Configure Elasticsearch integrations
Configure an integration for seamless log data streaming from Elasticsearch indices to your instance for processing by Health Log Analytics.
Before you begin
Note:
Health Log Analytics supports Elasticsearch versions above 7.10.2 and below 8.18.2. For advanced information about streaming log data from Elasticsearch indices to your instance, see the Stream logs using Elasticsearch data input - Advanced guide [KB1080162] article in the Now Support knowledge base.
- Ensure that the Health Log Analytics application is installed and provisioned on your instance. For more information, see Health Log Analytics (HLA) installation.
- Ensure that a service instance is available.
- Ensure that the Health Log Analytics AI Engine is up and running.
- Ensure that a MID Server is installed and configured with the Log Ingestion capability enabled. For more information, see MID Server system requirements.Important:Health Log Analytics does not support IPv6. To work with the application, configure the MID Server to IPv4.
- If the MID Server IP address is exposed by network address translation (NAT), a load balancer or a similar device, it must have a public IP address. In the MID Server properties, add a property named mid.public_ip with the public IP address as the value. For more information, see Create a MID Server property.
Role required: evt_mgmt_admin
Procedure
What to do next
Leverage the information on the Overview tab to refine how HLA reads the log data. For more information, see Review log data streaming status and sources of an integration.
Tip:
Use the More options menu (
) to open the Data Input Mapping, Source Type Structures, or Log Sources pages with context from the integration. If your log data is not properly
mapped, structured, or sourced, go back and adjust the configuration. If the Service Operations Workspace
Log Analytics application is installed, the More options menu also provides direct access to the Log Viewer, where you can review raw log messages ingested by the integration.
For
more information, see:
If you saved the integration as a draft, perform these steps to activate it later:
- Complete all the prior requirements.
- In the Integrations Launchpad Installed integrations tab, under Waiting for your action, locate and select the integration tile.
- On the configuration screen, select Activate.
Select Test & save to save the integration to the database and test connectivity. If an error is returned, adjust the configuration as suggested in the error message and then try to activate the integration again.
Once the test is successful, the integration is activated and the Overview tab is displayed. The integration tile is available in the Installed integrations tab on the Integrations Launchpad.Note:To test and save the integration without activating it, select the Test & save button at the top of the page.