Data Description

The SM12 event is used in SAP to display and delete enqueue application locks.

Potential Use Cases

This event could be used in the following scenarios:

  • Alert on aging enqueue entries.

  • Trend overall enqueue entry volume over time.

  • Alert on enqueue entry volume.

Splunk Event

The event will look like this in Splunk:

SAP Navigation

Log into the managed system and execute the SM12 t-code. Enter the desired user selection parameters and select the List button.

The information displayed will match the data in Splunk.

Field Mapping

Field

Description

Unit of Measure

CURRENT_TIMESTAMP

The date time stamp when the information was collected

YYYYMMDDHHMMSS

EVENT_SUBTYPE

String

EVENT_TYPE

SM12

String

GARG

Lock argument

String

GBCKTYPE

Backup flag

Boolean

GCLIENT

Client

String

GMODE

Lock Mode

String

GNAME

Table name

String

GOBJ

Lock Object Name

String

GTARG

Argument String of Lock Entry (Table Key Fields)

String

GTCODE

Transaction Code

String

GTDATE

Lock date

YYYYMMDD

GTHOST

Host name

String

GTMARK

Not used (added for compatibility reasons)

Boolean

GTSYSNR

System Number

Number

GTTIME

Lock time

HHMMSS

GTUSEC

Lock time microseconds

Number

GTWP

Work Process

Number

GUNAME

User Name

String

GUSE

Cumulative counter

Number (Count)

GUSETXT

Cumulative counter text formatted

String

GUSEVB

Cumulative counter update

Number (Count)

GUSEVBT

Cumulative counter update text formatted

String

GUSR

Lock Owner

String

GUSRVB

Lock Owner

String

UTCDIFF

The UTC OFFSSET in HHMMSS that the data was collected in

HHMMSS

UTCSIGN

The UTC positive or negative OFFSET indicator. Positive (+) means add UTCDIFF to find the time zone of the data, negative (-) means subtract the UTCDIFF to find the time zone adjusted date time the data was collected in.

+ | -