---
sourceDocument: Zurich IT Operations Management
sourceDocumentLink: https://www.servicenow.com/docs/r/zurich/it-operations-management

 Release :

    - zurich

ft:locale :

    - en-US

ft:publication_title :

    - Zurich IT Operations Management

ft:clusterId :

    - itom

bundleId :

    - itom

workflow :

    - Technology


---

# ServiceNow System Logs Retriever

# Configure a ServiceNow System Logs Retriever data input in Health Log Analytics manually {#ariaid-title1}

Release version: Zurich  
Updated July 31, 2025  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read  
Set up a data input for streaming log data from the ServiceNow System Log table to the HLA engine (aka Occultus).

## Before you begin

Note:  
Only a single ServiceNow System Logs Retriever data input can exist in the system. This data input doesn't run on a MID Server.

Role required: admin

## Procedure

1. Navigate to AllHealth Log AnalyticsData InputData Inputs.
2. On the Data Inputs page, select New.
3. Choose the ServiceNow System Logs Retriever data input.
4. On the form, fill in the fields.  
   For a description of the fields, see [ServiceNow System Logs Retriever data input configuration fields](https://www.servicenow.com/docs/ja0J7QJqVZQgStDBEULJdw "Description of the fields on the ServiceNow System Logs Retriever data input configuration form.").
5. Select Save.  
   Health Log Analytics adds the data input record to the Data Inputs table.

## Result

The data input configuration process is complete. Health Log Analytics adds the data input record to the Data Inputs table and attaches the configuration file to the data input record.

The data input starts streaming ServiceNow log data from the System Log table to the Health Log Analytics AI engine, based on the configured filters. Admin users can set filters to query the System Log table. Operators can monitor the logs and view the alerts that Health Log Analytics generates from them.

For a description of how this data input can help you detect and resolve emerging issues in your organization's ServiceNow instance, see [Use Case: Proactive monitoring of your ServiceNow instance in Health Log Analytics](https://www.servicenow.com/docs/lnuZAZDbyRiU_x8DSEJQcw "Use Health Log Analytics to detect and resolve emerging issues in your organization's ServiceNow instance before they negatively impact users.").  
Note:  
If the HLA engine is down and data has stopped streaming, a notification appears at the top of the data input configuration page. When this happens, contact ServiceNow support.

## What to do next

[Make sure that the data input is streaming data.](https://www.servicenow.com/docs/v7Cy1a07veJN~5vxESIzTw "Find and address log streaming issues to verify that your data inputs are streaming log data to your instance properly.")

*[\>]: and then


