You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
title: SAP agentless data connector prerequisites checker
3
+
ms.date: 03/13/2025
4
+
ms.topic: include
5
+
---
6
+
7
+
<!-- docutune:disable -->
8
+
9
+
**To run the tool**:
10
+
11
+
1. Open the integration package, navigate to the artifacts tab, and select the **Prerequisite checker** iflow > **Configure**.
12
+
1. Set the target RFC destination to the SAP system you want to check.
13
+
1. Deploy the iflow as you would otherwise for your SAP systems. For example, use the following sample PowerShell script, modifying the sample placeholder values for your environment:
Copy file name to clipboardExpand all lines: articles/sentinel/monitor-sap-system-health.md
+2-4Lines changed: 2 additions & 4 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -28,10 +28,8 @@ For a video demonstration of the procedures in this article, watch the following
28
28
:::zone pivot="connection-agentless"
29
29
30
30
> [!IMPORTANT]
31
-
> Monitoring the health of your SAP systems is currently in PREVIEW. The [Azure Preview Supplemental Terms](https://azure.microsoft.com/support/legal/preview-supplemental-terms/) include additional legal terms that apply to Azure features that are in beta, preview, or otherwise not yet released into general availability.
31
+
> The agentless data connector for SAP is currently in PREVIEW. The [Azure Preview Supplemental Terms](https://azure.microsoft.com/support/legal/preview-supplemental-terms/) include additional legal terms that apply to Azure features that are in beta, preview, or otherwise not yet released into general availability.
32
32
>
33
-
> Microsoft Sentinel's **Agentless solution** is in limited preview as a prereleased product, which may be substantially modified before it’s commercially released. Microsoft makes no warranties expressed or implied, with respect to the information provided here. Access to the **Agentless solution** also [requires registration](https://aka.ms/SentinelSAPAgentlessSignUp) and is only available to approved customers and partners during the preview period. For more information, see [Microsoft Sentinel for SAP goes agentless ](https://community.sap.com/t5/enterprise-resource-planning-blogs-by-members/microsoft-sentinel-for-sap-goes-agentless/ba-p/13960238).
34
-
35
33
:::zone-end
36
34
37
35
## Prerequisites
@@ -66,7 +64,7 @@ This procedure describes how to check your data connector's connection status fr
66
64
|---------|---------|
67
65
|**Production**| The system is defined by the SAP admin as a production system. |
68
66
|**Unknown (Production)**| Microsoft Sentinel couldn't retrieve the system status. Microsoft Sentinel regards this type of system as a production system for both security and billing purposes. <br><br>In such cases, we recommend that you check the Microsoft Sentinel role definitions and permissions on the SAP system, and validate that the system allows Microsoft Sentinel to read the content of the T000 table. Next, consider [updating the SAP connector](sap/update-sap-data-connector.md) to the latest version. |
69
-
|**Nonproduction**| Indicates roles like developing, testing, and customizing. |
67
+
|**Non-production**| Indicates roles like developing, testing, and customizing. |
70
68
71
69
-**Agent name**. Unique ID of the installed data connector agent.
Copy file name to clipboardExpand all lines: articles/sentinel/sap/collect-sap-hana-audit-logs.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -23,7 +23,7 @@ Content in this article is intended for your **security**, **infrastructure**, a
23
23
> Microsoft Sentinel SAP HANA support is currently in PREVIEW. The [Azure Preview Supplemental Terms](https://azure.microsoft.com/support/legal/preview-supplemental-terms/) include additional legal terms that apply to Azure features that are in beta, preview, or otherwise not yet released into general availability.
24
24
25
25
> [!NOTE]
26
-
> This article is relevant only for the data connector agent, and isn't relevant for the [SAP agentless solution](deployment-overview.md#data-connector) (limited preview).
26
+
> This article is relevant only for the data connector agent, and isn't relevant for the [SAP agentless data connector](deployment-overview.md#data-connector) (Preview).
Copy file name to clipboardExpand all lines: articles/sentinel/sap/cross-workspace.md
-2Lines changed: 0 additions & 2 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -31,8 +31,6 @@ This article discusses how to work with the Microsoft Sentinel solution for SAP
31
31
> [!IMPORTANT]
32
32
> Working with multiple workspaces is currently in preview. This feature is provided without a service-level agreement. For more information, see [Supplemental Terms of Use for Microsoft Azure Previews](https://azure.microsoft.com/support/legal/preview-supplemental-terms/).
33
33
34
-
> [!NOTE]
35
-
> Multi-workspace support is available only with the data connector agent, and isn't supported with the [SAP agentless solution](deployment-overview.md#data-connector) (limited preview).
36
34
37
35
## SAP and SOC data maintained in separate workspaces
Copy file name to clipboardExpand all lines: articles/sentinel/sap/deploy-command-line.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -21,7 +21,7 @@ However, if you're using a configuration file to store your credentials instead
21
21
While you can run multiple data connector agents on a single machine, we recommend that you start with one only, monitor the performance, and then increase the number of connectors slowly. We also recommend that your **security** team perform this procedure with help from the **SAP BASIS** team.
22
22
23
23
> [!NOTE]
24
-
> This article is relevant only for the data connector agent, and isn't relevant for the [SAP agentless solution](deployment-overview.md#data-connector) (limited preview).
24
+
> This article is relevant only for the data connector agent, and isn't relevant for the [SAP agentless data connector](deployment-overview.md#data-connector) (Preview).
Copy file name to clipboardExpand all lines: articles/sentinel/sap/deploy-data-connector-agent-container.md
+52-23Lines changed: 52 additions & 23 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -32,42 +32,28 @@ Content in this article is relevant for your **security**, **infrastructure**, a
32
32
33
33
:::zone pivot="connection-agentless"
34
34
35
-
:::image type="content" source="media/deployment-steps/deploy-data-connector-agentless.png" alt-text="Diagram of the SAP solution deployment flow, highlighting the Connect your SAP system step." :::
35
+
:::image type="content" source="media/deployment-steps/deploy-data-connector-agentless.png" alt-text="Diagram of the SAP solution deployment flow, highlighting the Connect your SAP system step." border="false":::
36
36
37
-
Content in this article is relevant for your **security** team, using information provided by your **SAP BASIS** teams.
37
+
Content in this article is relevant for your **security** team.
38
38
39
39
:::zone-end
40
40
41
41
42
42
> [!IMPORTANT]
43
-
> Microsoft Sentinel's **Agentless solution** is in limited preview as a prereleased product, which may be substantially modified before it’s commercially released. Microsoft makes no warranties expressed or implied, with respect to the information provided here. Access to the **Agentless solution** also [requires registration](https://aka.ms/SentinelSAPAgentlessSignUp) and is only available to approved customers and partners during the preview period. For more information, see [Microsoft Sentinel for SAP goes agentless ](https://community.sap.com/t5/enterprise-resource-planning-blogs-by-members/microsoft-sentinel-for-sap-goes-agentless/ba-p/13960238).
43
+
> Microsoft Sentinel's agentless data connector for SAP is currently in PREVIEW. The [Azure Preview Supplemental Terms](https://azure.microsoft.com/support/legal/preview-supplemental-terms/) include additional legal terms that apply to Azure features that are in beta, preview, or otherwise not yet released into general availability.
44
44
45
45
## Prerequisites
46
46
47
47
Before you connect your SAP system to Microsoft Sentinel:
48
48
49
49
- Make sure that all of the deployment prerequisites are in place. For more information, see [Prerequisites for deploying Microsoft Sentinel solution for SAP applications](prerequisites-for-deploying-sap-continuous-threat-monitoring.md).
50
50
51
-
:::zone pivot="connection-agent"
52
-
53
51
- Make sure that you have the Microsoft Sentinel solution for **SAP applications**[installed in your Microsoft Sentinel workspace](deploy-sap-security-content.md)
54
52
55
53
- Make sure that your SAP system is fully [prepared for the deployment](preparing-sap.md).
56
54
57
55
- If you're deploying the data connector agent to communicate with Microsoft Sentinel over SNC, make sure that you completed [Configure your system to use SNC for secure connections](preparing-sap.md#configure-your-system-to-use-snc-for-secure-connections).
58
56
59
-
:::zone-end
60
-
61
-
:::zone pivot="connection-agentless"
62
-
63
-
- Make sure that you have the Microsoft Sentinel **SAP Agentless** solution [installed in your Microsoft Sentinel workspace](deploy-sap-security-content.md)
64
-
65
-
- Make sure that your SAP system is fully [prepared for the deployment](preparing-sap.md).
66
-
67
-
- Make sure your DCR is configured as described in [Install the solution from the content hub](deploy-sap-security-content.md#install-the-solution-from-the-content-hub).
68
-
69
-
:::zone-end
70
-
71
57
:::zone pivot="connection-agent"
72
58
73
59
## Watch a demo video
@@ -235,7 +221,7 @@ While deployment is also supported from the command line, we recommend that you
235
221
236
222
1. In Microsoft Sentinel, select **Configuration > Data connectors**.
237
223
238
-
1. In the search bar, enter *SAP*. Select **Microsoft Sentinel for SAP** from the search results and then **Open connector page**.
224
+
1. In the search bar, enter *SAP*. Select **Microsoft Sentinel for SAP - agent-based** from the search results and then **Open connector page**.
239
225
240
226
1. In the **Configuration** area, select **Add new agent (Preview)**.
241
227
@@ -346,22 +332,65 @@ At this stage, the system's **Health** status is **Pending**. If the agent is up
346
332
347
333
:::zone pivot="connection-agentless"
348
334
349
-
## Connect your agentless data connector
335
+
## Connect your agentless data connector (Preview)
350
336
351
-
1. In Microsoft Sentinel, go to the **Configuration > Data connectors** page and locate the **SAP ABAP and S/4 via cloud connector (Preview)** data connector.
337
+
1. In Microsoft Sentinel, go to the **Configuration > Data connectors** page and locate the **Microsoft Sentinel for SAP - agent-less (Preview)** data connector.
352
338
353
-
1. In the **Configuration** area, under **Connect an SAP integration suite to Microsoft Sentinel**, select **Add connection**.
339
+
1. In the **Configuration** area, scroll down and select **Add SAP client**.
354
340
355
-
1. In the **Agentless connection** side pane, enter the following details:
341
+
1. In the **Connect to an SAP Client** side pane, enter the following details:
| **RFC destination name** | The name of the RFC destination, taken from your BTP destination. |
360
346
| **SAP Agentless Client ID** | The *clientid* value taken from the Process Integration Runtime service key JSON file. |
361
347
| **SAP Agentless Client Secret** | The *clientsecret* value taken from the Process Integration Runtime service key JSON file. |
362
-
| **Authorization server URL** | The *tokenurlurl* value taken from the Process Integration Runtime service key JSON file. For example: `https://your-tenant.authentication.region.hana.ondemand.com/oauth/token` |
348
+
| **Authorization server URL** | The *tokenurl* value taken from the Process Integration Runtime service key JSON file. For example: `https://your-tenant.authentication.region.hana.ondemand.com/oauth/token` |
363
349
| **Integration Suite Endpoint** | The *url* value taken from the Process Integration Runtime service key JSON file. For example: `https://your-tenant.it-account-rt.cfapps.region.hana.ondemand.com` |
364
350
351
+
1. Select **Connect**.
352
+
353
+
## Customize data connector behavior (optional)
354
+
355
+
If you have an SAP agentless data connector for Microsoft Sentinel, you can use the SAP Integration Suite to customize how the agentless data connector ingests data from your SAP system into Microsoft Sentinel.
356
+
357
+
This procedure is only relevant when you want to customize the SAP agentless data connector behavior. Skip this procedure if you're satisfied with the default functionality. For example, if you're using Sybase, we recommend that you turn off ingestion for Change Docs logs in the iflow by configuring the **collect-changedocs-logs** parameter. Due to database performance issues, ingesting Change Docs logs Sybase isn't supported.
358
+
359
+
### Prerequisites for customizing data connector behavior
360
+
361
+
- You must have access to the [SAP Integration Suite](https://help.sap.com/docs/cloud-integration/sap-cloud-integration/sap-cloud-integration), with permissions to [edit value mappings](https://help.sap.com/docs/cloud-integration/sap-cloud-integration/working-with-mapping).
362
+
- An SAP integration package, either existing or new, to upload the default value mapping file.
363
+
364
+
### Download the configuration file and customize settings
365
+
366
+
1. Download the default [**example-parameters.zip**](https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/Solutions/SAP/Agentless/example-parameters.zip) file, which provides settings that define default behavior and is a good starting point to start customizing.
367
+
368
+
Save the **example-parameters.zip** file to a location accessible to your SAP Integration Suite environment.
369
+
370
+
1. Use the standard SAP procedures for uploading a Value Mapping file and making changes to customize your data connector settings:
371
+
372
+
1. Upload the **example-parameters.zip** file to the SAP Integration Suite as a value mapping artifact. For more information, see the [SAP documentation](https://help.sap.com/docs/cloud-integration/sap-cloud-integration/creating-value-mapping).
373
+
1. Use one of the following methods to customize your settings:
374
+
375
+
- **To customize settings across all SAP systems**, add value mappings for the **global** bi-directional mapping agency.
376
+
- **To customize settings for specific SAP systems**, add new bi-directional mapping agencies for each SAP system, and then add value mappings for each one. Name your agencies to exactly match the name of the RFC destination that you want to customize, such as myRfc, key, myRfc, value.
377
+
378
+
For more information, see [SAP documentation on configuring Value Mappings](https://help.sap.com/docs/cloud-integration/sap-cloud-integration/configuring-value-mappings)
379
+
380
+
Make sure to deploy the artifact when you're done customizing to activate the updated settings.
381
+
382
+
The following table lists the customizable parameters for the SAP agentless data connector for Microsoft Sentinel:
| **changedocs-object-classes** | List of object classes that are ingested from Change Docs logs. | Comma separated list of object classes | `BANK, CLEARING, IBAN, IDENTITY, KERBEROS, OA2_CLIENT, PCA_BLOCK, PCA_MASTER, PFCG, SECM, SU_USOBT_C, SECURITY_POLICY, STATUS, SU22_USOBT, SU22_USOBX, SUSR_PROF, SU_USOBX_C, USER_CUA` |
387
+
| **collect-audit-logs** | Determines whether Audit Log data is ingested or not. | **true**: Ingested<br>**false**: Not ingested | **true** |
388
+
| **collect-changedocs-logs** | Determines whether Change Docs logs are ingested or not. | **true**: Ingested<br>**false**: Not ingested | **true** |
389
+
| **collect-user-master-data** | Determines whether User Master data is ingested or not. | **true**: Ingested<br>**false**: Not ingested | **true** |
390
+
| **force-audit-log-to-read-from-all-clients** | Determines whether the Audit Log is read from all clients. | **true**: Read from all clients<br>**false**: Not read from all clients | **false** |
391
+
| **ingestion-cycle-days** | Time, in days, given to ingest the full User Master data, including all roles and users. This parameter doesn't affect the ingestion of changes to User Master data. | Integer, between **1**-**14** | **1** |
392
+
| **offset-in-seconds** | Determines the offset, in seconds, for both the start and end times of a data collection window. Use this parameter to delay data collection by the configured number of seconds. | Integer, between **1**-**600** | **60** |
0 commit comments