Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

The event will look like this in Splunk:

...

SAP Navigation

Navigate to this data by using the RZ10 t-code. Enter the desired profile name in the “Profile Name” field, and the profile version in the “Version” field, select Extended Maintenance under the “Edit Profile” option, and select the “Display” button.

...

The data from the RZ10 event will then display.

...

Field Mapping

The field mapping between the data from SAP and values in Splunk can be seen in the table below:

...

Group Definition/EVENT_TYPE

...

EVENT_SUBTYPE (if applicable)

...

SAP Field Name

...

Splunk Field Name

...

RZ10

...

N/A

...

CURRENT_TIMESTAMP

...

RZ10

...

Description

...

DESCR

...

RZ10

...

N/A

...

EVENT_SUBTYPE

...

RZ10

...

N/A

...

EVENT_TYPE

...

RZ10

...

Unsubstituted standard value

...

PAR_DEFAULT_WERT1

...

RZ10

...

Substituted standard value

...

PAR_DEFAULT_WERT2

...

RZ10

...

Profile parameter name

...

PAR_NAME

...

RZ10

...

Parameter value

...

PAR_USER_WERT

...

RZ10

...

N/A

...

UTCDIFF

...

RZ10

...

N/A

...

UTCSIGN