cancel
Showing results for 
Search instead for 
Did you mean: 

SM20 Audit log - The result set for this selection was empty

Former Member
0 Kudos

Hello Gurus,

after Kernelupdate the audit log files changed her name?! *strange*

We do not changed any parameter.

Now we tried to add the parameter FN_AUDIT to instance profile with the new filename, but this changed nothing.

it seems that the kernel do not take the parameter, after restart.

System is EHP6 FOR SAP ERP 6.0 with NW 7.31

SAP Kernel :  721_EXT_REL Patch 512

has someone a suggestion?

regards

Chris

Accepted Solutions (1)

Accepted Solutions (1)

Former Member
0 Kudos

Hey there,

it was a simple set mistake.

After the right setting with ++++++++_######.AUD value, it's fine.

Thanks for your suggestions.

Chris

Answers (3)

Answers (3)

cris_hansen
Advisor
Advisor
0 Kudos

Hi Chris,

Be sure that you do not want more than one audit file per day. Thus, you should set only:

rsau/max_diskspace/local

-> here FN_AUDIT should use only +++ in the pattern, e.g. audit_++++++++.

If you really want more than only SAL file per day, then set:

rsau/max_diskspace/per_file

rsau/max_diskspace/per_day

-> here FN_AUDIT should contemplate this, e.g. audit_++++++++_######.

It is worth to read the following two SAP notes:

909738 - SecAudit: Files are created with other names

539404 - FAQ: Answers to questions about the Security Audit Log

I hope this helps,

Cris

Former Member
0 Kudos

Try ++++++++_######.AUD or ++++++++######.AUD once.

Former Member
0 Kudos

Hi Chris,

Please check your audit profile in SM19 and also ensure the parameters are set correctly.

The following parameters below are essential for you being able to read in SM20.

The parameter DIR_AUDIT in the current value fulfill your directory. All this configuration you can do this through SM19. After the changes don't forget to activate the the audit profile in SM19.