Data Description

The AL11 event is used in SAP to display the SAP Directories and associated files.

Potential Use Cases

This event could be used in the following scenarios:

  • Monitoring to confirm that files are being added to the directory at the correct time.

  • Confirm that critical files are added to the SAP directories.

  • Monitor the size of certain SAP directories.

Metric Filters

The Metric Filter needs to be defined to extract data for this event. Log into the managed system and execute the /n/bnwvs/main transaction code. Then go to Administrator → Metric filters → AL11 filter.

Then fill out the configuration based on your needs, and save. Below is a summary of the fields and their associated function:

  • Directory Parameters - This field is mandatory, and is the SAP directory where the information is stored.

  • Context Path - This field is mandatory, and is the file path where the information is stored.

  • Collect names - This field is optional, and is a checkbox to activate or deactivate the collection of the file names stored within the file path (i.e. AL11 with EVENT_SUBTYPE=”NAMES”).

  • Collect count - This field is optional, and is a checkbox used to activate or deactivate the collection of the summary level statistics associated with the directory (i.e. AL11 with EVENT_SUBTYPE=””)

Here is an example of what the AL11 metric filter looks like when it is filled out:

Splunk Event

AL11 with EVENT_SUBTYPE=””

Important Note: The Metric Filter needs to be configured to enable data extraction for this event.

The event will look like this in Splunk:

AL11 with EVENT_SUBTYPE=”NAMES”

Important Note: The Metric Filter needs to be configured to enable data extraction for this event.

The event will look like this in Splunk:

SAP Navigation

AL11 with EVENT_SUBTYPE=””

Important Note: The Metric Filter needs to be configured to enable data extraction for this event.

Log into the managed system and execute the AL11 transaction code. You will then be brought to the Directory summary page, which will match the data in Splunk.

AL11 with EVENT_SUBTYPE=”NAMES”

Important Note: The Metric Filter needs to be configured to enable data extraction for this event.

Log into the managed system and execute the AL11 transaction code. You will then be brought to the Directory summary page.

Double-click on the directory line of interest to go to the directory page where the file detail is shown.

Field Mapping

AL11 with EVENT_SUBTYPE=””

Important Note: The Metric Filter needs to be configured to enable data extraction for this event.

Field

Description

Unit of Measure

CURRENT_TIMESTAMP

The date time stamp when the information was collected

YYYYMMDDHHMMSS

DIRNAME

Directory name

String

EVENT_SUBTYPE

String

EVENT_TYPE

AL11

String

NRFILES

Number of files

Number (Count)

SAP_DIR

SAP directory name

String

USEDSPACE

Space used in bytes

Number (Sum)

UTCDIFF

The UTC OFFSSET in HHMMSS that the data was collected in

HHMMSS

UTCSIGN

The UTC positive or negative OFFSET indicator. Positive (+) means add UTCDIFF to find the time zone of the data, negative (-) means subtract the UTCDIFF to find the time zone adjusted date time the data was collected in.

+ | -

AL11 with EVENT_SUBTYPE=”NAMES”

Important Note: The Metric Filter needs to be configured to enable data extraction for this event.

Field

Description

Unit of Measure

CURRENT_TIMESTAMP

The date time stamp when the information was collected

YYYYMMDDHHMMSS

DATE

Change date

YYYYMMDD

DIRNAME

Directory name

String

EVENT_SUBTYPE

NAMES

String

EVENT_TYPE

AL11

String

FILENAM

File name

String

SAP_DIR

SAP directory name

String

TIME

Change time

HHMMSS

USEDSPACE

Space used in bytes

Number (Sum)

UTCDIFF

The UTC OFFSSET in HHMMSS that the data was collected in

HHMMSS

UTCSIGN

The UTC positive or negative OFFSET indicator. Positive (+) means add UTCDIFF to find the time zone of the data, negative (-) means subtract the UTCDIFF to find the time zone adjusted date time the data was collected in.

+ | -