---
sourceDocument: Yokohama IT Operations Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/yokohama/it-operations-management

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama IT Operations Management

ft:clusterId :

    - itom

bundleId :

    - itom

workflow :

    - Technology


---

# Set up data inputs for Health Log Analytics manually

# Set up data inputs for Health Log Analytics manually {#ariaid-title1}

* Release version: Yokohama
* 
* Updated January 30, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 4 minutes to read

Set up your Health Log Analytics data inputs for Health Log Analytics manually. Data input configuration is an essential step in setting up the Health Log Analytics application.

## Before you begin

Note:  
Consider using the Health Log Analytics data input guided setup, which ensures that you have the minimum required setup for the data input process. For more information, see [Set up data inputs using Health Log Analytics guided setup](https://servicenow-prod.fluidtopics.net/ByowkUIFyf7Z13xHLUFrAQ "The Health Log Analytics guided setup provides a sequence of tasks to help you create data inputs on your ServiceNow instance. Data input configuration is an essential step in setting up the Health Log Analytics application. Using guided setup ensures that you have the minimum required setup for the data input process.").  
* Verify that a MID Server is installed and configured with the Log Ingestion capability enabled. For more information, see [MID Server system requirements](https://www.servicenow.com/docs/access?context=r_MIDServerSystemRequirements&version=yokohama&pubname=yokohama-servicenow-platform&ft:locale=en-US).

  Important:  
  Health Log Analytics does not support IPv6. To work with the application, configure the MID Server to IPv4.
* Unless the MID Server and external clients are on the same network, the MID Server must have a public IP address. This is required when its IP is exposed through network address translation (NAT), a load balancer, or a similar device. The public IP address enables external clients, such as Filebeat agents located outside its network, to reach the MID Server. Private IP addresses are not routable over the internet. Without a public IP, external clients cannot connect to the MID Server even if they are configured with its address. In the MID Server properties, add a property named mid.public_ip with the public IP address as the value. For more information, see [Create a MID Server property](https://www.servicenow.com/docs/access?context=r_MIDServerProperties&version=yokohama&pubname=yokohama-servicenow-platform&section=t_SetMIDServerProperties&ft:locale=en-US). If the MID Server and external clients are on the same network, connections can be made using the private IP address.
* For shipping your logs encrypted using SSL TLS, see the [Streaming Data With Rsyslog \& Filebeat Using SSL \[KB0866319\]](https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB0866319) article in the Now Support Knowledge Base.
{#hla-data-input-setup-manual__ul_ql4_dhx_lnb}  
* For MID Server proxy requirements, see [MID Server proxy preconditions for streaming logs to HLA](https://servicenow-prod.fluidtopics.net/rJ75wl1dolIJZ~s7mqmqJA "Requirements for using a MID Server proxy to stream log data to Health Log Analytics.").
{#hla-data-input-setup-manual__ul_ccs_31z_nxb}

Role required: evt_mgmt_admin. For the ServiceNow System Logs data input: admin.

## Procedure

1. Configure a data input by performing the relevant procedure described in the product documentation.  
   {#hla-data-input-setup-manual__table_nyv_1rl_3fc__entry__2}

   | Data Input | Description |
   |-|-|
   | [Rsyslog or Beats](https://servicenow-prod.fluidtopics.net/EU~A9Jq6lfBOGqRxFBdRcg "Configure a data input for streaming log messages to your ServiceNow instance using an Rsyslog, Filebeat, or Winlogbeat agent.") | The data input streams log data into your instance using Rsyslog or Beats. |
   | [Splunk](https://servicenow-prod.fluidtopics.net/rqUo41HTt6I~ztET1cXTog "Configure a data input for streaming log messages to your ServiceNow instance using a Splunk heavy forwarder.") | The data input streams log data into your instance using Splunk. |
   | [Splunk Polling](https://servicenow-prod.fluidtopics.net/sLsVQvrG2MCZbX6cDSLQmg "Configure a data input that periodically pulls log data from Splunk by using a query.") | The data input periodically pulls log data from Splunk by using a query. |
   | [Elasticsearch](https://servicenow-prod.fluidtopics.net/oPgDlLaTpbdFC1i1fKIoMA "Configure a data input for streaming log data from Elasticsearch indices to your ServiceNow instance.") | The data input pulls log data from Elasticsearch indexes into your instance. |
   | [TCP](https://servicenow-prod.fluidtopics.net/jwQ3Prtw669a2UJVa5Ey2A "Configure a data input for sending raw log messages to your ServiceNow instance directly over a TCP/SSL socket.") | The data input sends raw log messages to your instance directly over a TCP/SSL socket. |
   | [UDP](https://servicenow-prod.fluidtopics.net/25L1eQTGuC_8oSbpsS7yJQ "Configure a data input for sending raw log messages to your ServiceNow instance directly over a UDP socket.") | The data input streams raw log messages to your ServiceNow instance directly over a UDP socket. |
   | [GCP Pub/Sub](https://servicenow-prod.fluidtopics.net/cuwMtAtmfMCY6eUJP6yKAw "Configure a data input for receiving log messages that are published to a Google Cloud Pub/Sub topic and streaming them to your ServiceNow instance.") | The data input receives log messages that are published to a Google Cloud Pub/Sub topic and streams them to your ServiceNow instance. |
   | [MID Server](https://servicenow-prod.fluidtopics.net/lhM9BSmNpq96MRmH_puB2Q "Configure a data input for collecting and streaming MID Server log messages to your ServiceNow instance.") | The data input collects MID Server log files and streams them to your instance. |
   | [Amazon CloudWatch](https://servicenow-prod.fluidtopics.net/EE79YFQ3urXaj0wwjtVa6g "Configure a data input for streaming log data from Amazon CloudWatch to your ServiceNow instance.") | The data input streams log data from Amazon CloudWatch to your ServiceNow instance. |
   | [Amazon S3](https://servicenow-prod.fluidtopics.net/HfPr7HDgf__FoVdJufN7Pg "Configure a data input for streaming log data from Amazon S3 (Simple Storage Service) buckets to your ServiceNow instance.") | The data input streams log data from Amazon S3 (Simple Storage Service) buckets to your ServiceNow instance. |
   | [Microsoft Azure Log Analytics](https://servicenow-prod.fluidtopics.net/7cT4ejwFri2SHQOdI8WfEg "Configure a data input for streaming log data from Microsoft Azure Log Analytics to your ServiceNow instance. The data input points the Health Log Analytics AI engine to a data source in your Microsoft Azure Log Analytics account.") | The data input streams log data from Microsoft Azure Log Analytics to your ServiceNow instance. |
   | [Microsoft Azure Event Hubs](https://servicenow-prod.fluidtopics.net/Tm8OQAiX8On_jIevHzfbfg "Configure a data input for streaming events from Microsoft Azure Event Hubs to your ServiceNow instance.") | The data input streams events from Microsoft Azure Event Hubs to your ServiceNow instance. |
   | [Apache Kafka](https://servicenow-prod.fluidtopics.net/5tShaLi~Pg5otePp6toVmw "Configure a data input for streaming log data from Apache Kafka to your ServiceNow instance.") | The data input streams log data from Apache Kafka to your ServiceNow instance. |
   | [REST API](https://servicenow-prod.fluidtopics.net/20~EhSo02sr_HLh_lnD7ug "Configure a REST API data input for streaming log data to your ServiceNow instance in JSON format.") | The data input streams log data to your ServiceNow instance in JSON format. |
   | [ServiceNow System Logs Retriever](https://servicenow-prod.fluidtopics.net/M5EttoAQBxYmq4dzTmqIbg "Configure a data input for streaming log data from the ServiceNow System Log table to the Health Log Analytics AI engine (Occultus).") | The data input streams log data from the ServiceNow System Log table to the Health Log Analytics AI engine. Note: Only a single ServiceNow System Logs Retriever data input can exist in the system, and only users with the admin role can create and configure it. This data input doesn't run on a MID Server. |
   | [Cribl](https://servicenow-prod.fluidtopics.net/Eg~Hh4AFeriXR0QU1FcxZg "Configure a dedicated Cribl data input to enable Health Log Analytics to process Cribl log messages streaming into your ServiceNow instance.") | The data input to enables Health Log Analytics to process Cribl log messages streaming into your ServiceNow instance. |
   | [Edge Delta](https://servicenow-prod.fluidtopics.net/Y_c3ztuVbQ_SxtwZ1cbW5g "Configure an Edge Delta data input to enable Health Log Analytics to process Edge Delta log messages streaming into your ServiceNow instance.") | The data input enables Health Log Analytics to process Edge Delta log messages streaming into your ServiceNow instance. |
   | [Vector Agent](https://servicenow-prod.fluidtopics.net/JOq28cuCGCASFq8jgS3UnQ "Configure a Vector Agent data input to enable Health Log Analytics to process log messages that are streaming into your ServiceNow instance via a Vector Agent.") | The data input enables Health Log Analytics to process log messages that are streaming into your ServiceNow instance via a Vector Agent. |
   | Agent Client Collector | The data input streams log messages to your ServiceNow instance using the ServiceNow Agent Client Collector. This data input is supported for use with the [Agent Client Collector Log Analytics](https://servicenow-prod.fluidtopics.net/SuAKpX6~2tbaSzdG4PW6ng "Agent Client Collector Log Analytics (ACC-L) enables you to stream log data from Linux and Windows hosts to a ServiceNow instance, using the Agent Client Collector.") application, available from the [ServiceNow Store](https://store.servicenow.com/sn_appstore_store.do#!/store/home). |
   [Table 1. Data Inputs]

   {#hla-data-input-setup-manual__table_nyv_1rl_3fc}  
   Note:  
   Selecting Test connection at the end of the procedure ensures that your data input is configured correctly. You can only publish a data input configuration when the connection between the MID Server and the data repository has been established.
2. Identify and address streaming issues to ensure that the data input is streaming log data to the MID Server from all sources.  
   For more information, see [Identify and resolve log streaming issues](https://servicenow-prod.fluidtopics.net/xKLHpaqO7y8J5FCQaVbyMw "Identify and address log streaming issues to ensure that the data inputs you have configured for Health Log Analytics are streaming data properly to your ServiceNow instance.").
3. **Optional:** Edit raw log data before Health Log Analytics maps and structures it.  
   For more information, see [Edit your raw log data before processing](https://servicenow-prod.fluidtopics.net/R8YQ8bBaQwl6UzzSdCocKA "You can modify raw log data and drop or break up log messages before they are processed in the MID Server, and therefore before Health Log Analytics maps and structures it. For example, you could prevent sensitive data from reaching the system by replacing user names and passwords with an asterisk (*).").
4. Determine how Health Log Analytics handles raw log data that is streaming into your instance.  
   By default, every incoming log line is auto-mapped to the correct tag. If properties aren't discovered automatically, map the data input sources manually by defining a JavaScript function. For more information, see [Map the raw data](https://servicenow-prod.fluidtopics.net/ENjBmAW1AM2qvvmJSA_YiQ "Mapping raw log data that streams into your instance determines how the data is handled. Health Log Analytics automatically structures logs, creates metrics for anomaly detection, and presents alerts based on how your data is tagged.").
5. **Optional:** Tweak the source type structure to make sure that Health Log Analytics extracts and classifies all properties correctly.  
   For more information, see [Refine the source type structure](https://servicenow-prod.fluidtopics.net/7xffVJXJtf_JlE08nlOH4w "Fine-tune how Health Log Analytics reads your inner log messages and detects anomalies by customizing the extracted properties in the source type structure.").
6. **Optional:** Perform additional data input setup tasks.  
   For more information, see [Additional data input setup tasks](https://servicenow-prod.fluidtopics.net/HM0Au25mm_UDAtXsG2FMxQ "After performing the initial data input setup and configuration, continue with the remaining data input setup tasks.").
* **[Configuring data inputs for Health Log Analytics manually](https://servicenow-prod.fluidtopics.net/nWveucimgeRiHu8W7B3cLw)**   
  Configure the data input process manually in Health Log Analytics. Data input configuration is an essential step in setting up the Health Log Analytics application.

**Related reference**   

* [Supported data inputs for Health Log Analytics](https://servicenow-prod.fluidtopics.net/2BBiqGf_XyB3Y7e3Ner22Q "Health Log Analytics (HLA) enables you to connect your ServiceNow instance to several types of data input.")

