You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/sentinel/feature-availability.md
+2-1Lines changed: 2 additions & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -6,7 +6,7 @@ ms.author: bagol
6
6
ms.topic: feature-availability
7
7
ms.custom: references_regions
8
8
ms.service: microsoft-sentinel
9
-
ms.date: 11/07/2024
9
+
ms.date: 11/26/2024
10
10
11
11
12
12
#Customer intent: As a security operations manager, I want to understand the Microsoft Sentinel's feature availability across different Azure environments so that I can effectively plan and manage our security operations.
@@ -160,6 +160,7 @@ For more information, see [Microsoft Defender XDR for US Government customers](/
160
160
|Feature |Feature stage |Azure commercial |Azure Government |Azure China 21Vianet |
Copy file name to clipboardExpand all lines: articles/sentinel/monitor-sap-system-health.md
+38-8Lines changed: 38 additions & 8 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -4,32 +4,48 @@ description: Use the SAP connector page and a dedicated alert rule template to k
4
4
author: batamig
5
5
ms.author: bagol
6
6
ms.topic: how-to
7
-
ms.date: 09/16/2024
7
+
ms.date: 12/10/2024
8
8
ms.service: microsoft-sentinel
9
+
zone_pivot_groups: sentinel-sap-connection
10
+
#customerIntent: As a security engineer, I want to learn how to monitor the health and connectivity of our SAP system connection to Microsoft Sentinel.
11
+
9
12
---
10
13
11
14
# Monitor the health and role of your SAP systems
12
15
13
16
After you [deploy the SAP solution](sap/deployment-overview.md), you want to ensure proper functioning and performance of your SAP systems, and keep track of your system health, connectivity, and performance. This article describes how you can check the connectivity health manually on the data connector page and use a dedicated alert rule template to monitor the health of your SAP systems.
14
17
18
+
:::zone pivot="connection-agent"
15
19
> [!IMPORTANT]
16
20
> Monitoring the health of your SAP systems is currently in PREVIEW. The [Azure Preview Supplemental Terms](https://azure.microsoft.com/support/legal/preview-supplemental-terms/) include additional legal terms that apply to Azure features that are in beta, preview, or otherwise not yet released into general availability.
17
21
18
22
For a video demonstration of the procedures in this article, watch the following video:
> Monitoring the health of your SAP systems is currently in PREVIEW. The [Azure Preview Supplemental Terms](https://azure.microsoft.com/support/legal/preview-supplemental-terms/) include additional legal terms that apply to Azure features that are in beta, preview, or otherwise not yet released into general availability.
32
+
>
33
+
> Microsoft Sentinel's **Agentless solution** is in limited preview as a prereleased product, which may be substantially modified before it’s commercially released. Microsoft makes no warranties expressed or implied, with respect to the information provided here. Access to the **Agentless solution** also [requires registration](https://aka.ms/SentinelSAPAgentlessSignUp) and is only available to approved customers and partners during the preview period. For more information, see [Microsoft Sentinel for SAP goes agentless ](https://community.sap.com/t5/enterprise-resource-planning-blogs-by-members/microsoft-sentinel-for-sap-goes-agentless/ba-p/13960238).
34
+
35
+
:::zone-end
36
+
22
37
## Prerequisites
23
38
24
-
- Before you can perform the procedures in this article, you need to have a SAP data connector agent deployed and connected to your SAP system. SAP logs aren't displayed in the Microsoft Sentinel **Logs** page until your SAP system is connected and data starts streaming into Microsoft Sentinel.
39
+
- Before you can perform the procedures in this article, you need to have an SAP data connector connected to your SAP system. SAP logs aren't displayed in the Microsoft Sentinel **Logs** page until your SAP system is connected and data starts streaming into Microsoft Sentinel.
40
+
41
+
For more information, see [Connect your SAP system to Microsoft Sentinel](sap/deploy-data-connector-agent-container.md).
25
42
26
-
For more information, see [Deploy and configure the container hosting the SAP data connector agent](sap/deploy-data-connector-agent-container.md).
43
+
:::zone pivot="connection-agent"
27
44
28
45
## Check your data connector's health and connectivity
29
46
30
47
This procedure describes how to check your data connector's connection status from the **Microsoft Sentinel for SAP** data connector page.
31
48
32
-
33
49
1. In Microsoft Sentinel, select **Data connectors** and search for *Microsoft Sentinel for SAP*.
34
50
35
51
1. Select the **Microsoft Sentinel for SAP** connector and select **Open connector page**.
@@ -42,7 +58,7 @@ This procedure describes how to check your data connector's connection status fr
42
58
43
59
The fields in the **Configure an SAP system and assign it to a collector agent** area are described as follows:
44
60
45
-
-**System display name**. The SAP system ID (SID) and its client number. Together, this value qualifies the connection to the SAP system and defines for SAP BASIS which system you're connecting to.
61
+
-**System display name**. The SAP system ID (SID) and its client number. Together, this value qualifies the connection to the SAP system and defines for SAP BASIS which system you're connecting to.
46
62
47
63
-**System role**. Indicates whether the system is production state or not, which also affects billing. For more information, see [Solution pricing](sap/solution-overview.md#solution-pricing). Values include:
48
64
@@ -64,6 +80,8 @@ This procedure describes how to check your data connector's connection status fr
64
80
|**System not connected**| Microsoft Sentinel was unable to connect to the SAP system, and cannot fetch the system role. In this case, Microsoft Sentinel doesn't have the details of whether the system is or isn't a production system. |
65
81
| Other statuses that reflect more details about connectivity issues | For example, **System unreachable for over 1 day**. |
66
82
83
+
:::zone-end
84
+
67
85
## View SAP logs streaming into Microsoft Sentinel
68
86
69
87
In Microsoft Sentinel, select **General** > **Logs > Custom logs** to view the logs streaming in from the SAP system. For example:
@@ -72,6 +90,17 @@ In Microsoft Sentinel, select **General** > **Logs > Custom logs** to view the l
72
90
73
91
For more information, see [Microsoft Sentinel solution for SAP applications solution logs reference](sap-solution-log-reference.md).
74
92
93
+
## Check the SentinelHealth table for health indicators
94
+
95
+
The **SentinelHealth** table in Microsoft Sentinel contains health indicators for the SAP data connector, among others. You can query this table to get a summary of the health of your SAP systems.
96
+
97
+
For more information, see:
98
+
99
+
-[Auditing and health monitoring in Microsoft Sentinel](health-audit.md)
100
+
-[Turn on auditing and health monitoring for Microsoft Sentinel (preview)](enable-monitoring.md)
101
+
-[Monitor the health of your data connectors](monitor-data-connector-health.md)
102
+
-[Microsoft Sentinel health tables reference](health-table-reference.md)
103
+
75
104
## Use an alert rule template to monitor the health of your SAP systems
76
105
77
106
The Microsoft Sentinel for SAP solution includes an alert rule template designed to give you insight into the health of your SAP agent's data collection.
@@ -93,7 +122,8 @@ The following screenshot shows an example of an alert generated by the *SAP - Da
93
122
94
123
:::image type="content" source="media/monitor-sap-system-health/alert-rule-example.png" alt-text="Screenshot of an alert triggered by the SAP - Data collection health check alert rule.":::
95
124
96
-
## Next steps
97
-
- Learn about the [Microsoft Sentinel Solution for SAP](sap/solution-overview.md).
125
+
## Related content
126
+
127
+
- Learn about the [Microsoft Sentinel Solution for SAP](sap/solution-overview.md)
98
128
- Learn how to [deploy the Microsoft Sentinel Solution for SAP](sap/deployment-overview.md)
99
-
- Learn about [auditing and health monitoring](health-audit.md) in other areas of Microsoft Sentinel.
129
+
- Learn about [auditing and health monitoring](health-audit.md) in other areas of Microsoft Sentinel
Copy file name to clipboardExpand all lines: articles/sentinel/sap/collect-sap-hana-audit-logs.md
+4Lines changed: 4 additions & 0 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -22,6 +22,10 @@ Content in this article is intended for your **security**, **infrastructure**, a
22
22
> [!IMPORTANT]
23
23
> Microsoft Sentinel SAP HANA support is currently in PREVIEW. The [Azure Preview Supplemental Terms](https://azure.microsoft.com/support/legal/preview-supplemental-terms/) include additional legal terms that apply to Azure features that are in beta, preview, or otherwise not yet released into general availability.
24
24
25
+
> [!NOTE]
26
+
> This article is relevant only for the data connector agent, and isn't relevant for the [SAP agentless solution](deployment-overview.md#data-connector) (limited preview).
27
+
>
28
+
25
29
## Prerequisites
26
30
27
31
SAP HANA logs are sent over Syslog. Make sure that your Azure Monitor Agent is configured to collect Syslog files. For more information, see [Ingest syslog and CEF messages to Microsoft Sentinel with the Azure Monitor Agent](../connect-cef-syslog-ama.md).
Copy file name to clipboardExpand all lines: articles/sentinel/sap/cross-workspace.md
+4Lines changed: 4 additions & 0 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -16,6 +16,7 @@ ms.collection: usx-security
16
16
17
17
# Integrate SAP across multiple workspaces
18
18
19
+
19
20
When you set up your Log Analytics workspace enabled for Microsoft Sentinel, you have [multiple architecture options](/azure/azure-monitor/logs/workspace-design?toc=/azure/sentinel/TOC.json&bc=/azure/sentinel/breadcrumb/toc.json) and factors to consider. Taking into account geography, regulation, access control, and other factors, you might choose to have multiple workspaces in your organization.
20
21
21
22
When working with SAP, your SAP and SOC teams might need to work in separate workspaces to maintain security boundaries. You might not want the SAP team to have visibility into all other security logs across your organization. However, the SAP BASIS team plays a critical role in successfully implementing and maintaining the Microsoft Sentinel solution for SAP applications. Their technical knowledge is essential for effectively monitoring SAP systems, configuring security settings, and ensuring that proper incident response procedures are in place. For this reason, the SAP BASIS team must have access to the Log Analytics workspace enabled for Microsoft Sentinel, allowing them to collaborate with the SOC team while focusing specifically on SAP-related security monitoring.
@@ -30,6 +31,9 @@ This article discusses how to work with the Microsoft Sentinel solution for SAP
30
31
> [!IMPORTANT]
31
32
> Working with multiple workspaces is currently in preview. This feature is provided without a service-level agreement. For more information, see [Supplemental Terms of Use for Microsoft Azure Previews](https://azure.microsoft.com/support/legal/preview-supplemental-terms/).
32
33
34
+
> [!NOTE]
35
+
> Multi-workspace support is available only with the data connector agent, and isn't supported with the [SAP agentless solution](deployment-overview.md#data-connector) (limited preview).
36
+
33
37
## SAP and SOC data maintained in separate workspaces
34
38
35
39
If your SAP and SOC teams have separate Log Analytics workspaces enabled for Microsoft Sentinel where team data is kept, we recommend that you provide some or all SOC team members with the **Sentinel Reader** role for the SAP BASIS team's workspace. This enables both teams to see SAP data by using cross-workspace queries.
Copy file name to clipboardExpand all lines: articles/sentinel/sap/deploy-command-line.md
+5-1Lines changed: 5 additions & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -18,7 +18,11 @@ This article provides command line options for deploying an SAP data connector a
18
18
19
19
However, if you're using a configuration file to store your credentials instead of Azure Key Vault, or if you're an advanced user who wants to deploy the data connector manually, such as in a Kubernetes cluster, use the procedures in this article instead.
20
20
21
-
While you can run multiple data connector agents on a single machine, we recommend that you start with one only, monitor the performance, and then increase the number of connectors slowly. We also recommend that your **security** team perform this procedure with help from the **SAP BASIS** team.
21
+
While you can run multiple data connector agents on a single machine, we recommend that you start with one only, monitor the performance, and then increase the number of connectors slowly. We also recommend that your **security** team perform this procedure with help from the **SAP BASIS** team.
22
+
23
+
> [!NOTE]
24
+
> This article is relevant only for the data connector agent, and isn't relevant for the [SAP agentless solution](deployment-overview.md#data-connector) (limited preview).
0 commit comments