---
sourceDocument: Yokohama IT Operations Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/yokohama/it-operations-management

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama IT Operations Management

ft:clusterId :

    - itom

bundleId :

    - itom

workflow :

    - Technology


---

# Configure advanced settings for Beats data inputs

# Configure advanced settings for Beats data inputs {#ariaid-title1}

* Release version: Yokohama
* 
* Updated January 30, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read

Configure advanced settings for data inputs that use Beats
agents.

## Before you begin

Role required: evt_mgmt_admin

## About this task

You can set system parameters for reading log data that determine the actions that
the system performs on log data arriving on log data arriving on the MID Server. For example, you can set the time zone to use if a log
lacks a timestamp. If no advanced settings are configured, the system uses the
default values.

For information about how to change settings that were configured when the data input
was created, such as adding a new path or changing the data input's MID Server destination or port, see [Modify data input configurations](https://servicenow-prod.fluidtopics.net/CwN2sCIzp_WLwyhbqO~Cyg "Modify the configuration of a data input for Health Log Analytics by adding a new path to an existing data input configuration or changing the data input's MID Server destination and port.").

## Procedure

1. Navigate to AllHealth Log AnalyticsData InputData Inputs.
2. Open a Beats data input record from the Data Inputs table.  
   The data input configuration displays.  
   Note:  
   The number of log sources that the data input has created is shown in the Sources count field. For more information about data input sources, see [Log data auto-mapping and mapping](https://servicenow-prod.fluidtopics.net/mf0bznHQxZJFB0M_~kSg~A "By default, the Health Log Analytics AI engine tries to auto-map every incoming log line to the correct tags. You can change automatic mapping results manually by defining a JavaScript function.").  
   Note:  
   If the HLA engine is down and data has stopped streaming, a notification appears at the top of the data input configuration page. When this happens, contact ServiceNow support.
3. Select Advanced.
4. On the form, fill in the fields.  
   For a description of the fields, see [Rsyslog, Filebeat, or Winlogbeat data input configuration fields](https://servicenow-prod.fluidtopics.net/1ap5RY5lyQIcjJMr93pn_A "Description of the fields on the Rsyslog, Filebeat, and Winlogbeat data input configuration forms.").
5. **Optional:** In the Streaming Sources related list, verify that this data input is streaming log data from all relevant endpoint devices.  
   For more information about streaming sources, see [Identify and resolve log streaming issues](https://servicenow-prod.fluidtopics.net/xKLHpaqO7y8J5FCQaVbyMw "Identify and address log streaming issues to ensure that the data inputs you have configured for Health Log Analytics are streaming data properly to your ServiceNow instance.").
6. Select Save.  
   Health Log Analytics adds the data input record to the Data Inputs table.
7. Ensure that the data input is configured correctly by selecting Test connection.  
   Health Log Analytics tries to connect the MID Server to the data repository.  
   * If the connection was established, the Test connection button is turned off and the Publish button is enabled.
   * If the connection failed, the reason for the failure displays in the Error message field. This field displays only when a streaming error has occurred.

     Resolve the issue, select
     Save if you modified the configuration,
     and then select Test connection to test the
     connection again.  
     Note:  
     You can only publish the data input configuration when the connection is created successfully.

   {#hla-data-input-adv-beats__ul_z2d_sxt_r5b}  
   Note:  
   You can revert to the last published configuration by selecting Revert Changes. This option is available only when you're modifying a configuration that has been published previously.
8. Select Publish to publish the data input to the MID Server.
**Related tasks**   

* [Configure Rsyslog, Filebeat, or Winlogbeat data inputs](https://servicenow-prod.fluidtopics.net/EU~A9Jq6lfBOGqRxFBdRcg "Configure a data input for streaming log messages to your ServiceNow instance using an Rsyslog, Filebeat, or Winlogbeat agent.")

*[\>]: and then


