---
sourceDocument: Zurich IT Operations Management
sourceDocumentLink: https://www.servicenow.com/docs/r/zurich/it-operations-management

 Release :

    - zurich

ft:locale :

    - en-US

ft:publication_title :

    - Zurich IT Operations Management

ft:clusterId :

    - itom

bundleId :

    - itom

workflow :

    - Technology


---

# Use Case: Proactive monitoring of your ServiceNow instance

# Use Case: Proactive monitoring of your ServiceNow instance in Health Log Analytics {#ariaid-title1}

Release version: Zurich  
Updated July 31, 2025  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read
Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Proactive monitoring of your ServiceNow instance in Health Log Analytics

This use case explains how ServiceNow customers can proactively monitor their ServiceNow instance using Health Log Analytics (HLA) combined with the ServiceNow System Logs Retriever integration.
It enables early detection and resolution of platform issues before they impact users, enhancing system reliability and performance.
Show full answer Show less  

## Key Features

* **ServiceNow System Logs Retriever integration:** Automatically detects errors and anomalies in system logs starting with HLA version 35.0.26, generating actionable alerts for operators.
* **Express List management:** Operators can view, filter by impacted services, and manage alerts efficiently in the Express List interface.
* **ServiceNow Otto AI integration:** Provides deep, AI-driven analysis of alerts with human-readable explanations and potential resolutions, leveraging an understanding of the Glide system.
* **Combined data inputs monitoring:** Admins can use both the MID Server data input and System Logs Retriever data input together to gain comprehensive monitoring of the instance.
* **Log viewer visualization:** Operators can drill down into alert logs using the Log viewer, filter by System Logs Retriever component, and visually analyze errors for faster troubleshooting.

## Practical Benefits for ServiceNow Customers

* Early identification of emerging platform issues through automated anomaly detection in system logs.
* Streamlined alert investigation and resolution using intuitive AI insights from ServiceNow Otto.
* Improved operational efficiency by filtering and managing alerts specific to impacted services.
* Enhanced troubleshooting capability by combining MID Server and system log data inputs for a holistic view of system health.
* Visual log analysis tools help operators quickly pinpoint the root cause of issues to minimize user impact.  
Use Health Log Analytics to detect and resolve emerging issues in your organization's ServiceNow instance before they negatively impact users.

## Using the ServiceNow System Logs Retriever integration to detect platform issues automatically {#hla-use-case-syslogs__section_wjh_gxh_jfc}

Starting with version 35.0.26 of Health Log Analytics, you can use the [ServiceNow System Logs Retriever integration](https://www.servicenow.com/docs/PiLuRqU5ZUg_aM2KYwzGmQ "Set up an integration for streaming log data from your ServiceNow platform's System Log table to the HLA engine.") to automatically detect errors and anomalies in your ServiceNow instance's system logs. As an operator you can view, manage, and respond to the generated alerts in the [Express List](https://www.servicenow.com/docs/uK9Lv7tVusvEoha9PHaIHg "You can monitor incoming alerts in Service Operations Workspace. You can also monitor and manage alerts in the Event Management interface."). Filter the list to show only alerts for the impacted service. Then, use ServiceNow Otto to get an in-depth analysis of the alert and potential resolutions in straightforward, human-readable language. This AI-driven tool demonstrates a deep understanding of the Glide system and offers
actionable insights.

Combining HLA anomaly detection with ServiceNow Otto AI capabilities provides a comprehensive toolkit for identifying and resolving platform system issues more effectively. This collaboration enables Health Log Analytics to help prevent system issues from impacting your platform users.

## Using the MID Server and System Logs Retriever data inputs together to monitor your instance {#hla-use-case-syslogs__section_nc4_cvc_3fc}

You can also stay ahead of disruptions to your ServiceNow environment by using the [MID Server data input](https://www.servicenow.com/docs/TlYX5o608dO3b2~ryQJCwA "Set up a data input for collecting and streaming MID Server log messages to your ServiceNow instance.") and the [ServiceNow System Logs Retriever data input](https://www.servicenow.com/docs/Kms1oQk5fHtBJcp9JMS7uQ "Set up a data input for streaming log data from the ServiceNow System Log table to the HLA engine (aka Occultus).") together.

As an admin, you select a MID Server from the MID Servers list. Under Related Links, choose Create MID Server Data Input using HLA to create a data input specific to the selected MID Server. Then activate the System Logs Retriever data input and configure it to collect your ServiceNow instance's system logs.

As an operator, you navigate to the [Express List](https://www.servicenow.com/docs/uK9Lv7tVusvEoha9PHaIHg "You can monitor incoming alerts in Service Operations Workspace. You can also monitor and manage alerts in the Event Management interface.") and select an alert from the Alerts list. Review the alert details, including duration and impacted services, and analyze the logs that surround the anomaly. Use ServiceNow Otto to get an in-depth analysis of the alert and potential resolutions in straightforward, human-readable language. If needed, for further investigation, you can navigate to the [Review alert logs on the Log viewer](https://www.servicenow.com/docs/xGsJxEGve7Bem4vrAbLfkQ "The Log Viewer tab lets you browse the logs for an alert by timestamp or time range, and visualize anomaly frequency within a specific time period. Customizing the displayed data and adjusting time filters enables you to better understand the framework in which the anomaly occurred, helping you find the root cause faster.") for a visual presentation of the system logs. Select System Logs Retriever from the components drop-down list to view all the errors that have occurred in the ServiceNow instance. You can customize the visualization by using filters.

By drilling down into the alert and MID Server logs, you can quickly identify the issue and resolve it before it affects your platform users.

