Interested in a ServiceNow event built for developers? Registration for now[dev]26 is officially open!

Work Note extraction from Incidents

luisenvenga
Mega Contributor

Dear community

 

How to get the complete conversation/work notes from the Incidents?

 

The task is simple. The steps are nowhere to be found.

 

The only piece of info I could get was a video claiming we can use APIs or Coding to get the incidents data, but nothing else and no additional detail was given

 

Appreciate your support.

9 REPLIES 9

VJ_Srivastava
Tera Expert

Hello @luisenvenga,

From an architectural standpoint, extracting journal fields requires careful planning, especially if you intend to do this at scale for thousands of incidents.

The sys_journal_field table is typically one of the absolute largest tables in any enterprise ServiceNow instance, frequently housing hundreds of millions of rows.

If your goal is to extract the complete conversation history for a single incident via a one-off API call, Neha’s REST API approach is perfectly fine. However, if you are attempting a bulk extraction—such as dumping all incident work notes into an external data lake, PowerBI, or an external LLM for analysis—you must exercise extreme caution.

Running heavy, unbound queries against sys_journal_field during business hours can severely degrade your database performance and cause platform-wide latency. For bulk extractions, I strongly advise against raw REST API loops. Instead, utilize native architectural mechanisms like the ServiceNow Instance Data Replication (IDR) or scheduled batched exports during off-peak hours to ensure your production instance remains highly performant.

Hello Srivastava

 

I don't think IDR or APIs are needed for this case. The data does not require continuos integration back and forth (for now). This is a single time event, for analaysis.

 

We will keep a keen eye on this in case if it's needed later.

 

Thanks again and regards

 

 

NehaG8791370651
Tera Expert

Hi ,

This is a very common requirement, and the reason you can't find it directly on the Incident form is because of how ServiceNow stores data. Because work notes and additional comments can be infinitely long, they are not stored in the incident table. Instead, they are stored in a separate, massive background table called sys_journal_field.

Here are the two best technical methods to extract them:

Method 1: Server-Side Scripting (The easiest way) If you are writing a Business Rule, Script Include, or Background Script, you do not need to query the journal table manually. ServiceNow has a built-in method called getJournalEntry(-1) which fetches the entire history as a single string.

  • The Code: var allNotes = current.work_notes.getJournalEntry(-1);

  • Note: Passing -1 tells the system to get all historical entries, not just the most recent one.

Method 2: REST API Integration (For external systems) If you are using Postman, Python, or a third-party tool to extract the data, you must query the journal table directly.

  • Endpoint: GET /api/now/table/sys_journal_field

  • Query Parameters: sysparm_query=name=incident^element=work_notes^element_id=YOUR_INCIDENT_SYS_ID

  • This will return a JSON array containing every individual work note for that specific incident.

Thank you  Neha

 

I will try method 1 with my dev team. i really appreciate your help. I will update you back once one.

 

Regards

Hello Neha,

 

Just spoke with system admins and Project stakeholders and they don't see any additional value on creating code or connecting an API for a single time event. 

 

Can you think about any other solution? Any way I can upate the properties of the sys_journal_field table into a regular table from which I can run standard reports?

 

Thanks and regards.