Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

The data from the RZ10 event will then display.

...

Field Mapping

The field mapping between the data from SAP and values in Splunk can be seen in the table below:

...

Field

...

Description

...

Unit of Measure

...

CURRENT_TIMESTAMP

...

The date time stamp when the information was collected

...

YYYYMMDDHHMMSS

...

EVENT_SUBTYPE

...

 

...

String

...

EVENT_TYPE

...

RZ10

...

String

...

UTCDIFF

...

The UTC OFFSSET in HHMMSS that the data was collected in

...

HHMMSS

...

UTCSIGN

...

The UTC positive or negative OFFSET indicator. Positive (+) means add UTCDIFF to find the time zone of the data, negative (-) means subtract the UTCDIFF to find the time zone adjusted date time the data was collected in.

...

+ | -

...

DESCR

...

Description

...

String

...

PAR_DEFAULT_WERT1

...

Unsubstituted standard value

...

String

...

PAR_DEFAULT_WERT2

...

Substituted standard value

...

String

...

PAR_NAME

...

Profile parameter name

...

String

...

PAR_USER_WERT

...

Parameter value

...

String

...

GROUPNAME

...

Parameter group

...

String