Use PDIs? Take our 5-minute survey to help shape the PDI roadmap.

Event Management – Storage Limit, Retention and Long-Term Event Data

SyedBurhanJamil
Tera Contributor

Hi Community,

I am trying to understand how ServiceNow Event Management should be sized and used when very large event volumes are involved.

I have already verified that raw events are stored in em_event, alerts in em_alert, and that em_event uses table rotation. In my test instance, the rotation is configured for 1 day with 7 rotations.

My main questions are:

  1. Is there any documented maximum storage/capacity limit for Event Management, such as a GB/TB limit, or is this based on customer-specific database/storage entitlement?

  2. With a 1-day duration and 7 rotations, is it correct to expect roughly 7 days of raw event retention before older rotation data is cleaned/reused?

  3. If an organization needs to retain millions of events for months or years, is the recommended approach to archive them in another ServiceNow table or export them to an external SIEM/data warehouse/data lake?

In short: If ServiceNow receives millions of events, how much data can realistically be retained, for how long, and what is the recommended architecture for longer-term retention?

Any official ServiceNow documentation, sizing guidance, entitlement information, or real-world implementation experience would be greatly appreciated.

Thank you.

1 REPLY 1

abbasshaik4
Tera Sage

Hello @SyedBurhanJamil,

 

Please refer to the link below:
https://www.bing.com/ck/a?!&&p=ec0f28ab0107413fb790811ac47bf9d22c70e277e0ff46c1963ab6d9d6331c06Jmltd...
https://www.bing.com/ck/a?!&&p=e39ec78f0e4b639f828e284477415301890d4ea0fce4d4570f405077fd59a088Jmltd...

If it is helpful, please mark it as helpful and accept the correct solution by referring to this solution in the future it will be helpful to them.

Thanks & Regards,

Abbas Shaik