Configure advanced settings for data inputs that use Rsyslog, Splunk, or TCP agents.
Avant de commencer
Role required: evt_mgmt_admin
Pourquoi et quand exécuter cette tâche
You can set system parameters for reading log data that determine the actions that the system performs on log data arriving on the MID Server. For example, you can set the time zone to use if a log lacks a timestamp. If no advanced settings are configured, the system uses the default values.
For information about how to change settings that were configured when the data input was created, such as adding a new path or changing the data input's MID Server destination or port, see Modify a data input configuration in Health Log Analytics.
Procédure
-
Navigate to .
-
Open a Rsyslog, Splunk, or TCP data input record from the Data Inputs table.
The data input configuration displays.
Remarque : If the HLA engine is down and data has stopped streaming, a notification appears at the top of the data input configuration page. When this happens, contact ServiceNow support.
-
Select Advanced.
-
On the form, fill in the fields.
- Facultatif :
In the Streaming Sources related list, verify that this data input is streaming log data from all relevant endpoint devices.
-
Select Save.
Health Log Analytics adds the data input record to the Data Inputs table.
-
Ensure that the data input is configured correctly by selecting Test connection.
Health Log Analytics tries to connect the MID Server to the data repository.
Remarque : You can revert to the last published configuration by selecting Revert Changes. This option is available only when you're modifying a configuration that has been published previously.
-
Select Publish to publish the data input to the MID Server.