---
sourceDocument: Yokohama IT Operations Management
sourceDocumentLink: https://www.servicenow.com/docs/r/yokohama/it-operations-management

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama IT Operations Management

ft:clusterId :

    - itom

bundleId :

    - itom

workflow :

    - Technology


---

# Header properties detection

# Header properties detection {#ariaid-title1}

* Release version: Yokohama
* 
* Updated January 30, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

In Health Log Analytics, automatic header properties detection separates the transport header from the inner log message and forwards only the inner log message to the source type structure. The inner message contains
the actual log data without including shipping information.

The Health Log Analytics
application supports header properties detection for Fluentd, Beats, and Syslog (RFC 3164, RFC 5424).

Starting with Version 33.0.27 - August 2024, the system also supports header properties detection for logs that follow the OpenTelemetry logs data model and semantic conventions. For more information, see
the [OpenTelemetry Logs Data Model documentation](https://opentelemetry.io/docs/specs/otel/logs/data-model/).

## Disabling header properties detection {#hla-header-detection__section_qbf_vqg_1cc}

When you disable header properties detection for a data input, the Health Log Analytics AI Engine stops extracting properties from the header. Forwarding the complete raw message can be useful in the following situations:  
* The inner log message lacks information for parsing, such as timestamp and severity.
* The data input contains information that can be used for structuring.
* The data input forwards the logs fully parsed.
{#hla-header-detection__ul_yqt_2bk_jnb}

For the procedure to disable header properties detection, see [Map raw log data](https://www.servicenow.com/docs/ENjBmAW1AM2qvvmJSA_YiQ "Mapping raw log data that streams into your instance determines how the data is handled. Health Log Analytics automatically structures logs, creates metrics for anomaly detection, and presents alerts based on how your data is tagged.").

