Configure data inputs (Elasticsearch)
Configure a data input for streaming log data from Elasticsearch indices to your ServiceNow instance. Data input configuration is an essential step in setting up the Health Log Analytics (HLA) application.
Before you begin
- Ensure that a MID Server is installed and configured with the Log Ingestion capability enabled. For more information, see MID Server system requirements.Important:Health Log Analytics does not support IPv6. To work with the application, configure the MID Server to IPv4.
- If the MID Server IP address is exposed by network address translation (NAT), a load balancer or a similar device, it must have a public IP address. In the MID Server properties, add a property named mid.public_ip with the public IP address as the value. For more information, see Create a MID Server property.
Health Log Analytics supports Elasticsearch versions above 7.10.2 and below 8.18.2.
Role required: evt_mgmt_admin
Procedure
Result
The data input configuration process is complete. Health Log Analytics adds the data input record to the Data Inputs table and attaches the configuration file to the data input record. The data input starts streaming log data from Elasticsearch indices to your ServiceNow instance.
For more information about streaming logs using the Elasticsearch data input, see the Stream logs using Elasticsearch data input - Advanced guide [KB1080162] article in the Now Support Knowledge Base.
What to do next
Make sure that the data input is streaming data.