Data Description

The SMQ2 event is used in SAP to view and administer inbound qRFC entries.

Potential Use Cases

This event could be used for the following scenarios:

  • Alert on qRFC errors for a specific destination.

  • Create a dashboard of qRFC error trends over time

Splunk Event

The event will look like this in Splunk:

SAP Navigation

Navigate to this data by using the SMQ2 t-code.

Enter “X” in the Waiting Queues Only field, and hit the Execute button.

You will now be able to see which qRFC entries have failed. Double-click on the value you are interested in the Queue Name field

You will now be able to see when the qRFC failure was created, the sender, and the number of entries. Double-click on the qRFC name to proceed to the next screen.

You will now be able to see the qRFC error detail.

Field Mapping

The field mapping between the data from SAP and values in Splunk can be seen in the table below:

Group Definition/EVENT_TYPE

EVENT_SUBTYPE (if applicable)

SAP Field Name

Splunk Field Name

SMQ2

Internal Data Element

BATCHPLA

SMQ2

N/A

CURRENT_TIMESTAMP

SMQ2

Destination

DEST

SMQ2

Error message

ERRMESS

SMQ2

N/A

EVENT_SUBTYPE

SMQ2

N/A

EVENT_TYPE

SMQ2

Failure date

FDATE

SMQ2

Character field of length 24

FIRSTTID

SMQ2

Counter for serialized tRFC

FQCOUNT

SMQ2

Failure Time

FTIME

SMQ2

System Date

LDATE

SMQ2

Counter for serialized tRFC

LQCOUNT

SMQ2

System Time

LTIME

SMQ2

Client

MANDT

SMQ2

Message ID

MSGID

SMQ2

Message Number

MSGNO

SMQ2

Queue depth

QDEEP

SMQ2

Counter within a transaction (LUW)

QLUWCNT

SMQ2

Queue Name

QNAME

SMQ2

Queue Status

QSTATE

SMQ2

N/A

UTCDIFF

SMQ2

N/A

UTCSIGN

SMQ2

Name of queue

WQNAME