---
sourceDocument: Yokohama IT Operations Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/yokohama/it-operations-management

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama IT Operations Management

ft:clusterId :

    - itom

bundleId :

    - itom

workflow :

    - Technology


---

# Configure Cribl data inputs

# Configure Cribl data inputs {#ariaid-title1}

* Release version: Yokohama
* 
* Updated January 30, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read

Configure a dedicated Cribl data input to enable Health Log Analytics to process Cribl log messages streaming into your ServiceNow instance.

## Before you begin

* Verify that a MID Server is installed and configured with the Log Ingestion capability enabled. For more information, see [MID Server system requirements](https://www.servicenow.com/docs/access?context=r_MIDServerSystemRequirements&version=yokohama&pubname=yokohama-servicenow-platform&ft:locale=en-US).

  Important:  
  Health Log Analytics does not support IPv6. To work with the application, configure the MID Server to IPv4.
* Unless the MID Server and external clients are on the same network, the MID Server must have a public IP address. This is required when its IP is exposed through network address translation (NAT), a load balancer, or a similar device. The public IP address enables external clients, such as Filebeat agents located outside its network, to reach the MID Server. Private IP addresses are not routable over the internet. Without a public IP, external clients cannot connect to the MID Server even if they are configured with its address. In the MID Server properties, add a property named mid.public_ip with the public IP address as the value. For more information, see [Create a MID Server property](https://www.servicenow.com/docs/access?context=r_MIDServerProperties&version=yokohama&pubname=yokohama-servicenow-platform&section=t_SetMIDServerProperties&ft:locale=en-US). If the MID Server and external clients are on the same network, connections can be made using the private IP address.

{#hla-data-input-cribl__ul_xk1_rhb_tdc}

Role required: evt_mgmt_admin

## About this task

If your organization uses Cribl for filtering and routing large volumes of log data from various sources, the log format Health Log Analytics receives is distinct from other types. The Cribl data input enables HLA to detect and separate transport headers from inner log messages in this format, forwarding only the inner message to the source type structure for processing.

## Procedure

1. Navigate to AllHealth Log AnalyticsData InputData Inputs.
2. On the Data Inputs page, select New.
3. Choose the Cribl data input.
4. On the Getting Started tab, fill in the form fields and then select Next.  
   For a description of the fields, see [Cribl data input configuration fields](https://servicenow-prod.fluidtopics.net/liSJ~VmJuguxz4MI81lm5A "Description of the fields on the Cribl data input configuration form.").
5. On the Config tab, fill in the form fields and then select Next.  
   For a description of the fields, see [Cribl data input configuration fields](https://servicenow-prod.fluidtopics.net/liSJ~VmJuguxz4MI81lm5A "Description of the fields on the Cribl data input configuration form.").
6. On the Process tab, select the required route and then select Next.  
   For more information, see [Cribl data input configuration fields](https://servicenow-prod.fluidtopics.net/liSJ~VmJuguxz4MI81lm5A "Description of the fields on the Cribl data input configuration form.").  
   Note:  
   For troubleshooting issues related to this step, see the [Cribl - Setting up Cribl data input \| Troubleshooting setup \& data ingestion issues \[KB0558611\]](https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB1787528) article in the Now Support Knowledge Base.  
   The Finish tab opens.
7. On the Cribl instance, verify that the configuration of the data input is correct.  
   You can use the Cribl commands displayed on the Finish tab as needed.
8. When the configuration is correct, return to the data input configuration Finish tab and select Publish to publish the data input.

## Result

The data input configuration process is complete. The data input starts streaming log data to your ServiceNow instance.

For troubleshooting issues related to the ingestion of log data from Cribl, see the [Cribl - Setting up Cribl data input \| Troubleshooting setup \& data ingestion issues \[KB0558611\]](https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB1787528) article in the Now Support Knowledge Base.  
Note:  
If the HLA engine is down and data has stopped streaming, a notification appears at the top of the data input configuration page. When this happens, contact ServiceNow support.

## What to do next

[Make sure that the data input is streaming data.](https://servicenow-prod.fluidtopics.net/xKLHpaqO7y8J5FCQaVbyMw "Identify and address log streaming issues to ensure that the data inputs you have configured for Health Log Analytics are streaming data properly to your ServiceNow instance.")

*[\>]: and then


