Configure Splunk UDP integrations
Configure an integration to stream log messages to your ServiceNow instance over the UDP transport protocol using a Splunk heavy forwarder. Health Log Analytics processes the ingested log data.
Before you begin
- Ensure that a MID Server is installed and configured with the Log Ingestion capability enabled. For more information, see MID Server system requirements. Important:Health Log Analytics does not support IPv6. To work with the application, configure the MID Server to IPv4.
- If the MID Server IP address is exposed by network address translation (NAT), a load balancer, or a similar device, it must have a public IP address. In the MID Server properties, add a property named mid.public_ip with the public IP address as the value. For more information, see Create a MID Server property.
- For shipping your logs encrypted using SSL TLS, see the Streaming Data With Rsyslog & Filebeat Using SSL [KB0866319] article in the Now Support Knowledge Base.
Role required: evt_mgmt_admin
Procedure
Result
The integration is activated and the Overview screen is displayed. The tile for the integration is available in the Installed integrations tab on the Integrations Launchpad.
What to do next
Leverage the information on the Overview tab to refine how HLA reads the log data. For more information, see Review log data streaming status and sources of an integration.
Tip:
Use the More options menu (
) to open the Data Input Mapping, Source Type Structures, or Log Sources pages with context from the integration. If your log data is not properly
mapped, structured, or sourced, go back and adjust the configuration. If the Service Operations Workspace
Log Analytics application is installed, the More options menu also provides direct access to the Log Viewer, where you can review raw log messages ingested by the integration.
For
more information, see: