> For the complete documentation index, see [llms.txt](https://sealights-docs.tricentis.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://sealights-docs.tricentis.com/setup-and-configuration/configuration-settings.md).

# Configuration settings

This section describes the ABAP Agent 2.1 configuration settings, stored in `config.toml`.

**Default location:**

```
%ProgramData%\Tricentis\SeaLights\ABAP Agent\config\config.toml
```

{% hint style="info" %}
Back up the `config.toml` file before you make any changes.
{% endhint %}

The `config.toml` file uses the [TOML](https://toml.io/) format. It is created automatically when you run `slabapcli setup install`. On a default Windows install, secrets (token, passwords) are encrypted at rest using AES, keyed by the `key` and `iv` values written to the `[settings]` section during installation.

**Schema version:** The current schema version is **`6`**. If you have a legacy configuration from an older agent version, run `slabapcli setup migrate` to upgrade it to version 6 automatically. See [Migrate a legacy configuration](broken://pages/NRR5ldRJ84vbe7IcN65N).

## Live reload and restart-required fields

While `SLABAPServer.exe` is running, the server **lazily reloads** `config.toml` on the **next configuration access** (for example a process API call, a token lookup, an RFC/pipeline/test-repository lookup, or `GET /ready`). Reload is driven by file change detection on that access — it is **not** an idle file-system watcher and is **not** instantaneous while the server is idle.

* **Hot fields** (everything not listed as cold below) apply from the newly loaded file after a successful reload. No service restart is required. Most lab settings hot-reload this way. Examples include `server.logging.defaultLevel`, `server.uploadBatching.*`, and the entire `[[rfc]]`, `[[pipeline]]`, and `[[testrepo]]` trees.
* **Cold fields** stay at the values captured when the server process started until you restart the Windows service (`slabapcli server stop`, then `slabapcli server start`). If a reload finds a cold-field change, hot fields from that edit still apply, but `/ready` returns `503` with `reasonCode: CONFIG_RESTART_REQUIRED` and `changedColdPaths`. Process APIs continue to accept work — this signal means a restart is required to apply the cold values, not that the server has stopped accepting tasks.
* **Mixed edits:** change hot and cold fields in one save → hot values apply; cold values remain at the startup baseline until restart. Reverting cold fields to their startup values clears the restart-required condition.
* **Failed reload:** if the new TOML is invalid or unreadable, the server keeps its last-known-good configuration, logs the reload failure, and retries on a later configuration access. Correct the file and check `/ready` (or another config-using operation). Restart is not the default remedy for a failed reload.
* **In-flight work:** after a hot change to RFC, pipeline, credential, logging, or similar context that an already-running footprint or other scheduled task may already be using, stop and start that **task** as needed (`footprints stop` / `footprints run`, and similar). That is a **task** restart — not a service restart.
* **`sealights.token` is cold:** changing the SeaLights token (via `slabapcli sealights set` or a direct `config.toml` edit) does **not** hot-reload. Restart the Windows service before the new token is active.

### Cold fields (server restart required)

| Path                                                                                              | Notes                                                                         |
| ------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------- |
| `sealights.token`                                                                                 | SeaLights bearer token. Set via `slabapcli sealights set`.                    |
| `version`                                                                                         | Schema generation; use `slabapcli setup migrate` to change it.                |
| `settings.userdata`, `settings.install`                                                           | Agent path layout.                                                            |
| `settings.key`, `settings.iv`                                                                     | Encryption material. Public `/ready` may show these as `settings.<redacted>`. |
| `server.port`                                                                                     | Listen port (process already bound).                                          |
| `server.retry.maxAttempts`, `initialDelayMs`, `maxDelayMs`, `backoffMultiplier`, `retryOnTimeout` | Internal retry host settings.                                                 |
| `server.seaLightsClient.timeoutSeconds`                                                           | SeaLights HTTP client timeout.                                                |
| `server.uploadClient.timeoutSeconds`                                                              | Upload HTTP client timeout.                                                   |
| `server.uploadRetry.enabled`, `scanIntervalSeconds`, `maxConcurrentUploads`                       | Upload-retry host enablement / scan / concurrency.                            |
| `http.disableSslCheck`                                                                            | TLS verification flag.                                                        |
| `proxy.server`, `proxy.username`, `proxy.password`                                                | Outbound proxy used by the server.                                            |

Each cold field is also marked with **Reload behavior: Restart required** in the reference tables below. That per-field annotation is authoritative; this summary is for scanning.

{% hint style="info" %}
Legitimate service restarts still apply for cold-field changes (including `sealights.token`), upgrades, and other process-lifecycle events. Do **not** restart the service after routine hot changes such as RFC, pipeline, test-repository, or adapter secret updates.
{% endhint %}

***

## Configuration file sections

### version

The root key that identifies the configuration schema version. The current supported version is `6`.

```toml
version = 6
```

Do not modify this value manually. Use `slabapcli setup migrate` to upgrade older configurations. The CLI refuses to start with a config version below 6 and prints a migration hint.

**Reload behavior:** Restart required. Migration remains the supported way to change `version`.

***

### \[settings]

Stores the agent's installation paths and encryption keys. This section is written by `slabapcli setup install`.

<table><thead><tr><th width="130">Field</th><th>Description</th><th>Reload behavior</th></tr></thead><tbody><tr><td>install</td><td>Path to the directory that contains the <code>bin</code>, <code>config</code>, and <code>userdata</code> subdirectories. Set by <code>setup install</code> to the current working directory.</td><td>Restart required</td></tr><tr><td>userdata</td><td>Path to the ABAP Agent's user-data directory. Default: <code>C:\ProgramData\Tricentis\SeaLights\ABAP Agent</code>.</td><td>Restart required</td></tr><tr><td>key</td><td>Encryption key used to protect secrets. Written during <code>setup install</code>.</td><td>Restart required</td></tr><tr><td>iv</td><td>Encryption initialisation vector. Written during <code>setup install</code>.</td><td>Restart required</td></tr></tbody></table>

You may modify **userdata** and **install** if you need to relocate the agent directories. Do not modify **key** or **iv** — these values are managed by the encryption subsystem.

***

### \[logging]

Defines the agent's C++ component logging settings.

<table><thead><tr><th width="160">Field</th><th>Description</th></tr></thead><tbody><tr><td>level</td><td>The minimum logging level. Default: <code>info</code>.</td></tr><tr><td>flushinterval</td><td>(Optional) Interval in seconds after which log messages are flushed to disk.</td></tr><tr><td>flushlevel</td><td>(Optional) Log level that triggers an immediate flush. Default: <code>info</code>.</td></tr><tr><td>consolelevel</td><td>(Optional) Minimum level for console output. Default: <code>info</code>.</td></tr><tr><td>retentionperiod</td><td>(Optional) Number of days to retain log files before deletion.</td></tr></tbody></table>

Valid **level** values:

<table><thead><tr><th width="120">Value</th><th>Description</th></tr></thead><tbody><tr><td>trace</td><td>Detailed trace information.</td></tr><tr><td>debug</td><td>Detailed debug information.</td></tr><tr><td>info</td><td>Informational messages (default).</td></tr><tr><td>warning</td><td>Warnings only.</td></tr><tr><td>error</td><td>Errors only.</td></tr><tr><td>critical</td><td>Critical messages only.</td></tr><tr><td>off</td><td>No logging.</td></tr></tbody></table>

**Reload behavior:** Hot for the server configuration snapshot. Already-running watcher / scheduled-task processes that read C++ `[logging].level` at their own start still need a **task** restart to pick up a new level.

***

### \[sealights]

Defines how the agent communicates with the SeaLights platform.

<table><thead><tr><th width="200">Field</th><th>Description</th><th>Reload behavior</th></tr></thead><tbody><tr><td>token</td><td>The SeaLights bearer token. Encrypted on disk. Set via <code>slabapcli sealights set</code>.</td><td>Restart required</td></tr><tr><td>delaybetweenmods</td><td>(Optional) Seconds between Build Modification uploads. Default: <code>45</code>.</td><td>Hot (no service restart)</td></tr><tr><td>clientattempts</td><td>(Optional) Number of retry attempts for SeaLights REST API calls. Default: <code>5</code>.</td><td>Hot (no service restart)</td></tr></tbody></table>

Do not modify the **token** field directly — it is encrypted. Use `slabapcli sealights set` to update the token, then restart the Windows service (`slabapcli server stop`, then `slabapcli server start`). You may modify **delaybetweenmods** and **clientattempts** as needed; they hot-reload on the next successful configuration access.

{% hint style="info" %}
The `delaybetweenmods` (45) and `clientattempts` (5) values are **runtime defaults applied when the key is omitted** — they are not written into the `config.toml` template that `setup install` generates. Add the keys explicitly only if you need non-default values.
{% endhint %}

{% hint style="info" %}
**Environment variable override:** Set `SL_AGENT_TOKEN` to override the token value without modifying `config.toml`. The environment variable takes precedence over the `token` field. Because the server runs as a Windows service, it inherits environment variables at process start — changing `SL_AGENT_TOKEN` for the service typically requires a service restart (`slabapcli server stop`, then `slabapcli server start`). See [Environment variable overrides](#environment-variable-overrides).
{% endhint %}

***

### \[proxy]

For a step-by-step setup, see [Configure a proxy](broken://pages/1XgHaBKc2oBX6lifmVPB). This section does not apply to test repositories; they use the `[adapters]` section below.

Optional. Defines the HTTP proxy the agent uses to connect to SeaLights. The proxy applies to `slabapcli`, the watcher, and the server (`SLABAPServer.exe`), including SeaLights API calls and uploads. If this section is present, the **server** field is required and must be an absolute `http://` or `https://` URI. An invalid value prevents the server from starting.

```toml
[proxy]
server   = 'http://proxy.example.com:8080'  # required when [proxy] is present; absolute http:// or https:// URI
username = 'user'                            # optional, encrypted
password = 'password'                        # optional, encrypted
```

The agent evaluates proxy settings in the following order of priority:

1. **Environment variables** (highest priority):
   * `SL_PROXY_SERVER`, then `SL_PROXY` — proxy server URI. If `SL_PROXY_SERVER` is set but empty, `SL_PROXY` is skipped and the agent uses `[proxy].server`.
   * `SL_PROXY_USERNAME` — proxy username (optional)
   * `SL_PROXY_PASSWORD` — proxy password (optional)
2. **Configuration file** — the `[proxy]` section in `config.toml`

Proxy credentials are applied only when both a username and a password are set. If neither environment variables nor `[proxy]` are configured, the agent connects directly without a proxy.

**Reload behavior:** Restart required. The server reads the `[proxy]` section and the `SL_PROXY*` environment variables at startup — restart the Windows service after changing them.

***

### \[http]

<table><thead><tr><th width="200">Field</th><th>Description</th><th>Reload behavior</th></tr></thead><tbody><tr><td>disableSslCheck</td><td>Disables TLS certificate verification on HTTPS calls made by <code>slabapcli</code>, the watcher, and the server. Default: <code>false</code>. Set to <code>true</code> only in trusted internal environments, for example behind a TLS-inspecting corporate proxy.</td><td>Restart required</td></tr></tbody></table>

***

### \[server]

Controls the ABAP Agent server (`SLABAPServer.exe`). Only the cold fields marked below require a server restart; other `[server]` settings are hot and apply on the next successful reload.

<table><thead><tr><th width="130">Field</th><th>Description</th><th>Reload behavior</th></tr></thead><tbody><tr><td>port</td><td>The TCP port the server listens on. Default: <code>17500</code>. Must match the port used by <code>slabapcli</code> when communicating with the server.</td><td>Restart required</td></tr></tbody></table>

```toml
[server]
port = 17500
```

{% hint style="info" %}
The server always binds to the loopback address `127.0.0.1` (localhost only); the bind host is not configurable. Only the `port` can be changed.
{% endhint %}

#### \[server.retry]

Retry policy for internal server-to-agent calls. All fields in this subsection are cold.

<table><thead><tr><th width="220">Field</th><th>Description</th><th>Reload behavior</th></tr></thead><tbody><tr><td>maxAttempts</td><td>Maximum number of attempts. Default: <code>3</code>.</td><td>Restart required</td></tr><tr><td>initialDelayMs</td><td>Initial retry delay in milliseconds. Default: <code>1000</code>.</td><td>Restart required</td></tr><tr><td>maxDelayMs</td><td>Maximum retry delay in milliseconds. Default: <code>30000</code>.</td><td>Restart required</td></tr><tr><td>backoffMultiplier</td><td>Exponential back-off multiplier. Default: <code>2.0</code>.</td><td>Restart required</td></tr><tr><td>retryOnTimeout</td><td>Whether to retry when a call times out. Default: <code>true</code>.</td><td>Restart required</td></tr></tbody></table>

#### \[server.tokenValidation]

<table><thead><tr><th width="220">Field</th><th>Description</th><th>Reload behavior</th></tr></thead><tbody><tr><td>timeoutSeconds</td><td>Timeout in seconds for token validation requests. Default: <code>10</code>.</td><td>Hot (no server restart)</td></tr></tbody></table>

#### \[server.logging]

<table><thead><tr><th width="220">Field</th><th>Description</th><th>Reload behavior</th></tr></thead><tbody><tr><td>defaultLevel</td><td>Minimum log level for the server. Default: <code>info</code>.</td><td>Hot (no server restart)</td></tr></tbody></table>

#### \[server.seaLightsClient]

<table><thead><tr><th width="220">Field</th><th>Description</th><th>Reload behavior</th></tr></thead><tbody><tr><td>timeoutSeconds</td><td>HTTP timeout in seconds for the SeaLights API client. Default: <code>100</code>.</td><td>Restart required</td></tr></tbody></table>

#### \[server.uploadClient]

<table><thead><tr><th width="220">Field</th><th>Description</th><th>Reload behavior</th></tr></thead><tbody><tr><td>timeoutSeconds</td><td>HTTP timeout in seconds for upload (presigned URL) requests. Default: <code>600</code>.</td><td>Restart required</td></tr></tbody></table>

#### \[server.uploadRetry]

Background retry of failed test-repository and impacted-graph uploads. Cold fields control host enablement, scan interval, and concurrency; the backoff / attempt policy fields are hot.

<table><thead><tr><th width="220">Field</th><th>Description</th><th>Reload behavior</th></tr></thead><tbody><tr><td>enabled</td><td>Whether the background upload-retry service runs. Default: <code>true</code>.</td><td>Restart required</td></tr><tr><td>scanIntervalSeconds</td><td>How often the service scans for failed uploads, in seconds. Default: <code>60</code>.</td><td>Restart required</td></tr><tr><td>maxConcurrentUploads</td><td>Maximum concurrent retry uploads. Default: <code>4</code>.</td><td>Restart required</td></tr><tr><td>minBackoffSeconds</td><td>Minimum backoff between retries for a row, in seconds. Default: <code>30</code>.</td><td>Hot (no server restart)</td></tr><tr><td>maxBackoffSeconds</td><td>Maximum backoff between retries for a row, in seconds. Default: <code>1800</code>.</td><td>Hot (no server restart)</td></tr><tr><td>backoffMultiplier</td><td>Exponential back-off multiplier for per-row retries. Default: <code>2.0</code>.</td><td>Hot (no server restart)</td></tr><tr><td>maxAttempts</td><td>Maximum retry attempts per failed upload. Applies to test-repository and impacted-graph uploads. <code>0</code> means unlimited. Default: <code>2</code>. When the retry attempts are exhausted, or an upload otherwise ends in a terminal error, the agent also reports the SeaLights process as <code>ERROR</code>, so the failure is visible in the SeaLights UI.</td><td>Hot (no server restart)</td></tr></tbody></table>

#### \[server.uploadBatching]

<table><thead><tr><th width="220">Field</th><th>Description</th><th>Reload behavior</th></tr></thead><tbody><tr><td>maxGzipBytesPerBatch</td><td>Hard cap on compressed SeaLights upload batch body size in bytes. Default: <code>94371840</code> (90 MiB). Caps batch size to improve upload stability on large builds and landscapes.</td><td>Hot (no server restart)</td></tr></tbody></table>

***

### \[adapters]

For a step-by-step proxy setup for test repositories, see [Configure a proxy](broken://pages/1XgHaBKc2oBX6lifmVPB#part-2-test-repositories).

Global settings for the adapter host (`SLABAPAdapterHost.exe`). These apply to all AdapterHost-backed `[[testrepo]]` types: `ado`, `tosca`, `toscacloud`, `excel`, `xray`, `qtest`, `certify`, `ssm`, `alm` (OpenText ALM), `octane` (OpenText Octane), and `calm` (SAP Cloud ALM). Per-type connection keys live under `[[testrepo]]` — see [Configure test repositories](broken://pages/RZTKL0g90WmKm4Prs0gG).

<table><thead><tr><th width="270">Field</th><th>Description</th></tr></thead><tbody><tr><td>proxyAddress</td><td>Proxy server URI used by adapters. Empty = no explicit proxy; the Windows host's default network behavior applies.</td></tr><tr><td>proxyUsername</td><td>Proxy username for adapter connections. Optional, encrypted on disk on a secure install.</td></tr><tr><td>proxyPassword</td><td>Proxy password for adapter connections. Optional, encrypted on disk on a secure install.</td></tr><tr><td>proxyDomain</td><td>Proxy domain for adapter connections. Optional, encrypted on disk on a secure install.</td></tr><tr><td>restClientTimeoutSeconds</td><td>HTTP client timeout for adapter REST calls in seconds. Default: <code>600</code>.</td></tr><tr><td>restClientRecycleThreshold</td><td>Number of requests after which the HTTP client is recycled. Default: <code>500</code>.</td></tr><tr><td>logLevel</td><td>Minimum log level for adapter processes. Default: <code>info</code>.</td></tr></tbody></table>

#### \[adapters.tosca]

<table><thead><tr><th width="270">Field</th><th>Description</th></tr></thead><tbody><tr><td>scanTestCases</td><td>Whether to scan individual test cases during the search. Default: <code>false</code>.</td></tr><tr><td>findSAPModules</td><td>Whether to search SAP module test cases. Default: <code>true</code>.</td></tr><tr><td>findUI5Modules</td><td>Whether to search UI5 module test cases. Default: <code>true</code>.</td></tr><tr><td>ui5ModuleNames</td><td>Array of UI5 module names to include. Default: empty (all).</td></tr><tr><td>reusableTestStepBlocksDepth</td><td>Depth for traversing reusable test step blocks. Default: <code>1</code>.</td></tr></tbody></table>

#### \[adapters.toscacloud]

<table><thead><tr><th width="270">Field</th><th>Description</th></tr></thead><tbody><tr><td>testCasesPageSize</td><td>Page size for paginated test case queries. Default: <code>1000</code>.</td></tr><tr><td>minimumSearchTermLength</td><td>Minimum length of a search term before it is sent to the adapter. Default: <code>0</code>.</td></tr><tr><td>ignoreCertificateErrors</td><td>(Optional) When <code>true</code>, accepts all TLS certificates for Tosca Cloud REST and identity provider (OIDC) calls. Use this behind a TLS-inspecting corporate proxy that also requires <code>[http].disableSslCheck</code>. Default: <code>false</code>.</td></tr></tbody></table>

#### \[adapters.excel]

<table><thead><tr><th width="270">Field</th><th>Description</th></tr></thead><tbody><tr><td>minimumSearchTermLength</td><td>Minimum length of a search term. Default: <code>0</code>.</td></tr></tbody></table>

#### \[adapters.xray]

<table><thead><tr><th width="270">Field</th><th>Description</th></tr></thead><tbody><tr><td>minimumSearchTermLength</td><td>Minimum length of a search term. Default: <code>0</code>.</td></tr></tbody></table>

#### \[adapters.qtest]

<table><thead><tr><th width="270">Field</th><th>Description</th></tr></thead><tbody><tr><td>testCasesPageSize</td><td>Page size for paginated test case queries. Default: <code>1000</code>.</td></tr><tr><td>userAgent</td><td>User-Agent string sent in HTTP headers. Default: <code>Sealights</code>.</td></tr><tr><td>minimumSearchTermLength</td><td>Minimum length of a search term. Default: <code>0</code>.</td></tr></tbody></table>

***

### \[rfcdata.prd]

Defines how the agent retrieves usage data from each PRD (Production) system.

<table><thead><tr><th width="200">Field</th><th>Description</th></tr></thead><tbody><tr><td>retentionperiod</td><td>Number of months of usage data the agent retains per PRD system. Default: <code>13</code>.</td></tr><tr><td>typequeries</td><td>Array of <code>{ type, query }</code> filter entries that exclude matching objects from the Production usage data (PHD) the agent collects from ST03. Uses the same <code>type</code> and <code>query</code> syntax as <a href="#footprints-type-queries">Footprints type queries</a>. See the default config for the pre-populated exclusion list.</td></tr></tbody></table>

You may modify **retentionperiod** as required. Do not modify **typequeries** unless Tricentis Support asks you to.

***

### \[rfcdata.qas]

Defines how the agent retrieves SCMON data from each QAS (Quality Assurance) system.

<table><thead><tr><th width="200">Field</th><th>Description</th></tr></thead><tbody><tr><td>retentionperiod</td><td>Number of months of SCMON data the agent retains per QAS system. Default: <code>1</code>.</td></tr><tr><td>tables</td><td>Array of SAP table names from which SCMON data is read. Default: <code>['SCMON_VDATA']</code>.</td></tr></tbody></table>

You may modify **retentionperiod** as required. Do not modify **tables** unless Tricentis Support asks you to.

***

### \[rfcdata.phd]

Defines how the agent parses Performance History Data (PHD) exported from SAP transaction ST03.

<table><thead><tr><th width="260">Field</th><th>Description</th></tr></thead><tbody><tr><td>separators</td><td>Field separator characters expected in PHD export files. Default: <code>[",", "|", "\t"]</code>.</td></tr><tr><td>mnemonicfieldtokens</td><td>Column header tokens that identify the "mnemonic" (program/transaction name) column across different SAP locales.</td></tr><tr><td>stepsfieldtokens</td><td>Column header tokens that identify the "steps/calls" column across different SAP locales.</td></tr><tr><td>descriptionfieldtokens</td><td>Column header tokens that identify the "description" column across different SAP locales.</td></tr></tbody></table>

Do not modify these fields unless Tricentis Support asks you to.

***

### \[componentstoignore]

Optional. Specifies SAP software components (delivery units, `DLVUNIT` values) to exclude when building the initial build map. Objects belonging to listed components are filtered out during `buildmap run`.

{% code title="Example" overflow="wrap" %}

```toml
[componentstoignore]
components = ["SAP_BASIS", "SAP_UI", "SAP_GWFND", "PERSONAS"]
```

{% endcode %}

| Field        | Description                                                                        |
| ------------ | ---------------------------------------------------------------------------------- |
| `components` | Array of SAP delivery-unit names (`DLVUNIT` values) to exclude from the build map. |

{% hint style="info" %}
**Default exclusion list:** The `[componentstoignore]` section is required in `config.toml`. `setup install` writes the defaults shown above (`SAP_BASIS`, `SAP_UI`, `SAP_GWFND`, and `PERSONAS`). To exclude nothing (include all objects), set `components` to an explicit empty array `[]`; an empty array does not restore the defaults.
{% endhint %}

See also: [Create an initial build map](broken://pages/6f4WDLP7ZxZdqhvqwcMb).

***

### \[buildmods]

Optional. Controls how `BUILD_MODS` chooses full versus incremental refresh of the SAP tables cache, object links, and impacted graph after transport discovery. See [Monitor your Pipeline for Build Modifications — Incremental cache and link refresh (2.1+)](broken://pages/JZVVGs3ieGcAwmbZ8qqj#incremental-cache-and-link-refresh-21).

<table><thead><tr><th width="220">Field</th><th>Description</th><th>Reload behavior</th></tr></thead><tbody><tr><td>foldedobjectthreshold</td><td>(Optional) Integer. Default when omitted: <code>1000</code>. When set, must be greater than zero. The agent compares this value to the number of <strong>changed or deleted code objects</strong> (by net effect) in the discovered transports. At or above the threshold, the tables cache is rebuilt in full while links and the impacted graph are updated incrementally; below the threshold, all three are updated incrementally. When a rebuild of the agent's cached data is required (for example, on the first run after an upgrade that changes the cache format), the tables cache and links are rebuilt in full regardless of this threshold. The impacted graph is always updated incrementally. A pipeline can override this value with <a href="#pipeline"><code>[[pipeline]].foldedobjectthreshold</code></a>.</td><td>Hot (no server restart)</td></tr><tr><td>maxtransportsperquery</td><td>(Optional) Integer. Default when omitted: <code>100</code>. When set, must be greater than zero. The maximum number of transports that one scheduled <code>BUILD_MODS</code> run processes; the remaining transports are picked up by the next scheduled run. Transports imported in the same second as the last transport that was kept are always kept together, so a run can process slightly more than this number. Does not apply to a manual run with <code>--transport_num</code>. See <a href="broken://pages/JZVVGs3ieGcAwmbZ8qqj">Monitor your Pipeline for Build Modifications</a>.</td><td>Hot (no server restart)</td></tr></tbody></table>

{% hint style="info" %}
The `foldedobjectthreshold` (1000) and `maxtransportsperquery` (100) defaults are **runtime defaults applied when the key is omitted** — they are not written into the `config.toml` template that `setup install` generates. Add the keys explicitly only if you need non-default values.
{% endhint %}

***

### \[footprints]

Defines how the agent processes Footprints data collected from Tosca test executions.

<table><thead><tr><th width="280">Field</th><th>Description</th></tr></thead><tbody><tr><td>testexecutionqueryingfreq</td><td>Frequency in seconds at which the agent queries the test repository for new test executions. Default: <code>5</code>.</td></tr><tr><td>scmonrecollectionfreqmins</td><td>(Optional) How often in minutes the agent re-collects SCMON baseline data. Uses the agent default when not set.</td></tr><tr><td>labid</td><td>(Optional) The lab ID for which to process Footprints data. Usually set automatically.</td></tr><tr><td>typequeries</td><td>Array of <code>{ type, query }</code> entries that exclude SCMON context objects from footprints collection. See <strong>Footprints type queries</strong> below.</td></tr><tr><td>readstartdate</td><td>Deprecated — retained for backward compatibility. Ignored by the agent.</td></tr><tr><td>readstarttime</td><td>Deprecated — retained for backward compatibility. Ignored by the agent.</td></tr><tr><td>readtime</td><td>Deprecated — retained for backward compatibility. Ignored by the agent.</td></tr></tbody></table>

You may modify **testexecutionqueryingfreq**, **scmonrecollectionfreqmins**, and **typequeries** as required.

#### Footprints type queries

The `typequeries` field lets you exclude specific SCMON context objects from footprints collection based on object type and name pattern. Each entry has a `type` and a `query` (glob pattern):

{% code title="Example" overflow="wrap" %}

```toml
[footprints]
typequeries = [
  { type = "PROG", query = "SAPL*" },
  { type = "TCOD", query = "SE*" },
  { type = "ALL",  query = "/SAP/*" },
]
```

{% endcode %}

| Type   | Matches              |
| ------ | -------------------- |
| `ALL`  | Any object type      |
| `PROG` | Programs             |
| `TCOD` | Transaction codes    |
| `FUNC` | RFC function modules |
| `ODAT` | OData services       |

Pattern syntax: `*` matches any sequence of characters, `?` matches a single character. Matching is case-insensitive.

{% hint style="info" %}
If `typequeries` is empty or not set, no objects are excluded. The agent auto-migrates older configs to include an empty `typequeries` array.
{% endhint %}

See also: [Collect Footprints data for your Pipeline](broken://pages/BtrDV52TrGwLRpGXR4Nd).

***

### \[\[rfc]]

Array table. Each `[[rfc]]` section stores the connection details for one RFC Destination. RFC Destinations are created and managed with `slabapcli rfc set`.

<table><thead><tr><th width="160">Field</th><th>Description</th></tr></thead><tbody><tr><td>name</td><td>The name of the RFC Destination. Used as the identifier in <code>[[pipeline]]</code> entries.</td></tr><tr><td>hostname</td><td>The SAP server hostname or IP address.</td></tr><tr><td>sysnr</td><td>The SAP system number (two-digit string, e.g. <code>"00"</code>).</td></tr><tr><td>client</td><td>The SAP client number (three-digit string, e.g. <code>"100"</code>).</td></tr><tr><td>language</td><td>The SAP logon language (e.g. <code>"EN"</code>).</td></tr><tr><td>username</td><td>The SLUSER account name. Encrypted on disk.</td></tr><tr><td>password</td><td>The SLUSER account password. Encrypted on disk.</td></tr><tr><td>router</td><td>(Optional) SAP router string for the connection.</td></tr><tr><td>cachedusage</td><td>Whether usage data is cached for this RFC Destination. Managed by <code>rfc set</code>.</td></tr><tr><td>cachedprdrfc</td><td>Effective PRD RFC name used when <code>cachedusage</code> is <code>true</code>. Added automatically in schema version 4. Do not edit manually.</td></tr><tr><td>maxretries</td><td>(Optional) Maximum number of RFC connection retries.</td></tr><tr><td>retrieswait</td><td>(Optional) Seconds to wait between RFC connection retries.</td></tr></tbody></table>

You may rename an RFC Destination by modifying its **name** field. If you do, also update the matching references in all `[[pipeline]]` sections.

Do not modify the **username**, **password**, or **cachedprdrfc** fields directly. These values are managed by the CLI.

{% hint style="info" %}
**Reload behavior:** `[[rfc]]` is hot — no server restart is required after a successful reload. You do not need to rerun `buildmap` or `buildmods`. If an active `footprints` (or other scheduled) task may already be using the old connection context, stop and start that **task** as needed (`footprints stop` followed by `footprints run`).
{% endhint %}

***

### \[\[pipeline]]

Array table. Each `[[pipeline]]` section stores the configuration for one Pipeline. Pipelines are created and managed with `slabapcli pipeline set`.

<table><thead><tr><th width="160">Field</th><th>Description</th></tr></thead><tbody><tr><td>appname</td><td>The SeaLights application name associated with this pipeline. Set by <code>pipeline set --appname</code>.</td></tr><tr><td>name</td><td>The pipeline identifier used by <code>buildmap</code>, <code>buildmods</code>, <code>footprints</code>, and <code>testrepo</code> commands. Auto-generated as <code>&#x3C;appname>-&#x3C;qas></code> if not set explicitly via <code>--name</code>.</td></tr><tr><td>qas</td><td>The QAS RFC Destination name for this pipeline. Mutually exclusive with <code>dev</code>.</td></tr><tr><td>dev</td><td>(Alternative to <code>qas</code>) The DEV RFC Destination name when the source system is a DEV system. Mutually exclusive with <code>qas</code>.</td></tr><tr><td>prd</td><td>The PRD RFC Destination name for this pipeline.</td></tr><tr><td>labid</td><td>The SeaLights lab ID for this pipeline. Leave unset so the agent derives it as <code>&#x3C;QAS SID> &#x3C;QAS hostname></code> (matches the QAS branch name). Do not override casually.</td></tr><tr><td>disablesetref</td><td>(Optional) Boolean. When <code>true</code>, disables the set-ref step for this pipeline. Managed by CLI only — do not edit directly.</td></tr><tr><td>useaddon</td><td>Boolean. Selects how the agent reads Production usage data (ST03) from the pipeline's PRD system. See <a href="#production-usage-data-source">Production usage data source</a> below. Default for new pipelines and migrated configurations: <code>false</code>.</td></tr><tr><td>foldedobjectthreshold</td><td>(Optional) Integer greater than zero. Overrides <a href="#buildmods"><code>[buildmods].foldedobjectthreshold</code></a> for this pipeline.</td></tr><tr><td>graphtraversal</td><td>(Optional) <code>topdown</code> or <code>bottomup</code>. Direction in which <code>BUILD_MODS</code> traverses the impacted graph when the changed-object count reaches the folded-object threshold. Default: <code>topdown</code>. Do not modify unless Tricentis Support asks you to.</td></tr></tbody></table>

#### Production usage data source

The `useaddon` field controls how the agent reads ST03 usage data from the pipeline's PRD system:

| Value             | Behavior                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| ----------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `false` (default) | The agent reads ST03 data through the standard SAP function module `SWNC_COLLECTOR_GET_AGGREGATES`. No SeaLights add-on is required on the PRD system. The PRD RFC user needs the [PRD authorizations without the add-on](broken://pages/JfFkO1xqq9huG22WXqhI#prd-without-add-on).                                                                                                                                                                                                                          |
| `true`            | The agent reads ST03 data through the SeaLights add-on function module `/TRICE/RFC_GET_ST03_DATA`. The add-on must be installed on the PRD system, and the PRD RFC user needs the [PRD authorizations with the add-on](broken://pages/JfFkO1xqq9huG22WXqhI#prd-with-add-on) (see also [Install the add-on on your Production system](broken://pages/KA26qNyaJ9N3X9bfhQmb#install-the-add-on-on-your-production-system)). There is no fallback: if the add-on is not available, usage data collection fails. |

All pipelines that use the same `prd` RFC Destination must use the same `useaddon` value. Set it with `slabapcli pipeline set --use-addon true|false`, or edit `config.toml` directly.

{% hint style="info" %}
**Reload behavior:** `[[pipeline]]` is hot — no server restart is required after a successful reload. You do not need to rerun `buildmap` or `buildmods`. If an active `footprints` (or other scheduled) task may already be using the old pipeline/RFC context, stop and start that **task** as needed.
{% endhint %}

***

### \[\[testrepo]]

Array table. Each `[[testrepo]]` section stores the configuration for one test repository adapter. Test repositories are created and managed with `slabapcli testrepo set`.

<table><thead><tr><th width="160">Field</th><th>Description</th></tr></thead><tbody><tr><td>name</td><td>Unique name for this test repository entry.</td></tr><tr><td>type</td><td>Adapter type: <code>ado</code>, <code>tosca</code>, <code>toscacloud</code>, <code>excel</code>, <code>xray</code>, <code>qtest</code>, <code>certify</code>, <code>ssm</code>, <code>alm</code> (OpenText ALM), <code>octane</code> (OpenText Octane), or <code>calm</code> (SAP Cloud ALM).</td></tr><tr><td>pipeline</td><td>The pipeline name this test repository is linked to.</td></tr><tr><td>searchpaths</td><td>(Optional) Array of repository or filesystem paths to scope the adapter search. Stored as a sibling key directly under <code>[[testrepo]]</code>, not in <code>[testrepo.settings]</code>.</td></tr><tr><td>teststage</td><td>(Optional) SeaLights test stage used when the agent uploads results for this test repository (unless a REST upload override supplies a stage). Top-level sibling of <code>searchpaths</code> — not a <code>[testrepo.settings]</code> key and not a CLI <code>--setting</code>. Direct TOML edits use <code>teststage</code>; the CLI flag is <code>--test-stage</code>. When omitted, the effective default is <code>"{type} Tests"</code> (for example <code>qtest Tests</code> or <code>ado Tests</code>).</td></tr></tbody></table>

Adapter-specific connection settings are stored in the `[testrepo.settings]` subtable. The keys depend on the adapter type — see [Configure test repositories](broken://pages/RZTKL0g90WmKm4Prs0gG) for the full per-adapter key reference, and the matching [Test Tool Integrations](broken://pages/X3jEQR7gju1fIaT7v4vC) page for type-specific examples.

{% code title="Example \[\[testrepo]] shape" overflow="wrap" %}

```toml
[[testrepo]]
  name = 'ALM_Demo-qtest'
  type = 'qtest'
  pipeline = 'ALM_Demo-S21'
  teststage = 'Regression Tests'

[testrepo.settings]
  url = 'https://mycompany.qtestnet.com'
  project = 'MyProject'
```

{% endcode %}

#### Config-only editing paths for `[[testrepo]]`

{% hint style="warning" %}
**`testrepo set` replaces settings on every call.** Running `slabapcli testrepo set` replaces the **entire** `[testrepo.settings]` block, `searchpaths`, and `teststage` on every invocation. Any key you omit is cleared — omitting `--test-stage` clears a previously stored `teststage`.

To make a partial change without re-entering all settings, edit `config.toml` directly. `[[testrepo]]` is hot — the next server configuration access uses the valid saved configuration without restarting `SLABAPServer.exe`. Optionally confirm readiness with `GET /ready` or re-run `testrepo test`.
{% endhint %}

Two categories of testrepo parameters can **only** be set by editing `config.toml` directly:

1. **Secrets** — credential fields are never accepted via `--setting`. They are entered interactively during `testrepo set` (input is hidden). To change a secret without re-running the full command, use the interactive `set` commands, or edit the field directly in `config.toml` when it is stored as plaintext (`key` and `iv` in `[settings]` are empty). No server restart is required after a successful reload; if a scheduled task may already hold the prior credentials, stop and start that **task** as needed.

   | Adapter      | Secret fields                                                                         |
   | ------------ | ------------------------------------------------------------------------------------- |
   | `qtest`      | `username`, `password`                                                                |
   | `tosca`      | `username` + `password` **or** `apikey` + `apisecret`                                 |
   | `toscacloud` | `clientId`, `clientSecret`                                                            |
   | `excel`      | *(none)*                                                                              |
   | `xray`       | *(none)*                                                                              |
   | `ado`        | `password` (Azure DevOps Personal Access Token)                                       |
   | `certify`    | `username`, `password` (optional — leave blank for Windows Integrated Authentication) |
   | `ssm`        | `username`, `password`                                                                |
   | `alm`        | `username` + `password` **or** `apikey` + `apisecret` (OpenText ALM)                  |
2. **Partial updates to optional fields** — because `testrepo set` replaces the whole settings block, editing an optional key (e.g. `workstates`, `bufferPatterns`, `confidenceThreshold`) without re-supplying all other keys requires a direct `config.toml` edit. The change applies on the next successful reload; no server restart is required.

***

## Environment variable overrides

The following environment variables override the corresponding `config.toml` settings at runtime. They do not modify the file on disk.

| Variable                        | Overrides           | Notes                                                                                                                                                   |
| ------------------------------- | ------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `SL_ABAP_SERVER_CONFIG_PATH`    | Config file path    | Server (`SLABAPServer.exe`) resolution order: this env var → `%ProgramData%\…\config\config.toml` → `{exe}\..\config` → ancestor walk.                  |
| `SL_AGENT_TOKEN`                | `[sealights].token` | Server only. Takes precedence over the encrypted token in `config.toml`. Changing the service process environment typically requires a service restart. |
| `SL_PROXY_SERVER` or `SL_PROXY` | `[proxy].server`    | CLI, watcher, and server. Takes precedence over the `[proxy]` section. The server reads it at startup — restart the Windows service after a change.     |
| `SL_PROXY_USERNAME`             | `[proxy].username`  | CLI, watcher, and server.                                                                                                                               |
| `SL_PROXY_PASSWORD`             | `[proxy].password`  | CLI, watcher, and server.                                                                                                                               |

***

## Database locations

All agent databases and artifacts are stored under the `userdata` directory (default: `%ProgramData%\Tricentis\SeaLights\ABAP Agent`). This is a change from ABAP Agent 1.x, where databases lived in the install directory.

The directory has two subtrees:

* `private\` — Databases and generated artifacts (agent-internal; encrypted where applicable)
* `public\` — Logs and shared output

### Database path reference

The following table lists every database file managed by the agent. All paths are relative to the `userdata` root.

| Database                                  | Path                                                                           | Created by                 |
| ----------------------------------------- | ------------------------------------------------------------------------------ | -------------------------- |
| Process state                             | `private\Processes.db`                                                         | Server startup             |
| SAP tables cache                          | `private\SapTables\{rfc}\tables_cache.db`                                      | `buildmap run`             |
| Common pipeline data                      | `private\common\{pipeline}\common.db`                                          | `buildmap run`             |
| Links (impacted set)                      | `private\Links\{rfc}\{pipeline}\{run}\links.db`                                | Server (link computation)  |
| Impacted graph                            | `private\Graph\{rfc}\{pipeline}\{run}\impacted_graph.db`                       | Server (upload)            |
| Build modifications                       | `private\DiscoveredTransports\{rfc}\{pipeline}\{run}\discovered_transports.db` | `buildmods run`            |
| Build map                                 | `private\BuildMapping\{pipeline}\data.db`                                      | `buildmap run`             |
| Performance history (PHD)                 | `private\PerfHist\{RFC}_PHD.db`                                                | `rfc phd`                  |
| FLPCA data                                | `private\flpca\{rfc-lowercase}.db`                                             | `upload_flpca import`      |
| Test-repository search artifacts          | `private\SearchTestRepo\{pipeline}\{yyyy-MM-dd}\{testrepo}\{run}\`             | Server (`search_testrepo`) |
| Test-repository connection test artifacts | `private\TestTestRepo\{pipeline}\{yyyy-MM-dd}\{testrepo}\{run}\`               | Server (`test_testrepo`)   |

**Path variable key:**

| Placeholder       | Value                                                                                                                               |
| ----------------- | ----------------------------------------------------------------------------------------------------------------------------------- |
| `{rfc}`           | RFC Destination name (as configured in `[[rfc]].name`; case as stored)                                                              |
| `{rfc-lowercase}` | RFC Destination name lowercased (e.g. `S21` → `s21`)                                                                                |
| `{RFC}`           | RFC Destination name uppercased as used by the PHD naming convention (e.g. `S21_PHD.db`)                                            |
| `{pipeline}`      | Pipeline effective name (as stored in `[[pipeline]].name`)                                                                          |
| `{run}`           | Run identifier generated per execution. For test-repository artifacts, the watcher run ID, or the `processId` for one-off CLI runs. |
| `{testrepo}`      | Test repository name (as stored in `[[testrepo]].name`)                                                                             |

{% hint style="info" %}
When `key` and `iv` in `[settings]` are empty, `config.toml` and the databases are stored without encryption at rest, so their contents can be inspected directly for troubleshooting.
{% endhint %}

### Log locations

Most agent logs are written under the `public\Logs\` subtree of the userdata directory (default: `%ProgramData%\Tricentis\SeaLights\ABAP Agent`). For server-backed failures (Initial Build Map, Build Modifications, test-repository search/test, and similar), start with the **server per-task** folders below. The CLI itself does not write a log file — it logs to the console only. Symptom → log guidance: [Troubleshooting — Server task logs](broken://pages/DTAUuyOmlKawT2B8UTYM#server-task-logs).

| Component                                            | Log location                                                                                                                                                  |
| ---------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Server per-task log                                  | `public\Logs\{pipeline}\{origin}\{yyyy-MM-dd}\{run}\{taskType}_{processId}.log`                                                                               |
| Native CAPI agent (per server task)                  | Same task folder: `{taskType}_{processId}_agent.log`                                                                                                          |
| Adapter host (`SLABAPAdapterHost.exe`)               | Same task folder: `{taskType}_{processId}_adapter.log` (and `{taskType}_{processId}_worker.log` for adapters that use a worker process, such as OpenText ALM) |
| Server (`SLABAPServer.exe`) daily host log           | `public\Logs\server-YYYYMMDD.log` (one file per day)                                                                                                          |
| Pipeline watcher actions (summaries / watcher-local) | `public\Logs\{pipeline}\InitialBuildMapping_YYYY-MM-DD.log`, `BuildMods_YYYY-MM-DD.log`, `Footprints_YYYY-MM-DD.log` (one file per day)                       |
| Watcher bootstrap (`main_logger`)                    | `%ProgramData%\Tricentis\SeaLights\ABAP Agent\public\Logs\watcher\main_logger_<timestamp>_<pid>.log` (always ProgramData)                                     |
| Purger (`purger.exe`)                                | `public\Logs\purger_YYYY-MM-DD.log`                                                                                                                           |
| CLI (`slabapcli.exe`)                                | Console only (stdout/stderr); no log file                                                                                                                     |

{% hint style="info" %}
Relocating `[settings].userdata` moves userdata-relative logs; the watcher bootstrap logger stays under ProgramData.
{% endhint %}

#### Per-task log layout

When the server runs a background task (initial build map stages, build modifications, test-repository search/test, and similar), it groups all log files for that run in one folder:

```
public\Logs\{pipeline}\{origin}\{yyyy-MM-dd}\{run}\
```

Test-repository tasks add the test repository name before the run folder:

```
public\Logs\{pipeline}\{origin}\{yyyy-MM-dd}\{testrepo}\{run}\
```

* **`{pipeline}`** — Pipeline name. Tasks that are not tied to a pipeline (for example `upload_flpca`) use the RFC Destination name instead.
* **`{origin}`** — The action that started the task (see [Log origins](#log-origins) below).
* **`{yyyy-MM-dd}`** — UTC date when the task started.
* **`{testrepo}`** — Test repository name (`search_testrepo` and `test_testrepo` only).
* **`{run}`** — The watcher run ID, shared by every server task started in the same watcher run (for example all five Initial Build Map stages). One-off CLI tasks (such as `testrepo test` or `upload_flpca import`) use the task's `processId` instead.

Each folder contains one set of files per server task:

| File                                 | Written by                             | Controlled by                   |
| ------------------------------------ | -------------------------------------- | ------------------------------- |
| `{taskType}_{processId}.log`         | Server (`SLABAPServer.exe`)            | `[server.logging].defaultLevel` |
| `{taskType}_{processId}_agent.log`   | Native CAPI (`slabap.agent.dll`)       | `[logging]`                     |
| `{taskType}_{processId}_adapter.log` | Adapter host (`SLABAPAdapterHost.exe`) | `[adapters].logLevel`           |
| `{taskType}_{processId}_worker.log`  | Adapter worker process (OpenText ALM)  | `[adapters].logLevel`           |

For example, the `sync_phd` stage of an Initial Build Map for pipeline `app1-S21` writes:

```
public\Logs\app1-S21\InitialBuildMap\2026-09-27\<run>\sync_phd_<processId>.log
public\Logs\app1-S21\InitialBuildMap\2026-09-27\<run>\sync_phd_<processId>_agent.log
```

These levels are independent. Raise `[adapters].logLevel` when diagnosing Tosca/qTest/Excel (and other adapter) connectivity; raise `[server.logging].defaultLevel` when diagnosing server orchestration; use `[logging]` for watcher and native CAPI verbosity.

#### Log origins

| `{origin}` folder | Started by                                                                           | Server `taskType` values                                                                       |
| ----------------- | ------------------------------------------------------------------------------------ | ---------------------------------------------------------------------------------------------- |
| `InitialBuildMap` | `INIT_BUILD_MAP` watcher action (`buildmap run`)                                     | `generate_cache`, `sync_phd`, `generate_links`, `generate_graph`, `generate_buildmap`          |
| `BuildMods`       | `BUILD_MODS` watcher action (`buildmods run`)                                        | `query_transports`, `generate_cache`, `generate_links`, `generate_graph`, `generate_buildmods` |
| `SearchTestRepo`  | Scheduled test-repository search (`search_testrepo run`)                             | `search_testrepo`                                                                              |
| `TestTestRepo`    | `slabapcli testrepo test` (and auto-test after `testrepo set` when the server is up) | `test_testrepo`                                                                                |
| `UploadFlpca`     | `slabapcli upload_flpca import`                                                      | `upload_flpca`                                                                                 |
| `DirectApi`       | Direct calls to the server REST API that do not identify an origin                   | Any                                                                                            |

Initial Build Map stages run in the order listed above. For what each stage does and how long an Initial Build Map can take, see [Create an Initial Build Map for your Pipeline](broken://pages/6f4WDLP7ZxZdqhvqwcMb).

**Footprints** is watcher-local: it writes only the pipeline daily log (`Footprints_YYYY-MM-DD.log`) and does not create server task folders.

#### What `processId` is

`processId` is the server's identifier for one task run — a short opaque string (typically 12 hexadecimal characters) assigned when the process starts. It is **not** the Windows OS process ID (PID).

Use it to find the correct log files. Ways to find it:

1. **Server daily log** — `public\Logs\server-YYYYMMDD.log` lines for the task include the `processId`.
2. **File name** — Every per-task log file name ends with `_{processId}` (for example `generate_links_4332c28cc8d3.log`).
3. **Task / CLI output** — Watcher and CLI output for server-backed work (build map stages, `testrepo test`, `search_testrepo`, and similar) surface the `processId` when the server starts or reports the process.
4. **Inside the log lines** — Server task logs include `[ProcessId]` in each line; the adapter log also logs `processId` at startup.
