The old adage that you cannot manage what you cannot measure has never applied
more directly than it does to IT asset identification.
Not being able to measure accurately what hardware and software you have
installed reaches well past basic IT Asset Management. It determines whether you
can defend a software audit, and whether you can optimise licensing to reduce
cost going forward. Both of those are downstream of one question: do you actually
know what is there?
Here are the issues organisations most often run into.
The first problem is the inventory tooling itself.
Most organisations work out quickly that manual discovery and inventory is not
viable. It takes so long that the information is stale on delivery. So the first
requirement of a discovery and inventory tool is that it gives you current
information, continuously, rather than a periodic snapshot.
What happens next is more insidious. An organisation buys a tool to solve one
problem, then a different tool to solve another. There is hardware to discover
and software to discover, and the two rarely arrive in the same product. Add a
tool for the data centre, one for Unix, one for mobile, and the number of tools
in use — each of which itself needs managing — grows past the point of
usefulness.
The result is many separate information feeds that have to be collated before
they mean anything for ITAM, SAM or software licence optimisation. You would
expect that collation to be straightforward. It very rarely is, even between
products from the same vendor.
Are you discovering everything?
A fragmented approach makes it hard to introduce any real quality assurance over
whether all hardware and software is being found.
You might be content with a discovery rate of, say, 95%. Consider what that
means. Across 10,000 devices, 95% leaves 500 machines you do not know about. Not
500 devices that are slightly out of date — 500 you have no record of at all.
Whatever is installed on them is unlicensed by default, unpatched by default, and
invisible to every control you have built.
You do not need an industry average to make that uncomfortable. Put your own
device count and your own confidence level into the same sum, and the number that
comes out is the size of the gap you are currently carrying.
Attributes, not just presence
Even where a tool finds everything, it may not return everything you need.
Effective SAM depends on attributes that basic discovery tends to get wrong or
omit entirely. Processor core counts and core factors. Which hypervisor a
workload sits on, and how that hypervisor’s licensing rules apply. Cluster
membership. Partition configuration on Unix hardware. Whether a machine is
covered by a licence pool, and under which hosting terms.
These are exactly the fields a publisher’s audit turns on. A tool that reports a
server exists, but reports its processor topology incorrectly, has not given you
a compliance position. It has given you a liability with a tick next to it.
Entitlement you cannot produce
Beyond tools, there is the question of how you manage licence entitlement.
Many organisations have no central repository for entitlements, or a fragmented
one spread across procurement systems, mailboxes and spreadsheets. Combined with
the absence of a Definitive Media Library, that means you cannot prove your right
to use software when you are challenged during an audit.
This one is genuinely solvable in-house. Collecting and collating entitlements
into a central repository that incorporates a DML lets you understand your
shortfalls before someone else does, and react properly when an audit is
announced. The work is unglamorous and it is worth doing regardless of tooling.
What closes these gaps
Each of the four problems above has a specific answer in CerteroX ITAM and
CerteroX SAM.
Against tool sprawl: one schema. Ten discovery methods — native agent,
command-line inventory (csinvcli), agentless, standalone, Active Directory
import, network scan, third-party ITAM import, cloud and SaaS connectors, browser
monitoring and file metering — all land in the same data model. Twenty-eight
named system connectors bring in what you already run rather than demanding you
replace it. There is no collation step afterwards, because the feeds were never
separate.
Against incomplete discovery: find things before you own them. Network
Discovery sweeps a class-C subnet in under five seconds using NetBIOS, SNMP and
ICMP, then probes to establish where an agent can actually be deployed. Six
operating system families share one native agent — Windows, macOS, Linux, IBM
AIX, HP-UX and Oracle Solaris — so the platforms most tools treat as an
integration problem are treated here as operating systems. Agentless and
command-line inventory cover locked-down machines, standalone inventory covers
air-gapped and offline systems, and non-persistent VDI is supported directly.
Duplicate system detection and stale device archiving keep the record honest as
it ages.
Against missing attributes: the fields the audit turns on. Processor types
and core factors, cluster and virtualisation awareness for SQL Server and Windows
Server core licensing, IBM PVU and Virtual Processor Core metrics with an ILMT
connector and compliance gap analysis, and Oracle options and packs reported with
evidence and an override. Connectors read VMware, Hyper-V, Citrix XenServer, IBM
HMC, Oracle VM, Red Hat oVirt and Nutanix, so virtualisation is interpreted from
the platform rather than inferred from the guest.
Against unprovable entitlement: a repository that is part of the position.
Licences, transactions, agreements, maintenance, suppliers and publishers are
held in one place, with assignment by device, processor or core, Microsoft
Licence Statement import, volume, retail, OEM and FPP transaction capture,
subscription expiry tracking, and purchase order and invoice capture. The
effective licence position — purchased, used, available, required, variance,
exposure — is computed continuously from that entitlement against real inventory,
rather than assembled the week the audit letter arrives.
On the question of whether the evidence survives contact with a publisher:
Certero is verified by Oracle License Management Services, which means Oracle’s
audit team can accept data from Certero during an official audit, as an
alternative to installing Oracle’s own measurement tools.
The point
No tool will honestly promise you perfect discovery, and you should be wary of
one that does. What you can reasonably demand is that every method reports into
one model, that the difficult platforms are covered natively rather than
excluded, that the attributes licensing actually depends on are collected
correctly, and that your entitlement sits somewhere you can produce it from under
pressure.
Get those four right and IT asset identification stops being the thing that
delays every other decision.
Book a demo, or read more about CerteroX ITAM and
CerteroX SAM.