---
sourceDocument: Australia IT Operations Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/de-DE/it-operations-management

 Release :

    - australia

ft:locale :

    - de-DE

ft:publication_title :

    - Australia IT Operations Management

ft:clusterId :

    - itom

bundleId :

    - itom

workflow :

    - Technology


---

# Beats

# Configure advanced settings for Beats data inputs in Health Log Analytics manually {#ariaid-title1}

* Freigeben Version: Australia
* 
* Aktualisiert 12. März 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 Minuten Lesedauer

Configure advanced settings for data inputs that use Beats agents.

## Vorbereitungen

Role required: evt_mgmt_admin

## Warum und wann dieser Vorgang ausgeführt wird

You can set system parameters for reading log data that determine the actions that the system performs on log data arriving on log data arriving on the MID Server. For example, you can set the time zone to use if a log lacks a timestamp. If no advanced settings are configured, the system uses the default values.

For information about how to change settings that were configured when the data input was created, such as adding a new path or changing the data input's MID Server destination or port, see [Modify a data input configuration in Health Log Analytics](https://servicenow-prod.fluidtopics.net/~mWyF~DUvSr5fOXgJV8_Tw "Change the configuration of a data input for Health Log Analytics by adding a new path to an existing data input configuration or modifying the data input's MID Server destination and port.").

## Prozedur

1. Navigate to AllHealth Log AnalyticsData InputData Inputs.
2. Open a Beats data input record from the Data Inputs table.  
   The data input configuration displays.  
   Hinweis:  
   The number of log sources that the data input has created is shown in the Sources count field. For more information about data input sources, see [Log data auto-mapping and mapping in Health Log Analytics](https://servicenow-prod.fluidtopics.net/8w9omk2yu0EcrcYh342TMw "By default, the HLA Engine tries to auto-map every incoming log line to the correct tags. You can change automatic mapping results manually by defining a JavaScript function.").  
   Hinweis:  
   If the HLA engine is down and data has stopped streaming, a notification appears at the top of the data input configuration page. When this happens, contact ServiceNow support.
3. Select Advanced.
4. On the form, fill in the fields.  
   For a description of the fields, see [Rsyslog, Filebeat, or Winlogbeat data input configuration fields](https://servicenow-prod.fluidtopics.net/rlkBguXfEQAWbgf0QmSSDQ "Description of the fields on the Rsyslog, Filebeat, and Winlogbeat data input configuration forms.").
5. **Wahlweise:** In the Streaming Sources related list, verify that this data input is streaming log data from all relevant endpoint devices.  
   For more information about streaming sources, see [Identify and resolve a log streaming issue in Health Log Analytics](https://servicenow-prod.fluidtopics.net/2seky3xZmOq3ItIEPJ43OQ "Find and address log streaming issues to verify that your data inputs are streaming log data to your instance properly.").
6. Select Save.  
   Health Log Analytics adds the data input record to the Data Inputs table.
7. Ensure that the data input is configured correctly by selecting Test connection.  
   Health Log Analytics tries to connect the MID Server to the data repository.  
   * If the connection was established, the Test connection button is turned off and the Publish button is enabled.
   * If the connection failed, the reason for the failure displays in the Error message field. This field displays only when a streaming error has occurred.

     Resolve the issue, select
     Save if you modified the configuration, and then select Test connection to test the connection again.  
     Hinweis:  
     You can only publish the data input configuration when the connection is created successfully.

   {#hla-data-input-adv-beats__ul_z2d_sxt_r5b}  
   Hinweis:  
   You can revert to the last published configuration by selecting Revert Changes. This option is available only when you're modifying a configuration that has been published previously.
8. Select Publish to publish the data input to the MID Server.
**Zugehörige Tasks**   

* [Configure a Rsyslog, Filebeat, or Winlogbeat data input in Health Log Analytics manually](https://servicenow-prod.fluidtopics.net/V2AZuTqA~S1YTQlsWjhC~Q "Set up a data input for streaming log messages to your ServiceNow instance using an Rsyslog, Filebeat, or Winlogbeat agent.")

