Best Practice for Deployment Order to Avoid Issues
New article articles in ServiceNow Community
·
Aug 24, 2026
·
article
I am sure you all have heard the story of the sand, pebbles, and rocks before. It is all about the order you add them, so everything fits in a jar. Let’s put this in Centrix terms.
If you add the “sand or span” first, then you increase the number of duplicate devices that may not get merged later down the road.
If you add the integrations with strong identifiers first, then by the time the “sand or span” is added everything merges correctly and the system runs in the most efficient manner.
Why is this? Placement of Armis collectors determines the quality of the span. If the span is mostly L3 or IP only traffic, then strong identifiers are not created. For Centrix to create a “strong” device or what we call “Full Visibility” we need a valid MAC address and IP address pair. If the span is getting good L2 & L3 traffic, then we have better quality data.
There is a better process to always guarantee good quality data upfront. It is all about deployment order.
You want the span as close to the assets as possible. Distribution switches are ideal for span location as they will see traffic coming from access switches plus see traffic going to the core.
Let’s talk about how we can improve deployments.
Device ARP = Rocks
Device MAC = Pebbles
SPAN = Sand
Data enrichment integrations can be added later to add more data to Centrix.
What integrations provide the strong ARP identity data (in preferred order):
Network Mapper
WLC
Aruba Central
Aruba Instant
Aruba WLC
Cambium cnMaestro
Cisco Catalyst
Cisco WLC
Cisco DNA Center
Cisco Meraki
ExtremeWireless WING
HP WLC
Juniper MIST
What integrations provide the strong MAC identity data (in preferred order):
Endpoint Agents
Absolute
Carbon Black Defense
Check Point Harmony
Cisco Secure Endpoint
Cortex XDR
Crowdstrike
CylancePROTECT
FireEye Endpoint Protection
Ivanti Endpoint Manager
Malwarebytes
McAfee ePO
Microsoft Defender
SentinelOne
Symantec Endpoint Protection
Sophos Endpoint Protection
DHCP
BlueCat DDI
Infoblox DDI
Infoblox DDI Syslog
Microsoft DHCP
Efficient SOLIDserver DDI
Cloud Integrations
AWS
Microsoft Azure
Google Cloud
Virtual System Management
Microsoft Hyper-V
vSphere vCenter
Nutanix Prism
NAC/Firewall
Aruba Clearpass
Check Point IoT Controller
Cisco ASA
Cisco ISE
Fortinet Fortigate
Palo Alto Network Enrichment
Palo Alto GlobalProtect
Zscaler
Once the device IDs are created with good MAC and IP pair information then you go for the spread effect with SPAN. Think of it this way. The ARP and MAC information is very focused like a sniper rifle. The SPAN is like a big net catching the spray of pellets from a shotgun.
After the assets (device IDs) are created, then focus on all the other integrations to add data enrichment. The are integrations that provide user information, application data, endpoint information, etc. Please do not add enrichment integrations (e.g. SCCM, Active Directory, JAMF, InTune, etc) until you have added the ones from the above list first. This will help reduce duplicate device issues.
Centrix does have auto merging but there are limitations.
We first merge devices that have strong identifiers like ARP and MAC data.
We next merge by device name but only if both devices are classified as Full Visibility. We do not merge a Limited Visibility (IP address only) with a Full Visibility.
We can merge by Serial numbers which is good for medical devices.
If you do not start with a good foundation of ARP and MAC, then your tenant will have more duplicate devices. To address this, Centrix has a manual merge feature by name. Each time you do a manual merge the AI learns from this to help future merging.
https://www.servicenow.com/community/armis-articles/best-practice-for-deployment-order-to-avoid-issues/ta-p/3590708