diff --git a/Solutions/SAP S4 Cloud Public Edition/Data Connectors/SAPS4PublicPollerConnector/SAPS4Public_DCR.json b/Solutions/SAP S4 Cloud Public Edition/Data Connectors/SAPS4PublicPollerConnector/SAPS4Public_DCR.json index a2ecc0b3cdd..138f02545c0 100644 --- a/Solutions/SAP S4 Cloud Public Edition/Data Connectors/SAPS4PublicPollerConnector/SAPS4Public_DCR.json +++ b/Solutions/SAP S4 Cloud Public Edition/Data Connectors/SAPS4PublicPollerConnector/SAPS4Public_DCR.json @@ -99,7 +99,7 @@ "destinations": [ "clv2ws1" ], - "transformKql": "source\n| extend TimeGenerated = now(), AgentId = \"S4-Public-Cloud\", ClientID = slgmand, Computer = terminal_name, Email = email_adress, MessageClass = eventID, MessageText = rsau_text, SystemID = sid, UpdatedOn = todatetime(log_tstmp), TransactionCode = slgtc, User = UserID, Variable1 = param_a, Variable2 = param_b, Variable3 = param_c, Variable4 = param_d\n| project TimeGenerated, AgentId, ClientID, Computer, Email, MessageClass, MessageText, SystemID, UpdatedOn, TransactionCode, User, Variable1, Variable2, Variable3, Variable4", + "transformKql": "source\n| extend TimeGenerated = now(), AgentId = \"S4-Public-Cloud\", ClientId = slgmand, Computer = terminal_name, Email = email_adress, MessageClass = eventID, MessageText = rsau_text, SystemId = sid, UpdatedOn = todatetime(log_tstmp), TransactionCode = slgtc, User = UserID, Variable1 = param_a, Variable2 = param_b, Variable3 = param_c, Variable4 = param_d, AbapProgramName = slgrepna\n| project TimeGenerated, AgentId, ClientId, Computer, Email, MessageClass, MessageText, SystemId, UpdatedOn, TransactionCode, User, Variable1, Variable2, Variable3, Variable4, AbapProgramName", "outputStream": "Microsoft-ABAPAuditLog" } ] diff --git a/Solutions/SAP S4 Cloud Public Edition/Data Connectors/SAPS4PublicPollerConnector/SAPS4Public_connectorDefinition.json b/Solutions/SAP S4 Cloud Public Edition/Data Connectors/SAPS4PublicPollerConnector/SAPS4Public_connectorDefinition.json index 1a8ff33f3c7..83480d3083f 100644 --- a/Solutions/SAP S4 Cloud Public Edition/Data Connectors/SAPS4PublicPollerConnector/SAPS4Public_connectorDefinition.json +++ b/Solutions/SAP S4 Cloud Public Edition/Data Connectors/SAPS4PublicPollerConnector/SAPS4Public_connectorDefinition.json @@ -10,7 +10,7 @@ "title": "SAP S/4HANA Cloud Public Edition", "logo": "SapLogo.svg", "publisher": "SAP", - "descriptionMarkdown": "The SAP S/4HANA Cloud Public Edition data connector enables ingestion of SAP's security audit log into the Microsoft Sentinel Solution for SAP, supporting cross-correlation, alerting, and threat hunting. Looking for alternative authentication mechanisms? See [here](https://github.com/Azure-Samples/Sentinel-For-SAP-Community/tree/main/integration-artifacts).", + "descriptionMarkdown": "The SAP S/4HANA Cloud Public Edition (GROW with SAP) data connector enables ingestion of SAP's security audit log into the Microsoft Sentinel Solution for SAP, supporting cross-correlation, alerting, and threat hunting. Looking for alternative authentication mechanisms? See [here](https://github.com/Azure-Samples/Sentinel-For-SAP-Community/tree/main/integration-artifacts).", "graphQueriesTableName": "ABAPAuditLog", "graphQueries": [ { diff --git a/Solutions/SAP S4 Cloud Public Edition/Data/Solution_SAPS4Public.json b/Solutions/SAP S4 Cloud Public Edition/Data/Solution_SAPS4Public.json index a786fc06c0c..41a27f2761a 100644 --- a/Solutions/SAP S4 Cloud Public Edition/Data/Solution_SAPS4Public.json +++ b/Solutions/SAP S4 Cloud Public Edition/Data/Solution_SAPS4Public.json @@ -17,7 +17,7 @@ "Watchlists": [], "WatchlistDescription": [], "BasePath": "C:\\GitHub\\Azure-Sentinel\\Solutions\\SAP S4 Cloud Public Edition", - "Version": "3.0.1", + "Version": "3.0.2", "Metadata": "SolutionMetadata.json", "TemplateSpec": true, "Is1PConnector": false diff --git a/Solutions/SAP S4 Cloud Public Edition/Package/3.0.2.zip b/Solutions/SAP S4 Cloud Public Edition/Package/3.0.2.zip new file mode 100644 index 00000000000..e6bb6806aee Binary files /dev/null and b/Solutions/SAP S4 Cloud Public Edition/Package/3.0.2.zip differ diff --git a/Solutions/SAP S4 Cloud Public Edition/Package/mainTemplate.json b/Solutions/SAP S4 Cloud Public Edition/Package/mainTemplate.json index a86a3ee6db4..c63b90a35df 100644 --- a/Solutions/SAP S4 Cloud Public Edition/Package/mainTemplate.json +++ b/Solutions/SAP S4 Cloud Public Edition/Package/mainTemplate.json @@ -45,7 +45,7 @@ }, "variables": { "_solutionName": "SAP S4 Cloud Public Edition", - "_solutionVersion": "3.0.1", + "_solutionVersion": "3.0.2", "solutionId": "sap_jasondau.azure-sentinel-solution-s4hana-public", "_solutionId": "[variables('solutionId')]", "workspaceResourceId": "[resourceId('microsoft.OperationalInsights/Workspaces', parameters('workspace'))]", @@ -89,7 +89,7 @@ "title": "SAP S/4HANA Cloud Public Edition", "logo": "SapLogo.svg", "publisher": "SAP", - "descriptionMarkdown": "The SAP S/4HANA Cloud Public Edition data connector enables ingestion of SAP's security audit log into the Microsoft Sentinel Solution for SAP, supporting cross-correlation, alerting, and threat hunting. Looking for alternative authentication mechanisms? See [here](https://github.com/Azure-Samples/Sentinel-For-SAP-Community/tree/main/integration-artifacts).", + "descriptionMarkdown": "The SAP S/4HANA Cloud Public Edition (GROW with SAP) data connector enables ingestion of SAP's security audit log into the Microsoft Sentinel Solution for SAP, supporting cross-correlation, alerting, and threat hunting. Looking for alternative authentication mechanisms? See [here](https://github.com/Azure-Samples/Sentinel-For-SAP-Community/tree/main/integration-artifacts).", "graphQueriesTableName": "ABAPAuditLog", "graphQueries": [ { @@ -360,7 +360,7 @@ "destinations": [ "clv2ws1" ], - "transformKql": "source\n| extend TimeGenerated = now(), AgentId = \"S4-Public-Cloud\", ClientID = slgmand, Computer = terminal_name, Email = email_adress, MessageClass = eventID, MessageText = rsau_text, SystemID = sid, UpdatedOn = todatetime(log_tstmp), TransactionCode = slgtc, User = UserID, Variable1 = param_a, Variable2 = param_b, Variable3 = param_c, Variable4 = param_d\n| project TimeGenerated, AgentId, ClientID, Computer, Email, MessageClass, MessageText, SystemID, UpdatedOn, TransactionCode, User, Variable1, Variable2, Variable3, Variable4", + "transformKql": "source\n| extend TimeGenerated = now(), AgentId = \"S4-Public-Cloud\", ClientId = slgmand, Computer = terminal_name, Email = email_adress, MessageClass = eventID, MessageText = rsau_text, SystemId = sid, UpdatedOn = todatetime(log_tstmp), TransactionCode = slgtc, User = UserID, Variable1 = param_a, Variable2 = param_b, Variable3 = param_c, Variable4 = param_d, AbapProgramName = slgrepna\n| project TimeGenerated, AgentId, ClientId, Computer, Email, MessageClass, MessageText, SystemId, UpdatedOn, TransactionCode, User, Variable1, Variable2, Variable3, Variable4, AbapProgramName", "outputStream": "Microsoft-ABAPAuditLog" } ] @@ -389,7 +389,7 @@ "title": "SAP S/4HANA Cloud Public Edition", "logo": "SapLogo.svg", "publisher": "SAP", - "descriptionMarkdown": "The SAP S/4HANA Cloud Public Edition data connector enables ingestion of SAP's security audit log into the Microsoft Sentinel Solution for SAP, supporting cross-correlation, alerting, and threat hunting. Looking for alternative authentication mechanisms? See [here](https://github.com/Azure-Samples/Sentinel-For-SAP-Community/tree/main/integration-artifacts).", + "descriptionMarkdown": "The SAP S/4HANA Cloud Public Edition (GROW with SAP) data connector enables ingestion of SAP's security audit log into the Microsoft Sentinel Solution for SAP, supporting cross-correlation, alerting, and threat hunting. Looking for alternative authentication mechanisms? See [here](https://github.com/Azure-Samples/Sentinel-For-SAP-Community/tree/main/integration-artifacts).", "graphQueriesTableName": "ABAPAuditLog", "graphQueries": [ { @@ -707,7 +707,7 @@ "apiVersion": "2023-04-01-preview", "location": "[parameters('workspace-location')]", "properties": { - "version": "3.0.1", + "version": "3.0.2", "kind": "Solution", "contentSchemaVersion": "3.0.0", "displayName": "SAP S4 Cloud Public Edition", diff --git a/Solutions/SAP S4 Cloud Public Edition/ReleaseNotes.md b/Solutions/SAP S4 Cloud Public Edition/ReleaseNotes.md index e0c08d66518..1e2bb2a15f2 100644 --- a/Solutions/SAP S4 Cloud Public Edition/ReleaseNotes.md +++ b/Solutions/SAP S4 Cloud Public Edition/ReleaseNotes.md @@ -1,4 +1,5 @@ | **Version** | **Date Modified (DD-MM-YYYY)** | **Change History** | |-------------|--------------------------------|---------------------------------------------------------------------| +| 3.0.2 | 30-10-2025 |DCR transform updates| | 3.0.1 | 16-10-2025 |DCR transform updates| | 3.0.0 | 06-10-2025 |Initial release| \ No newline at end of file