---
sourceDocument: Yokohama IT Operations Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/yokohama/it-operations-management

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama IT Operations Management

ft:clusterId :

    - itom

bundleId :

    - itom

workflow :

    - Technology


---

# Modify data input configurations

# Modify data input configurations {#ariaid-title1}

* Release version: Yokohama
* 
* Updated January 30, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 3 minutes to read

Modify the configuration of a data input for Health Log Analytics by
adding a new path to an existing data input configuration or changing the data input's MID Server destination and port.

## Before you begin

Role required: evt_mgmt_admin

## Procedure

1. Navigate to AllHealth Log AnalyticsData InputData Inputs.
2. Open a record from the Data Inputs table.
3. Modify the data input configuration.  
   {#hla-data-input-modify__table_mcn_jdb_n4b__entry__2}

   | Column | Description |
   |-|-|
   | Name | Name of the data input. |
   | Description | Description of the data input. |
   | Port | The port on the MID Server. Note: The port must not be occupied by another process. Make sure that your organization's security team opens the selected port. |
   | MID | The MID Server to which the logs stream. Note: * You can select only MID Servers with log ingestion capability that support basic authentication. MID Servers that support mTLS are not listed. * The default maximum number of data inputs streaming logs to a single MID Server is 10. You can modify this number in the MID Server properties. {#hla-data-input-modify__ul_pq2_qq3_nsb} |
   [ ]

   {#hla-data-input-modify__table_mcn_jdb_n4b}  
   {#hla-data-input-modify__table_xxt_k53_n4b__entry__2}

   | Column | Description |
   |-|-|
   | Path | The full path from which to stream logs. You can use a wildcard. Note: This column is not available on Windows systems using Winlogbeat. |
   | Service instance | The service instance to which to bind the log data. Note: If no relevant service instance exists, [Create an service instance](https://www.servicenow.com/docs/access?context=create-it-services&version=yokohama&pubname=yokohama-servicenow-platform&ft:locale=en-US) and add CIs to it. Set the status of the new service instance to Operational. |
   | Component | The device type or stack layer as context for the logs that is used for anomaly detection and correlation. For example, Tomcat. Components typically represent CIs in the CMDB. Several components are often clustered together in a single service instance. |
   | Source Type | The source type that defines how Health Log Analytics handles a specific application and parses the log data. For example: Tomcat Catalina. Each data input can have multiple source types depending on the diversity of its log formats. Service instances and components can have any number of source types. |
   | For handling multiline messages on Linux / Windows systems using Filebeat only: ||
   | Match | Specifies how Filebeat combines matching lines into an event, either after or before. |
   | Negate | Boolean that defines whether the pattern identified in the log lines is negated. The default is false. |
   | Regex | The regular expression to match. |
   [Table 1. Settings]

   {#hla-data-input-modify__table_xxt_k53_n4b}  
   Note:  
   You can modify the Rsyslog configuration file to make the agent ship system logs in addition to application logs. For more information, see the [Shipping system logs using Rsyslog
   \[KB0954507\]](https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB0954507) article in the Now Support Knowledge Base.
4. Select Update.
5. For data inputs that use Rsyslog or Beats agents only, rebuild the server-side configuration file and install it on the endpoint device.  
   1. Select Rebuild configuration file.

      Health Log Analytics rebuilds the file and saves it
      in the Manage Attachments section. Depending on the agent used, the
      rebuilt file is saved as either rsyslog.yml,
      filebeat.yml, or
      winlogbeat.yml.

      The system
      automatically renames the previous configuration file by adding a
      suffix with the date and time the file was rebuilt to the file
      name.
   2. Install the rebuilt configuration file on the endpoint according to your data input type.{#hla-data-input-modify__table_sw2_2y5_s4b__entry__2}

      | Data input type | Action |
      |-|-|
      | Rsyslog | 1. Download the file and install it on the endpoint device in the /etc/rsyslog.d/rsyslog.conf directory. 2. Validate the configuration by running the `rsyslogd -N1` command. 3. Verify the output. If it contains errors, check the /var/log/messages system log file for error messages and fix the errors. 4. Restart Rsyslog by running the `sudo systemctl restart rsyslog` command. {#hla-data-input-modify__ol_nhw_gy5_s4b} |
      | Linux | 1. Download the file and install it on the endpoint device in the /etc/filebeat/ directory. 2. Restart the agent service by running the `sudo service filebeat restart` command. {#hla-data-input-modify__ol_iry_3y5_s4b} Note: The generated configuration ignores files that were last changed more than six hours ago. If needed, you can change this setting in the configuration file. |
      | Windows using Beats (Filebeat or Winlogbeat): | 1. Download the file and install it on the endpoint device in the C:\\Program Files\\ directory. 2. Restart the agent service by running the appropriate command in PowerShell: * Filebeat: `PS > Restart-Service filebeat` * Winlogbeat: `PS > Restart-Service winlogbeat` {#hla-data-input-modify__ul_rgq_ly5_s4b} {#hla-data-input-modify__ol_qgq_ly5_s4b} Note: The generated configuration ignores files that were last changed more than six hours ago. If needed, you can change this setting in the configuration file. |
      [ ]

      {#hla-data-input-modify__table_sw2_2y5_s4b}
   {#hla-data-input-modify__ol_hc1_fw1_n4b}
**Related tasks**   

* [Configure advanced settings for Rsyslog, Splunk, TCP data inputs](https://servicenow-prod.fluidtopics.net/xUDAhqL4PuYI9IOrYuGiGQ "Manually configure advanced settings for data inputs that use Rsyslog, Splunk, or TCP agents in Health Log Analytics.")
* [Configure advanced settings for Beats data inputs](https://servicenow-prod.fluidtopics.net/U9SxS9DIgt4a6y5x2GE0Kg "Configure advanced settings for data inputs that use Beats agents.")

*[\>]: and then


