You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/sentinel/sap/collect-sap-hana-audit-logs.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -23,7 +23,7 @@ Content in this article is intended for your **security**, **infrastructure**, a
23
23
> Microsoft Sentinel SAP HANA support is currently in PREVIEW. The [Azure Preview Supplemental Terms](https://azure.microsoft.com/support/legal/preview-supplemental-terms/) include additional legal terms that apply to Azure features that are in beta, preview, or otherwise not yet released into general availability.
24
24
25
25
> [!NOTE]
26
-
> This article is relevant only for the data connector agent, and isn't relevant for the [SAP agentless solution](deployment-overview.md#data-connector) (Preview).
26
+
> This article is relevant only for the data connector agent, and isn't relevant for the [SAP agentless data connector](deployment-overview.md#data-connector) (Preview).
Copy file name to clipboardExpand all lines: articles/sentinel/sap/deploy-command-line.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -21,7 +21,7 @@ However, if you're using a configuration file to store your credentials instead
21
21
While you can run multiple data connector agents on a single machine, we recommend that you start with one only, monitor the performance, and then increase the number of connectors slowly. We also recommend that your **security** team perform this procedure with help from the **SAP BASIS** team.
22
22
23
23
> [!NOTE]
24
-
> This article is relevant only for the data connector agent, and isn't relevant for the [SAP agentless solution](deployment-overview.md#data-connector) (Preview).
24
+
> This article is relevant only for the data connector agent, and isn't relevant for the [SAP agentless data connector](deployment-overview.md#data-connector) (Preview).
Copy file name to clipboardExpand all lines: articles/sentinel/sap/deployment-attack-disrupt.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -26,7 +26,7 @@ For a video demonstration of attack disruption for SAP, watch the following vide
26
26
Content in this article is intended for your **security**, **infrastructure**, and **SAP BASIS** teams.
27
27
28
28
> [!NOTE]
29
-
> Attack disruption requires a data connector agent and isn't supported for the [SAP agentless solution](deployment-overview.md#data-connector) (Preview).
29
+
> Attack disruption requires a data connector agent and isn't supported for the [SAP agentless data connector](deployment-overview.md#data-connector) (Preview).
30
30
31
31
## Attack disruption for SAP in Microsoft's unified security operations platform
Copy file name to clipboardExpand all lines: articles/sentinel/sap/deployment-overview.md
+6-7Lines changed: 6 additions & 7 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -38,9 +38,9 @@ The Microsoft Sentinel agentless data connector for SAP uses the SAP Cloud Conne
38
38
39
39
:::image type="content" source="media/deployment-overview/agentless-connector.png" alt-text="Diagram that shows the Microsoft Sentinel agentless data connector in an SAP environment." border="false" lightbox="media/deployment-overview/agentless-connector.png":::
40
40
41
-
By using the SAP Cloud Connector, the **Agentless solution** profits from already existing setups and established integration processes. This means you don't have to tackle network challenges again, as the people running your SAP Cloud Connector have already gone through that process.
41
+
By using the SAP Cloud Connector, the agentless data connector profits from already existing setups and established integration processes. This means you don't have to tackle network challenges again, as the people running your SAP Cloud Connector have already gone through that process.
42
42
43
-
The **Agentless solution** is compatible with SAP S/4HANA Cloud, Private Edition RISE with SAP, SAP S/4HANA on-premises, and SAP ERP Central Component (ECC), ensuring continued functionality of existing security content, including detections, workbooks, and playbooks.
43
+
The agentless data connector is compatible with SAP S/4HANA Cloud, Private Edition RISE with SAP, SAP S/4HANA on-premises, and SAP ERP Central Component (ECC), ensuring continued functionality of existing security content, including detections, workbooks, and playbooks.
44
44
45
45
The agentless data connector ingests critical security logs such as the security audit log, change docs logs and user master data including user roles and authorizations.
46
46
@@ -76,29 +76,28 @@ For more information, see [Microsoft Sentinel solution for SAP applications: sec
76
76
77
77
## Deployment flow and personas
78
78
79
-
Deploying the Microsoft Sentinel solutions for SAP applications involves several steps and requires collaboration across multiple teams, differing depending on whether you're using a data connector agent or the agentless solution. Select one of the following tabs to learn more:
79
+
Deploying the Microsoft Sentinel solutions for SAP applications involves several steps and requires collaboration across multiple teams, differing depending on whether you're using the agentless data connector or a data connector agent. Select one of the following tabs to learn more:
80
80
81
81
### [Agentless data connector (Preview)](#tab/agentless)
82
82
83
83
Deploying the Microsoft Sentinel solutions for SAP applications involves several steps and requires collaboration across your **security** and **SAP BASIS** teams. The following image shows the steps in deploying the Microsoft Sentinel solutions for SAP applications, with relevant teams indicated:
84
84
85
-
:::image type="content" source="media/deployment-steps/full-flow-agentless.png" alt-text="Diagram showing the full steps in the Microsoft Sentinel agentless solution for SAP applications deployment flow." border="false":::
85
+
:::image type="content" source="media/deployment-steps/full-flow-agentless.png" alt-text="Diagram showing the full steps in the deployment flow for the Microsoft Sentinel agentless data connector for SAP applications." border="false":::
86
86
87
87
We recommend that you involve both teams when planning your deployment to ensure that effort is allocated and the deployment can move smoothly.
88
88
89
89
**Deployment steps include**:
90
90
91
-
1.[Review the prerequisites for deploying the SAP agentless solution](prerequisites-for-deploying-sap-continuous-threat-monitoring.md).
91
+
1.[Review the prerequisites for deploying the SAP agentless data connector](prerequisites-for-deploying-sap-continuous-threat-monitoring.md).
92
92
93
-
1.[Deploy the SAP agentless solution from the content hub](deploy-sap-security-content.md). This step is handled by the security team on the Azure portal.
93
+
1.[Deploy the SAP applications solution from the content hub](deploy-sap-security-content.md). This step is handled by the security team on the Azure portal.
94
94
95
95
1.[Configure your SAP system for the Microsoft Sentinel solution](preparing-sap.md), including configuring SAP authorizations, configuring SAP auditing, and more. We recommend that these steps be done by your SAP BASIS team, and our documentation includes references to SAP documentation. Some of the procedures in this step can be done by the SAP BASIS team before installing the solution.
96
96
97
97
1.[Connect your SAP system](deploy-data-connector-agent-container.md) using an agentless data connector with the SAP Cloud Connector. This step is handled by your security team on the Azure portal, using information provided by your SAP BASIS team.
98
98
99
99
1.[Enable SAP detections and threat protection](deployment-solution-configuration.md). This step is handled by the security team on the Azure portal.
100
100
101
-
102
101
### [Containerized data connector agent](#tab/agent)
103
102
104
103
Deploying the Microsoft Sentinel solutions for SAP applications involves several steps and requires collaboration across multiple teams, including the **security**, **infrastructure**, and **SAP BASIS** teams. The following image shows the steps in deploying the Microsoft Sentinel solutions for SAP applications, with relevant teams indicated:
Copy file name to clipboardExpand all lines: articles/sentinel/sap/preparing-sap.md
+3-3Lines changed: 3 additions & 3 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -42,7 +42,7 @@ Many of the procedures in this article are typically performed by your **SAP BAS
42
42
43
43
- Before you start, make sure to review the [prerequisites for deploying the Microsoft Sentinel solution for SAP applications](prerequisites-for-deploying-sap-continuous-threat-monitoring.md).
44
44
:::zone pivot="connection-agentless"
45
-
- If you're working with the agentless solution, some steps are performed in Microsoft Sentinel and require that the [solution be installed first](deploy-sap-security-content.md).
45
+
- If you're working with the agentless data connector, some steps are performed in Microsoft Sentinel and require that the [solution be installed first](deploy-sap-security-content.md).
46
46
47
47
:::zone-end
48
48
@@ -100,7 +100,7 @@ Some installations of SAP systems might not have audit logging enabled by defaul
100
100
We recommend that you configure auditing for *all* messages from the audit log, instead of only specific logs. Ingestion cost differences are generally minimal and the data is useful for Microsoft Sentinel detections and in post-compromise investigations and hunting.
101
101
102
102
:::zone pivot="connection-agentless"
103
-
For full monitoring coverage with the agentless solution, we recommend that you enable monitoring on all client IDs of your monitored SAP systems, including clients 000 and 066.
103
+
For full monitoring coverage with the agentless data connector, we recommend that you enable monitoring on all client IDs of your monitored SAP systems, including clients 000 and 066.
104
104
:::zone-end
105
105
106
106
For more information, see the [SAP community](https://community.sap.com/t5/application-development-blog-posts/analysis-and-recommended-settings-of-the-security-audit-log-sm19-rsau/ba-p/13297094) and [Collect SAP HANA audit logs in Microsoft Sentinel](collect-sap-hana-audit-logs.md).
@@ -116,7 +116,7 @@ In a production environment, we strongly recommend that your consult with SAP ad
116
116
When configuring SNC:
117
117
118
118
- If the client certificate was issued by an enterprise certification authority, transfer the issuing CA and root CA certificates to the system where you plan to create the data connector agent.
119
-
- If you're using the data connector agent, make sure to also enter the relevant values and use the relevant procedures when [configuring the SAP data connector agent container](deploy-data-connector-agent-container.md). If you're using the agentless solution, the SNC configuration is done in the SAP Cloud Connector.
119
+
- If you're using the data connector agent, make sure to also enter the relevant values and use the relevant procedures when [configuring the SAP data connector agent container](deploy-data-connector-agent-container.md). If you're using the agentless data connector, the SNC configuration is done in the SAP Cloud Connector.
120
120
121
121
122
122
For more information about SNC, see [Getting started with SAP SNC for RFC integrations - SAP blog](https://community.sap.com/t5/enterprise-resource-planning-blogs-by-members/getting-started-with-sap-snc-for-rfc-integrations/ba-p/13983462).
# Deployment prerequisites for the Microsoft Sentinel solutions for SAP applications
19
19
20
-
This article lists the prerequisites required for deployment of the Microsoft Sentinel solution for SAP applications, which differ depending on whether you're deploying a data connector agent or using the agentless solution with the SAP Cloud Connector. Select the option at the top of this page that matches your deployment.
20
+
This article lists the prerequisites required for deployment of the Microsoft Sentinel solution for SAP applications, which differ depending on whether you're deploying a data connector agent or using the agentless data connector with the SAP Cloud Connector. Select the option at the top of this page that matches your deployment.
21
21
22
22
Reviewing and ensuring that you have or understand all the prerequisites is the first step in deploying the Microsoft Sentinel solution for SAP applications. Select a connection type to list the prerequisites for your environment.
Copy file name to clipboardExpand all lines: articles/sentinel/sap/sap-deploy-troubleshoot.md
+2-2Lines changed: 2 additions & 2 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -21,15 +21,15 @@ This article includes troubleshooting steps to help you ensure accurate and time
21
21
22
22
:::zone pivot="connection-agentless"
23
23
24
-
When working with the agentless solution, most troubleshooting is done directly in the SAP Integration Suite, where the message log displays errors indicating the nature of the issue encountered.
24
+
When working with the agentless data connector, most troubleshooting is done directly in the SAP Integration Suite, where the message log displays errors indicating the nature of the issue encountered.
25
25
26
26
Starting my examining the message processing logs. For more information, see the [SAP documentation](https://help.sap.com/docs/cloud-integration/sap-cloud-integration/monitor-message-processing-monitor). The error messages there can help you diagnose issues with missing permissions, connectivity errors, and other misconfigurations.
27
27
28
28
If you don't see a related error to your issue, turn on trace logging for more in-depth troubleshooting. For more information, see the [SAP documentation](https://help.sap.com/docs/cloud-integration/sap-cloud-integration/setting-log-levels).
29
29
30
30
## Check for prerequisites
31
31
32
-
The agentless solution package, deployed while [performing the initial connector configuration](preparing-sap.md#perform-initial-connector-configuration), includes a tool to help SAP admins diagnose and fix issues related to the SAP environment configuration.
32
+
The agentless data connector package, deployed while [performing the initial connector configuration](preparing-sap.md#perform-initial-connector-configuration), includes a tool to help SAP admins diagnose and fix issues related to the SAP environment configuration.
Copy file name to clipboardExpand all lines: articles/sentinel/sap/sap-solution-deploy-alternate.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -21,7 +21,7 @@ This article provides procedures for deploying and configuring the Microsoft Sen
21
21
Content in this article is intended for your **SAP BASIS** teams. For more information, see [Deploy an SAP data connector agent from the command line](deploy-command-line.md).
22
22
23
23
> [!NOTE]
24
-
> This article is relevant only for the data connector agent, and isn't relevant for the [SAP agentless solution](deployment-overview.md#data-connector) (Preview).
24
+
> This article is relevant only for the data connector agent, and isn't relevant for the [SAP agentless data connector](deployment-overview.md#data-connector) (Preview).
Copy file name to clipboardExpand all lines: articles/sentinel/sap/sap-solution-function-reference.md
+7-7Lines changed: 7 additions & 7 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -33,37 +33,37 @@ These functions are intended to serve as the principal user interface to the dat
33
33
34
34
The **BAPI_XMI_LOGON** function is relevant when your SAP system is an older system using XAL, and authenticates to collect SAP XAL audit logs.
35
35
36
-
The **BAPI_XMI_LOGON** function is available only with the SAP agentless solution. For more information, see [Install a Microsoft Sentinel solution for SAP applications](deploy-sap-security-content.md?pivots=connection-agentless).
36
+
The **BAPI_XMI_LOGON** function is supported only for the SAP agentless data connector. For more information, see [Install a Microsoft Sentinel solution for SAP applications](deploy-sap-security-content.md?pivots=connection-agentless).
37
37
38
38
## BAPI_SYSTEM_MTE_GETTIDBYNAME (Preview)
39
39
40
40
The **BAPI_SYSTEM_MTE_GETTIDBYNAME** function is relevant when your SAP system is an older system using XAL, and retrieves the ID of a system monitoring element by name.
41
41
42
-
The **BAPI_SYSTEM_MTE_GETTIDBYNAME** function is available only with the SAP agentless solution. For more information, see [Install a Microsoft Sentinel solution for SAP applications](deploy-sap-security-content.md?pivots=connection-agentless).
42
+
The **BAPI_SYSTEM_MTE_GETTIDBYNAME** function is supported only for the SAP agentless data connector. For more information, see [Install a Microsoft Sentinel solution for SAP applications](deploy-sap-security-content.md?pivots=connection-agentless).
43
43
44
44
## BAPI_SYSTEM_MTE_GETTREE (Preview)
45
45
46
46
The **BAPI_SYSTEM_MTE_GETTREE** function is relevant when your SAP system is an older system using XAL, and retrieves the structure of system monitoring elements.
47
47
48
-
The **BAPI_SYSTEM_MTE_GETTREE** function is available only with the SAP agentless solution. For more information, see [Install a Microsoft Sentinel solution for SAP applications](deploy-sap-security-content.md?pivots=connection-agentless).
48
+
The **BAPI_SYSTEM_MTE_GETTREE** function is supported only for the SAP agentless data connector. For more information, see [Install a Microsoft Sentinel solution for SAP applications](deploy-sap-security-content.md?pivots=connection-agentless).
49
49
50
50
## BAPI_SYSTEM_MTE_GETMLHIS (Preview)
51
51
52
52
The **BAPI_SYSTEM_MTE_GETMLHIS** function is relevant when your SAP system is an older system using XAL, and fetches historical performance and status data.
53
53
54
-
The **BAPI_SYSTEM_MTE_GETMLHIS** function is available only with the SAP agentless solution. For more information, see [Install a Microsoft Sentinel solution for SAP applications](deploy-sap-security-content.md?pivots=connection-agentless).
54
+
The **BAPI_SYSTEM_MTE_GETMLHIS** function is supported only for the SAP agentless data connector. For more information, see [Install a Microsoft Sentinel solution for SAP applications](deploy-sap-security-content.md?pivots=connection-agentless).
55
55
56
56
## BAPI_XMI_SET_AUDITLEVEL (Preview)
57
57
58
58
The **BAPI_XMI_SET_AUDITLEVEL** function is relevant when your SAP system is an older system using XAL, and configures the XAL audit logging level.
59
59
60
-
The **BAPI_XMI_SET_AUDITLEVEL** function is available only with the SAP agentless solution. For more information, see [Install a Microsoft Sentinel solution for SAP applications](deploy-sap-security-content.md?pivots=connection-agentless).
60
+
The **BAPI_XMI_SET_AUDITLEVEL** function is supported only for the SAP agentless data connector. For more information, see [Install a Microsoft Sentinel solution for SAP applications](deploy-sap-security-content.md?pivots=connection-agentless).
61
61
62
62
## BAPI_XMI_GET_LOGHISTORY (Preview)
63
63
64
64
The **BAPI_XMI_GET_LOGHISTORY** function is relevant when your SAP system is an older system using XAL, and retrieves past XAL audit log entries.
65
65
66
-
The **BAPI_XMI_GET_LOGHISTORY** function is available only with the SAP agentless solution. For more information, see [Install a Microsoft Sentinel solution for SAP applications](deploy-sap-security-content.md?pivots=connection-agentless).
66
+
The **BAPI_XMI_GET_LOGHISTORY** function is supported only for the SAP agentless data connector. For more information, see [Install a Microsoft Sentinel solution for SAP applications](deploy-sap-security-content.md?pivots=connection-agentless).
67
67
68
68
## SAPUsersAssignments
69
69
@@ -432,7 +432,7 @@ The **SAPUsersHeader** function returns the following output:
432
432
433
433
The **TH_SERVER_LIST** function function is relevant when your SAP system is an older system using XAL, and lists active SAP application servers.
434
434
435
-
The **TH_SERVER_LIST** function is available only with the SAP agentless solution. For more information, see [Install a Microsoft Sentinel solution for SAP applications](deploy-sap-security-content.md?pivots=connection-agentless).
435
+
The **TH_SERVER_LIST** function is supported only with the SAP agentless data connector. For more information, see [Install a Microsoft Sentinel solution for SAP applications](deploy-sap-security-content.md?pivots=connection-agentless).
0 commit comments