Configure data inputs (Elasticsearch)
Configure a data input for streaming log data from Elasticsearch indices to your ServiceNow instance.
Before you begin
Important:
Health Log Analytics does not support IPv6. To work with the application, configure the MID Server to IPv4.
- You must have an installed and configured MID Server with the log ingestion capability enabled.
- If the MID Server IP address is exposed by network address translation (NAT), a load balancer or a similar device, it must have a public IP address. In the MID Server properties, add a property named mid.public_ip with the public IP address as the value. For more information, see Create a MID Server property.
Health Log Analytics supports Elasticsearch versions 5.4 and above.
Note:
For advanced information about streaming log data from Elasticsearch indices to your instance, see the Stream logs using Elasticsearch data input - Advanced guide [KB1080162] article in the Now Support knowledge base.
Role required: evt_mgmt_admin
Procedure
Result
The data input starts streaming log data from Elasticsearch indices to your instance.
For more information about streaming logs using the Elasticsearch data input, see the Stream logs using Elasticsearch data input - Advanced guide [KB1080162] article in the Now Support Knowledge Base.
Note:
If the Health Log Analytics AI engine is down and data has stopped streaming, a notification appears at the top of the data input configuration page. When this happens, contact ServiceNow support.
What to do next
Make sure that the data input is streaming data.
Note:
If you experience permissions-related issues with streaming log data from Elasticsearch, refer to the Granting privileges for data streams from
Elasticsearch [KB0967366] article in the Now Support Knowledge
Base.