Ivanti Automation Integration
13 min
ivanti automation (ia) integration enables customers to create requests for every day manual tasks like account unlock, reset password, computer provisioning and more using the integration of with ivanti automation, administrators can automate these tasks to remove the manual steps configuring neurons for itsm utility connector docid\ gfregvwv4kvxzpo5ejbvvconfiguring ivanti automation in neurons for itsm docid\ gfregvwv4kvxzpo5ejbvvconfiguring and syncing run books docid\ gfregvwv4kvxzpo5ejbvvconfiguring ivanti automation block properties docid\ gfregvwv4kvxzpo5ejbvvenabling automation for other business objects docid\ gfregvwv4kvxzpo5ejbvvtroubleshooting docid\ gfregvwv4kvxzpo5ejbvv intended audience this guide is intended for administrators who are familiar with setting up integrations through the administration ui users should also be familiar with the terminology and navigation of the ivanti automation console in order to set up and configure global variables, modules and run books prerequisites ivanti version 2018 1 x or later ivanti automation version 2018 1 or later download of the ivanti utility connector from the ivanti marketplace at the following path https //marketplace ivanticloud com/packages/ivanti service manager update record connector/ https //marketplace ivanticloud com/packages/ivanti service manager update record connector/ follow the instructions in the configuring neurons for itsm utility connector docid\ gfregvwv4kvxzpo5ejbvv section (below) to install and configure the connector ensure the following global variables are included in your ivanti automation environment (refer to screen shot below) ivanti service manager password password to connect to the server ivanti service manager role role of the user to connect to the server ivanti service manager tenant tenant that must be connected ivanti service manager tenant url url of the server that must be connected ivanti service manager username user name to connect to the server ivanti automation, version 2018 1 needs to be installed on one of the computers with all the necessary components such as the console, as well as at least one dispatcher, and an agent the dispatcher webapi is disabled by default you can enable it by enabling the global setting webapi state ( setup > global settings > dispatcher webapi section) or the setting on dispatcher level ( topology > dispatchers > settings > dispatcher webapi section) when using the dispatcher webapi in your ia environment, it is also possible to secure communication using https configuring neurons for itsm utility connector save the following two files to the ivanti automation server ivanti service manager go to ivanti marketplace and search for ivanti service manager utility connector at the following path https //marketplace ivanticloud com/packages/ivanti service manager update record connector/ https //marketplace ivanticloud com/packages/ivanti service manager update record connector/ ivanti solution installer download the ivanti marketplace solution installer exe at the following path https //marketplace ivanticloud com/tools/importer https //marketplace ivanticloud com/tools/importer run the ivanti package installer when prompted browse to the location of the connector installer it will have a nupkg extension follow the steps of the unpackaging wizard you may need to close and reopen ivanti automation to see the ivanti service manager general task by default, integration to ivanti automation is enabled for request offerings only automation can be enabled for additional business objects as required configuring ivanti automation in neurons for itsm log in to and select your role as an administrator navigate to more , and under my workspace , select the ivanti automation configuration workspace the ivanti automation configuration workspace is displayed with default values host base url to access the automation server username username that is used to access the automation server password password that is used to access the automation server authentication type of authentication to connect the automation server primary host option to be selected, if it is a primary host for the automation server update the configuration details click save to save the configuration details configuring and syncing run books in ivanti automation, you can create and configure specific tasks by creating separate modules these modules are included in run books, which can carry out the set of tasks that are needed to be executed for routine it tasks integration requires the ism transaction and p status to trigger completed/failed in the workflow run books that have been created must contain defined parameters ism transactionid recordid of the ivanti automation transaction record which will be sent by p status job status that need to be sent back to using the update record task when configuring the run book, ensure that the parameter setting on the input tab new input value “when scheduling job” is unchecked when configuring the run book in automation, valid values for p status are ‘completed’ and ‘failed’ make sure to enter in one of these two values only once run books have been created, they must be synced with by completing the following steps log in to and select your role as an administrator click the configuration icon in the upper right corner in the left hand pane, go to integration tools and then select web service connections scroll down to ivnt automation runbooks and select the edit icon follow the steps to run the integration process and select next after each step once you are done, select publish you can also schedule this to run every day/hours by defining the schedule entry verifying the synced run books back in , leave the administration ui and from the client ui, open the request offering workspace click account unlock to open this request offering select the plan request fulfillment tab double click the ivanti automation block in the workflow the ivanti automation block properties dialog box opens the value drop down list shows all the run books that have been created select the appropriate run book for this particular task and click save if the synced run books do not appear; give the process a minute or two to complete if run books still do not appear in the drop down, refer to the troubleshooting section (below) to review the logs that will help guide you in verifying settings once complete, re run the process to sync run books configuring ivanti automation block properties log in to and select your role as an administrator navigate to more , and under my workspace , select the request offering workspace from the list available, select the desired request offering select the plan request fulfillment tab from the fulfill as list, the workflow option is selected by default navigate to integration , and then double click the ivanti automation block in the workflow the ivanti automation block properties dialog box opens depending on the run books created in the ivanti automation tool, add or edit the required parameters for example, for account unlock, only the p username parameter is required in the example below, a service request variable was used as the p username parameter no values are required for p status or ism transactionid click save to save the parameters click save on the page to save the entire request offering enabling automation for other business objects to enable the ability for other business objects to call runbooks and trigger automation, follow these steps prerequisite create a relationship between the target business object for example, change and the ivnt automation transactions business object example relationship between servicereq and ivnt automation transactions it is mandatory to create a relationship between the target business object and the automation business object before you run the automation workflow, else it will not work steps configure the automation integration per the instructions above; ensuring runbooks sync without issue run the workflow field description relationship details designer name the name of the relationship the system enters a dummy value when you first create the relationship you can change this name; however, after you save the relationship for the first time, you cannot change this value display name the relationship name that is displayed in the ui you can change the name that the system displays in the ui, but that does not change the actual (designer) name of the relationship internal reference name the exact, internal reference name for this relationship you set this value when you initially create the relationship however, after you save the relationship for the first time, you cannot change the value this name is part of the relationship key name and the other object relationship key you use this name in expressions when you refer to other business objects we recommend that you make the name compact and meaningful because there can be several relationships between the same two database tables to set the value, click not set and enter a value relation to the related business object the system automatically populates this field based on the business object that you selected in step 5 above relationship key specifies the name of the relationship you use this name in expressions when you refer to other business objects the system automatically populates this field and you cannot change it it is in the format \<relation to># \<internal reference name> reverse relationship key specifies the name of the other object relationship you use this name in expressions when you refer to other business objects the system automatically populates this field and you cannot change it it is in the format \<business object># \<internal reference name> direction specifies the direction of the relationship, either normal or reversed can be used for troubleshooting the system automatically populates this field and you cannot change it relationship is audited specifies if the relationship is to be audited the system automatically creates an entry in the audit history log when the relationship is used to link or unlink related business objects full text search enabled enables the relationship to be included in full text searches for queries to return related business objects, at least one field in the business object and related business objects must be enabled for full text search prevent delete when linked objects exist shown only if the value of the direction field is set to normal prevents you from unexpectedly deleting linked business objects, which could cause problems when checked, you cannot delete an instance of the business object type that contains the relationship definition if one or more related business object links exist this setting only applies to one side of the relationship for example, incidentassociateschange is a many to many relationship the incident business object definition contains a relationship definition for incidentassociateschange the change business object definition contains a reverse relationship definition for incidentassociateschange if you check prevent delete when linked objects exist for the incident business object but do not check that field for the change business object, when an incident is linked to a change, you cannot delete the incident until the link is removed however, you can delete the change without first removing the link this business object \[defines how many parent business objects are permitted relative to the child business object (cardinality)] zero or one specifies that a parent record in this business object either has a zero to one or a one to one relationship with a single child record for example, an employee (parent) can have one service level agreement (child) exactly one specifies that a parent record in this business object has a one to one relationship with a single child record for example, an employee (parent) can have one service level agreement (child) zero or many specifies that a parent record in this business object either has a zero to many or a one to many relationship with its child records for example, an employee (parent) has many incidents (children) many specifies that a parent record in this business object has a one to many relationship with its child records for example, an employee (parent) has many incidents (children) binding type associates with makes the current business object related to the child business object so that if you delete the current business object, the system does not delete the child business object contains makes the current business object the parent business object in a parent child relationship if you delete the parent business object, the system deletes the child business object that is specified in the relationship use link table (for many to many relationships) read only, and only used with many to many relationships defines how the data is passed between records in a many to many relationship, two business objects are considered related when the appropriate record containing recids of two business objects exists in a link table if this option is selected, you can use the default fusion link table, which contains standard constraints called parent link fields (housed in the child and store the recid of the parent), or you can enter another database table to be used as a link table specific transaction details zero or one specifies that a parent record in this business object either has a zero to one or a one to one relationship with a single child record for example, an employee (parent) can have one service level agreement (child) exactly one specifies that a parent record in this business object has a one to one relationship with a single child record for example, an employee (parent) can have one service level agreement (child) zero or many specifies that a parent record in this business object either has a zero to many or a one to many relationship with its child records for example, an employee (parent) has many incidents (children) many specifies that a parent record in this business object has a one to many relationship with its child records for example, an employee (parent) has many incidents (children) one of the following primary key (if normal direction) foreign key (if reversed direction) the primary key (if this is a normal relationship) or the foreign key (if this is a reversed relationship) the system automatically populates this field, but you can overwrite it troubleshooting if your run book does not execute as planned or the workflow does not execute properly, there are a number of areas you can go to troubleshoot viewing the automation transaction business object ivanti automation transaction this business object logs all the transactions that have been carried out particular to this integration this provides the status of the job and the logs related to a particular transaction viewing the integration log to view the details of the processed job, you can view the integration log workspace log in to using the administrator role open the integration log workspace to open the workspace, select more > integration log from the integration log workspace, view the information in the columns for the list of logs or open a record to view details viewing the integration queue while the job is being processed, you can view the record from the integration queue workspace after the job is processed, the record will not be available from the integration queue workspace you can then view it from the integration log workspace log in to using the administrator role open the integration queue workspace to open the workspace, select more > integration queue the workspace will be empty when there are no records to process when the record appears in queued status in the integration log workspace, then the record appears while it is being processed in the integration queue workspace
