IT CanvassTalk to an advisor
ITOM deep-dive · LessonBy , ServiceNow Trainer, 8 yrs · Published · current release · advanced

Health Log Analytics

Spot problems in log noise before they become outages.

Quick answer

Health Log Analytics (HLA) reads the log streams from your applications and infrastructure and detects anomalies before they become outages, spotting the unusual pattern that precedes a failure, often ahead of any threshold-based alert.

Key takeaways
  • Logs as an early-warning signal
  • How it works
  • Part of AIOps
  • Common mistakes

Health Log Analytics (HLA) reads the log streams from your applications and infrastructure and detects anomalies before they become outages, spotting the unusual pattern that precedes a failure, often ahead of any threshold-based alert.

Logs as an early-warning signal

Where Event Management reacts to alerts that monitoring tools already raised, HLA looks deeper, at raw logs, and learns each system's normal behaviour. A sudden spike in error patterns or log volume becomes an anomaly signal.

Log streams --> learn a baseline of "normal" per source detect deviation (error spike, volume surge, new pattern) --> anomaly alert --> bound to a CI --> AIOps pipeline

How it works

Ingest
Collect logs from apps, hosts and services via the MID Server / agents.
Baseline
Machine-learn normal log behaviour per source over time.
Detect
Flag deviations, anomalies, and score them.
Correlate
Bind anomalies to CIs and feed the same alert pipeline as Event Management.

Part of AIOps

HLA reduces mean-time-to-detect by catching the anomaly in the logs rather than waiting for a hard failure and a user complaint. It complements Event Management (which needs a threshold to trip) by finding the unknown-unknowns, patterns no one wrote a rule for.

Common mistakes

  • Expecting value on day one, the baseline needs time to learn.
  • Feeding it unstructured, unlabelled logs and hoping for signal.
  • Treating HLA as a replacement for, not a complement to, Event Management.
  • Ignoring the anomalies it raises because they don't fit an existing rule.

Practice challenge

+0 XPStreak ×0
Question 1 of 3
HLA detects problems by:

Frequently asked questions

What does the term Health Log Analytics refer to in ServiceNow?
Health Log Analytics (HLA) reads the log streams from your applications and infrastructure and detects anomalies before they become outages, spotting the unusual pattern that precedes a failure, often ahead of any threshold-based alert.
What is another point to note about Health Log Analytics?
Where Event Management reacts to alerts that monitoring tools already raised, HLA looks deeper, at raw logs, and learns each system's normal behaviour.
What else is worth knowing about Health Log Analytics?
A sudden spike in error patterns or log volume becomes an anomaly signal.
What tends to go wrong with Health Log Analytics?
Expecting value on day one, the baseline needs time to learn. Feeding it unstructured, unlabelled logs and hoping for signal. Treating HLA as a replacement for, not a complement to, Event Management.
Already working on ServiceNow and stuck on a live ticket?Get an expert ServiceNow developer on screen-share to finish your daily tasks with you. Deliver on time, protect your reputation and your job. Monthly support only, no task-wise plans.Task assigned · no idea where to startStill stuck · your job on the lineExpert joins your screenDelivered on timeExplore On Job Support