Set up an Elasticsearch integration for Health Log Analytics
Set up an integration to stream log data seamlessly from Elasticsearch indices to your instance for Health Log Analytics processing.
始める前に
- Verify that the Health Log Analytics application is installed and provisioned on your instance. For more information, see Install Health Log Analytics (HLA).
- Verify that a service instance is available.
- Verify that the Health Log Analytics AI Engine is up and running.
- Verify that a MID Server is installed and configured with the Log Ingestion capability enabled. For more information, see MID Server system requirements.重要:Health Log Analytics does not support IPv6. To work with the application, configure the MID Server to IPv4.
- Unless the MID Server and external clients are on the same network, the MID Server must have a public IP address. This is required when its IP is exposed through network address translation (NAT), a load balancer, or a similar device. The public IP address enables external clients, such as Filebeat agents located outside its network, to reach the MID Server. Private IP addresses are not routable over the internet. Without a public IP, external clients cannot connect to the MID Server even if they are configured with its address. In the MID Server properties, add a property named mid.public_ip with the public IP address as the value. For more information, see Create a MID Server property. If the MID Server and external clients are on the same network, connections can be made using the private IP address.
Role required: evt_mgmt_admin
このタスクについて
You set up integrations through the Integrations Launchpad in Service Operations Workspace, which you access from the ITOM AIOps configuration center. The AIOps configuration center is a centralized workspace for configuring and managing AIOps features from a single place. The integrations setup process reduces implementation time compared to manual data input setup in the classic interface in Health Log Analytics. For more information, see Integrations Launchpad in Service Operations Workspace for ITOM.
手順
次のタスク
- Use the displayed information to refine how Health Log Analytics reads the log data. For more information, see Review log streaming data and adjust integration settings in Health Log Analytics.
- Use the More options menu (
) to open the Data Input Mapping, Source Type Structures, or Log Sources pages with context from the integration. If your log data is not properly mapped, structured, or sourced, go back and adjust the configuration. If the Service Operations Workspace Log Analytics application is installed, the More options menu also provides direct access to the Log Viewer. Use the Log Viewer to review raw log messages ingested by the integration. For more information, see:
If you activated the integration with AI, verify that AI correctly auto-mapped log data to service instances and components. To do this, select View mapping under Log context mapping. You can override the AI mapping by selecting a different log field from each list. For more information, see Map logs to service instances, components, and source types for contextual alerts in Health Log Analytics.