---
sourceDocument: Australia Platform security
sourceDocumentLink: https://www.servicenow.com/docs/r/platform-security

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Platform security

ft:clusterId :

    - psec

bundleId :

    - psec

workflow :

    - Platform


---

# Log history

# Log history {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

The system uses table rotation and table extension to archive older logs.
By default, the system uses the following schedule to archive common logs:  
{#r_LogHistory__table_dht_zwj_sq__entry__4}

| Table | Archive schedule | Rotations | Type |
|-|-|-|-|
| Event \[ecc_event\] | Every day | 7 | Rotation |
| Queue \[ecc_queue\] | Every day | 7 | Rotation |
| Event \[sysevent\] | Every day | 7 | Rotation |
| Log \[syslog\] | Every week | 8 | Rotation |
| Transaction Log \[syslog_transaction\] | Every week | 8 | Rotation |
[Table 1. Common log archive schedule]

{#r_LogHistory__table_dht_zwj_sq}  
Note:  
The Email \[sys_email\] table is not managed using table rotation or extension. Instead, use the [Email retention](https://www.servicenow.com/docs/access?context=email-retention&version=australia&pubname=australia-platform-administration&ft:locale=en-US) plugin to archive and destroy email records. By default, email records are archived after one year and destroyed after an additional year in the archive.

