0
40.5.0
Brazil, Australia Patch 5, Australia, Zurich Patch 12, Zurich Patch 8, Zurich, Yokohama Patch 4, Yokohama
Standalone Application
The ServiceNow® Health Log Analytics application helps predict IT issues before they affect users. The application helps you solve issues faster by ingesting, analyzing, and correlating machine-generated log data in real-time.
When Health Log Analytics helps detect a deviation from a normal pattern, it alerts you of a possible business-impacting issue.
Health Log Analytics is a ServiceNow ITOM AIOps application.
- Log ingestion and processing
- Predictive alerts based on anomaly detection
- MTTR and Root Cause Analysis
- Machine Learning (ML) and Artificial Intelligence (AI) - Discover patterns in your log data
- Log Viewer
- Alert visualization
- Log analytics alert rules - Define rules that detect anomalous behavior
- Executive dashboards
New
- Host Label correlation now supports tiered lookup across multiple CMDB CI classes. Host Labels assigned to Kubernetes services and other modern infrastructure types are now correlated to their respective CMDB CIs using an ordered search across hardware, Virtual Machines, Kubernetes, and API-based fallbacks. This enables alert enrichment and topology context for a broader range of infrastructure.
- Admins can now configure and manage OpenTelemetry ingest sources via ServiceNow-native APIs. The new API endpoints allow registration, listing, status checking, updating, and removal of OTel data sources. MCP tool definitions are provided for agent-driven and Otto workflows, enabling programmatic onboarding and management without manual UI steps.
- Expiring token email notifications are now available for MID-less data integrations. Users receive email alerts when integration tokens are nearing expiration, prompting timely refresh actions.
- Admins can now add a certificate policy check option for Splunk Poll data inputs. The new usemidcertificatepolicycheck setting enables admins to control MID certificate policy enforcement for Splunk Poll integrations, with UI placement and compatibility logic for Brazil and later releases.
Changed
- Raw manual test samples are now transient in Source Type Structure. Test samples entered in the manual sample field are no longer permanently saved; they are cleared on refresh, preventing contamination of subsequent flows.
Fixed
- Admins can now suppress redundant keyword detections and prioritize message detections in HLA anomaly alerts. When multiple keyword detections occur for the same component at the same time, only the first detection is surfaced as an alert; subsequent detections are suppressed. If a message detection exists for the same component and pattern, keyword detections are suppressed in favor of message detection. Suppression is silent and applied in real time.
Not applicable for this application version.
ITOM AIOps.