...
The data will then be displayed, which will match the values in Splunk.
...
Field Mapping
The field mapping between the data from SAP and values in Splunk can be seen in the table below:
...
Group Definition/EVENT_TYPE
...
EVENT_SUBTYPE (if applicable)
...
SAP Field Name
...
Splunk Field Name
...
ROLE_AUTH
...
Role Name
...
AGR_NAME
...
ROLE_AUTH
...
Role name description
...
AGR_TEXT
...
ROLE_AUTH
...
Authorization name in user master maintenance
...
AUTH
...
ROLE_AUTH
...
ID whether object is copied
...
COPIED
...
ROLE_AUTH
...
Menu ID for BIW
...
COUNTER
...
ROLE_AUTH
...
N/A
...
CURRENT_TIMESTAMP
...
ROLE_AUTH
...
ID whether object is deleted
...
DELETED
...
ROLE_AUTH
...
N/A
...
EVENT_SUBTYPE
...
ROLE_AUTH
...
N/A
...
EVENT_TYPE
...
ROLE_AUTH
...
Field name of an authorization
...
FIELD
...
ROLE_AUTH
...
Filter value defined in the Metric Filters above
...
FLT_HIGH
...
ROLE_AUTH
...
Filter value defined in the Metric Filters above
...
FLT_LOW
...
ROLE_AUTH
...
Authorization value
...
HIGH
...
ROLE_AUTH
...
Authorization value
...
LOW
...
ROLE_AUTH
...
Client ID
...
MANDT
...
ROLE_AUTH
...
Object status
...
MODIFIED
...
ROLE_AUTH
...
ID whether object is new
...
NEU
...
ROLE_AUTH
...
Internal: Node ID
...
NODE
...
ROLE_AUTH
...
Auth. Object in User Master Maintenance
...
OBJECT
...
ROLE_AUTH
...
N/A
...
UTCDIFF
...
ROLE_AUTH
...
N/A
...
UTCSIGN
...
ROLE_AUTH
...
Variants for Profile Generator
...
VARIANT