---
sourceDocument: Yokohama IT Operations Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/yokohama/it-operations-management

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama IT Operations Management

ft:clusterId :

    - itom

bundleId :

    - itom

workflow :

    - Technology


---

# Identify and resolve log streaming issues

# Identify and resolve log streaming issues {#ariaid-title1}

* Release version: Yokohama
* 
* Updated January 30, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read

Identify and address log streaming issues to ensure that the data inputs you have configured for Health Log Analytics are streaming data properly to your ServiceNow instance.

## Before you begin

Role required: evt_mgmt_admin

## Procedure

1. Navigate to AllHealth Log AnalyticsStreaming Sources.  
   The Streaming Sources page shows all data inputs and the MID Servers that are receiving logs from them.  
   Note:  
   * When Look up hostnames is selected in the [advanced data input configuration](https://servicenow-prod.fluidtopics.net/e3FMJrIm4WaboyFIAFZY0g "When you have configured a data input successfully, Health Log Analytics adds a record to the Data Inputs table and attaches the configuration file to it. You can configure advanced settings for your data input. Configuring advanced settings is optional."), the Streaming Sources page shows the hostname of devices that use an Rsyslog or a Filebeat shipper. For Elasticsearch indices, it displays the index name.
   * Streaming Sources is also available as a related list on the data input form. The related list displays only the endpoint devices that are relevant to that data input.
   * If the HLA engine is down and data has stopped streaming, a notification appears at the top of the Streaming Sources page. When this happens, contact ServiceNow support.
   {#hla-data-input-streaming__ul_cdw_hlj_nsb}
2. Select a data input record to view the streaming data of its sources and identify streaming issues and their possible cause.  
   For example, if the last recorded event time for a data input's endpoint server is yesterday, that server might be down or configured incorrectly. A streaming issue might also be caused by the data input configuration file not being installed on the endpoint.  
   {#hla-data-input-streaming__table_k2m_wq3_qmb__entry__2}

   | Filter | Description |
   |-|-|
   | Status | The status of the source. A red bullet indicates that this source has not streamed data in the last hour. |
   | Last event time | The last recorded time an event arrived at the MID Server in the last one-minute interval. Health Log Analytics continuously updates the last event time. If the last event time is not up to date, data is not streaming. |
   | Raw log lines/sec | The average number of raw log lines that streamed to the MID Server per second in the last one-minute interval. Note: This value represents the number of raw log lines before preprocessing. |
   | Preprocessed log lines/sec | The average number of preprocessed log lines that streamed to the MID Server per second in the last one-minute interval. Note: This value can differ from the number of raw log lines per second. For example, the difference can be a result of logs having been dropped during preprocessing. |
   [ ]

   {#hla-data-input-streaming__table_k2m_wq3_qmb}
3. Investigate and resolve any data streaming issues.  
   Note:  
   If you experience permissions-related issues with streaming log data from Elasticsearch, refer to the [Granting privileges for data streams from Elasticsearch \[KB0967366\]](https://support.servicenow.com/kb?id=kb_article_view&sys_kb_id=9648a9281b61b4100b8a9979b04bcb04) article in the Now Support Knowledge Base.

## What to do next

When the logs are streaming properly, proceed to [map your raw log data](https://servicenow-prod.fluidtopics.net/ENjBmAW1AM2qvvmJSA_YiQ "Mapping raw log data that streams into your instance determines how the data is handled. Health Log Analytics automatically structures logs, creates metrics for anomaly detection, and presents alerts based on how your data is tagged.").  
Note:  
You can choose to [edit incoming raw log data](https://servicenow-prod.fluidtopics.net/R8YQ8bBaQwl6UzzSdCocKA "You can modify raw log data and drop or break up log messages before they are processed in the MID Server, and therefore before Health Log Analytics maps and structures it. For example, you could prevent sensitive data from reaching the system by replacing user names and passwords with an asterisk (*).") before Health Log Analytics processes it. For example, preprocessing enables you to discard log portions or remove sensitive data from your logs. This task is optional.

*[\>]: and then


