...
Determine candidates for data archiving.
Understand if records for a large table were unexpectedly deleted.
Metric Filters
Metric filter is available in Administrator->Metric Filters->More->Record count filter menu option
The filter accepts the list of tables which needs to checked:
...
Metric Configuration
By default, the extractor pulling top 50 tables by record count. However, in case manual input is used, the recommendation is to set the parameter below to 0 in Administrator->Setup Metric->Metric Configuration menu option.
...
Splunk Event
The event will look like this in Splunk:
...
Then the information regarding the record count, which matches the data in Splunk will appear.
...
Field Mapping
The field mapping between the data from SAP and values in Splunk can be seen in the table below:
...
Field
...
Description
...
Unit of Measure
...
CURRENT_TIMESTAMP
...
The date time stamp when the information was collected
...
YYYYMMDDHHMMSS
...
DBSPACE
...
Storage size in database (kilobytes)
...
Number
...
EVENT_SUBTYPE
...
String
...
EVENT_TYPE
...
TABLE_COUNT
...
String
...
RECORDS
...
Number of records in the table
...
Number
...
TABNAME
...
Table name
...
String
...
UTCDIFF
...
The UTC OFFSSET in HHMMSS that the data was collected in
...
HHMMSS
...
UTCSIGN
...
The UTC positive or negative OFFSET indicator. Positive (+) means add UTCDIFF to find the time zone of the data, negative (-) means subtract the UTCDIFF to find the time zone adjusted date time the data was collected in.
...
+ | -