Skip to content
Release: Australia · Updated: 2026-05-04 · Official documentation · View source

MID-less log streaming via ITOM Gateway in Health Log Analytics

Health Log Analytics (HLA) can receive log data from external sources directly through the ITOM Gateway, without routing data through a MID Server. This architecture supports cloud-native log sources such as Amazon Data Firehose, Cribl, and OpenTelemetry, and is required for high-volume HLA deployments.

How log streaming via ITOM Gateway works

External log sources send data to the ITOM Gateway over gRPC. The ITOM Gateway forwards the data to the  Hermes  Messaging Service, which delivers it to the AI Engine, the HLA processing back-end. This design separates log streaming from ingestion, enabling higher throughput than direct MID Server streaming.

Deployment scenarios

The setup path depends on your expected log volume.

Deployment typeSetup
StandardFor typical log volumes, enable ITOM Gateway and the  Hermes  Messaging Service on your instance, configure a JSON Web Token \(JWT\) provider and token, and set up your log source from Integrations Launchpad. For more information, see Configure a JSON Web Token (JWT) provider and token for Health Log Analytics and Set up log streaming via ITOM Gateway for Health Log Analytics.
High-volume

For deployments requiring 30,000 or more log events per second, you must scale the HLA infrastructure before enabling ITOM Gateway. This process involves resizing the AI Engine and Elasticsearch nodes and coordinating a cross-team migration.Contact ServiceNow Support to request infrastructure scaling. For details and the required information to provide, see Set up log streaming via ITOM Gateway for Health Log Analytics

Note: Infrastructure scaling requires a 6-hour change window and involves expected downtime of 2–6 hours for HLA functions only.

Supported log sources

Currently, the following log sources can stream data to HLA via ITOM Gateway:

Each source has a dedicated tile in Integrations Launchpad for configuration.

Authentication

Log sources authenticate to HLA using a JWT token. You must configure a JWT provider and generate a token on the ServiceNow instance before activating an ITOM Gateway integration.

Key components

ComponentDescription
ITOM GatewayReceives incoming log data from external sources over gRPC and forwards it to the  Hermes  Messaging Service.
Hermes  Messaging ServiceMessage broker that routes data from ITOM Gateway to the HLA back-end.
AI EngineHLA back-end component that processes and analyzes ingested log data.
Integrations LaunchpadServiceNow interface for configuring log source integrations. Each supported log source has a dedicated tile.

Parent Topic:Set up Health Log Analytics on your ServiceNow instance

Related topics

Configure a JSON Web Token (JWT) provider and token for Health Log Analytics

Set up log streaming via ITOM Gateway for Health Log Analytics