Log Export Service release notes
Summarize
Summarized using AI
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.
Summary of Log Export Service release notes
The Log Export Service (LES) on the ServiceNow Store enables customers to export and manage system and audit logs efficiently, supporting integration with log analytics tools via Kafka and REST protocols. LES simplifies log data export, enhances compliance with extended audit coverage, and offers improved operational visibility, scalability, and security controls through regular updates.
Show less
Key Features
- Auto-Configuration: LES automatically configures default log sources (syslog and sysaudit) upon plugin activation, reducing setup time and ensuring consistent baseline configurations.
- Expanded Audit Log Support: Support for additional audit log sources like sysauditdelete and sysauditrelation enhances compliance and audit capabilities, especially for relational and deletion record tracking.
- Enhanced Visibility and Metrics: New APIs surface LES metrics directly within the Vault Console, allowing security administrators to monitor export health, throughput, and connectivity alongside platform security data.
- Improved MID Server Integration: Guided Setup tools and updated connectivity validation streamline MID Server configuration, including Kafka cluster connectivity testing, with clear setup instructions and performance guidelines.
- Role-Based Access Control: Fine-grained, feature-specific administrative roles allow delegated LES management without granting full platform admin rights.
- Log Export Flexibility: Ability to assign different filters and topics per log source, with support for multiple consumers running in parallel without conflicts.
- Comprehensive Reporting: Enhanced export reports with intuitive drill-downs over extended timeframes and new data consumption reports per log source improve operational insights.
- Connectivity Options: Supports Kafka native integration, Splunk Connect for Kafka, and REST protocol through dedicated MID Servers for flexible log event forwarding.
Key Outcomes
- Reduced post-installation configuration effort through auto-configuration of default log sources.
- Improved compliance and audit readiness with expanded audit log source coverage.
- Streamlined operational monitoring by consolidating LES metrics within the Vault Console.
- Simplified and reliable MID Server setup and connectivity validation for seamless log export.
- Enhanced security posture with granular, role-based administration of LES features.
- Greater flexibility in log export configuration, enabling tailored filtering and topic assignment per log source.
- More actionable insights through detailed reporting and analytics on log data export volumes and trends.
- Stable and scalable log export operations with support for parallel consumers and improved handling of service slowness.
Version history for the Log Export Service on the ServiceNow Store.
Important:
For details on system requirements and family compatibility, view the application
listing on the ServiceNow Store
website.
Version history
- Version 3.5.0 - June 2026
-
- What's New:
- Auto-Configuration of Default Log Sources on Plugin Activation Log Export Service now automatically configures syslog and sys_audit as default log sources when the LES plugin is activated. Previously, administrators had to manually configure these sources after activation. This reduces post-install setup time and ensures a consistent baseline configuration out of the box.
- LES Metrics Visibility in Vault Console New APIs expose LES operational metrics directly within the Vault Console. Security administrators can now view export health, throughput, and connectivity status alongside other platform security posture data without context-switching to a separate LES admin view. This closes a key dependency (DEP0046129) required for the Vault Console integration.
- Extended Audit Log Source Support: sys_audit_delete and sys_audit_relation LES now supports two additional audit log source types: sys_audit_delete (records of deleted records) and sys_audit_relation (relationship-level audit changes). This expands audit coverage for customers with compliance requirements around deletion and relational data changes, and addresses a request from SAP customers.
- Updated Guided Setup for MID Server Connectivity (Hermes) The LES guided setup flow has been refreshed to include an updated connectivity check for Hermes-based MID server configurations, improving clarity and reducing friction during initial setup and re-configuration.
- What's New:
- Version 3.4.0 - March 2026
-
- New:
- Introduced network connectivity validation UI action for MID Server, enabling one-click Kafka cluster connectivity testing directly from the ServiceNow interface without requiring manual network commands in the MID Server environment.
- Published MID Server performance guidelines for Log Export Service, including validated scalability thresholds and capacity planning recommendations.
- Changed: Enhanced granular role-based access control across Log Export Service, enabling delegation of LES administration through feature-specific roles (sn_logstoanalytics.admin) without requiring full platform admin privileges.
- Fixed: Enhanced Log Export Service to maintain reliable operations during Hermes service slowness, without impacting instance stability.
- New:
- Version 3.3.0 - August 2025
-
- New:
- Enhanced Logs Exported reports with intuitive drill-down from month to week to day, source-level breakdown, and support for 395 days of data.
- Enable multiple LES consumers to run in parallel across different topics without conflict or failure.
- Fixed:
- Removed unnecessary informational logs being continuously generated by the MID Server LES consumer.
- Fixed a bug where selecting an existing topic during consumer creation caused an error, and selecting a correct new topic did not create the expected record.
- The system property sn_logstoanalytics.debug is now disabled by default to prevent unnecessary debug logs in node logs.
- Fixed an issue where updating existing syslog log source records to sys_audit did not remove associated log source topic and logger configuration records.
- New:
- Version 3.2.0 - May 2025
-
- New: Added the ability to set different filters for the syslog source and assign the log source configuration to different topics.
- Fixed: Resolved an issue where consumer context records were not deleted properly when cloning an instance with a MID server configuration.
- Version 3.1.0 - February 2025
-
- New: The capability to create and name the topics, as well as assign various sys_audit tables to each topic.
- Fixed: System log filters not applied accurately while pushing system log events to the Hermes topic.
- Version 2.2.3 - November 2024
- New: Option to store log events from each log source into a separate Kakfa topic in Hermes Messaging Service.
- Version 3.0.6 - August 2024
-
- New:
- New data consumption report that shows how much data has been copied to Hermes Messaging Service per each log source
- Option to store log events from each log source into a separate Kakfa topic in Hermes Messaging Service.
- Added description to sys_logger_configuration record
- New:
- Version 2.2.1 - May 2024
-
- This is a minor release with a small number of user experience improvements including:
- The organization of Log Export Service pages in the universal navigation dropdown has been improved
- The status details information in the Consumer page has been moved to its own page called Consumer Status
- This is a minor release with a small number of user experience improvements including:
- Version 2.1.0 - November 2023
-
- New:
- Added two new Guided Setup tools to the App to help cutomers complete the initial setup with step by step instructions and guidance.
- One Guided Setup tool is for the MID Server integration option and the other for the Kafka Consumer option.
- New:
- Version 2.0.1 - August 2023
- New:
- New functionality with Log Export Service v2
- Added support for leveraging dedicated MID Server to easily connect to ServiceNow cloud and then push log events to your own log analytics tool via standard REST protocol.
- Version 1.0.4 - May 2023
-
Improvements for ServiceNow cloud internal reporting purposes.
- Version 1.0.3 - January 2023
- Fixed: Security fix
- Version 1.0.1 - November 2022
-
- First version of this service; we plan to add more connectivity options and log sources in future versions.
- Supports the following connectivity options:
- Kafka native
- Splunk Connect for Kafka
- Supports the following system and application log sources:
- System Log Tables
- syslog table
- syslog_transaction table
- Audit Table
- sys_audit table
- Node Log Files
- localhost files (for all nodes)
- System Log Tables
- Supports filters to reduce log source export size.
- Provides report and analytics for log sources data size.