---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Legacy: Execution Tracking - Begin Flow Action

# Legacy: Execution Tracking - Begin Flow Action {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

The Execution Tracking - Begin flow action starts the auditing process for a Security Operations Integration flow that operates on observables.  
Important:  
This feature is no longer deployed, enhanced, or supported. It has been replaced by Capability Implementation Execution. For details, see the [Deprecation Process \[KB0867184\]](https://support.servicenow.com/kb_view.do?sysparm_article=KB0867184) article in the
Now Support knowledge base.
The Execution Tracking - Begin flow action can be used with any flow to begin recording the progress of the flow in an audit.

## Results {#execution-tracking-begin__section_ux5_rz5_ndb}

Possible results for this flow action are:
{#execution-tracking-begin__table_lg3_dm5_vy__entry__2}

| Result | Description |
|-|-|
| Success | An audit record is created. |
[Table 1. Results]

{#execution-tracking-begin__table_lg3_dm5_vy}

## Input variables {#execution-tracking-begin__section_alh_hfm_3z}

Input variables determine the initial behavior of the flow action.
{#execution-tracking-begin__table_pgm_tfy_jr__entry__2}

| Variable | Description |
|-|-|
| capabilityId | System identifier of the Integration Capability being executed. |
| isImpl | Flag that specifies whether auditing is done for an Integration Capability flow or an Integration Capability implementation flow. Possible values are: * false - denotes auditing on an abstract Integration Capability flow such as Sightings Search. (default.) * true - denotes auditing on an Integration Capability implementation flow. For example, Splunk or Elasticsearch. {#execution-tracking-begin__ul_ady_ymc_ty} |
| taskId | System identifier for any task associated with the flow. |
| observableList | One or more observable SysIDs to perform the desired action. Used as a flow input. |
| flowContextId | System identifier of the associated flow context record. Supplied by the system. |
| flowName | Name of the flow. Supplied by the system. |
| parentCapabilityExcutionId | System identifier of the audit record that launched the implementation flow. Only required for Integration Capability implementation flows such as Splunk, Elasticsearch, and VirusTotal. |
[ ]

{#execution-tracking-begin__table_pgm_tfy_jr}

## Output variables {#execution-tracking-begin__section_vx5_rz5_ndb}

The output variables contain data that can be used in subsequent actions.
{#execution-tracking-begin__table_bnj_jfy_jr__entry__2}

| Variable | Description |
|-|-|
| capabilityExecutionId | System identifier of the audit record. |
[Table 2. Output variables]

{#execution-tracking-begin__table_bnj_jfy_jr}  
* [Get Supported Security Capabilities action](https://servicenow-prod.fluidtopics.net/iiKXFyzD8b7PaGdn84u7ag "The Get Supported Capabilities flow action retrieves the name and number of integrations that are active and support the requested capability.")
* [Legacy: Capability Execution Tracking- No Impls action](https://servicenow-prod.fluidtopics.net/8gyoOnrdwEvCZgYXRRg4eg "The Capability Execution Tracking - No Impls flow action creates an error record when no integration capability implementation is found.")
{#execution-tracking-begin__ul_wt4_fcy_hcc}

