Mapping logs for contextual alerts in Health Log Analytics

  • Release version: Australia
  • Updated March 12, 2026
  • 1 minute to read
  • Map your logs to service instances, components, and source types so that Health Log Analytics can generate alerts in context.

    Mapping your log data to the correct context is especially important when the integration processes logs from multiple service instances and components. ServiceNow Otto suggests the best log field for mapping to service instances and components. When you use the AI-suggested field, or when that field is the default, an AI sparkle icon () appears. You can select a different field if needed. If the AI agent can't find a suitable match, HLA uses the system default. The system default also applies if the selected field is not present in the sample log.

    For a walkthrough of how to set up and review AI-suggested mappings, see AI-assisted log mapping in Health Log Analytics.

    Example

    A large financial institution might face performance issues with its e-banking application, which relies on various components like web, application, and database servers. Without log context mapping, logs from these components appear isolated, making it difficult to correlate issues. An anomaly in a Tomcat server log might be detected, but without proper context, the operator struggles to assess its impact. Log context mapping enables you to define rules to map logs to the e-banking application service instance and the Tomcat server component. This mapping provides a contextualized view for root cause analysis and resolution.