Use case · Oracle

Oracle monitoring for SAP, with a user that only reads

SUPtime queries Oracle over SQL with a dedicated read-only user, and puts slow queries, tables, RMAN backups and tablespaces next to the Basis probes of the same system. From 10.2 onwards, so the ECC and R/3 systems nobody has migrated yet are covered too.

V$SQLAREAV$BACKUP_SETDBA_FREE_SPACEDBA_OUTSTANDING_ALERTSV$ARCHIVE_DEST_STATUSV$SESSION

What it reads

The system views, one by one

Only V$ dynamic views and DBA_ catalog views: never application tables, no Diagnostics Pack, no AWR or Statspack. Without database credentials, the tab says so instead of showing numbers.

SourceWhat it shows
V$INSTANCE · V$DATABASEVersion, instance and database name, uptime from STARTUP_TIME
V$OSSTATHost CPU and memory
V$SESSION · V$SYSSTATActive and idle connections, buffer cache hit ratio
V$SQLAREAThe slowest queries and the average response time
DBA_SEGMENTS · DBA_TABLESThe largest tables and the ones you choose to watch, with rows from the last statistics gathering
V$BACKUP_SET · V$BACKUP_PIECEOutcome and age of the last RMAN backups
SDBAHOutcome and age of BR*Tools backups: a SAP running brbackup without RMAN is not reported as having no backup
DBA_DATA_FILES · DBA_FREE_SPACE · DBA_TEMP_FILESTablespace usage, computed as allocated minus free, and database size
DBA_OUTSTANDING_ALERTSThe alerts the server raises on its own, with Oracle's reason and suggested action
V$ARCHIVE_DEST_STATUS · V$LOG · V$LOGFILEArchiver destinations in error and unarchived redo logs, only when the database runs in ARCHIVELOG
V$SESSION (BLOCKING_SESSION)Blocked sessions, by whom and for how long
DBA_USERS · DBA_ROLE_PRIVS (own user)Whether the monitoring user is still OPEN, when it expires, which roles it has

Every morning

The questions a Basis admin asks about Oracle

Did last night's backup run?

Outcome and age of the last backup, read from RMAN and from the BR*Tools history alike: whoever uses brbackup is not reported as having none. An old backup shows up before you need it.

Are the tablespaces holding?

Allocated minus free, tablespace by tablespace. A full PSAPSR3 stops SAP: better to know with room to spare.

Is the archiver writing?

If a destination is in error or every redo log is waiting to be archived, the database will stop shortly. It is the first Oracle problem a Basis admin actually meets.

What is slowing the system down?

Slowest queries from the shared pool, largest tables and blocked sessions.

Oracle health

Not just load: the diagnostics Oracle already computes

The server raises its own alerts, with reason and suggested action. SUPtime collects them instead of duplicating them, and adds the three signals that matter most on an SAP system.

Server-generated alerts

DBA_OUTSTANDING_ALERTS

Warnings and criticals, with Oracle's own explanation and suggested action: not just a counter.

Archiver and redo logs

V$ARCHIVE_DEST_STATUSV$LOG

A destination in error, or every redo log unarchived. On a NOARCHIVELOG database the check stays quiet: there is nothing to archive, and a false alarm teaches people to ignore the real ones.

Blocked sessions

V$SESSION

Who is blocked, by whom, for how many seconds.

The monitoring user itself

DBA_USERS

Whether it is still OPEN, when the password expires, which roles it has: a locked-out user shows up on the tab, not in the logs.

Releases

From 10.2 to 23ai, with the same script

The views used are the ones available since 8i, on purpose: nothing that exists only in recent releases, so the user script works everywhere unchanged.

Oracle 12.1 and later

thin

The Python driver connects on its own, with no Oracle libraries on the SUPtime server.

Oracle 10.2 and 11g

Instant Client

Oracle's client libraries are needed on the SUPtime server, once. The connector switches to the mode it needs by itself, nothing to configure per system.

SID or service name

Chosen in the system form. Older SAP installations expose only the SID, and that is fine.

Access

A read-only user, not SAPSR3

Never the schema owner

SAPSR3 can write to every table. SUPtime only reads, so it uses a dedicated user with CREATE SESSION and the SELECTs it needs.

No DBA, no SELECT_CATALOG_ROLE

GRANT SELECT ON V_$…

That role would cover everything with one command, but it covers much more too. The explicit list wins, view by view: the documentation gives it with the reason for every line.

It never locks itself out

After refused credentials the connector stops retrying for 15 minutes: an Oracle profile locks the user after a few attempts, and a monitoring tool must not shut its own door.

One system, two channels

Oracle and ABAP in the same view

Basis probes over RFC

ST22SM37SM12SM20

Dumps, jobs, locks and the Security Audit Log of the ABAP stack running on that database.

Even without RFC

A system configured with the database only shows the database tabs and availability over sapcontrol; the tabs that live on RFC alone stay disabled, without showing zeros.

Rules on any monitor

ORACLE

The ORACLE monitor carries findings that are already evaluated: "at least one open issue" fires at the first one and clears by itself when there is none.

Declared limits

What it does not cover

Knowing what a monitor does not see matters as much as knowing what it sees.

  • Database growth over time: without AWR there is no internal history to compute it from, and an estimated number in place of a real one does not go on a tab.
  • Data Guard, RAC and failover: no management, and no status read beyond the archiver's.
  • Diagnostics and Tuning Pack: not required and not used. Slow queries come from V$SQLAREA, not from AWR.
  • Features that would need more than the listed SELECTs: not built, as a security choice.
  • Forecasts: SUPtime shows the values it read, it does not estimate future ones.

Want to see it on your Oracle?

We will show you the tabs on a real system and the script for the read-only user, grant by grant.

Request a demo