Back to blog

How to Monitor Configuration Changes Using Audit Logs in NetSuite

Why Monitor Configuration Changes

Even with a strong change management process and tickets in place, auditors and control owners need technical evidence to validate what was changed, by whom, and when. In NetSuite, this evidence comes from the built-in System Notes Audit Trail features. Reviewing these logs is essential because configuration pages directly impact financial reporting, workflows, and system integrity. Without monitoring, organizations risk unauthorized changes going unnoticed — whether accidental or malicious.

Built-In Audit Logging in NetSuite

NetSuite provides native audit capabilities through System Notes, which capture:

  • The specific field that was updated.
  • The user ID of the person who made the change.
  • The role that the user leveraged to make the change.
  • The old value and the new value.
  • The timestamp of the change.

For configuration pages like Enable Features, NetSuite maintains a full audit trail that shows when a feature was turned on or off. This is critical for controls because enabling or disabling a feature can dramatically change how transactions are processed or reported.

The Enable Features Page

The Enable Features Page Audit Trail

External Monitoring Options

For larger organizations, audit logs can be exported and ingested into external monitoring solutions such as SIEM tools (Splunk, QRadar, etc.) or GRC platforms. This enables real-time alerting if sensitive configurations are modified outside of approved change windows.

Reporting Frequency & Scope

Monitoring should be aligned with the risk level of the configuration page:

  • High-risk configuration pages (e.g., Enable Features, Accounting Preferences, General Preferences) → Should be reviewed on a weekly basis at minimum, with daily or near real-time monitoring recommended for organizations with a lower risk tolerance.
  • Medium-risk configuration pages (e.g., Payment Terms, Tax Codes) → Can be reviewed monthly, or more frequently (weekly) if aligned with the organization’s risk appetite or regulatory obligations.
  • Periodic assurance → Conduct quarterly attestations by control owners to verify that no unauthorized changes occurred and that all recorded changes were properly supported by approved change tickets.

By aligning monitoring frequency with risk, organizations can balance effort with effectiveness.

When Audit Logs Are Absent

Most NetSuite configuration pages have audit logs, but if your organization identifies a page that does not, you can consider implementing compensating controls. For example:

  • Require workflow-based approval before changes are applied.
  • Capture before/after snapshots of the configuration settings.

These measures provide visibility when System Notes are unavailable.

Controls & Recommendations

To make monitoring effective, organizations should:

  • Periodically Review System Notes for all critical setup pages.
  • Compare audit logs to change tickets to confirm changes were authorized.
  • Alert on anomalies such as changes made outside approved maintenance windows or by users not expected to perform configuration work.

Periodic reviews of these audit logs are more than a compliance exercise — they can reveal unauthorized or even malicious activity that would otherwise go undetected.

Summary – Reviewing Audit Logs Over Key Configuration Pages Strengthens Security and Controls

Audit logs transform “trust” into verified evidence, making them the foundation of reliable IT General Controls in NetSuite. By periodically reviewing the audit trails of key configuration pages — especially Enable Features, General Preferences, and Accounting Preferences — and reconciling them against approved change tickets, organizations strengthen both compliance posture and security. This practice ensures that NetSuite remains a trustworthy system of record, resilient against unauthorized changes and fraud.