IT CanvassTalk to an advisor
SAP administration · LessonBy , SAP Trainer, 10 yrs · Published · SAP S/4HANA 2023 · all levels

System logs

System logs record what happens inside an SAP system, errors, warnings and significant events, and are a primary tool for diagnosing problems. The main one is the system log (SM21), complemented by developer traces and other logs.

Quick answer

Logs need appropriate retention, enough to investigate incidents, not so much they consume space, and some (like security-relevant events) may have compliance retention requirements.

Key takeaways
  • SM21 shows the system log: time-stamped entries for events like failed logons, database problems, work-process errors and…
  • Effective troubleshooting correlates logs by time: an error a user reports at 10:05 is investigated by looking at SM21, ST22 and…
  • Developer traces (ST11 / dev_* files): low-level work-process traces for deep issues.
  • Watch out: Ignoring SM21 when diagnosing incidents.

The SAP system log (SM21)

SM21 shows the system log: time-stamped entries for events like failed logons, database problems, work-process errors and configuration issues, per instance. When something goes wrong, SM21 is one of the first places to look for what the system itself recorded around that time.

Other important logs

  • Developer traces (ST11 / dev_* files): low-level work-process traces for deep issues.
  • ST22 dumps: ABAP runtime errors with full context.
  • Update log (SM13): failed asynchronous updates.
  • Job logs (SM37): per-job output and errors.

Using logs to diagnose

Effective troubleshooting correlates logs by time: an error a user reports at 10:05 is investigated by looking at SM21, ST22 and relevant job/update logs around that moment. The logs together usually pinpoint the cause.

Housekeeping and retention

Logs need appropriate retention, enough to investigate incidents, not so much they consume space, and some (like security-relevant events) may have compliance retention requirements.

Common pitfalls

  • Ignoring SM21 when diagnosing incidents.
  • Not correlating logs by time.
  • Poor log retention, evidence gone when needed.

Practice challenge

+0 XPStreak ×0
Question 1 of 3
Which statement is true of System logs?

Frequently asked questions

What does the term System logs refer to in SAP?
System logs record what happens inside an SAP system, errors, warnings and significant events, and are a primary tool for diagnosing problems. The main one is the system log (SM21), complemented by developer traces and other logs.
What is worth checking when troubleshooting System logs?
Developer traces (ST11 / dev_* files): low-level work-process traces for deep issues. ST22 dumps: ABAP runtime errors with full context. Update log (SM13): failed asynchronous updates.
What is another point to note about System logs?
Logs need appropriate retention, enough to investigate incidents, not so much they consume space, and some (like security-relevant events) may have compliance retention requirements.
What tends to go wrong with System logs?
Ignoring SM21 when diagnosing incidents. Not correlating logs by time. Poor log retention, evidence gone when needed.
Already working on SAP and stuck on a live ticket?Get an expert SAP developer on screen-share to finish your daily tasks with you. Deliver on time, protect your reputation and your job. Monthly support only, no task-wise plans.Task assigned · no idea where to startStill stuck · your job on the lineExpert joins your screenDelivered on timeExplore On Job Support