---
sourceDocument: Australia IT Operations Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/de-DE/it-operations-management

 Release :

    - australia

ft:locale :

    - de-DE

ft:publication_title :

    - Australia IT Operations Management

ft:clusterId :

    - itom

bundleId :

    - itom

workflow :

    - Technology


---

# Supported data inputs for HLA

# Supported data inputs for Health Log Analytics {#ariaid-title1}

* Freigeben Version: Australia
* 
* Aktualisiert 12. März 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 Minuten Lesedauer

Health Log Analytics (HLA) enables you to connect your ServiceNow instance to several types of data input.
HLA supports the following data input types:

* Passive data inputs (listeners), which wait for log data to be pushed to them. These data inputs require a network port to be open on the MID Server:  
  * [Rsyslog](https://servicenow-prod.fluidtopics.net/V2AZuTqA~S1YTQlsWjhC~Q "Set up a data input for streaming log messages to your ServiceNow instance using an Rsyslog, Filebeat, or Winlogbeat agent.")
  * [Beats](https://servicenow-prod.fluidtopics.net/V2AZuTqA~S1YTQlsWjhC~Q "Set up a data input for streaming log messages to your ServiceNow instance using an Rsyslog, Filebeat, or Winlogbeat agent.")
  * [Splunk](https://servicenow-prod.fluidtopics.net/3bCDv_HckUIkdOB6nnXR3w "Set up a data input for streaming log messages to your ServiceNow instance using a Splunk heavy forwarder.")
  * [TCP](https://servicenow-prod.fluidtopics.net/KvUdBHsuRCrvS_KRv2y9Rw "Set up a data input for sending raw log messages to your ServiceNow instance directly over a TCP/SSL socket.")
  * [UDP](https://servicenow-prod.fluidtopics.net/drtm6EwOPZ1og0jNt3wafA "Set up a data input for sending raw log messages to your ServiceNow instance directly over a UDP socket.")
  * [MID Server](https://servicenow-prod.fluidtopics.net/DI19Pdu1idMRkffW3JrAvA "Set up a data input for collecting and streaming MID Server log messages to your ServiceNow instance.")
  * [GCP PubSub](https://servicenow-prod.fluidtopics.net/8GZGg0_Ds~pwkzNCej4cgA "Set up a data input for receiving log messages that were published to a Google Cloud Platform (GCP) Pub/Sub topic and streaming them to your ServiceNow instance.")
  * [REST API](https://servicenow-prod.fluidtopics.net/kkI5xHL2vIx9pickAp9Ngg "Set up a REST API data input for streaming log data to your ServiceNow instance.")
  {#hla-data-input-supported__ul_knc_dvl_3fc}

  The Agent Client Collector data input is supported for use with the [Agent Client Collector Log Analytics](https://servicenow-prod.fluidtopics.net/~YCIZgNv3aQGzaz98AjFxQ "Agent Client Collector Log Analytics (ACC-L) enables you to stream log data from Linux and Windows hosts to a ServiceNow instance, using the Agent Client Collector.") application, available from the [ServiceNow Store](https://store.servicenow.com/sn_appstore_store.do#!/store/home).
* Active data inputs (pullers), which pull data from repositories:  
  * [Elasticsearch](https://servicenow-prod.fluidtopics.net/vuc195rajuwe7qYyNoagEQ "Set up a data input for streaming log data from Elasticsearch indices to your ServiceNow instance.")
  * [Splunk Polling](https://servicenow-prod.fluidtopics.net/XsEsj5Dm_A36lnb6FNoy8w "Set up a data input that periodically pulls log data from Splunk by using a query.")
  * [Amazon CloudWatch](https://servicenow-prod.fluidtopics.net/cOrwvWrhcafkXBW6teH0qg "Set up a data input for streaming log data from Amazon CloudWatch to your ServiceNow instance.")
  * [Amazon S3](https://servicenow-prod.fluidtopics.net/MZaJ5xNf0sHZ7MZT3p9ujg "Set up a data input for streaming log data from Amazon S3 (Simple Storage Service) buckets to your ServiceNow instance.")
  * [Microsoft Azure Log Analytics](https://servicenow-prod.fluidtopics.net/Xm2v_1VjL1Hhx_b9~5c3yA "Set up a data input for streaming log data from Microsoft Azure Log Analytics to your ServiceNow instance. The data input points the Health Log Analytics AI engine to a data source in your Microsoft Azure Log Analytics account.")
  * [Microsoft Azure Event Hubs](https://servicenow-prod.fluidtopics.net/hoJNWB6xcj3pJf1Igz2t7A "Set up a data input for streaming events from Microsoft Azure Event Hubs to your ServiceNow instance.")
  * [Apache Kafka](https://servicenow-prod.fluidtopics.net/j8jxlGKetywRQJfFz68s5w "Set up a data input for streaming log data from Apache Kafka to your ServiceNow instance.")
  {#hla-data-input-supported__ul_oct_p5l_3fc}

  For all active data inputs, Health Log Analytics supports MID Server clusters for failover protection. The active data input runs on a single MID Server in the cluster. If that MID Server fails, the system moves its tasks to the next available MID Server in the cluster in a configured order.  
  The Elasticsearch data input fetches data from a data repository or database using credentials. If your data is in Elasticsearch, Health Log Analytics must have the following:
  * Permissions to query Elasticsearch  
    One of the following types of credentials:
    * Basic authentication (user and password)
    * AWS, for Elasticsearch on Amazon AWS Cloud
    {#hla-data-input-supported__ul_j2y_jrg_5nb}
  * Network connectivity to the relevant Elasticsearch cluster
  {#hla-data-input-supported__ul_pyh_ypl_mmb}  
  Hinweis:  
  Health Log Analytics must be pointed to the correct index to start pulling the data.
{#hla-data-input-supported__ul_png_kqv_lmb}

In addition, Health Log Analytics supports [Crible](https://servicenow-prod.fluidtopics.net/7870zplpqWcIBAIMf5BXNw "Configure a dedicated Cribl data input to enable Health Log Analytics to process Cribl log messages streaming into your ServiceNow instance."), [Edge Delta](https://servicenow-prod.fluidtopics.net/F~YyNMyMMzP2iCm98qKuZg "Set up an Edge Delta data input to enable Health Log Analytics to process Edge Delta log messages streaming into your ServiceNow instance."), and [Vector Agent](https://servicenow-prod.fluidtopics.net/Bo~jmptfioax9zOh8oexQw "Set up a Vector Agent data input to enable Health Log Analytics to process log messages that are streaming into your ServiceNow instance via a Vector Agent.") data inputs. These data inputs enable HLA to process log messages that are streaming from these tools into your instance.

## Native ServiceNow data inputs {#hla-data-input-supported__section_nhx_fd5_v1c}

Streaming logs from Cloud Observability to Health Log Analytics

:   Health Log Analytics can process log data it ingests from the ServiceNow®
    Cloud Observability application, formerly  Lightstep. HLA automatically sets up the configuration needed to enable log streaming from Cloud Observability as part of its native integration. Setting up the connection from Cloud Observability to HLA must be done in the Cloud Observability application. In HLA, you handle log records from Cloud Observability in the same way as any other Data Input Mapping and Source Type Structure records, as explained in [Log data auto-mapping and mapping in Health Log Analytics](https://servicenow-prod.fluidtopics.net/8w9omk2yu0EcrcYh342TMw "By default, the HLA Engine tries to auto-map every incoming log line to the correct tags. You can change automatic mapping results manually by defining a JavaScript function.") and [Source type structure adjustment in Health Log Analytics](https://servicenow-prod.fluidtopics.net/brXXHUVHvJ6m1g4_nei8fw "Health Log Analytics (HLA) enables you to reclassify auto-classified log properties and change auto-mapped labels. These adjustments help HLA machine learning analyze your data accurately."). For more information about Cloud Observability, see [Explore Cloud Observability documentation](https://docs.lightstep.com/).

**Zugehörige Konzepte**   

* [Set up Health Log Analytics on your ServiceNow instance](https://servicenow-prod.fluidtopics.net/HDH4GxVn0VKWdZueCaJJ1g "Implement Health Log Analytics on your ServiceNow instance.")

