Skip to main content
VanPaulTek
ServiceNow ITOM

IT Operations Management on ServiceNow.

Discovery, Service Mapping, Event Management, Orchestration, Cloud Management — the operational layer that makes ITSM actionable.

6
ITOM sub-modules
3
Cloud providers (AWS/Azure/GCP)
24/7
Ops coverage available
90%
Alert-noise reduction possible
About ITOM

The eyes, ears, and hands of IT operations.

ITOM (IT Operations Management) is what turns raw infrastructure signals into actionable operational intelligence. Discovery tells you what exists; Service Mapping tells you what depends on what; Event Management tells you what's broken; Orchestration lets you fix it.

Done right, ITOM is the multiplier for every other ServiceNow investment — the trusted CMDB, the accurate impact analysis, the auto-created incidents, the runbook automation.

VanPaulTek has been delivering IT operations tooling for over 20 years — pre-ServiceNow, we delivered it on Micro Focus, HP Openview, and homegrown platforms. That history informs how we deliver ITOM today.

Sub-modules

Six sub-modules, one operational layer.

Each solves a distinct operational problem. Together they form the fabric under ITSM.

DISC

Discovery

Automated discovery of servers, applications, network devices, storage, and cloud resources across the estate.

  • Agentless SSH/WMI/SNMP discovery
  • MID Server design and deployment
  • Discovery schedules + IP address management
  • Credential vault + credentialless discovery
  • Discovery data reconciliation to CMDB
  • Cloud discovery via Service Graph Connectors
SMAP

Service Mapping

Business services mapped to the infrastructure that runs them. The foundation for real impact analysis.

  • Top-down service definition
  • Pattern-based service maps
  • Application dependency mapping
  • Manual + automatic map maintenance
  • Service map health monitoring
  • Impact + change simulation using maps
EVT

Event Management

Correlation, deduplication, enrichment, and auto-incident creation from monitoring signals.

  • Event ingestion connectors (Splunk, Datadog, Dynatrace, SolarWinds…)
  • Event field mapping and normalization
  • Correlation rules + alert clustering
  • Auto-incident creation with impact analysis
  • Event-driven remediation triggers
  • Operator Workspace for real-time triage
ORCH

Orchestration

Automation of repeatable operational tasks — password resets, provisioning, remediation.

  • Flow Designer for cross-system orchestration
  • Runbook automation library
  • Provisioning workflows (AD, cloud, VDI)
  • Self-service automation via catalog
  • Remediation triggered from events
  • Approvals + audit trail for automated actions
CLD

Cloud Management

Multi-cloud governance — provisioning, cost, and policy across AWS, Azure, GCP.

  • Cloud provisioning via catalog
  • Multi-cloud CMDB integration
  • Cloud discovery scheduling
  • Tag governance + policy enforcement
  • Cost attribution + showback
  • Cloud service graph for topology
MID

MID Server

The bridge between ServiceNow (cloud) and your on-prem environments. Fundamental for discovery and orchestration.

  • MID Server architecture design
  • High availability + load balancing
  • Credential vault + secure access
  • Network segmentation strategy
  • Capacity planning + monitoring
  • MID Server upgrade + patch cycles
Full lifecycle

How we deliver ITOM.

Design, architect, develop, implement, and support — five phases, one accountable team.

01
Phase 01

Design

Operational goals + CMDB strategy come before tool configuration.

  • Discovery scope: what's in, what's out, phases
  • Business service inventory + prioritization for Service Mapping
  • Event routing strategy: which sources, which teams, which SLAs
  • Automation candidates: repetitive tasks to orchestrate first
  • CMDB target class model + data quality objectives
  • Cloud governance policies (tags, provisioning, cost)
02
Phase 02

Architect

The network, security, and data plumbing that ITOM needs.

  • MID Server placement + high-availability topology
  • Network + firewall design for discovery access
  • Credential management strategy (vaults, service accounts, PAM)
  • Event source integration architecture (streams, adapters, APIs)
  • Service map pattern architecture
  • Data flow: discovery → CMDB → ITSM impact analysis
03
Phase 03

Develop

Configuration, integrations, patterns, workflows.

  • MID Server deployment + hardening
  • Discovery schedule development + tuning
  • Service Map pattern development (out-of-box + custom)
  • Event connector configuration + field mapping
  • Correlation rules + alert clustering logic
  • Orchestration workflow build with test coverage
04
Phase 04

Implement

Phased rollout — infrastructure first, then services, then automation.

  • MID Server rollout + connectivity validation
  • Discovery pilot → phased production rollout
  • Service Map build for tier-1 business services first
  • Event source cutover with parallel-run period
  • Auto-incident enablement with human review initially
  • Runbook automation launch with approval gates
05
Phase 05

Support

Continuous tuning — discovery, events, and automation drift over time.

  • Discovery tuning: new hardware, network changes, edge cases
  • Service Map maintenance: new services, deprecated apps
  • Event correlation rule tuning + noise reduction
  • MID Server capacity monitoring + scaling
  • Orchestration expansion: new automation candidates
  • Quarterly CMDB health scoring + remediation
Reference roadmap

A realistic implementation timeline.

Sample roadmap based on real implementations — adjustable to your scope, but grounded in what actually works. Not vendor marketing timelines.

Wk 1-3
Phase 1

Assess & Scope

  • Discovery scope decision (network segments, phases)
  • MID Server topology design
  • Business service inventory + tier-1 selection
  • Event source inventory (SIEM, monitoring, cloud)
  • Automation candidate list (top 10 repetitive tasks)
Wk 4-8
Phase 2

Architect & Deploy

  • MID Server rollout + HA validation
  • Discovery credential vault + service accounts
  • Network + firewall access verified
  • CMDB class model configured
  • Event routing framework defined
Wk 9-14
Phase 3

Discover & Map

  • Discovery pilot → full production rollout
  • Service Map build for tier-1 services
  • Event Management connectors live
  • Correlation + suppression rules baseline
  • Auto-incident creation with review gates
Wk 15-18
Phase 4

Orchestrate

  • Top-5 orchestration workflows built
  • Runbook automation library seed
  • Approval gates for high-impact actions
  • Cloud provisioning via catalog live
  • Multi-cloud governance policies enforced
Wk 19-22
Phase 5

Tune & Optimize

  • Alert-noise reduction (target 80%)
  • Discovery accuracy tuning
  • Service Map accuracy validation
  • Automation expansion (10+ more workflows)
  • KPI baseline captured
Quick wins

Actionable improvements — start Monday.

Practical fixes that don't need a project charter. Ordered by timeframe and impact — the stuff experienced practitioners just do.

Day 1
High

Kill duplicate CIs with reconciliation rule

One-line reconciliation rule can merge dupes based on serial number / cloud instance ID. Immediate CMDB health boost.

Week 1
Medium

Suppress alerts from Retired CIs

Retired assets often still emit signals. Simple suppression rule kills 5-15% of alert noise instantly.

Week 1
High

Enable cloud discovery for AWS via Service Graph

Service Graph Connector for AWS auto-populates 100+ CI classes. First cloud discovery run in <60 min.

Week 2
High

Add priority normalization to Event connector

Every source uses different severity scales. Normalize to a single 1-5 scale at ingestion — downstream everything gets simpler.

Week 2
High

Cluster events by CI + time window

One CI throwing 500 events in 5 min → one incident, not 500. Basic clustering rule = 90% noise cut.

Month 1
High

Automate password reset via chatbot + orchestration

Virtual Agent → Orchestration → Active Directory. Password reset = 15-30% of L1 workload; automate 90%.

Month 1
Medium

Set CMDB attribute-required at import

Force required fields on CI import. Prevents 90% of quality drift at the source vs. cleaning up after.

Month 2
Medium

Auto-remediate disk-space alerts

Common cases: log rotation, temp file cleanup. Orchestration executes runbook; if not resolved, escalate. Reduces P2 volume 10-20%.

Month 2
High

Cloud rightsizing recommendation report

Weekly automated report: over-provisioned cloud instances >2 CPU units unused. Ownership + action tracking.

Success metrics

What good looks like — measurable.

Real KPIs and targets from mature implementations. Track these; if they trend the wrong way, something is off.

Discovery Accuracy
≥95%
within 60 days

% of discovered CIs matching current reality. Below 90% signals credential or reconciliation issues.

Alert Noise Reduction
80-90%
within 90 days

Raw event count vs. correlated incidents. Well-tuned correlation cuts noise 80-90%.

Auto-Incident Accuracy
≥90% actionable
within 60 days

% of auto-created incidents that turn into real work. Below 80% = correlation too loose.

Service Map Freshness
≥90% <90 days old
within 180 days

Stale maps mislead. Should have ownership + refresh workflow.

CMDB Class Coverage
≥85% expected classes
within 180 days

Discovered vs. expected CIs per class. Business services should be near 100%.

Runbook Automation Rate
≥40% of L1 volume
within 12 months

% of L1 work automated end-to-end. Below 20% = orchestration underused.

MID Server Uptime
≥99.5%
within steady state

MID = fabric. Uptime issues cascade into discovery drift + event backlog.

Cloud Cost Attribution
≥95%
within 90 days

Cloud spend attributed to owner via CAM tags. Under 90% = governance failure.

Common pitfalls

The traps we see every project.

Honest warnings from many deliveries — the mistakes that cost time, money, and adoption. These aren't in vendor guides.

!

Discovering everything on day one

Why it fails: Discovery scope creep = crushing amounts of low-value data, huge event volume, unusable CMDB. Data without purpose is noise.

Do this instead: Phase discovery by business value: tier-1 services first, tier-2 next quarter, tier-3 after that.

!

Service Maps that don't get maintained

Why it fails: Applications change; maps go stale in 60-90 days without discipline. Stale maps mislead incident impact.

Do this instead: Service Map ownership + quarterly review workflow. Deprecated apps get maps retired proactively.

!

Alert-to-incident with no correlation

Why it fails: Every monitoring alert = a new incident = 1000+ open incidents/day. On-call rebels, tickets get closed unread.

Do this instead: Correlation + suppression rules before enabling auto-incident. Target 90% event → 10% incident ratio.

!

MID Server sized for day-one workload only

Why it fails: Discovery + event + orchestration workloads grow. Undersized MIDs cause discovery drift, event backlog, timeouts.

Do this instead: Capacity plan for 3-year growth + HA. Monitor MID CPU/memory + queue depth. Scale before problems.

!

Runbook automation without approval gates

Why it fails: Automated actions in production = one bad script = outage at scale. 'It worked in dev' has ruined careers.

Do this instead: Approval gates for high-impact + first-time automations. Gradually loosen once trust is earned.

!

Cloud discovery credentials over-scoped

Why it fails: Discovery credential with Admin access = huge security blast radius. Auditors love this finding.

Do this instead: Read-only cloud roles per provider. Least-privilege discovery. Rotate credentials quarterly.

!

Ignoring CI relationships

Why it fails: Flat CI list = no impact analysis, no service maps, no root cause. CMDB devolves to inventory.

Do this instead: Relationship discovery in scope from day one. Depends On + Runs On + Hosted On populated.

!

Event Management without asset context

Why it fails: Events without CI context can't be routed by ownership. On-call gets everything, ignores most.

Do this instead: Event → CI matching at ingestion. Owner routing based on CI service assignment. Alerts hit the right team.

!

Orchestration workflows in scope-agnostic global scope

Why it fails: Global scope = broken cross-scope calls, upgrade brittleness, permission chaos.

Do this instead: Scoped applications for orchestration. Explicit cross-scope contracts. Upgrade-safe.

Common engagements

What we're typically hired to do.

🔍

CMDB Foundation via Discovery

Populate and maintain a trusted CMDB automatically — servers, applications, network, storage.

🌐

Service Map Build

Map your top-20 business services to infrastructure for real impact analysis.

🔔

Alert-Noise Reduction

Cut 80–90% of alert noise via correlation, deduplication, and enrichment.

Runbook Automation

Automate password resets, VM provisioning, disk-space cleanup — reduce toil.

☁️

Multi-Cloud Governance

Discover, tag, and govern AWS + Azure + GCP from one console.

🌉

Monitoring Consolidation

Bring Splunk + Datadog + Dynatrace + SolarWinds events into a unified operational view.

FAQ

Questions we hear often.

Do we need Discovery before Service Mapping? +

Yes — Service Mapping consumes Discovery data to build application dependency maps. They're typically implemented together, but Discovery first.

How many MID Servers do we need? +

Depends on network topology, discovery volume, and security zones. Small environments: 2 (HA pair). Mid: 4–8. Large / segmented: 10+. We size this in architecture.

Can Event Management ingest from our existing monitoring tools? +

Yes — connectors for Splunk, Datadog, Dynatrace, SolarWinds, Nagios, PRTG, Prometheus, and custom REST integrations for anything else.

What's the typical alert-noise reduction? +

Well-tuned Event Management routinely reduces raw alert volume 80–90% through correlation, deduplication, and enrichment — while raising the signal quality of what does become an incident.

Does Cloud Management replace AWS/Azure native tools? +

No — it augments them. Native tools are best for cloud-specific optimization; ITOM adds cross-cloud governance, ITSM integration, and provisioning-via-catalog.

Can Orchestration replace our existing automation platform? +

Sometimes yes, sometimes no. For ServiceNow-adjacent automation, Flow Designer + IntegrationHub is powerful. For deep DevOps automation (Ansible, Terraform, custom scripts), we integrate rather than replace.

Other ServiceNow modules

Explore the full Now Platform.

Ready to talk about your project?

Reach out — we get back within 1 business day.