-world) training data. With a sufficient set of entries (e.g., at least several hundred), this training data can be used to train the machine learning model. Once training is complete, the model may be able to predict the values ​​of missing attributes from the discovered attributes based on its training data. Therefore, the model can be applied to a subset of configuration items stored in storage device 620 and predict the values ​​of their missing attributes for at least some of the configuration items.

[0188] This process is most efficient if the missing attribute is predictable given the discovered attributes. For example, if the discovered attributes include the computing device's model_id (e.g., "PowerEdge R740"), it might be possible to predict the device's manufacturer (e.g., "Dell"). However, the device's serial number might not be as easily predicted, as serial numbers tend to be unique to each device. In another example, the device's location attribute might be predictable based on its ip_address attribute. In full generalization, missing attributes can be predicted based on more than one discovered attribute.

[0189] Machine learning models can include any one or more of the following: decision trees (a flowchart-like tree structure where each node represents a feature, each branch represents a decision or rule, and each leaf represents an outcome), random forests (an ensemble technique that creates multiple decision trees during training and outputs the most common classification results from each decision tree), support vector machines (finding a hyperplane that best divides a dataset into multiple classes), neural networks (layers of interconnected nodes through which inputs are propagated to provide output predictions), and / or gradient boosting machines (an ensemble technique that builds a series of weak learners (typically decision trees) sequentially, where each decision tree corrects for the errors of the preceding decision trees). Other possibilities exist.

[0190] Even if a machine learning model can predict the value of a missing attribute with high confidence, such a model is not perfect. Therefore, it may be beneficial to allow users to review these predictions before they are written to the CMDB 500. For example, the results of applying a machine learning model to a subset of configuration items could be presented to the user for approval or rejection of each item.

[0191] C. Generative AI

[0192] Alternatively or additionally, secondary reconciliation application 802 may involve using a trained generative AI model to predict the values ​​of missing attributes. In this case, the generative AI model can be trained (or fine-tuned) according to the full configuration records in CMDB 500, enabling it to understand common structures and values ​​in missing attributes. In some cases, the generative AI model may be a large language model (LLM).

[0193] Generative AI models are a type of natural language application designed to generate coherent, context-sensitive sequences of text that are similar to their training text. The term "generative" indicates that, in addition to classifying or predicting based on existing data, they can generate (or produce) new content. These models are typically based on deep learning architectures, whose structure involves multiple layers of interconnected nodes (or neurons) and are designed to capture complex patterns in the data.

[0194] One of the most prominent architectures used in modern generative AI models is the transformer architecture. This architecture includes an embedding layer (where input data (e.g., text terms) is transformed into vectors that capture semantic information about the input), a self-attention mechanism (which enables the model to weigh the relative importance of different parts of the input to each other), a feedforward neural network (used to transform the data after the self-attention mechanism has processed it), a position encoder (providing model information about the position of each term), and normalization (balancing the weights of activation functions in one or more layers).

[0195] Multiple such transformer blocks (including self-attention networks and feedforward networks) are stacked to deepen the model, enabling it to learn more complex patterns and relationships. The output layer can be used to generate output. For language models, the output layer can produce the probability of the next token in a sequence.

[0196] Generative AI models are typically driven by prompts. A prompt can be a text string that serves as the initial input sequence, which modulates the state of the generative AI model to determine its subsequent output. Generally, the more specific the prompt, the more likely the generative AI model is to produce the desired result.

[0197] Based on its training, a generative AI model may be able to establish associations between attribute groups and their values. For example, a generative AI model can determine that various patterns exist in configuration items of CMDB 500. One such pattern might be that a certain `model_id` is always associated with a specific manufacturer, but the reverse is not necessarily true. Therefore, a generative AI model can predict the manufacturer based on `model_id`, but not vice versa. Alternatively, a generative AI model might discover that most or all configuration items with a specific `model_id` and location have a specific `cpu_count`. Other possibilities exist.

[0198] Figure 10 A process 1000 for training and using a generative AI model is described. Assume a CMDB 500 contains complete configuration items with associated attributes having correct values. Generative AI training 1002 is applied to these configuration items to generate a generative AI model 1004. In operation, a hint 1006 may be provided to the generative AI model 1004. This hint may include at least some attributes from the attributes of a partial configuration item and a request for the generative AI model 1004 to predict the value of a missing attribute. An example of such a hint might be “For a configuration item with [attribute value], predict the value of [missing attribute]”, where [attribute value] represents a list of attributes from the partial configuration item and associated values ​​of those attributes, and [missing attribute] is one or more missing attributes from the missing attributes of that partial configuration item. The result may be a complete configuration item 1008 (or at least a list of values ​​for missing attributes). Although not shown, a complete configuration item 1008 may not be considered complete or added to the CMDB 500 before passing through the identification process of IRE 514.

[0199] Compared to trained machine learning models, generative AI has the advantage of being able to be trained on static data in CMDB500 without needing to track differences in configuration items before and after secondary reconciliation. This allows for faster training and can be performed more frequently to keep the generative AI model up-to-date.

[0200] Unlike machine learning models, generative AI models can predict the values ​​of missing attributes with high confidence, but such models are not perfect. Therefore, it may be beneficial to allow users to review these predictions before they are written into the CMDB 500. For example, the results of applying a generative AI model to a subset of configuration items could be presented to the user for approval or rejection of each item.

[0201] D. Manual input

[0202] In some cases, secondary reconciliation application 802 may involve prompting the user to manually input information to reconcile partial configuration items. For example, a list of one or more partial configuration items, each with an actuable control (such as a button or menu item), may be presented to the user on a graphical user interface. Actuation of the control for a specific partial configuration item may allow the graphical user interface to further present the user with options for modifying that specific partial configuration item. In some cases, missing attributes may be highlighted in a way that attracts the user's attention. Modifications made to the attributes may allow that specific partial configuration item to be submitted to IRE 514 to determine whether it has been completed.

[0203] VIII. Streaming architecture

[0204] To reduce memory footprint and improve performance, the secondary coordination application 802 can employ a streaming architecture 1100. This allows the secondary coordination application 802 to read blocks of configuration items from storage device 620 into main memory and process the configuration items within each block. Once a block is processed, the next block is read from storage device 620, possibly using a sliding window approach. This is an improvement over previous techniques that read all partial configuration items from storage device 620 into main memory at once (potentially tens of megabytes).

[0205] As shown in the figure, storage device 620 includes block 1102, which can represent one or more configuration items encoded in storage device 620. This encoding can be in JSON or XML format, as an entry in a database structure, or in other formats. In any case, secondary reconciliation application 802 can read block 1102 from storage device 620 into main memory for processing. The result can be one or more potentially reconciled configuration items. These potentially reconciled configuration items can be provided to IRE 514. Those reconciled configuration items can be written to CMDB 500 and removed from storage device 620. Those unreconciled configuration items can be written back to storage device 620 in an updated form. For example, if a configuration item has two missing attributes, and secondary reconciliation application 802 determines the correct value for only one of the two missing attributes, that value can be written to that attribute in storage device 620.

[0206] As described above, this process can continue for each block of partial configuration items in storage device 620. These blocks may have a fixed or variable size (e.g., 1 to 50 kilobytes) or be configured to contain a fixed number of partial configuration items (e.g., 1 to 10).

[0207] IX. Example technology improvement

[0208] These embodiments provide technical solutions to technical problems. One technical problem being addressed is the reconciliation of partial configuration items. In practice, partial configuration items are problematic because their number can reach thousands or more, and maintaining these configuration items requires significant storage space. Furthermore, reconciling these partial configuration items so that they can be represented in a CMDB and used by other applications is beneficial.

[0209] In existing technologies, some configuration items are silently written to storage, and users may not even be aware of their existence. Even when coordination exists, it is at most performed manually. Therefore, these technologies cannot scale to large discovery targets that may generate thousands of partial configuration items. Furthermore, existing technologies rely on users' subjective decisions and experience, leading to significant differences in results between instances and the potential use of incorrect values ​​for missing attributes to complete configuration items. Consequently, existing technologies are almost incapable of resolving the coordination of partial configuration items in a timely, efficient, and accurate manner.

[0210] The embodiments described herein overcome these limitations by providing a variety of possible techniques based on re-executing the discovery process in various ways, on secondary coordination of partial configuration items based on trained machine learning models, and / or on generative AI models. In this way, coordination can be performed in a more accurate and robust manner. This brings several advantages. First, coordination can be performed automatically and periodically, without requiring the user to remember and initiate it. Second, coordination can remove partial configuration items from storage devices, freeing up memory for other uses. Third, coordination can occur in a streaming, pipelined manner, limiting the amount of main memory occupied by partial configuration items at any given point in time.

[0211] Other technical improvements may also be derived from these embodiments, and other technical problems may be solved. Therefore, the description of this technical improvement is not limiting, but rather constitutes an example of advantages that can be realized from the embodiments.

[0212] X. Example Operation

[0213] Figure 12 This is a flowchart illustrating an example embodiment. Figure 12 The process shown can be performed by a computing device (e.g., computing device 100) and / or a cluster of computing devices (e.g., server cluster 200). However, the process can also be performed by other types of devices or device subsystems. For example, the process can be performed by a computing instance of a remote network management platform or a portable computer (e.g., a laptop or tablet device).

[0214] It can be removed Figure 12The embodiments are simplified by using any one or more of the features shown in the foregoing figures or otherwise described herein. Furthermore, these embodiments may be combined with features, aspects, and / or implementation methods illustrated in any of the foregoing figures or otherwise described herein.

[0215] Block 1200 may involve determining that a configuration item has failed to be identified (i.e., a partial configuration item), where the configuration item represents computing hardware or software associated with the network. In some cases, the configuration item represents a virtual machine, a service, or some other aspect of the managed network.

[0216] Block 1202 may involve performing a coordination process (i.e., secondary coordination) based on configuration item identification failure, where this coordination process modifies the attributes of the configuration item. In some cases, modifying attributes involves changing the value of the attribute. In other cases, modifying attributes involves creating a new attribute that did not previously exist for that configuration item. Other possibilities exist.

[0217] Block 1204 may involve identifying modified configuration items through recognition.

[0218] Block 1206 may involve writing the modified configuration items to the database.

[0219] In some implementations, computing hardware or software is deployed on a network.

[0220] In some implementations, the configuration item before modification is the result of a discovery process performed on the network, wherein the coordination process includes re-performing the discovery process on at least a portion of the network.

[0221] In some implementations, re-performing the discovery process involves performing the discovery process on a subset of networks identified by a set of network addresses or a series of component identifiers.

[0222] In some implementations, re-performing the discovery process involves performing it using a different set of access credentials.

[0223] In some implementations, the configuration item before modification is the result of performing a discovery process on the network, wherein the coordination process includes performing different discovery processes on at least a portion of the network.

[0224] In some implementations, the property has a null or improperly formatted value before the reconciliation process is executed, in which the reconciliation process modifies the property to have a non-null and properly formatted value.

[0225] In some implementations, the attribute has a null or improperly formatted value before the coordination process is executed, where the configuration item requires the attribute to have a non-null and properly formatted value for it to be recognized.

[0226] Some implementations may also involve: storing the configuration item in memory if the configuration item fails to be identified; and deleting the configuration item from memory if the modified configuration item is successfully identified.

[0227] In some implementations, the configuration item is associated with multiple attributes, wherein the configuration item before modification is the result of a discovery process performed on the network, and wherein the coordination process includes: providing a subset of the attributes to a trained machine learning model, wherein the trained machine learning model is trained to predict target attribute values ​​that have enabled other configuration items to pass identification based on the values ​​of the subset of attributes; receiving the target attribute value of the attribute from the trained machine learning model; and modifying the attributes of the configuration item to have the target attribute value.

[0228] In some implementations, the configuration item is associated with multiple attributes, wherein the configuration item before modification is the result of a discovery process performed on the network, and wherein the coordination process includes: providing a subset of the attributes to a trained generative artificial intelligence (AI) model, wherein the trained generative AI model is trained to predict groupings of attribute values ​​based on other configuration items already identified; receiving a target attribute value for the attribute from the trained generative AI model based on a representation of the groupings of attribute values; and modifying the attributes of the configuration item to have the target attribute value.

[0229] In some implementations, the configuration item is one of a plurality of identified failed configuration items, wherein the plurality of configuration items are stored in memory as one or more files or database entries, and wherein performing the coordination process includes reading a data block containing the configuration item but less than all of the plurality of configuration items from the one or more files or database entries.

[0230] In some implementations, the configuration item is one of a plurality of identified failed configuration items, wherein the plurality of configuration items are stored in memory as one or more files or database entries, and wherein performing the coordination process includes iteratively streaming data blocks, each containing a different subset of the configuration item, from the one or more files or database entries.

[0231] XI. End

[0232] This disclosure is not limited to the specific embodiments described herein, which are intended to illustrate various aspects. Many modifications and variations can be made without departing from its scope, as will be apparent to those skilled in the art. In addition to those described herein, functionally equivalent methods and apparatus within the scope of this disclosure will be apparent to those skilled in the art based on the foregoing description. Such modifications and variations are intended to fall within the scope of the appended claims.

[0233] The above detailed description, with reference to the accompanying drawings, illustrates various features and operations of the disclosed systems, apparatus, and methods. The exemplary embodiments described herein and in the drawings are not intended to be limiting. Other embodiments may be utilized, and other changes may be made, without departing from the scope of the subject matter presented herein. It will be readily understood that the various aspects of this disclosure, as generally described herein and illustrated in the accompanying drawings, can be arranged, substituted, combined, separated, and designed in a variety of different configurations.

[0234] Regarding any or all message flow graphs, scenarios, and flowcharts discussed herein, each step, block, and / or communication may represent information processing and / or information transmission according to exemplary embodiments. Alternative embodiments are included within the scope of these exemplary embodiments. In these alternative embodiments, for example, operations described as steps, blocks, transmissions, communications, requests, responses, and / or messages may be performed in a different order than that shown or discussed, including substantially simultaneously, in reverse order, or repeatedly, depending on the functionality involved. Furthermore, for any message flow graph, scenario, and flowchart discussed herein, more or fewer blocks and / or operations may be used, and these message flow graphs, scenarios, and flowcharts may be combined partially or entirely with each other.

[0235] A step or block representing information processing may correspond to a circuit that can be configured to perform a specific logical function of the method or technique described herein. Alternatively or additionally, a step or block representing information processing may correspond to a module, segment, or portion of program code (including associated data). The program code may include one or more instructions executable by a processor for implementing a specific logical operation or action in the method or technique. The program code and / or associated data may be stored on any type of computer-readable medium, such as storage devices including RAM, disk drives, solid-state drives, or other storage media.

[0236] Computer-readable media may also include non-transitory computer-readable media, such as non-transitory computer-readable media that store short-term data (e.g., register memory and processor cache). Non-transitory computer-readable media may also include non-transitory computer-readable media that store program code and / or long-term data. Therefore, non-transitory computer-readable media may include secondary or persistent long-term storage, such as ROM, optical discs or disks, solid-state drives, or read-only optical disc storage (CD-ROM). Non-transitory computer-readable media may also be any other volatile or non-volatile storage system. Non-transitory computer-readable media can be considered, for example, computer-readable storage media or tangible storage devices.

[0237] Furthermore, steps or blocks representing one or more information transfers can correspond to information transfers between software and / or hardware modules within the same physical device. However, other information transfers can occur between software and / or hardware modules in different physical devices.

[0238] The specific arrangement shown in the figures should not be considered limiting. It should be understood that other embodiments may include more or less each element shown in the given figures. Furthermore, some of the illustrated elements may be combined or omitted. Additionally, exemplary embodiments may include elements not shown in the figures.

[0239] While various aspects and embodiments have been disclosed herein, other aspects and embodiments will be apparent to those skilled in the art. The various aspects and embodiments disclosed herein are for illustrative purposes only and are not intended to be limiting; the true scope is indicated by the appended claims.

Claims

1. A method comprising: The configuration item identification failed, whereby the configuration item represents computing hardware or software associated with the network; If the configuration item fails to be identified, a coordination process is executed, wherein the coordination process modifies the attributes of the configuration item. Confirm that the modified configuration items pass the identification; and Write the modified configuration items into the database.

2. The method according to claim 1, wherein, The computing hardware or software is deployed on the network.

3. The method of claim 1, wherein the configuration item before modification is the result of a discovery process performed on the network, and wherein, The coordination process includes re-executing the discovery process on at least a portion of the network.

4. The method of claim 3, wherein performing the discovery process again comprises performing the discovery process on a subset of the network identified by a set of network addresses or a series of component identifiers.

5. The method of claim 3, wherein performing the discovery process again comprises performing the discovery process using a different set of access credentials.

6. The method of claim 1, wherein the configuration item before modification is the result of a discovery process performed on the network, and wherein, The coordination process includes performing different discovery processes on at least a portion of the network.

7. The method of claim 1, wherein the attribute has a null value or an improperly formatted value before the coordination process is performed, and wherein, The coordination process modifies the attribute to have a non-empty and correctly formatted value.

8. The method of claim 1, wherein the attribute has a null value or an improperly formatted value before the coordination process is performed, and wherein, For a configuration item to be recognized, the attribute must have a non-empty and correctly formatted value.

9. The method according to claim 1, further comprising: If the configuration item fails to be identified, the configuration item will be stored in the memory. as well as Based on the modified configuration item, the configuration item is deleted from the memory.

10. The method according to claim 1, wherein, The configuration item is associated with multiple attributes, wherein the configuration item before modification is the result of a discovery process performed on the network, and wherein the coordination process includes: A subset of the attributes is provided to a trained machine learning model, wherein the trained machine learning model is trained to predict the target attribute value that has enabled other configuration items to pass identification based on the values ​​of the subset of the attributes. Receive the target attribute value of the attribute from the trained machine learning model; and Modify the attribute of the configuration item to have the target attribute value.

11. The method according to claim 1, wherein, The configuration item is associated with multiple attributes, wherein the configuration item before modification is the result of a discovery process performed on the network, and wherein the coordination process includes: A subset of the attributes is provided to a trained generative artificial intelligence (AI) model, wherein the trained generative AI model is trained to predict grouping of attribute values ​​based on other configuration items that have been identified. Based on the grouping representation of the attribute values, the target attribute value of the attribute is received from the trained generative AI model; and Modify the attribute of the configuration item to have the target attribute value.

12. The method according to claim 1, wherein, The configuration item is one of a plurality of configuration items that have been identified as failing, wherein the plurality of configuration items are stored in memory as one or more files or database entries, and wherein performing the coordination process includes reading a data block containing the configuration item but less than all of the plurality of configuration items from the one or more files or database entries.

13. The method according to claim 1, wherein, The configuration item is one of a plurality of configuration items that have been identified as failing, wherein the plurality of configuration items are stored in memory as one or more files or database entries, and wherein performing the coordination process includes iteratively streaming data blocks, each containing a different subset of the configuration item, from the one or more files or database entries.

14. A non-transitory computer-readable medium having stored thereon program instructions, which, when executed by a computing system, cause the computing system to perform operations including: The configuration item recognition failed, among which, The configuration item represents the computing hardware or software associated with the network; If the configuration item fails to be identified, a coordination process is executed, wherein the coordination process modifies the attributes of the configuration item. Confirm that the modified configuration items pass the identification; and Write the modified configuration items into the database.

15. The non-transitory computer-readable medium of claim 14, wherein the configuration item prior to modification is the result of a discovery process performed on the network, wherein, The coordination process includes re-executing the discovery process on at least a portion of the network, wherein re-executing the discovery process includes performing the discovery process on a subset of the network identified by a set of network addresses or a series of component identifiers.

16. The non-transitory computer-readable medium according to claim 14, wherein, The configuration item before modification is the result of a discovery process performed on the network, wherein the coordination process includes re-performing the discovery process on at least a portion of the network, and wherein re-performing the discovery process includes performing the discovery process using a different set of access credentials.

17. The non-transitory computer-readable medium of claim 14, wherein the attribute has a null value or an improperly formatted value prior to the execution of the coordination process, and wherein, The coordination process modifies the attribute to have a non-empty and correctly formatted value.

18. The non-transitory computer-readable medium according to claim 14, wherein, The configuration item is associated with multiple attributes, wherein the configuration item before modification is the result of a discovery process performed on the network, and wherein the coordination process includes: A subset of the attributes is provided to a trained machine learning model, wherein the trained machine learning model is trained to predict the target attribute value that has enabled other configuration items to pass identification based on the values ​​of the subset of the attributes. Receive the target attribute value of the attribute from the trained machine learning model; and Modify the attribute of the configuration item to have the target attribute value.

19. The non-transitory computer-readable medium according to claim 14, wherein, The configuration item is associated with multiple attributes, wherein the configuration item before modification is the result of a discovery process performed on the network, and wherein the coordination process includes: A subset of the attributes is provided to a trained generative artificial intelligence (AI) model, wherein the trained generative AI model is trained to predict grouping of attribute values ​​based on other configuration items that have been identified. Based on the grouping representation of the attribute values, the target attribute value of the attribute is received from the trained generative AI model; and Modify the attribute of the configuration item to have the target attribute value.

20. A system comprising: One or more processors; as well as A memory containing program instructions that, when executed by the one or more processors, cause the system to perform operations including: The configuration item identification failed, whereby the configuration item represents computing hardware or software associated with the network; If the configuration item fails to be identified, a coordination process is executed, wherein the coordination process modifies the attributes of the configuration item. Confirm that the modified configuration items pass the identification; and Write the modified configuration items into the database.