Skip to content

Commit 81b82f1

Browse files
authored
Merge pull request #179848 from batamig/sap-updates
sap experimental logs
2 parents 2f86b6c + 1f00bbe commit 81b82f1

File tree

1 file changed

+26
-10
lines changed

1 file changed

+26
-10
lines changed

articles/sentinel/sap-solution-log-reference.md

Lines changed: 26 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -12,18 +12,15 @@ ms.date: 11/09/2021
1212

1313
[!INCLUDE [Banner for top of topics](./includes/banner.md)]
1414

15-
This article describes the SAP logs available from the Microsoft Sentinel SAP data connector, including the table names in Microsoft Sentinel, the log purposes, and detailed log schemas. Schema field descriptions are based on the field descriptions in the relevant [SAP documentation](https://help.sap.com/).
16-
17-
This article is intended for advanced SAP users.
18-
19-
> [!NOTE]
20-
> When using the XBP 3.0 interface, the Microsoft Sentinel SAP solution uses *Not Released* services. These services do not affect backend system or connector behavior.
21-
>
22-
> To "release" these services, implement the [SAP Note 2910263 - Unreleased XBP functions](https://launchpad.support.sap.com/#/notes/2910263).
23-
2415
> [!IMPORTANT]
2516
> The Microsoft Sentinel SAP solution is currently in PREVIEW. The [Azure Preview Supplemental Terms](https://azure.microsoft.com/support/legal/preview-supplemental-terms/) include additional legal terms that apply to Azure features that are in beta, preview, or otherwise not yet released into general availability.
2617
>
18+
> Some logs, noted below, are not sent to Microsoft Sentinel by default, but you can manually add them as needed. For more information, see [Define the SAP logs that are sent to Microsoft Sentinel](sap-solution-deploy-alternate.md#define-the-sap-logs-that-are-sent-to-microsoft-sentinel).
19+
>
20+
21+
This article describes the SAP logs available from the Microsoft Sentinel SAP data connector, including the table names in Microsoft Sentinel, the log purposes, and detailed log schemas. Schema field descriptions are based on the field descriptions in the relevant [SAP documentation](https://help.sap.com/).
22+
23+
This article is intended for advanced SAP users.
2724

2825
## ABAP Application log
2926

@@ -35,7 +32,6 @@ This article is intended for advanced SAP users.
3532

3633
Available by using RFC with a custom service based on standard services of XBP interface. This log is generated per client.
3734

38-
3935
### ABAPAppLog_CL log schema
4036

4137
| Field | Description |
@@ -159,6 +155,8 @@ This article is intended for advanced SAP users.
159155

160156
## ABAP DB table data log
161157

158+
To have this log sent to Microsoft Sentinel, you must [add it manually to the **systemconfig.ini** file](sap-solution-deploy-alternate.md#define-the-sap-logs-that-are-sent-to-microsoft-sentinel).
159+
162160
- **Name in Microsoft Sentinel**: `ABAPTableDataLog_CL`
163161

164162
- **Related SAP documentation**: [SAP Help Portal](https://help.sap.com/viewer/56bf1265a92e4b4d9a72448c579887af/7.5.7/en-US/c769bcd2f36611d3a6510000e835363f.html)
@@ -191,6 +189,9 @@ This article is intended for advanced SAP users.
191189

192190
## ABAP Gateway log
193191

192+
To have this log sent to Microsoft Sentinel, you must [add it manually to the **systemconfig.ini** file](sap-solution-deploy-alternate.md#define-the-sap-logs-that-are-sent-to-microsoft-sentinel).
193+
194+
194195
- **Name in Microsoft Sentinel**: `ABAPOS_GW_CL`
195196

196197
- **Related SAP documentation**: [SAP Help Portal](https://help.sap.com/viewer/62b4de4187cb43668d15dac48fc00732/7.5.7/en-US/48b2a710ca1c3079e10000000a42189b.html)
@@ -211,6 +212,9 @@ This article is intended for advanced SAP users.
211212

212213
## ABAP ICM log
213214

215+
To have this log sent to Microsoft Sentinel, you must [add it manually to the **systemconfig.ini** file](sap-solution-deploy-alternate.md#define-the-sap-logs-that-are-sent-to-microsoft-sentinel).
216+
217+
214218
- **Name in Microsoft Sentinel**: `ABAPOS_ICM_CL`
215219

216220
- **Related SAP documentation**: [SAP Help Portal](https://help.sap.com/viewer/683d6a1797a34730a6e005d1e8de6f22/7.52.4/en-US/a10ec40d01e740b58d0a5231736c434e.html)
@@ -437,6 +441,9 @@ This article is intended for advanced SAP users.
437441

438442
## ABAP SysLog
439443

444+
To have this log sent to Microsoft Sentinel, you must [add it manually to the **systemconfig.ini** file](sap-solution-deploy-alternate.md#define-the-sap-logs-that-are-sent-to-microsoft-sentinel).
445+
446+
440447
- **Name in Microsoft Sentinel**: `ABAPOS_Syslog_CL`
441448

442449
- **Related SAP documentation**: [SAP Help Portal](https://help.sap.com/viewer/56bf1265a92e4b4d9a72448c579887af/7.5.7/en-US/c769bcbaf36611d3a6510000e835363f.html)
@@ -521,6 +528,9 @@ This article is intended for advanced SAP users.
521528

522529
## ABAP WorkProcess log
523530

531+
To have this log sent to Microsoft Sentinel, you must [add it manually to the **systemconfig.ini** file](sap-solution-deploy-alternate.md#define-the-sap-logs-that-are-sent-to-microsoft-sentinel).
532+
533+
524534
- **Name in Microsoft Sentinel**: `ABAPOS_WP_CL`
525535

526536
- **Related SAP documentation**: [SAP Help Portal](https://help.sap.com/viewer/d0739d980ecf42ae9f3b4c19e21a4b6e/7.3.15/en-US/46fb763b6d4c5515e10000000a1553f6.html)
@@ -546,6 +556,9 @@ This article is intended for advanced SAP users.
546556

547557
## HANA DB Audit Trail
548558

559+
To have this log sent to Microsoft Sentinel, you must [add it manually to the **systemconfig.ini** file](sap-solution-deploy-alternate.md#define-the-sap-logs-that-are-sent-to-microsoft-sentinel).
560+
561+
549562
- **Name in Microsoft Sentinel**: `Syslog`
550563

551564
- **Related SAP documentation**: [General](https://help.sap.com/viewer/6b94445c94ae495c83a19646e7c3fd56/2.0.03/en-US/48fd6586304c4f859bf92d64d0cd8b08.html) | [Audit Trail](https://help.sap.com/viewer/b3ee5778bc2e4a089d3299b82ec762a7/2.0.03/en-US/0a57444d217649bf94a19c0b68b470cc.html)
@@ -570,6 +583,9 @@ This article is intended for advanced SAP users.
570583

571584
## JAVA files
572585

586+
To have this log sent to Microsoft Sentinel, you must [add it manually to the **systemconfig.ini** file](sap-solution-deploy-alternate.md#define-the-sap-logs-that-are-sent-to-microsoft-sentinel).
587+
588+
573589
- **Name in Microsoft Sentinel**: `JavaFilesLogsCL`
574590

575591
- **Related SAP documentation**: [General](https://help.sap.com/viewer/2f8b1599655d4544a3d9c6d1a9b6546b/7.5.9/en-US/485059dfe31672d4e10000000a42189c.html) | [Java Security Audit Log](https://help.sap.com/viewer/1531c8a1792f45ab95a4c49ba16dc50b/7.5.9/en-US/4b6013583840584ae10000000a42189c.html)

0 commit comments

Comments
 (0)