---
sourceDocument: Zurich Platform security
sourceDocumentLink: https://www.servicenow.com/docs/r/zurich/platform-security

 Release :

    - zurich

ft:locale :

    - en-US

ft:publication_title :

    - Zurich Platform security

ft:clusterId :

    - psec

bundleId :

    - psec

workflow :

    - Platform


---

# Explore

# Exploring Auditing {#ariaid-title1}

* Release version: Zurich
* 
* Updated July 31, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Track record changes on auditing-enabled tables. By default, the system tracks changes to the incident, change, and problem tables, among others.{#exploring-auditing__audit-desc}

## Auditing overview {#exploring-auditing__section_ogd_wwc_4gc}

Enabling auditing tracks the creation, update, and deletion of all records in the table. If you want to audit individual fields in a table, you can hide fields you don't want to track using a dictionary attribute.  
Auditing information is kept in the following tables:

* [Audit](https://www.servicenow.com/docs/NlCa6S2kWwSAppzmDly4_g#c_UnderstandingTheSysAuditTable "The ServiceNow AI Platform tracks inserts and updates to audited records in the Sys Audit (sys_audit) and Audit Relationship Change (sys_audit_relation) tables.")
* [Knowing about History sets](https://www.servicenow.com/docs/LDR_qODooj9s~fcebEuzMA "The system automatically generates History Set records as needed from the Audit table when a user either creates a record or views its history.")
{#exploring-auditing__ul_hxz_g2l_sq}  
Warning:  
Auditing system tables that receive a large amount of traffic, such as workflow Contexts \[wf_context\] or Event Management Alerts \[em_alert\], can impact performance. For this reason, you can't audit the em_alert table as a whole. Instead, audit selected fields of interest. Set audit=true on both the em_alert table and the selected fields. Try to audit as few fields as possible.

## Auditing users {#exploring-auditing__section_gmq_f1d_4gc}

Auditing has the following users.

* admin
* security_admin
{#exploring-auditing__ul_fbr_b55_4gc}

## Auditing benefits {#exploring-auditing__section_dgr_p1d_4gc}

{#exploring-auditing__table_egr_p1d_4gc__entry__3}

| Benefit | Feature | Users |
|-|-|-|
| Enable table auditing to track changes to all or some of the table's fields | [Configuring auditing for a table](https://www.servicenow.com/docs/UaBpSvztlkw5yv1TGXDgBw "You can enable table auditing to track changes to all or some of the table's fields.") | admin |
| Experience a more enhanced way of defining and configuring the audit capability | [Configure auditing using Audit Management Console](https://www.servicenow.com/docs/fili3Xo65ueUccfW3rme0w "Use Audit Management Console module to experience a more enhanced way of defining and configuring the audit capability within your instance.") | admin |
| Automate and simplify the deletion of audit data | [Setup your audit retention](https://www.servicenow.com/docs/owU7ZUZzJSfR5_RHhpLe3A "Use the Retention option to automate and simplify the deletion of audit data as per your requirement.") | security_admin |
[ ]

{#exploring-auditing__table_egr_p1d_4gc}

## What to explore next {#exploring-auditing__cf-exploring-parent-links}

To learn more about using Auditing, see:

* [Configuring auditing for a table](https://www.servicenow.com/docs/UaBpSvztlkw5yv1TGXDgBw "You can enable table auditing to track changes to all or some of the table's fields.")
* [Configure auditing using Audit Management Console](https://www.servicenow.com/docs/fili3Xo65ueUccfW3rme0w "Use Audit Management Console module to experience a more enhanced way of defining and configuring the audit capability within your instance.")
* [Viewing Sys Audit and Audit Relationship Change tables](https://www.servicenow.com/docs/NlCa6S2kWwSAppzmDly4_g#c_UnderstandingTheSysAuditTable "The ServiceNow AI Platform tracks inserts and updates to audited records in the Sys Audit (sys_audit) and Audit Relationship Change (sys_audit_relation) tables.")
* [Knowing about History sets](https://www.servicenow.com/docs/LDR_qODooj9s~fcebEuzMA "The system automatically generates History Set records as needed from the Audit table when a user either creates a record or views its history.")
{#exploring-auditing__ul_fhy_xfw_sbc}

