...
The event will look like this in Splunk:
...
SAP Navigation
Navigate to this data by using the RZ10 t-code. Enter the desired profile name in the “Profile Name” field, and the profile version in the “Version” field, select Extended Maintenance under the “Edit Profile” option, and select the “Display” button.
...
The field mapping between the data from SAP and values in Splunk can be seen in the table below:
...
Group Definition/EVENT_TYPE
...
Field |
---|
RZ10
N/A
Splunk Field Name
RZ10
N/A
Description | Unit of Measure |
---|---|
CURRENT_TIMESTAMP |
RZ10
Description
DESCR
The date time stamp when the information was collected | YYYYMMDDHHMMSS |
EVENT_SUBTYPE |
|
String | |
EVENT_TYPE | RZ10 |
String | ||
UTCDIFF | The UTC OFFSSET in HHMMSS that the data was collected in | HHMMSS |
UTCSIGN | The UTC positive or negative OFFSET indicator. Positive (+) means add UTCDIFF to find the time zone of the data, negative (-) means subtract the UTCDIFF to find the time zone adjusted date time the data was collected in. | + | - |
DESCR | Description | String |
PAR_DEFAULT_WERT1 |
RZ10
Unsubstituted standard value | String |
PAR_DEFAULT_WERT2 |
RZ10
Substituted standard value | String |
PAR_NAME |
RZ10
Profile parameter name | String |
PAR_USER_WERT |
RZ10
N/A
UTCDIFF
RZ10
N/A
Parameter value | String | |
GROUPNAME | Parameter group | String |