You are here:
Agentless Discovery for Scanning IT Assets
Use agentless discovery to identify assets across on-premises, virtual, and cloud environments without installing software agents on each device. Do agentless discovery by using discovery applications, targets, probes, and scan jobs to collect system data through secure network protocols. After each scan, the collected information is processed and updated in CMDB to maintain accurate configuration data.
Required Editions
| Available in: Lightning Experience |
| Available in: Unlimited, Enterprise, and Performance Editions with Agentforce IT Service that have Discovery enabled. |
Start agentless discovery by downloading and installing the discovery application on a Windows host. The application acts as the scanning engine for agentless discovery. After installation, create discovery targets to define what to scan, such as IP ranges, hostnames, or cloud connectors. Each target includes one or more probes that determine how data is collected from systems in that scope. Probes gather information about the operating system, network, hardware, and applications. Associate credentials with each target to allow authenticated access and ensure accurate data collection.
Run scan jobs to manage and monitor agentless discovery. Each scan job initiates the scanning process, tracks the progress, and records when the discovery run starts and completes. The scan job also captures the targets covered and the data collected during the run. After completion, the discovery application sends the scan results to CMDB, where CMDB processes the information, identifies unique assets, and updates configuration items to keep data accurate and current.
See Key Terms in Discovery for definitions of discovery applications, targets, probes, and scan jobs.
An IT administrator installs the discovery application on a Windows host to perform agentless scans. The administrator creates a discovery target and selects deep host scan (WMIC, SSH, SNMP) as the probe type. The target includes IP ranges for Windows and Linux servers within the data center, along with the required SSH and WMI credentials. When the scan job runs, the discovery application connects securely to each server, collects data about the operating system, network interfaces, and installed applications, and sends the results to CMDB. CMDB processes the collected information and updates configuration items to reflect accurate configuration data.
- Download and Install the Discovery Application
Use the Discovery Application to perform agentless scans and collect asset data without installing software on each device. The Discovery Application runs on a Windows host and securely connects with your network to detect systems, identify configurations, and send discovery data to Configuration Management Database (CMDB) for processing. - Create Discovery Credentials for Secure Scanning
Use discovery credentials to securely connect to systems and collect data during agentless scans. Credentials authenticate access to devices, applications, and cloud environments without manual sign-in. Create and manage credentials for supported types such as Windows, SSH, SNMP, or AWS to ensure accurate and authorized discovery results. - Create a Discovery Target
Create a discovery target to define where and how agentless discovery scans IT environments. Targets define the systems, IP ranges, and environments included in agentless discovery. Each target also specifies probe types that determine how those systems are scanned. When a target runs, it creates a scan job that collects discovery data and updates asset information in Configuration Management Database (CMDB). - Configuration Fields for Target Categories and Probe Types
Understand the configuration fields that define each agentless discovery target type. Identify which fields appear dynamically for different target category and probe types in the Configure Scan Target Details page so that you can configure discovery targets accurately. - Manage Discovery Targets
View, run, or manage existing discovery targets to maintain and reuse scan configurations efficiently. - Monitor and Review Scan Jobs
Monitor discovery progress and review scan results with scan jobs. Each scan job tracks the execution of a discovery target and provides detailed visibility into discovered assets, scan duration, and completion status. Use the scan job details to verify discovery coverage and ensure that your CMDB data remains accurate and up to date.

