Servicenow Discovery Command Audit Logs(New feature in Quebec)
Ravindra Reddy Duggireddy
Experienced ServiceNow Architect | Transforming Business Processes with Innovative Solutions | AI Enthusiast
During the servicenow discovery we may executes list of PowerShell and ssh commands on the remoter servers.
The MID server command audit log is a record of the command.
How to enable the command audit log?
Add following MID server property to access the feature
Once enabled, the MID Server command audit log are access in the in MID Server > Command Audit Logs.
By default, the table is rotated every seven days.
Table column details:
Command:
The exact command that MID server run on the server or in cased running a script, it would be the script name.
Credentials :
Display the credentials used for running the commands.
Execution Status:
Identifies if the command execution was success or failed
MID Server:
Which MID server being used to run the commands
Target Device:
IP Address of the server
Roles
Visible only to the users with "agent_security_admin" role.