Skip to Content
avatar image
Former Member

Carriage Return on SAP Security Audit Log

Hi,

Would like to ask if anyone can help me write a Unix script that will break the Security Audit log into one security entry per line or insert a carriage return per entry which will be written to a new log file? We need to setup log file monitoring via RZ20 in Security Audit log file to monitor and capture specific pattern but we are having problem capturing accurate and correct entries in the log due to the nature of Security Audit log file that has no carriage return or line separator.

Thanks.

Rupert

Add comment
10|10000 characters needed characters exceeded

  • Follow
  • Get RSS Feed

1 Answer

  • avatar image
    Former Member
    Jan 31, 2008 at 01:49 PM

    Hello Rupert

    these few lines of perl code should help you to split a Security Audit Log

    open(FILE, "<FILE-NAME>") || die("Error reading file, stopped");
    while(read(FILE, $buffer, 200) ) {
    	print "$buffer\n";
    }
    close(FILE);
    

    BTW you can also expand the print statement with an if clause and regexp to filter by Message-ID. The example shows a filter for logged RFC calls (MNo=AUK).

    print "$buffer\n" if ($buffer=~/2AUK/);
    

    regards/marc 😊

    Add comment
    10|10000 characters needed characters exceeded