Data Description
The SMQ1 event is used in SAP to view and administer outbound qRFC entries.
Potential Use Cases
This event could be used for the following scenarios:
Alert on qRFC errors for a specific destination.
Create a dashboard of qRFC error trends over time
Splunk Event
The event will look like this in Splunk:
SAP Navigation
Navigate to this data by using the SMQ1 t-code.
Enter “X” in the Waiting Queues Only field, and hit the Execute button.
You will now be able to see which qRFC entries have failed. Double-click on the value you are interested in the Queue Name field
You will now be able to see when the qRFC failure was created, what destination is impacted, and the number of entries. Double-click on the qRFC name to proceed to the next screen.
You will now be able to see the qRFC error detail.
Field Mapping
The field mapping between the data from SAP and values in Splunk can be seen in the table below:
Group Definition/EVENT_TYPE | EVENT_SUBTYPE (if applicable) | SAP Field Name | Splunk Field Name |
---|---|---|---|
SMQ1 | Internal Data Element | BATCHPLA | |
SMQ1 | N/A | CURRENT_TIMESTAMP | |
SMQ1 | Destination | DEST | |
SMQ1 | Error message | ERRMESS | |
SMQ1 | N/A | EVENT_SUBTYPE | |
SMQ1 | N/A | EVENT_TYPE | |
SMQ1 | Failure date | FDATE | |
SMQ1 | Character field of length 24 | FIRSTTID | |
SMQ1 | Counter for serialized tRFC | FQCOUNT | |
SMQ1 | Failure Time | FTIME | |
SMQ1 | System Date | LDATE | |
SMQ1 | Counter for serialized tRFC | LQCOUNT | |
SMQ1 | System Time | LTIME | |
SMQ1 | Client | MANDT | |
SMQ1 | Queue depth | QDEEP | |
SMQ1 | Counter within a transaction (LUW) | QLUWCNT | |
SMQ1 | Queue Name | QNAME | |
SMQ1 | Queue Status | QSTATE | |
SMQ1 | N/A | UTCDIFF | |
SMQ1 | N/A | UTCSIGN | |
SMQ1 | Name of queue | WQNAME |