Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Rsyslog, Filebeat, or Winlogbeat data input configuration fields

Description of the fields on the Rsyslog, Filebeat, and Winlogbeat data input configuration forms.

Basic configuration

FieldDescription
Data input nameName of the new data input. This field is required.
DescriptionDescription of the data input.
MID Server

The MID Server to which the logs stream.Note:

  • You can select only MID Servers with log ingestion capability that support basic authentication. MID Servers that support mTLS are not listed.
  • The default maximum number of data inputs streaming logs to a single MID Server is 10. You can modify this number in the MID Server properties.

This field is required.

PortThe port on the MID Server. Choose a port within the suggested range from the array. The port must not be occupied by another process. Make sure that your organization’s security team opens the selected port. This field is required.
Content pack\(Linux using Filebeat only\) The content pack to use.Content packs contain default source types and mapping script templates. Health Log Analytics activates the selected pack automatically and uses its mapping script for mapping the data input sources. For more information, see Health Log Analytics content packs for quicker time to value.
FieldDescription
PathThe full path from which to stream logs. You can use a wildcard. This field is required.
Service instanceThe service instance to which to bind the log data. This field is required.Note: If no relevant service instance exists, Create an service instance and add CIs to it. Set the status of the new service instance to Operational.
ComponentThe device type or stack layer as context for the logs that is used for anomaly detection and correlation. For example: Tomcat.Components typically represent CIs in the CMDB. Several components are often clustered together in a single service instance.
Source TypeThe source type, which defines how Health Log Analytics handles a specific application and parses the log data. For example: Tomcat Catalina.Each data input can have multiple source types, based on the diversity of its log formats. Service instances and components can have any number of source types.

Advanced configuration

For Rsyslog data inputs:

FieldDescriptionDefault values
Use SSL/TLSOption to use SSL/TLS. 
Look up hostnamesOption to perform DNS lookup to resolve IPs to hostnames.false
Boss thread countThe number of threads that manage connections.1
Worker thread countThe number of threads that handle incoming data.4
Read timeout secondsThe timeout in seconds since the last read. When the timeout expires, the system closes the channel.30
Default timezoneThe default time zone of events. The system uses this default when the log does not specify a time zone.GMT
Sub sample drop ratioThe ratio of events to drop.-1
Sub sample receive ratioThe ratio of events to receive.-1
Max length in bytesThe maximum length of log messages in bytes.32766
Character encodingThe character encoding for this data input.UTF-8
Drop if queue is fullOption to discard logs if there is a load on the MID Server. 

For data inputs that use Beats agents:

FieldDescriptionDefault value
Client inactivity timeout (sec)The timeout, in seconds, to close an inactive channel.15
Worker thread countThe number of threads that handle incoming data.4
Default time zoneThe default time zone of events. The system uses this default when the log does not specify a time zone.GMT
Sub sample drop ratioThe ratio of events to drop.-1
Sub sample receive ratioThe ratio of events to receive.-1
Max length in bytesThe maximum length of log messages, in bytes.32766
Character encodingThe character encoding for this data input.UTF-8
Drop if queue is fullOption to discard logs if there is a load on the MID Server.false

Parent Topic:Data input configuration fields