Skip to Content

No SM21 Log

Hi All

I m trying to fetch logs from Tcode-SM21. However I m not able to see records in output screen. I already tried different methods like System Log--Choose--All Remote system Logs. Also tried selecting all options setting--system log layout--selected all option. Still I m not able to see any records.




I also tried by specifying user at the input screen & even that shows blank result.

I want to send SM21 log to auditor. I also tried SM20 for which user was not maintained at SM19. ST03N only shows Tcodes used by this user but not his activity like SM20 or SM21.



Add a comment
10|10000 characters needed characters exceeded

Related questions

3 Answers

  • Posted on Feb 10, 2019 at 11:46 AM

    You are looking for logs from the 25-09-2018 until 31-12-2018. Logs are written in a cyclical way and old messages have been replaced with new entries now. Check if you are able to see the recent ones and if yes old ones are overwritten.

    Add a comment
    10|10000 characters needed characters exceeded

    • Pankaj,

      System logs are not deleted by any house keeping jobs or reports. They are not renamed to a new file with a ".old" extension like you observe in the work directory of the instance for developer traces when you restart the instance. The file is basically overwritten with new contents in a cyclical way, means old entries will be replaced with new ones. System logs are not stored anywhere else. There is nothing much you can do here.



  • Posted on Feb 11, 2019 at 10:00 AM

    Also, if you system has been restarted since, your logs would have been overwritten... or moved to .old

    Regards, JP

    Add a comment
    10|10000 characters needed characters exceeded

  • Posted on Feb 11, 2019 at 02:12 PM

    Hello Pankaj,

    About your comments on Juan's reply:

    (a), those are job logs (logs for batch jobs that you can see in the transaction SM37), not related to the system log (SM21).

    (b), SM21 would not show you the information mentioned at this item. To gather this information, you would need a security log (SM19/SM20). If the information is not on SM19/SM20 anymore, check whether you have a backup from the "DIR_AUDIT" folder (default path is: "/usr/sap/<SID>/<Instance Name>/log") that has the audit files covering the period that you need.



    Add a comment
    10|10000 characters needed characters exceeded

    • Hello Pankaj,

      I am not aware of any tcode or report that would show what the user did within each tcode.

      Maybe the SAP GRC offers that feature, but I am not sure (I do not work with the SAP GRC product).

      In any case, installing a GRC system now would not provide information from the past.



Before answering

You should only submit an answer when you are proposing a solution to the poster's problem. If you want the poster to clarify the question or provide more information, please leave a comment instead, requesting additional details. When answering, please include specifics, such as step-by-step instructions, context for the solution, and links to useful resources. Also, please make sure that you answer complies with our Rules of Engagement.
You must be Logged in to submit an answer.

Up to 10 attachments (including images) can be used with a maximum of 1.0 MB each and 10.5 MB total.