C_RSAU_LOG_API
SIEM API for Security Audit Log
C_RSAU_LOG_API is a CDS View that provides data about "SIEM API for Security Audit Log" in SAP S/4HANA. It reads from 1 data source (rsau_log) and exposes 23 fields with key fields eventID, log_tstmp, slgproc, slgmand, sid. It has 5 associations to related views. It is exposed through 1 OData service (RSAU_LOG_API_SERVICE).
Data Sources (1)
| Source | Alias | Join Type |
|---|---|---|
| rsau_log | _header | from |
Associations (5)
| Cardinality | Target | Alias | Condition |
|---|---|---|---|
| [0..*] | I_RSAU_MESSAGETEXT | _text_active | _text_active.msgid = _header.event and _text_active.spras = $session.system_language -- text English |
| [0..*] | I_RSAU_MESSAGETEXT | _text_english | _text_english.msgid = _header.event and _text_english.spras = 'E' |
| [0..*] | tsl1d_attr | _pseudo_attr | _pseudo_attr.event = _header.event |
| [0..1] | I_RSAU_UGROUP | _usergrp | _usergrp.bname = _header.slguser and _usergrp.mandt = $session.client |
| [0..1] | I_User | _user | _user.UserID = _header.slguser |
Annotations (4)
| Name | Value | Level | Field |
|---|---|---|---|
| AbapCatalog.sqlViewName | C_RSAU_API | view | |
| AbapCatalog.preserveKey | true | view | |
| AccessControl.authorizationCheck | #NOT_REQUIRED | view | |
| EndUserText.label | SIEM API for Security Audit Log | view |
OData Services (1)
| Service | Binding | Version | Contract | Release |
|---|---|---|---|---|
| RSAU_LOG_API_SERVICE | RSAU_LOG_API | V4 | C2 | C1 |
Fields (23)
| Key | Field | Source Table | Source Field | Description |
|---|---|---|---|---|
| KEY | eventID | rsau_log | event | Time |
| KEY | log_tstmp | rsau_log | log_tstmp | Timestamp |
| KEY | slgproc | slgproc | Process | |
| KEY | slgmand | rsau_log | slgmand | Client |
| KEY | sid | sid | SID | |
| KEY | instance | instance | TaskCount | |
| KEY | counter | counter | Version | |
| param_a | Parameter A | |||
| param_b | Parameter B | |||
| param_c | Parameter C | |||
| param_d | Parameter D | |||
| slgtc | slgtc | Transaction Code | ||
| slgrepna | slgrepna | Program | ||
| rsau_text | ||||
| pseudo_vars | _pseudo_attr | var_set_1 | ||
| slgltrm2 | slgltrm2 | Terminal | ||
| sal_data | sal_data | Variable Data | ||
| raw_text | ||||
| UserID | _user | UserID | User Name | |
| useralias | _usergrp | useralias | Alias | |
| email_adress | _usergrp | smtp_addr | E-Mail Address | |
| UserDescription | _user | UserDescription | Full Name | |
| UserIDSAP_WFRTthenXelseendasis_relevant |
Derived SQL interpretation, reconstructed from the parsed view metadata (data sources, associations, and field mappings). SAP annotations are omitted and the structure is reformulated as SQL — this is a functional approximation, not the verbatim SAP source.
-- Derived SQL interpretation of CDS view C_RSAU_LOG_API.
-- Reconstructed from parsed metadata (data sources, associations, fields).
-- SAP annotations are omitted and the structure is reformulated as SQL;
-- this is a functional approximation, not the verbatim SAP source. Some join
-- conditions may be unavailable and a few CDS constructs are kept as-is.
-- SQL view name: C_RSAU_API
CREATE VIEW C_RSAU_LOG_API AS
SELECT
_header.event AS eventID,
_header.log_tstmp AS log_tstmp,
slgproc,
_header.slgmand AS slgmand,
sid,
instance,
counter,
cast( ' ' as abap.sstring( 255 )) AS param_a,
cast( ' ' as abap.sstring( 255 )) AS param_b,
cast( ' ' as abap.sstring( 255 )) AS param_c,
cast( ' ' as abap.sstring( 255 )) AS param_d,
slgtc,
slgrepna,
cast( ' ' as abap.sstring( 1024 ) ) AS rsau_text,
_pseudo_attr.var_set_1 AS pseudo_vars,
slgltrm2,
sal_data,
coalesce( _text_active.raw_text, _text_english.raw_text) AS raw_text,
_user.UserID AS UserID,
_usergrp.useralias AS useralias,
_usergrp.smtp_addr AS email_adress,
_user.UserDescription AS UserDescription,
case when _user.UserID like 'CB%' then 'X' when _user.UserID like 'CC%' then 'X' when _user.UserID like 'CP%' then 'X' when _user.UserID like 'SAP_INTE_%' then 'X' when _user.UserID like '_SAP%' then 'X' when _user.UserID = 'SAP_CUST_INI' then 'X' when _user.UserID = 'SAP*' then 'X' when _user.UserID = 'SAP_CUST_BUS' then 'X' when _user.UserID = 'SAP_WFRT' then 'X' else ' ' end as is_relevant AS UserIDSAP_WFRTthenXelseendasis_relevant
FROM rsau_log AS _header
LEFT OUTER JOIN I_RSAU_MESSAGETEXT AS _text_active ON _text_active.msgid = _header.event AND _text_active.spras = $session.system_language -- association [0..*]
LEFT OUTER JOIN I_RSAU_MESSAGETEXT AS _text_english ON _text_english.msgid = _header.event AND _text_english.spras = 'E' -- association [0..*]
LEFT OUTER JOIN tsl1d_attr AS _pseudo_attr ON _pseudo_attr.event = _header.event -- association [0..*]
LEFT OUTER JOIN I_RSAU_UGROUP AS _usergrp ON _usergrp.bname = _header.slguser AND _usergrp.mandt = $session.client -- association [0..1]
LEFT OUTER JOIN I_User AS _user ON _user.UserID = _header.slguser -- association [0..1]
;
Learn More
- OData Services in SAP S/4HANA Explained
- Service Bindings and Service Definitions in SAP S/4HANA
- CDS View Annotations — A Complete Guide
- What Is a CDS View in SAP S/4HANA?
- Types of CDS Views: Basic, Composite, Consumption, and Transactional
- SAP Tables vs CDS Views — Key Differences
- Understanding Data Lineage in SAP S/4HANA
- VDM (Virtual Data Model) in SAP S/4HANA Explained
- CDS View Field Mapping and Associations
- Understanding the SAP S/4HANA Data Model
- CDS View Extensions and Custom Fields in SAP S/4HANA
- Released APIs and Stability Contracts in SAP S/4HANA
- BSEG to ACDOCA: The Universal Journal Migration
- Business Partner Migration: KNA1/LFA1 to BUT000
- Material Document Migration: MSEG/MKPF to MATDOC
- How to Find the Right CDS View for an SAP Table
- BW Extractor to CDS View Migration Guide
- S/4HANA CDS View Deprecation: What You Need to Know
- ABAP CDS View Tutorial — From Basics to Real-World Examples
- RAP and CDS Views — Building Transactional Apps in SAP S/4HANA
- Sales Document Status Migration: VBUP/VBUK Removal in S/4HANA
- CO Tables in S/4HANA: COEP, COBK, COSS, COSP to ACDOCA