Data Description

The SMQ1 event is used in SAP to view and administer outbound qRFC entries.

Potential Use Cases

This event could be used for the following scenarios:

  • Alert on qRFC errors for a specific destination.

  • Create a dashboard of qRFC error trends over time

Splunk Event

The event will look like this in Splunk:

SAP Navigation

Navigate to this data by using the SMQ1 t-code.

Enter “X” in the Waiting Queues Only field, and hit the Execute button.

You will now be able to see which qRFC entries have failed. Double-click on the value you are interested in the Queue Name field

You will now be able to see when the qRFC failure was created, what destination is impacted, and the number of entries. Double-click on the qRFC name to proceed to the next screen.

You will now be able to see the qRFC error detail.

Field Mapping

The field mapping between the data from SAP and values in Splunk can be seen in the table below:

Group Definition/EVENT_TYPE

EVENT_SUBTYPE (if applicable)

SAP Field Name

Splunk Field Name

SMQ1

Internal Data Element

BATCHPLA

SMQ1

N/A

CURRENT_TIMESTAMP

SMQ1

Destination

DEST

SMQ1

Error message

ERRMESS

SMQ1

N/A

EVENT_SUBTYPE

SMQ1

N/A

EVENT_TYPE

SMQ1

Failure date

FDATE

SMQ1

Character field of length 24

FIRSTTID

SMQ1

Counter for serialized tRFC

FQCOUNT

SMQ1

Failure Time

FTIME

SMQ1

System Date

LDATE

SMQ1

Counter for serialized tRFC

LQCOUNT

SMQ1

System Time

LTIME

SMQ1

Client

MANDT

SMQ1

Queue depth

QDEEP

SMQ1

Counter within a transaction (LUW)

QLUWCNT

SMQ1

Queue Name

QNAME

SMQ1

Queue Status

QSTATE

SMQ1

N/A

UTCDIFF

SMQ1

N/A

UTCSIGN

SMQ1

Name of queue

WQNAME