...
The data displayed below will match with what you see in Splunk.
...
Field Mapping
The field mapping between the data from SAP and values in Splunk can be seen in the table below:
...
Field
...
Description
...
Unit of Measure
...
ACCNT
...
Account ID
...
String
...
BNAME
...
User Name in User Master Record
...
String
...
CLASS
...
User group in user master maintenance
...
String
...
CURRENT_TIMESTAMP
...
The date time stamp when the information was collected
...
YYYYMMDDHHMMSS
...
EVENT_SUBTYPE
...
String
...
EVENT_TYPE
...
USH02
...
String
...
GLTGB
...
User valid to
...
YYYYMMDD
...
GLTGV
...
User valid from
...
YYYYMMDD
...
MODBE
...
Last changed by
...
String
...
MODDA
...
Modification date
...
HHMMSS
...
MODTI
...
Modification time
...
YYYYMMDD
...
PWDINITIAL
...
Indicator: Password Is Initial
...
0 | 1
...
REPID
...
ABAP Program Name
...
String
...
TCODE
...
Transaction code used to modify account
...
String
...
UFLAG
...
User Lock Status
...
String
...
USTYP
...
User type
...
String
...
UTCDIFF
...
The UTC OFFSSET in HHMMSS that the data was collected in
...
HHMMSS
...
UTCSIGN
...
The UTC positive or negative OFFSET indicator. Positive (+) means add UTCDIFF to find the time zone of the data, negative (-) means subtract the UTCDIFF to find the time zone adjusted date time the data was collected in.
...
+ | -