Skip to content

Commit 7ea0764

Browse files
authored
Merge pull request #291092 from batamig/sap-agentless-ii
SAP agentless
2 parents e28e504 + 88aa850 commit 7ea0764

33 files changed

+544
-117
lines changed

articles/sentinel/TOC.yml

Lines changed: 6 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -154,13 +154,13 @@
154154
- name: Connect your SAP system
155155
displayName: disable, stop ingestion, stop
156156
href: sap/deploy-data-connector-agent-container.md
157-
- name: Troubleshoot SAP solution deployment
157+
- name: Troubleshoot SAP data connector agent
158158
href: sap/sap-deploy-troubleshoot.md
159159
- name: Extra deployment steps
160160
items:
161161
- name: Collect SAP HANA audit logs
162162
href: sap/collect-sap-hana-audit-logs.md
163-
- name: Update the connector
163+
- name: Update the data connector agent
164164
href: sap/update-sap-data-connector.md
165165
- name: Deploy from the command line
166166
href: sap/deploy-command-line.md
@@ -170,13 +170,13 @@
170170
items:
171171
- name: Required ABAP permissions
172172
href: sap/required-abap-authorizations.md
173-
- name: Kickstart script reference
173+
- name: Data connector agent kickstart script reference
174174
href: sap/reference-kickstart.md
175-
- name: Container update script reference
175+
- name: Data connector agent update script reference
176176
href: sap/reference-update.md
177-
- name: Systemconfig.json file reference
177+
- name: Data connector agent systemconfig.json file reference
178178
href: sap/reference-systemconfig-json.md
179-
- name: Systemconfig.ini file reference (legacy)
179+
- name: Data connector agent systemconfig.ini file reference (legacy)
180180
href: sap/reference-systemconfig.md
181181
- name: Enable SAP detections and threat protection
182182
href: sap/deployment-solution-configuration.md

articles/sentinel/feature-availability.md

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,7 @@ ms.author: bagol
66
ms.topic: feature-availability
77
ms.custom: references_regions
88
ms.service: microsoft-sentinel
9-
ms.date: 11/07/2024
9+
ms.date: 11/26/2024
1010

1111

1212
#Customer intent: As a security operations manager, I want to understand the Microsoft Sentinel's feature availability across different Azure environments so that I can effectively plan and manage our security operations.
@@ -160,6 +160,7 @@ For more information, see [Microsoft Defender XDR for US Government customers](/
160160
|Feature |Feature stage |Azure commercial |Azure Government |Azure China 21Vianet |
161161
|---------|---------|---------|---------|---------|
162162
|[Threat protection for SAP](sap/deployment-overview.md)</sup> |GA |&#x2705;|&#x2705; |&#x2705; |
163+
|[Agentless data connector](sap/deployment-overview.md#data-connector) | Limited preview | &#x2705; |&#10060; | &#10060;|
163164

164165
## Threat intelligence support
165166

articles/sentinel/monitor-sap-system-health.md

Lines changed: 38 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -4,32 +4,48 @@ description: Use the SAP connector page and a dedicated alert rule template to k
44
author: batamig
55
ms.author: bagol
66
ms.topic: how-to
7-
ms.date: 09/16/2024
7+
ms.date: 12/10/2024
88
ms.service: microsoft-sentinel
9+
zone_pivot_groups: sentinel-sap-connection
10+
#customerIntent: As a security engineer, I want to learn how to monitor the health and connectivity of our SAP system connection to Microsoft Sentinel.
11+
912
---
1013

1114
# Monitor the health and role of your SAP systems
1215

1316
After you [deploy the SAP solution](sap/deployment-overview.md), you want to ensure proper functioning and performance of your SAP systems, and keep track of your system health, connectivity, and performance. This article describes how you can check the connectivity health manually on the data connector page and use a dedicated alert rule template to monitor the health of your SAP systems.
1417

18+
:::zone pivot="connection-agent"
1519
> [!IMPORTANT]
1620
> Monitoring the health of your SAP systems is currently in PREVIEW. The [Azure Preview Supplemental Terms](https://azure.microsoft.com/support/legal/preview-supplemental-terms/) include additional legal terms that apply to Azure features that are in beta, preview, or otherwise not yet released into general availability.
1721
1822
For a video demonstration of the procedures in this article, watch the following video:
1923
<br><br>
2024
> [!VIDEO https://www.youtube.com/embed/FasuyBSIaQM?si=apdesRR29Lvq6aQM]
2125
26+
:::zone-end
27+
28+
:::zone pivot="connection-agentless"
29+
30+
> [!IMPORTANT]
31+
> Monitoring the health of your SAP systems is currently in PREVIEW. The [Azure Preview Supplemental Terms](https://azure.microsoft.com/support/legal/preview-supplemental-terms/) include additional legal terms that apply to Azure features that are in beta, preview, or otherwise not yet released into general availability.
32+
>
33+
> Microsoft Sentinel's **Agentless solution** is in limited preview as a prereleased product, which may be substantially modified before it’s commercially released. Microsoft makes no warranties expressed or implied, with respect to the information provided here. Access to the **Agentless solution** also [requires registration](https://aka.ms/SentinelSAPAgentlessSignUp) and is only available to approved customers and partners during the preview period. For more information, see [Microsoft Sentinel for SAP goes agentless ](https://community.sap.com/t5/enterprise-resource-planning-blogs-by-members/microsoft-sentinel-for-sap-goes-agentless/ba-p/13960238).
34+
35+
:::zone-end
36+
2237
## Prerequisites
2338

24-
- Before you can perform the procedures in this article, you need to have a SAP data connector agent deployed and connected to your SAP system. SAP logs aren't displayed in the Microsoft Sentinel **Logs** page until your SAP system is connected and data starts streaming into Microsoft Sentinel.
39+
- Before you can perform the procedures in this article, you need to have an SAP data connector connected to your SAP system. SAP logs aren't displayed in the Microsoft Sentinel **Logs** page until your SAP system is connected and data starts streaming into Microsoft Sentinel.
40+
41+
For more information, see [Connect your SAP system to Microsoft Sentinel](sap/deploy-data-connector-agent-container.md).
2542

26-
For more information, see [Deploy and configure the container hosting the SAP data connector agent](sap/deploy-data-connector-agent-container.md).
43+
:::zone pivot="connection-agent"
2744

2845
## Check your data connector's health and connectivity
2946

3047
This procedure describes how to check your data connector's connection status from the **Microsoft Sentinel for SAP** data connector page.
3148

32-
3349
1. In Microsoft Sentinel, select **Data connectors** and search for *Microsoft Sentinel for SAP*.
3450

3551
1. Select the **Microsoft Sentinel for SAP** connector and select **Open connector page**.
@@ -42,7 +58,7 @@ This procedure describes how to check your data connector's connection status fr
4258

4359
The fields in the **Configure an SAP system and assign it to a collector agent** area are described as follows:
4460

45-
- **System display name**. The SAP system ID (SID) and its client number. Together, this value qualifies the connection to the SAP system and defines for SAP BASIS which system you're connecting to.
61+
- **System display name**. The SAP system ID (SID) and its client number. Together, this value qualifies the connection to the SAP system and defines for SAP BASIS which system you're connecting to.
4662

4763
- **System role**. Indicates whether the system is production state or not, which also affects billing. For more information, see [Solution pricing](sap/solution-overview.md#solution-pricing). Values include:
4864

@@ -64,6 +80,8 @@ This procedure describes how to check your data connector's connection status fr
6480
| **System not connected** | Microsoft Sentinel was unable to connect to the SAP system, and cannot fetch the system role. In this case, Microsoft Sentinel doesn't have the details of whether the system is or isn't a production system. |
6581
| Other statuses that reflect more details about connectivity issues | For example, **System unreachable for over 1 day**. |
6682

83+
:::zone-end
84+
6785
## View SAP logs streaming into Microsoft Sentinel
6886

6987
In Microsoft Sentinel, select **General** > **Logs > Custom logs** to view the logs streaming in from the SAP system. For example:
@@ -72,6 +90,17 @@ In Microsoft Sentinel, select **General** > **Logs > Custom logs** to view the l
7290

7391
For more information, see [Microsoft Sentinel solution for SAP applications solution logs reference](sap-solution-log-reference.md).
7492

93+
## Check the SentinelHealth table for health indicators
94+
95+
The **SentinelHealth** table in Microsoft Sentinel contains health indicators for the SAP data connector, among others. You can query this table to get a summary of the health of your SAP systems.
96+
97+
For more information, see:
98+
99+
- [Auditing and health monitoring in Microsoft Sentinel](health-audit.md)
100+
- [Turn on auditing and health monitoring for Microsoft Sentinel (preview)](enable-monitoring.md)
101+
- [Monitor the health of your data connectors](monitor-data-connector-health.md)
102+
- [Microsoft Sentinel health tables reference](health-table-reference.md)
103+
75104
## Use an alert rule template to monitor the health of your SAP systems
76105

77106
The Microsoft Sentinel for SAP solution includes an alert rule template designed to give you insight into the health of your SAP agent's data collection.
@@ -93,7 +122,8 @@ The following screenshot shows an example of an alert generated by the *SAP - Da
93122

94123
:::image type="content" source="media/monitor-sap-system-health/alert-rule-example.png" alt-text="Screenshot of an alert triggered by the SAP - Data collection health check alert rule.":::
95124

96-
## Next steps
97-
- Learn about the [Microsoft Sentinel Solution for SAP](sap/solution-overview.md).
125+
## Related content
126+
127+
- Learn about the [Microsoft Sentinel Solution for SAP](sap/solution-overview.md)
98128
- Learn how to [deploy the Microsoft Sentinel Solution for SAP](sap/deployment-overview.md)
99-
- Learn about [auditing and health monitoring](health-audit.md) in other areas of Microsoft Sentinel.
129+
- Learn about [auditing and health monitoring](health-audit.md) in other areas of Microsoft Sentinel

articles/sentinel/sap/collect-sap-hana-audit-logs.md

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -22,6 +22,10 @@ Content in this article is intended for your **security**, **infrastructure**, a
2222
> [!IMPORTANT]
2323
> Microsoft Sentinel SAP HANA support is currently in PREVIEW. The [Azure Preview Supplemental Terms](https://azure.microsoft.com/support/legal/preview-supplemental-terms/) include additional legal terms that apply to Azure features that are in beta, preview, or otherwise not yet released into general availability.
2424
25+
> [!NOTE]
26+
> This article is relevant only for the data connector agent, and isn't relevant for the [SAP agentless solution](deployment-overview.md#data-connector) (limited preview).
27+
>
28+
2529
## Prerequisites
2630

2731
SAP HANA logs are sent over Syslog. Make sure that your Azure Monitor Agent is configured to collect Syslog files. For more information, see [Ingest syslog and CEF messages to Microsoft Sentinel with the Azure Monitor Agent](../connect-cef-syslog-ama.md).

articles/sentinel/sap/cross-workspace.md

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -16,6 +16,7 @@ ms.collection: usx-security
1616

1717
# Integrate SAP across multiple workspaces
1818

19+
1920
When you set up your Log Analytics workspace enabled for Microsoft Sentinel, you have [multiple architecture options](/azure/azure-monitor/logs/workspace-design?toc=/azure/sentinel/TOC.json&bc=/azure/sentinel/breadcrumb/toc.json) and factors to consider. Taking into account geography, regulation, access control, and other factors, you might choose to have multiple workspaces in your organization.
2021

2122
When working with SAP, your SAP and SOC teams might need to work in separate workspaces to maintain security boundaries. You might not want the SAP team to have visibility into all other security logs across your organization. However, the SAP BASIS team plays a critical role in successfully implementing and maintaining the Microsoft Sentinel solution for SAP applications. Their technical knowledge is essential for effectively monitoring SAP systems, configuring security settings, and ensuring that proper incident response procedures are in place. For this reason, the SAP BASIS team must have access to the Log Analytics workspace enabled for Microsoft Sentinel, allowing them to collaborate with the SOC team while focusing specifically on SAP-related security monitoring.
@@ -30,6 +31,9 @@ This article discusses how to work with the Microsoft Sentinel solution for SAP
3031
> [!IMPORTANT]
3132
> Working with multiple workspaces is currently in preview. This feature is provided without a service-level agreement. For more information, see [Supplemental Terms of Use for Microsoft Azure Previews](https://azure.microsoft.com/support/legal/preview-supplemental-terms/).
3233
34+
> [!NOTE]
35+
> Multi-workspace support is available only with the data connector agent, and isn't supported with the [SAP agentless solution](deployment-overview.md#data-connector) (limited preview).
36+
3337
## SAP and SOC data maintained in separate workspaces
3438

3539
If your SAP and SOC teams have separate Log Analytics workspaces enabled for Microsoft Sentinel where team data is kept, we recommend that you provide some or all SOC team members with the **Sentinel Reader** role for the SAP BASIS team's workspace. This enables both teams to see SAP data by using cross-workspace queries.

articles/sentinel/sap/deploy-command-line.md

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -18,7 +18,11 @@ This article provides command line options for deploying an SAP data connector a
1818

1919
However, if you're using a configuration file to store your credentials instead of Azure Key Vault, or if you're an advanced user who wants to deploy the data connector manually, such as in a Kubernetes cluster, use the procedures in this article instead.
2020

21-
While you can run multiple data connector agents on a single machine, we recommend that you start with one only, monitor the performance, and then increase the number of connectors slowly. We also recommend that your **security** team perform this procedure with help from the **SAP BASIS** team.
21+
While you can run multiple data connector agents on a single machine, we recommend that you start with one only, monitor the performance, and then increase the number of connectors slowly. We also recommend that your **security** team perform this procedure with help from the **SAP BASIS** team.
22+
23+
> [!NOTE]
24+
> This article is relevant only for the data connector agent, and isn't relevant for the [SAP agentless solution](deployment-overview.md#data-connector) (limited preview).
25+
>
2226
2327
## Prerequisites
2428

0 commit comments

Comments
 (0)