Use case · Oracle
Oracle monitoring for SAP, with a user that only reads
SUPtime queries Oracle over SQL with a dedicated read-only user, and puts slow queries, tables, RMAN backups and tablespaces next to the Basis probes of the same system. From 10.2 onwards, so the ECC and R/3 systems nobody has migrated yet are covered too.
What it reads
The system views, one by one
Only V$ dynamic views and DBA_ catalog views: never application tables, no Diagnostics Pack, no AWR or Statspack. Without database credentials, the tab says so instead of showing numbers.
| Source | What it shows |
|---|---|
| V$INSTANCE · V$DATABASE | Version, instance and database name, uptime from STARTUP_TIME |
| V$OSSTAT | Host CPU and memory |
| V$SESSION · V$SYSSTAT | Active and idle connections, buffer cache hit ratio |
| V$SQLAREA | The slowest queries and the average response time |
| DBA_SEGMENTS · DBA_TABLES | The largest tables and the ones you choose to watch, with rows from the last statistics gathering |
| V$BACKUP_SET · V$BACKUP_PIECE | Outcome and age of the last RMAN backups |
| SDBAH | Outcome and age of BR*Tools backups: a SAP running brbackup without RMAN is not reported as having no backup |
| DBA_DATA_FILES · DBA_FREE_SPACE · DBA_TEMP_FILES | Tablespace usage, computed as allocated minus free, and database size |
| DBA_OUTSTANDING_ALERTS | The alerts the server raises on its own, with Oracle's reason and suggested action |
| V$ARCHIVE_DEST_STATUS · V$LOG · V$LOGFILE | Archiver destinations in error and unarchived redo logs, only when the database runs in ARCHIVELOG |
| V$SESSION (BLOCKING_SESSION) | Blocked sessions, by whom and for how long |
| DBA_USERS · DBA_ROLE_PRIVS (own user) | Whether the monitoring user is still OPEN, when it expires, which roles it has |
Every morning
The questions a Basis admin asks about Oracle
Did last night's backup run?
Outcome and age of the last backup, read from RMAN and from the BR*Tools history alike: whoever uses brbackup is not reported as having none. An old backup shows up before you need it.
Are the tablespaces holding?
Allocated minus free, tablespace by tablespace. A full PSAPSR3 stops SAP: better to know with room to spare.
Is the archiver writing?
If a destination is in error or every redo log is waiting to be archived, the database will stop shortly. It is the first Oracle problem a Basis admin actually meets.
What is slowing the system down?
Slowest queries from the shared pool, largest tables and blocked sessions.
Oracle health
Not just load: the diagnostics Oracle already computes
The server raises its own alerts, with reason and suggested action. SUPtime collects them instead of duplicating them, and adds the three signals that matter most on an SAP system.
Server-generated alerts
Warnings and criticals, with Oracle's own explanation and suggested action: not just a counter.
Archiver and redo logs
A destination in error, or every redo log unarchived. On a NOARCHIVELOG database the check stays quiet: there is nothing to archive, and a false alarm teaches people to ignore the real ones.
Blocked sessions
Who is blocked, by whom, for how many seconds.
The monitoring user itself
Whether it is still OPEN, when the password expires, which roles it has: a locked-out user shows up on the tab, not in the logs.
Releases
From 10.2 to 23ai, with the same script
The views used are the ones available since 8i, on purpose: nothing that exists only in recent releases, so the user script works everywhere unchanged.
Oracle 12.1 and later
The Python driver connects on its own, with no Oracle libraries on the SUPtime server.
Oracle 10.2 and 11g
Oracle's client libraries are needed on the SUPtime server, once. The connector switches to the mode it needs by itself, nothing to configure per system.
SID or service name
Chosen in the system form. Older SAP installations expose only the SID, and that is fine.
Access
A read-only user, not SAPSR3
Never the schema owner
SAPSR3 can write to every table. SUPtime only reads, so it uses a dedicated user with CREATE SESSION and the SELECTs it needs.
No DBA, no SELECT_CATALOG_ROLE
That role would cover everything with one command, but it covers much more too. The explicit list wins, view by view: the documentation gives it with the reason for every line.
It never locks itself out
After refused credentials the connector stops retrying for 15 minutes: an Oracle profile locks the user after a few attempts, and a monitoring tool must not shut its own door.
One system, two channels
Oracle and ABAP in the same view
Basis probes over RFC
Dumps, jobs, locks and the Security Audit Log of the ABAP stack running on that database.
Even without RFC
A system configured with the database only shows the database tabs and availability over sapcontrol; the tabs that live on RFC alone stay disabled, without showing zeros.
Rules on any monitor
The ORACLE monitor carries findings that are already evaluated: "at least one open issue" fires at the first one and clears by itself when there is none.
Declared limits
What it does not cover
Knowing what a monitor does not see matters as much as knowing what it sees.
- Database growth over time: without AWR there is no internal history to compute it from, and an estimated number in place of a real one does not go on a tab.
- Data Guard, RAC and failover: no management, and no status read beyond the archiver's.
- Diagnostics and Tuning Pack: not required and not used. Slow queries come from V$SQLAREA, not from AWR.
- Features that would need more than the listed SELECTs: not built, as a security choice.
- Forecasts: SUPtime shows the values it read, it does not estimate future ones.
Want to see it on your Oracle?
We will show you the tabs on a real system and the script for the read-only user, grant by grant.