Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

The event will look like this in Splunk:

...

SAP Navigation

Navigate to this data by using the RZ10 t-code. Enter the desired profile name in the “Profile Name” field, and the profile version in the “Version” field, select Extended Maintenance under the “Edit Profile” option, and select the “Display” button.

...

The field mapping between the data from SAP and values in Splunk can be seen in the table below:

...

Group Definition/EVENT_TYPE

...

SAP

Field

Name

RZ10

N/A

Splunk Field Name

RZ10

N/A

Description

Unit of Measure

CURRENT_TIMESTAMP

RZ10

Description

DESCR

The date time stamp when the information was collected

YYYYMMDDHHMMSS

EVENT_SUBTYPE

RZ10

 

N/A

String

EVENT_TYPE

RZ10

Unsubstituted standard valueSubstituted

String

UTCDIFF

The UTC OFFSSET in HHMMSS that the data was collected in

HHMMSS

UTCSIGN

The UTC positive or negative OFFSET indicator. Positive (+) means add UTCDIFF to find the time zone of the data, negative (-) means subtract the UTCDIFF to find the time zone adjusted date time the data was collected in.

+ | -

DESCR

Description

String

PAR_DEFAULT_WERT1

RZ10

Profile parameter name

Unsubstituted standard value

String

PAR_DEFAULT_WERT2

RZ10

Parameter value

Substituted standard value

String

PAR_NAME

RZ10

Profile parameter name

String

PAR_USER_WERT

RZ10

N/A

UTCDIFF

RZ10

N/A

UTCSIGN

Parameter value

String

GROUPNAME

Parameter group

String