Integrating with Ivanti Neurons for Discovery (for ITAM On-Premises only)
12 min
this topic describes how to integrate your local implementation of itam on premises with ivanti neurons for discovery (accessed via the ivanti neurons platform) integration enables you to transfer data from neurons for discovery, such as device and invoice records, into your itam database the transfer of data goes one way, meaning you can't transfer updated records back into neurons for discovery at this time, installed software information for device records is transferable from neurons for discovery, but licensable software information is not getting started before getting started with the integration, make sure you're running itam on premises 2022 3 or higher for details on setting up itam on premises, see setup docid\ mf5nvrumvj5vslsor28gt for existing itsm customers, upgrade to itam by applying the latest itam content package (available from the ivanti marketplace https //marketplace ivanticloud com/?typesearch=c%23ivantiprovided+p%23assetmanagement ) you're licensed to access the neurons platform you have an neurons for discovery tenant set up with data you want to transfer next, follow the sections below, in the order listed, to complete the integration updating the uno landscape configuration this is a one time update required to integrate with neurons for discovery if you need assistance or details about the neurons for discovery tenant settings, contact ivanti customer support before you can update the uno landscape, you first need to obtain url and tenant id values from the neurons platform obtain these values by following the procedure below to identify the apibaseurl and tenant id needed for the uno landscape update log in to the neurons platform as administrator using chrome (or any other supported browser) click the browser's menu and open more tools > developer tools under application > session storage , copy the baseserviceurl value this is the apibaseuri value needed in step 3 of the next procedure under application > session storage , copy the tenantid value (in the username section) this is the unotenantrecid value needed in step 5 of the next procedure to update the uno landscape configuration log in to the itam tenant centralconfig application as administrator if you need assistance accessing this application, contact ivanti customer support if your itam installation doesn't currently display the administrator user role, log in as asset administrator, then add the role via the configuration console > roles and permissions menu for details, see setting up roles https //help ivanti com/ht/help/en us/ism/2022/admin/content/configure/roles/setting up roles htm?highlight=adding%20roles%20and%20permissions in the configuring ivanti neurons for itsm help open the uno landscape workspace click new uno landscape , then enter the following values name any identifiable name, such as "neurons onprem " apibaseuri this is the neurons service fabric url (without an http/s prefix) identified in the procedure above asset import api uri this should be the same value as the apibaseuri, also without an http/s prefix click save open the tenants workspace from the list, select the itam tenant where the data import from neurons platform is to occur, then enter the following values uno landscape from the drop down list, select the name created above in step 3 unotenantrecid this is the neurons platform tenant id identified in the procedure above unotenanturl this is the neurons platform tenant url click save click the reset tenant cache button (top right of page) to ensure that the updates will take effect immediately setting up the app and client registrations complete these procedures to enable the tenants for neurons for discovery and itam to communicate with each other to set up app registration log in to the neurons platform as administrator in the left navigation pane, click admin > app registrations click new registration from the new app registration drop down, select ivanti neurons for itsm and itam , then click continue add a meaningful description, such as "itam on premises," then click register copy both the neurons auth url and client id (you'll need these for the next procedure when you set up client registration in the itam user console) click finish and close to set up client registration log in to itam as administrator open the client registration workspace and click new client registration at the top add the following details from ivanti neurons name any identifiable name, such as "neurons " is on premise this option is selected by default—leave as is client registration url the neurons auth url copied from the procedure above client id the client id copied from the procedure above client secret isn't needed here and verificationurl will auto fill in step 9 below click save in the upper right corner, click register device to register your itam tenant with neurons a pop up message displays, telling you to enter the url into a web browser to finalize the registration copy this url and click ok open a browser and paste in the url (log in as administrator if prompted ) the following screen displays click yes, allow "success" will display if verification was successful in the client registration workspace, click get token (upper right corner) the verificationurl field should update click save important you cannot access data discovered from neurons for discovery from more than one itam tenant at a time because of way app registration works—this is by design to prevent unauthorized access the prior itam tenant ceases receiving data from neurons for discovery if the same neurons for discovery tenant is configured to communicate with another itam tenant enabling the ability to transfer data into itam next, enable the ability to transfer data from neurons for discovery invoice transfers require an additional procedure to update a web config file to set up data transfers log in to itam as asset administrator click the icon in the menu bar at the top of any workspace the configuration console displays in a new browser tab in the left navigation pane, expand build > global constants scroll down the list to enableneuronssyncbyapi and set the value to true click save an information dialog will display; click ok expand configure > cache management click remove all cache items , then click yes click reset cached validation lists only , then click ok important by clearing the cache and then resetting it, you can speed up the process for enabling the connection between the tenants the data transfer may not work immediately if this step isn't performed complete two final procedures from the itam user console, open the asset processor configuration workspace and enable the configurations as shown below on the itam tenant, open the integrationservicehost exe config file (located by default at c \program files\heatsoftware\heat) and do the following update the isonpremise flag by setting it to true the flag is case sensitive and should be in lowercase restart iis and the integration service to update a web config file for invoice transfers on the itam tenant, open the web config file in the installation folder (located by default at c \program files\heatsoftware\heat\imserver\imservices\assetprocessor) copy the data displayed below this section \<centralconfigapikeyconfigprotectionprovider="dataprotectionconfigurationprovider"> for example \<encrypteddata>\<cipherdata>\<ciphervalue>aqaaan aaaeaacaaaadq6\</ciphervalue>\</cipherdata>\</encrypteddata>\</centralconfigapikey> paste the copied data into the web config file in the ivanticlouddataprocessor folder (located by default at c \program files\heatsoftware\heat\imserver\imservices\ivanticlouddataprocessor) confirm \<section name="centralconfigapikey" type="system configuration namevaluesectionhandler"/> is available in the ivanticlouddataprocessor web config file restart iis configuring the neurons connector settings finally, configure the neurons device and/or invoice connector settings for importing the data into itam settings include data filters, field mappings, and the import schedule this is a one time configuration that is saved until you manually change it again to configure the neurons connector settings log in to itam as asset administrator click the icon in the menu bar at the top of any workspace the configuration console displays in a new browser tab in the left navigation pane, expand extend > integration tools > data import connections scroll down the list to ivanti neurons connector – device or ivanti neurons connector invoice ensure the connector is on and set to run now depending on the type of records you want to import (device or invoice), click the corresponding link to open and edit the connector connection setting page we recommend leaving the defaults as they are, although you can change as needed click test connection near the bottom of the page to verify that the connection settings work it's important to test each connector that you're using if the test connection fails, it's most likely a configuration issue and the data will not transfer into the itam database contact ivanti customer support for assistance if the test connection is successful, click next object mapping page we recommend leaving the defaults as they are, although you can change as needed source mapping tables is a list of populated tables based on settings defined on the previous page batch size is the number of records processed at a time for any given job max size is the number of records retrieved each time the connector queries the source database root table is the primary table containing the master data that defines all devices in your organization unique key uniquely identifies all devices in your organization change time column is not currently in use click next filter setting page click create filter to define optional filter conditions for the records you want to import based on the filters defined, only those devices or invoices will be imported from the source database for example, you can choose to import an asset type of laptop by creating the filter value laptop as shown below in the left drop down, select a field from the source database in the middle drop down, select an operator in most cases, you’ll want to select equal in the field to the right, enter your filter condition you can only add one filter per row use the and/or conditions as necessary and click the icon to add more filters to the list to remove a filter, click the icon when finished, click next field mapping page define how fields in the source database are mapped to fields in the target itam database the left column displays source field names, the middle column displays transformation functions, and the right column displays target field names it's assumed that the source mapping names are known or identified in advance for an overview of available functions, see (pdf) for guidance about target field mappings, see (pdf) when finished, click next schedule setting page schedule when the connector will sync with the neurons platform to import data into itam available options are located in the schedule list you can select more than one schedule using the ctrl button on your keyboard click next review & publish page click preview to ensure that the mappings look as expected click back to make any changes when you’re satisfied with the results, click one of these options publish to save your settings and run the connector at the schedule(s) you set publish & run now to save your settings and run the connector immediately with this option, you can monitor the data transfer in real time see the next section for details publish & test run to conduct a test run of the connector but not save the records to the target itam database confirming the data is importing correctly after integration is complete, you can view details about an import job as it's occurring from the itam user console open the integration queue workspace to monitor the job progress, which may take a while refresh the page as often as needed you’ll see the status of the import job go from queued to running to completed the job will disappear from this workspace when completed open the message queue journal workspace to view incoming messages related to the transferred data click decompress message (top right of page) to view details about specific, discovered records by default, this option is disabled to enable it, see the troubleshooting section below open the integration log workspace to view any errors associated with the import job if a job was successful, stats display under logtype when errors are encountered, stats and errorstats display double click errorstats to view a summary of the errors imported data will display in the correct workspace for the record type—devices display in hardware assets and invoices display in the invoices workspace you may need to refresh those workspaces before the data displays at this time, installed software information for device records is transferable from neurons for discovery, but licensable software information is not troubleshooting the integration log workspace may display an error during token renewal for the itam tenant you can ignore this error or use the following workaround to prevent it from happening to work around a token renewal error log in to itam as asset administrator click the icon in the menu bar at the top of any workspace the configuration console displays in a new browser tab in the left navigation pane, expand extend > integration tools > web service connections scroll down the list to renew jwt for neurons and click the edit icon click next to open the integration script page update the scripts section with the following text console log("start token refresh");refreshonpremtoken('refreshtokenfromneurons');console log("end token refresh"); click next until you reach the review and publish page click publish and run now the following tips address issues you may encounter when viewing the message queue journal workspace during a data transfer to fix invoice messages struck in a dispatched state or marked as timed out before updating the web config file in this procedure, make sure you make a backup of the original on the itam tenant, go to c \program files\heatsoftware\heat\imserver\imservices\ivanticlouddataprocessor open the web config file under the \<client> section, do the following ensure there's only one element with an attribute binding of nettcpbinding imessagequeueservice if there are multiple elements, remove all except one ensure the address attribute of that element is this address net tcp\ //localhost 720 0 / for example \<endpoint address="net tcp\ //localhost 7200/" binding="nettcpbinding" bindingconfiguration="nettcpbinding imessagequeueservice" contract="messagequeueservice imessagequeueservice" name="nettcpbinding imessagequeueservice" /> you can use the host name/server name instead of localhost update the port number to 7200 if any other port is configured save the file to enable the decompress message option enable this option to view details about specific records as they're being processed during a data transfer log in to itam as asset administrator click the icon in the menu bar at the top of any workspace the configuration console displays in a new browser tab in the left navigation pane, expand build > automation tools > quick actions to open the quick actions workspace scroll down the list and click frs messagequeuejournal click the quick actions tab in the left side panel, click decompress message click edit to open the edit expression window add the device type in the disable in ui when expression field as shown below click save
