C_RSAU_LOG_API

DDL: C_RSAU_LOG_API SQL: C_RSAU_API Type: view

SIEM API for Security Audit Log

C_RSAU_LOG_API is a CDS View that provides data about "SIEM API for Security Audit Log" in SAP S/4HANA. It reads from 1 data source (rsau_log) and exposes 23 fields with key fields eventID, log_tstmp, slgproc, slgmand, sid. It has 5 associations to related views. It is exposed through 1 OData service (RSAU_LOG_API_SERVICE).

Data Sources (1)

SourceAliasJoin Type
rsau_log _header from

Associations (5)

CardinalityTargetAliasCondition
[0..*] I_RSAU_MESSAGETEXT _text_active _text_active.msgid = _header.event and _text_active.spras = $session.system_language -- text English
[0..*] I_RSAU_MESSAGETEXT _text_english _text_english.msgid = _header.event and _text_english.spras = 'E'
[0..*] tsl1d_attr _pseudo_attr _pseudo_attr.event = _header.event
[0..1] I_RSAU_UGROUP _usergrp _usergrp.bname = _header.slguser and _usergrp.mandt = $session.client
[0..1] I_User _user _user.UserID = _header.slguser

Annotations (4)

NameValueLevelField
AbapCatalog.sqlViewName C_RSAU_API view
AbapCatalog.preserveKey true view
AccessControl.authorizationCheck #NOT_REQUIRED view
EndUserText.label SIEM API for Security Audit Log view

OData Services (1)

ServiceBindingVersionContractRelease
RSAU_LOG_API_SERVICE RSAU_LOG_API V4 C2 C1

Fields (23)

KeyFieldSource TableSource FieldDescription
KEY eventID rsau_log event Time
KEY log_tstmp rsau_log log_tstmp Timestamp
KEY slgproc slgproc Process
KEY slgmand rsau_log slgmand Client
KEY sid sid SID
KEY instance instance TaskCount
KEY counter counter Version
param_a Parameter A
param_b Parameter B
param_c Parameter C
param_d Parameter D
slgtc slgtc Transaction Code
slgrepna slgrepna Program
rsau_text
pseudo_vars _pseudo_attr var_set_1
slgltrm2 slgltrm2 Terminal
sal_data sal_data Variable Data
raw_text
UserID _user UserID User Name
useralias _usergrp useralias Alias
email_adress _usergrp smtp_addr E-Mail Address
UserDescription _user UserDescription Full Name
UserIDSAP_WFRTthenXelseendasis_relevant

Derived SQL interpretation, reconstructed from the parsed view metadata (data sources, associations, and field mappings). SAP annotations are omitted and the structure is reformulated as SQL — this is a functional approximation, not the verbatim SAP source.

-- Derived SQL interpretation of CDS view C_RSAU_LOG_API.
-- Reconstructed from parsed metadata (data sources, associations, fields).
-- SAP annotations are omitted and the structure is reformulated as SQL;
-- this is a functional approximation, not the verbatim SAP source. Some join
-- conditions may be unavailable and a few CDS constructs are kept as-is.
-- SQL view name: C_RSAU_API

CREATE VIEW C_RSAU_LOG_API AS
SELECT
  _header.event AS eventID,
  _header.log_tstmp AS log_tstmp,
  slgproc,
  _header.slgmand AS slgmand,
  sid,
  instance,
  counter,
  cast( ' ' as abap.sstring( 255 )) AS param_a,
  cast( ' ' as abap.sstring( 255 )) AS param_b,
  cast( ' ' as abap.sstring( 255 )) AS param_c,
  cast( ' ' as abap.sstring( 255 )) AS param_d,
  slgtc,
  slgrepna,
  cast( ' ' as abap.sstring( 1024 ) ) AS rsau_text,
  _pseudo_attr.var_set_1 AS pseudo_vars,
  slgltrm2,
  sal_data,
  coalesce( _text_active.raw_text, _text_english.raw_text) AS raw_text,
  _user.UserID AS UserID,
  _usergrp.useralias AS useralias,
  _usergrp.smtp_addr AS email_adress,
  _user.UserDescription AS UserDescription,
  case when _user.UserID like 'CB%' then 'X' when _user.UserID like 'CC%' then 'X' when _user.UserID like 'CP%' then 'X' when _user.UserID like 'SAP_INTE_%' then 'X' when _user.UserID like '_SAP%' then 'X' when _user.UserID = 'SAP_CUST_INI' then 'X' when _user.UserID = 'SAP*' then 'X' when _user.UserID = 'SAP_CUST_BUS' then 'X' when _user.UserID = 'SAP_WFRT' then 'X' else ' ' end as is_relevant AS UserIDSAP_WFRTthenXelseendasis_relevant
FROM rsau_log AS _header
LEFT OUTER JOIN I_RSAU_MESSAGETEXT AS _text_active ON _text_active.msgid = _header.event AND _text_active.spras = $session.system_language  -- association [0..*]
LEFT OUTER JOIN I_RSAU_MESSAGETEXT AS _text_english ON _text_english.msgid = _header.event AND _text_english.spras = 'E'  -- association [0..*]
LEFT OUTER JOIN tsl1d_attr AS _pseudo_attr ON _pseudo_attr.event = _header.event  -- association [0..*]
LEFT OUTER JOIN I_RSAU_UGROUP AS _usergrp ON _usergrp.bname = _header.slguser AND _usergrp.mandt = $session.client  -- association [0..1]
LEFT OUTER JOIN I_User AS _user ON _user.UserID = _header.slguser  -- association [0..1]
;