Configure data inputs (Splunk)
Configure a data input for streaming log messages to your ServiceNow instance using a Splunk heavy forwarder.
Before you begin
Important:
Health Log Analytics does not support IPv6. To work with the application, configure the MID Server to IPv4.
- You must have an installed and configured MID Server with the log ingestion capability enabled.
- If the MID Server IP address is exposed by network address translation (NAT), a load balancer, or a similar device, it must have a public IP address. In the MID Server properties, add a property named mid.public_ip with the public IP address as the value. For more information, see Create a MID Server property.
- For information about shipping your logs encrypted using SSL TLS, see the Streaming Data With Rsyslog & Filebeat Using SSL [KB0866319] article in the Now Support Knowledge Base.
- Configure Splunk to forward logs to your ServiceNow instance using Syslog.
- The configuration of this data input assumes the existence of an environment
variable named $SPLUNK_HOME. In Unix-like environments, this variable
typically points to /opt/splunk. Note:The Windows environment uses the same directory structure but with backslashes (\).
Role required: evt_mgmt_admin
About this task
This setup procedure is for streaming logs to your instance using a Splunk heavy forwarder. If you can't use a heavy forwarder, you can use a universal forwarder instead. For more information, see the Splunk Universal Forwarder as a Shipping method [KB0961378] article in the Now Support Knowledge Base.
Note:
A MID Server that is down can cause a blockage in your Splunk pipeline. A full processing queue does not affect the
pipeline.
Note:
All Splunk configuration files are located in the
$SPLUNK_HOME/etc/system/local/ folder. If a
configuration file that you need to modify doesn't exist, create it and save it
to this folder.
Procedure
Result
The data input starts streaming log messages to your instance using a Splunk shipper.
Note:
If the Health Log Analytics AI engine is down and data has stopped streaming, a notification appears at the top of the data input configuration page. When this happens, contact ServiceNow support.