Combined Health Log Analytics release notes for upgrades from Yokohama to Zurich

  • Release version: Zurich
  • Updated August 11, 2026
  • 7 minutes to read
  • Summarize
    Summarized using AI
    This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.

    Summary of Combined Health Log Analytics Release Notes for Upgrades from Yokohama to Zurich

    This consolidated guide assists ServiceNow customers in upgrading Health Log Analytics (HLA) from the Yokohama release to the Zurich release. It outlines new features, important changes, and integration enhancements introduced between these versions, along with key pre- and post-upgrade considerations to ensure a smooth transition.

    Show full answer Show less

    Key Features

    • Splunk Polling and Data Input Enhancements (Yokohama): Enables consistent, recurring data fetches from Splunk with minimal configuration on the HLA side, accelerating proof of concepts and integration speed. Also supports ingestion of preprocessed, structured Splunk data for efficient workflows.
    • Integrations Launchpad Enhancements: Provides a unified interface to configure log data connectors such as Elasticsearch, ServiceNow System Logs, UDP, TCP, and supports additional integrations for Splunk TCP/UDP, MID Server, Apache Kafka, Microsoft Azure Log Analytics, REST API, Amazon Data Firehose (real-time streaming without MID Server), GCP Pub/Sub, Microsoft Azure Event Hubs, and Edge Delta TCP/REST.
    • Cribl and Edge Delta Data Inputs: Dedicated inputs streamline ingestion of large log volumes from multiple sources, with Zurich adding a Cribl-specific integration that detects and processes Cribl log formats effectively.
    • Enhanced Monitoring and Contextualization (Zurich): The integration Overview screen now displays ITOM Gateway pipeline stages and log streaming metrics. Log data can be mapped to service instances and components to generate alerts with precise context, improving alert accuracy and management.
    • Source Type Export and ServiceNow Log Monitoring: Export source types by log source to update sets for easier environment migration. Monitor ServiceNow instance node logs from Java and JavaScript using the new Log Export data input.
    • Centralized Configuration: Access the Integrations Launchpad directly from the ITOM AIOps configuration center for streamlined setup and management of AIOps features.

    Key Changes

    • Alert Grouping Model Update: Yokohama deprecated component-based alert grouping in favor of a streamlined two-tier model (Log Analytics Group to Single Alert). This aligns alerts with service-level anomalies rather than individual hosts, enhancing alert visibility, correlation, and management.
    • No Removals or Deprecations in Zurich: The Zurich release does not introduce additional removals or deprecations beyond those noted previously.

    Activation and Requirements

    • Health Log Analytics installation requires requesting the app from the ServiceNow Store for both Yokohama and Zurich releases.
    • No additional activation changes or browser requirements were introduced between these releases.

    Localization and Accessibility

    • Supported languages include US English (default), UK English, French, German, Italian, Japanese, and Spanish for both releases.
    • No new accessibility updates were introduced in the Zurich release.

    Practical Benefits for ServiceNow Customers

    • Improved and simplified log data ingestion through multiple new and enhanced integrations reduces setup complexity and accelerates data availability.
    • Enhanced alerting models and contextual log mapping improve the relevance and manageability of alerts, helping teams respond more effectively.
    • Centralized configuration and monitoring interfaces streamline operational management of Health Log Analytics and related ITOM AIOps capabilities.
    • Support for real-time streaming and high-volume log processing via integrations like Amazon Data Firehose, Cribl, and Edge Delta ensures scalability for diverse log sources.
    • Export capabilities facilitate migration of configurations between environments, supporting consistent deployments across your ServiceNow instances.

    Consolidated page of all release notes for Health Log Analytics from Yokohama to Zurich.

    How to use this page

    To help you prepare for your upgrade, we have combined the cross-family Health Log Analytics release notes onto one page. Read this summary of the new features, changes, and updated information for your product from Yokohama to Zurich.

    Tip:
    If there were no updates for a release notes section in a certain family release, we included a short note for your reference. For example, if a product did not have any updates in Tokyo, the row says "No updates for this release."

    Important information for upgrading Health Log Analytics to Zurich

    Before you upgrade to Zurich, review these pre- and post-upgrade tasks and complete the tasks as needed.

    Release Release notes

    Yokohama

    No updates for this release.

    Zurich

    No updates for this release.

    New features

    Between your current release family and Zurich, new features were introduced for Health Log Analytics.

    Release Release notes

    Yokohama

    Pull data from Splunk regularly using the Splunk Polling data input
    Make your data workflows more consistent and productive by fetching data consistently over time using the Splunk Polling data input, which sends recurring queries (polls) to Splunk. Handling most configurations on the HLA side means you need minimal additional stakeholder involvement, which enables swift integration with your existing Splunk setup. This enhancement accelerates proofs of concept (POCs) and enables faster iterations using real data.
    Use your Splunk data input to ingest preprocessed data from Splunk
    Ingest data from Splunk in a preprocessed, structured format using your existing Splunk data input.
    Integrate with log data connectors from the Integrations Launchpad
    Take advantage of the Integrations Launchpad's unified interface for convenient integration with log data connectors that feed raw log data from external sources into your instance. You set up log data connectors for HLA from the Event Management Integrations Launchpad in Service Operations Workspace for ITOM. In this release, the Integrations Launchpad enables integration with the following connectors: Elasticsearch, ServiceNow System Logs, UDP, and TCP.
    Use Cribl and Edge Delta data inputs to streamline HLA data ingestion with tools handling large log volumes
    Use dedicated data inputs to facilitate data ingestion from Cribl or Edge Delta when using these tools to handle large volumes of log data from multiple sources before sending it to HLA.
    Configure log data integrations from the Integrations Launchpad
    Starting in version 36.0.19, benefit from additional log data integrations for Splunk TCP/UDP, Splunk Poller, MID Server, Apache Kafka, Microsoft Azure Log Analytics, and REST API that can be easily set up through the Integrations Launchpad.
    Set up an Amazon Data Firehose integration for real-time log data streaming from multiple sources
    Starting in version 36.0.19, leverage an integration for streaming log data from Amazon Data Firehose directly to the collector service in ITOM Gateway, where it is queued and then processed by Health Log Analytics. This integration doesn't run on a MID Server and can be configured from the Integrations Launchpad.

    Zurich

    Facilitate Cribl log data ingestion by Health Log Analytics using the Cribl integration
    Starting in version 37.0.15, use the Cribl log data integration to streamline Health Log Analytics data ingestion with Cribl. If your organization uses Cribl for filtering and routing large volumes of log data from various sources, the log format received by HLA is distinct from other types. The Cribl integration enables HLA to detect and separate transport headers from inner log messages in this format, forwarding only the inner message to the source type structure for processing. You can configure the Cribl integration conveniently through the Integrations Launchpad.
    Leverage additional information available on the integration's Overview screen

    Starting in version 37.0.15, take advantage of extra information presented on the Overview screen. The screen now displays the ITOM Gateway in the log processing pipeline and the log streaming rate per minute, aligning it with the metrics for the MID Server and the HLA Engine. The Overview screen also shows the source time of the last processed log.

    Export source types to an update set by log source
    Starting in version 38.0.16, export all source types related to one or more selected log sources to an update set together. You can then import the update set to the target environment.
    Map log data to service instances and components for alerts in context
    Starting in version 38.0.16, map your logs to service instances and components so that Health Log Analytics can generate alerts in the correct context. Contextualizing your log data is especially important when the integration processes logs from multiple service instances and components.
    Display Integrations Launchpad from the ITOM AIOps configuration center
    Starting in version 38.0.16, open the Integrations Launchpad from ITOM AIOps configuration center. The ITOM AIOps configuration center is a centralized workspace that enables you to configure and manage AIOps features from a single place.
    Set up a GCP PubSub integration from the Integrations Launchpad
    Starting in version 38.0.16, set up an integration from the Integrations Launchpad for receiving log messages that were published to a Google Cloud Platform (GCP) Pub/Sub topic and streaming them to your ServiceNow instance.
    Set up a Microsoft Azure Event Hubs integration from the Integrations Launchpad
    Starting in version 38.0.16, set up an integration from the Integrations Launchpad for streaming events from Microsoft Azure Event Hubs to your ServiceNow instance.
    Set up an Edge Delta TCP or REST integration from the Integrations Launchpad
    Starting in version 38.0.16, set up an integration from the Integrations Launchpad to enable Health Log Analytics to process Edge Delta log messages streaming into your ServiceNow instance over the TCP transport protocol or via REST.
    Monitor ServiceNow instance logs with the ServiceNow Log Export data input
    Starting in version 38.0.16, set up a data input for monitoring ServiceNow instance node logs from both Java code and JavaScript in Health Log Analytics.

    Changes

    Between your current release family and Zurich, some changes were made to existing Health Log Analytics features.

    Release Release notes

    Yokohama

    Component-based alert grouping is deprecated
    Starting in version 36.0.19, the adoption of a streamlined two-tier alert model, Log Analytics Group to Single Alert, has replaced component-based alert groups, which have been removed. This model aligns alert representation with the service-level anomalies identified by Health Log Analytics, rather than individual host CIs. The update improves alert visibility, simplifies correlation, and enhances overall alert management efficiency.

    Zurich

    No updates for this release.

    Removed

    Between your current release family and Zurich, some Health Log Analytics features or functionality were removed.

    Release Release notes

    Yokohama

    No updates for this release.

    Zurich

    No updates for this release.

    Deprecations

    Between your current release family and Zurich, some Health Log Analytics features or functionality were deprecated.

    Release Release notes

    Yokohama

    No updates for this release.

    Zurich

    No updates for this release.

    Activation information

    Review information on how to activate Health Log Analytics.

    Release Release notes

    Yokohama

    Install Health Log Analytics by requesting it from the ServiceNow Store. Visit the ServiceNow Store website to view all the available apps and for information about submitting requests to the store. For cumulative release notes information for all released apps, see the ServiceNow Store version history release notes.

    Zurich

    Install Health Log Analytics by requesting it from the ServiceNow Store.

    Additional requirements

    If any additional requirements were introduced or changed for Health Log Analytics we have noted them here.

    Release Release notes

    Yokohama

    No updates for this release.

    Zurich

    No updates for this release.

    Browser requirements

    If any specific browser requirements were introduced or changed for Health Log Analytics we have noted them here.

    Release Release notes

    Yokohama

    No updates for this release.

    Zurich

    No updates for this release.

    Accessibility information

    Review details on accessibility information for Health Log Analytics, such as specific requirements or compliance levels.

    Release Release notes

    Yokohama

    No updates for this release.

    Zurich

    Localization information

    If there are specific localization considerations for Health Log Analytics we have noted them here.

    Release Release notes

    Yokohama

    The current available languages for Health Log Analytics are US English, UK English, French, German, Italian, Japanese, and Spanish. The default language is US English.

    Zurich

    The current available languages for Health Log Analytics are US English, UK English, French, German, Italian, Japanese, and Spanish. The default language is US English.

    Highlight information

    If there are specific highlight considerations for Health Log Analytics we have noted them here.

    Release Release notes

    Yokohama

    • Use the enhanced Splunk data input to ingest data from Splunk in a preprocessed structured format. You can also pull data from Splunk regularly using the new Splunk Polling data input.
    • Take advantage of a unified interface for convenient data input integration by setting up integrations from the Integrations Launchpad.
    • Streamline HLA data ingestion with tools for handling large log volumes by using dedicated Cribl and Edge Delta data inputs.
    • Configure log data integrations for Splunk TCP/UDP, Splunk Poller, MID Server, Apache Kafka, Microsoft Azure Log Analytics, REST API, and Amazon Data Firehose conveniently from the Integrations Launchpad.
    • Generate a description of Health Log Analytics alerts using Now Assist.

    See Health Log Analytics for more information.

    Zurich

    • Use the Cribl integration to streamline Health Log Analytics data ingestion with Cribl.
    • Leverage additional information presented on the integration's Overview screen, such as the ITOM Gateway in the processing pipeline and the log streaming rate per minute.
    • Map log data to service instances and components for alerts in context.
    • Monitor ServiceNow instance logs with the ServiceNow Log Export data input.

    See Health Log Analytics for more information.