Log data auto-mapping and mapping
Summarize
Summary of Log data auto-mapping and mapping
Health Log Analytics automatically assigns incoming log lines to relevant tags—service instance, component, and source type—to organize and analyze log data effectively. By default, it derives the service instance from the data input setup, while component and source type tags are auto-extracted from fields likesource,path, and others. This intelligent auto-mapping streamlines log ingestion and classification for better monitoring and root cause analysis.
Show less
Customizing Mapping and Data Extraction
You can manually override automatic mapping results by defining a JavaScript function during data input setup. This allows precise control over how log data is classified and tagged. Test mode is available to preview mapping changes safely without impacting production data or storage. It processes sample log data to help you refine your mapping scripts before publishing.
Additionally, Health Log Analytics provides options to:
- Stop extracting unnecessary or redundant log data to improve clarity and reduce noise.
- Ensure the extraction of specific desired terms from logs and map them to particular components.
Managing Data Input Sources and Limits
Mapping raw log data correctly is key to generating meaningful metrics and alerts. The system can create multiple data input sources based on your logs, but excessive source creation—potentially caused by faulty mapping scripts—is controlled via configurable system properties. These properties set warning and critical limits on the number of sources per data input. When limits are breached, notifications are sent and data input streaming can be stopped to prevent storage overload. Guidance is available for resolving such issues.
Binding Logs to Configuration Items (CIs)
Binding log entries to service instances linked with Configuration Items (CIs) in the CMDB enables correlation between logs and infrastructure components. This integration supports advanced root cause analysis by allowing Health Log Analytics to trace issues through related CIs.
Key Benefits for ServiceNow Customers
- Automated, accurate classification of log data improves monitoring efficiency.
- Customizable mapping and extraction enable tailored log analysis aligned with organizational needs.
- Test mode and system limits help maintain data quality and prevent resource overuse.
- Integration with CMDB enhances root cause analysis by linking logs to configuration items.
By default, the Health Log Analytics AI engine tries to auto-map every incoming log line to the correct tags. You can change automatic mapping results manually by defining a JavaScript function.
Auto-mapping incoming log lines
Health Log Analytics auto-mapping assigns log samples and metadata to three tags: service instance, component, and source type. The service instance assignment is based on the service instance specified in the data input setup. The remaining tags are assigned automatically.
For example, in the following example log line, Health Log Analytics uses the "source" field to find the component and source type.
{"beat":{"version":"6.8","name":"abc3.prd.acme.com","hostname":"abc3.prd.acme.com"},"@timestamp":"2020-08-27T10:12:24.792Z","prospector":{"type":"log"},"message":"**** User null is requesting the following page http://www.acme.com PROPS:{"subcategory1":"home pages","httpStatus":"200","loginLevel":"Anonymous","userAgent":"Mozilla5.0", ("pageUrl":\"http://www.acme.com","host":"abc3.prd.acme.com","@version":"1","source":"/opt/oracle/weblogic/abc/online_store3/logs/online_store3.out","offset":3951550786}
In the example, Health Log Analytics extracts the string "online_store". It analyzes the following fields if they exist in the log line: source, path, channel, namespace_name, name, pod_name, source_name, and aws_lambda_name. When data is sent over Syslog, it also analyzes the syslog tag.
- Stop extraction of unneeded data
- If an extracted string is not descriptive enough or contains redundant text or information, you can stop extracting such expendable data. For more information, see Stop extraction of unneeded log data.
- Ensuring extraction of specific data
- You can make sure that Health Log Analytics extracts specific desired terms. For more information, see Ensure extraction of specific log data.
Mapping data input sources
You can change automatic mapping results manually by defining a JavaScript function. Data input mapping enables you to organize your log data by service instance and by availability zone. A single service instance can include multiple components, and a component can receive logs from many different source types. An service instance-component pair, however, is unique. Source types are based on a specific log structure and format. Service instances and components are defined more broadly and are therefore used mainly for logical mapping.
Activating Test mode avoids blowing up Elasticsearch storage with sample data that is used only for perfecting the log data mapping. When the data input is in Test mode, Health Log Analytics doesn’t create the source types, sources, or any other objects it creates in the standard flow. It saves the streamed data in dedicated temporary Elasticsearch indices that appear as components in the Log viewer. When you publish the script and exit Test mode, these temporary indices are deleted to minimize storage space consumption.
| System property | Description | Default |
|---|---|---|
| log_source.sources_warning_limit | The warning limit for the number of sources created per data input. | 500 |
| log_source.sources_critical_limit | The critical limit for the number of sources created per data input. | 600 |
Binding log data
Binding log data to Configuration Items (CIs) in the Configuration Management Database (CMDB) enables you to search the CMDB for endpoints that match a log. When you configure a data input, you bind log entries to a service instance that is bound to a CI in the CMDB. Binding log entries, service instances, and CIs enables the Health Log Analytics AI engine to correlate them for use in root cause analysis (RCA). For more information, see Configure Rsyslog, Filebeat, or Winlogbeat data inputs or Configure Elasticsearch data inputs.