0
3.6.0
Australia Patch 5, Australia, Zurich, Yokohama
Standalone Application
Log Export Service enables customers to export their ServiceNow instance system and application logs at scale and in near real time as a service to their enterprise log analytics solutions (e.g. Splunk) and Kafka environments.
- Easily export system and application logs without any coding or integration scripts.
- Highly scalable and near real-time data transmission architecture (leverages internal Kafka cloud infrastructure).
- Reduce complexity and increase efficiency by being able to specify log sources and data filters for them.
New
- Historical log backfill: You can now replay historical log data to your Kafka destination, in addition to live logs. A new setup screen lets you select the log table, date range, target topic, batch size, and throttling. Backfill settings are locked once a run begins to prevent accidental changes mid-run, and a live run status is displayed while the backfill is in progress.
- LES now supports the following additional log source tables:
-
- sys_flow_log: Captures execution details and status of flow engine processes, for both live and historical export
- sys_user_login_history: Captures user login attempts and authentication events
- sys_audit_delete and sys_audit_relation: Delete and relationship audit records — so your compliance trail now includes record deletions and reference-field changes, not just regular field changes.
- Auditor role: A new sn_logstoanalytics.auditor role lets auditors view Log Export Service activity without broader administrator access.
Changed
- Guided setup now includes a Test MID Connection step, so you can verify connectivity to the Kafka cluster before exporting logs catching configuration problems earlier.
Fixed
- Log sources created with a scope filter exported logs using the default Syslog configuration instead of the specified configuration.
- The Topic field did not appear when creating a Syslog or sys_audit log source until the record was saved and reopened.
- Broken links in the Kafka and MID Server consumer guided setup screens.
- A broken link on the Hermes Messaging Service setup step, which also displayed an inaccurate status.
- The backfill run table earlier displayed an inaccurate report visibility issue for some users due to a missing ACL.
Not applicable for this application version.
- Australia
- Zurich
- External connectivity: we support two main modes:
- 1. Dedicated MID Server
- 2. Native Kafka binary protocol:
- Kafka to Kafka native connectivity from external Kafka deployments
- With third-party supported Kafka connectors such as the Splunk Connect for Kafka.
- Licenses:
- Sub-production instances: don't require licenses
- Production instances:
- Begin with a zero-dollar license.
- For extended usage, one or more premium SKUs — such as Log Export Service Additional — can be added.
- With a ServiceNow Vault license, Log Export Service (LES) can be used without any usage limitations.
- On-premise installations: not supported
- External connectivity: we support two main modes: