You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/sentinel/sap/deploy-data-connector-agent-container.md
+10-8Lines changed: 10 additions & 8 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -34,7 +34,7 @@ Content in this article is relevant for your **security**, **infrastructure**, a
34
34
35
35
:::image type="content" source="media/deployment-steps/deploy-data-connector-agentless.png" alt-text="Diagram of the SAP solution deployment flow, highlighting the Connect your SAP system step." border="false":::
36
36
37
-
Content in this article is relevant for your **security** team, using information provided by your **SAP BASIS** teams.
37
+
Content in this article is relevant for your **security** team.
38
38
39
39
:::zone-end
40
40
@@ -60,11 +60,11 @@ Before you connect your SAP system to Microsoft Sentinel:
60
60
61
61
:::zone pivot="connection-agentless"
62
62
63
-
- Make sure that you have the Microsoft Sentinel **SAP Agentless** solution [installed in your Microsoft Sentinel workspace](deploy-sap-security-content.md)
63
+
- Make sure that you have the Microsoft Sentinel **SAP Agentless** solution [installed in your Microsoft Sentinel workspace](deploy-sap-security-content.md)<!--what is this solution's new name?-->
64
64
65
65
- Make sure that your SAP system is fully [prepared for the deployment](preparing-sap.md).
66
66
67
-
- Make sure your DCR is configured as described in [Install the solution from the content hub](deploy-sap-security-content.md#install-the-solution-from-the-content-hub).
67
+
<!--removed- Make sure your DCR is configured as described in [Install the solution from the content hub](deploy-sap-security-content.md#install-the-solution-from-the-content-hub).-->
68
68
69
69
:::zone-end
70
70
@@ -235,7 +235,7 @@ While deployment is also supported from the command line, we recommend that you
235
235
236
236
1. In Microsoft Sentinel, select **Configuration > Data connectors**.
237
237
238
-
1. In the search bar, enter *SAP*. Select **Microsoft Sentinel for SAP** from the search results and then **Open connector page**.
238
+
1. In the search bar, enter *SAP*. Select **Microsoft Sentinel for SAP - agent-based** from the search results and then **Open connector page**.
239
239
240
240
1. In the **Configuration** area, select **Add new agent (Preview)**.
241
241
@@ -348,11 +348,11 @@ At this stage, the system's **Health** status is **Pending**. If the agent is up
348
348
349
349
## Connect your agentless data connector
350
350
351
-
1. In Microsoft Sentinel, go to the **Configuration > Data connectors** page and locate the **SAP ABAP and S/4 via cloud connector (Preview)** data connector.
351
+
1. In Microsoft Sentinel, go to the **Configuration > Data connectors** page and locate the **Microsoft Sentinel for SAP - agent-less (Preview) (Preview)** data connector.
352
352
353
-
1. In the **Configuration** area, under **Connect an SAP integration suite to Microsoft Sentinel**, select **Add connection**.
353
+
1. In the **Configuration** area, scroll down and select **Add SAP client**.
354
354
355
-
1. In the **Agentless connection** side pane, enter the following details:
355
+
1. In the **Connect to an SAP Client** side pane, enter the following details:
@@ -362,11 +362,13 @@ At this stage, the system's **Health** status is **Pending**. If the agent is up
362
362
| **Authorization server URL** | The *tokenurlurl* value taken from the Process Integration Runtime service key JSON file. For example: `https://your-tenant.authentication.region.hana.ondemand.com/oauth/token` |
363
363
| **Integration Suite Endpoint** | The *url* value taken from the Process Integration Runtime service key JSON file. For example: `https://your-tenant.it-account-rt.cfapps.region.hana.ondemand.com` |
364
364
365
+
1. Select **Connect**.
366
+
365
367
## Customize data connector behavior (optional)
366
368
367
369
If the agentless data connector's default functionality doesn't fit your organization's needs, customize it using SAP Integration Suite value mapping.
368
370
369
-
Also, due to database performance issues, ingesting Change Docs logs Sybase isn't supported. We recommend that customers using Sybase turn off ingestion for Change Docs logs in the iflow by configuring the **collect-changedocs-logs** parameter.
371
+
Also, due to database performance issues, ingesting Change Docs logs running on Sybase isn't supported. We recommend that customers using Sybase turn off ingestion for Change Docs logs in the iflow by configuring the **collect-changedocs-logs** parameter.
370
372
371
373
For more information, see [Customize your SAP agentless data connector for Microsoft Sentinel](configure-agentless.md).
This article describes how to prepare your SAP environment for connecting to the SAP data connector. Preparation differs, depending on whether you're using the containerized data connector agent. Select the option at the top of the page that matches your environment.
21
21
22
-
This article is part of the second step in deploying the Microsoft Sentinel solution for SAP applications.
22
+
:::zone pivot="connection-agent"
23
+
This article is part of the second step in deploying the Microsoft Sentinel solution for SAP applications.
24
+
25
+
:::image type="content" source="media/deployment-steps/prepare-sap-environment.png" alt-text="Diagram of the deployment flow for the Microsoft Sentinel solution for SAP applications, with the preparing SAP step highlighted." border="false":::
26
+
27
+
The procedures in this article are typically performed by your **SAP BASIS** team.
28
+
:::zone-end
29
+
30
+
:::zone pivot="connection-agentless"
31
+
This article is part of the second step in deploying the Microsoft Sentinel solution for SAP applications. While steps that are performed in Microsoft Sentinel require that the solution be installed first, other preparations in the SAP environment can happen in parallel. <!--need new images across-->
23
32
24
33
:::image type="content" source="media/deployment-steps/prepare-sap-environment.png" alt-text="Diagram of the deployment flow for the Microsoft Sentinel solution for SAP applications, with the preparing SAP step highlighted." border="false":::
25
34
26
-
The procedures in this article are typically performed by your **SAP BASIS** team. If you're using the agentless solution, you might also need to involve your **security** team.
35
+
Many of the procedures in this article are typically performed by your **SAP BASIS** team. Some steps include your **security** team too.
36
+
:::zone-end
27
37
28
38
> [!IMPORTANT]
29
39
> Microsoft Sentinel's agentless data connector for SAP is currently in PREVIEW. The [Azure Preview Supplemental Terms](https://azure.microsoft.com/support/legal/preview-supplemental-terms/) include additional legal terms that apply to Azure features that are in beta, preview, or otherwise not yet released into general availability.
30
40
31
41
## Prerequisites
32
42
33
43
- Before you start, make sure to review the [prerequisites for deploying the Microsoft Sentinel solution for SAP applications](prerequisites-for-deploying-sap-continuous-threat-monitoring.md).
44
+
:::zone pivot="connection-agentless"
45
+
- If you're working with the agentless solution, some steps are performed in Microsoft Sentinel and require that the [solution be installed first](deploy-sap-security-content.md).
46
+
47
+
:::zone-end
34
48
35
49
## Configure the Microsoft Sentinel role
36
50
@@ -85,11 +99,14 @@ Some installations of SAP systems might not have audit logging enabled by defaul
85
99
86
100
We recommend that you configure auditing for *all* messages from the audit log, instead of only specific logs. Ingestion cost differences are generally minimal and the data is useful for Microsoft Sentinel detections and in post-compromise investigations and hunting.
87
101
102
+
:::zone pivot="connection-agentless"
103
+
For full monitoring coverage with the agentless solution, we recommend that you enable monitoring on all client IDs of your monitored SAP systems, including clients 000 and 066.
104
+
:::zone-end
105
+
88
106
For more information, see the [SAP community](https://community.sap.com/t5/application-development-blog-posts/analysis-and-recommended-settings-of-the-security-audit-log-sm19-rsau/ba-p/13297094) and [Collect SAP HANA audit logs in Microsoft Sentinel](collect-sap-hana-audit-logs.md).
89
107
90
108
## Configure your system to use SNC for secure connections
91
109
92
-
93
110
By default, the SAP data connector agent connects to an SAP server using a remote function call (RFC) connection and a username and password for authentication.
94
111
95
112
However, you might need to make the connection on an encrypted channel or use client certificates for authentication. In these cases, use Smart Network Communications (SNC) from SAP to secure your data connections, as described in this section.
@@ -172,6 +189,16 @@ For more information, see [Database Collector in Background Processing](https://
172
189
173
190
For more information, see the [SAP documentation](https://help.sap.com/docs/integration-suite/sap-integration-suite/initial-setup).
174
191
192
+
## Perform initial connector configuration
193
+
194
+
1. In Microsoft Sentinel, go to the **Configuration > Data connectors** page and locate the **Microsoft Sentinel for SAP - agent-less (Preview) (Preview)** data connector.
195
+
196
+
1. In the **Configuration** area, expand and follow the instructions in the **Initial connector configuration - Run the steps below once:** area. These steps will require a mixture of your Security and SAP BASIS teams.
197
+
198
+
If, after you deploy the Azure resources step 1, the values in the steps 2 and 3 aren't automatically populated, close and re-expand step 1 to refresh the values in steps 2 and 3.
199
+
200
+
1. Scroll further down in the **Configuration** area, and expand and follow the instructions in the **Add monitored SAP Systems - Run the steps below for each monitored SAP system:** area for each SAP system you want to monitor.
201
+
175
202
## Configure SAP Cloud Connector settings
176
203
177
204
1. Install the SAP Cloud Connector. For more information, see the [SAP documentation](https://help.sap.com/docs/connectivity/sap-btp-connectivity-cf/installation).
@@ -216,36 +243,6 @@ For more information, see the [SAP documentation](https://help.sap.com/docs/inte
216
243
217
244
-**Location**: Only required when you connect multiple Cloud Connectors to the same BTP subaccount. For more information, see the [SAP Documentation](https://help.sap.com/docs/connectivity/sap-btp-connectivity-cf/parameters-influencing-communication-behavior).
218
245
219
-
## Configure SAP Integration Suite settings
220
-
221
-
Create a new OAuth2 client credential to store the connection details for the Microsoft Entra ID app registration that you'd created [earlier](deploy-sap-security-content.md#deployment).
222
-
223
-
When creating the credential, enter the following details:
224
-
225
-
-**Name:**`LogIngestionAPI`
226
-
227
-
-**Token Service URL:**`https://login.microsoftonline.com/<your Microsoft Entra ID tenant ID>/oauth2/v2.0/token`
## Import and deploy the Microsoft Sentinel solution for SAP package
238
-
239
-
1. Download the Microsoft Sentinel solution for SAP package from [https://aka.ms/SAPAgentlessPackage](https://aka.ms/SAPAgentlessPackage).
240
-
1. Import the downloaded package to SAP Integration Suite.
241
-
1. Open the Microsoft Sentinel solution for SAP package and browse to the artifacts.
242
-
1. Select **Send security logs to Microsoft - application layer** artifact.
243
-
1. Select **Configure** and then enter your DCR details:
244
-
245
-
-**LogsIngestionURL** the Ingestion URL from the DCR's DCE, as saved [earlier](deploy-sap-security-content.md#install-the-solution-from-the-content-hub).
246
-
-**DCRImmutableId**: The DCR's immutable ID, as saved [earlier](deploy-sap-security-content.md#install-the-solution-from-the-content-hub).
247
-
248
-
1. Select **Deploy** to deploy the i-flow using SAP Cloud Integration as the runtime service.
Copy file name to clipboardExpand all lines: articles/sentinel/sap/prerequisites-for-deploying-sap-continuous-threat-monitoring.md
+3-2Lines changed: 3 additions & 2 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -91,15 +91,16 @@ Typically, Azure prerequisites are managed by your **security** teams.
91
91
| Prerequisite | Description |Required/optional |
92
92
| ---- | ----------- |----------- |
93
93
|**Permissions to create Azure resources**| You must have: <br><br>- The necessary permissions to deploy solutions from the Microsoft Sentinel content hub. For more information, see [Prerequisites for deploying Microsoft Sentinel solutions](../sentinel-solutions-deploy.md#prerequisites) and [Microsoft Entra built-in roles](/entra/identity/role-based-access-control/permissions-reference#application-administrator). <br>Owner on the Microsoft Sentinel resource group , required for:<br><br>- Creation of data collection rule and data collection endpoint.<br><br>- Monitoring Metrics Publisher role assignment on data collection rule. |Required |
94
-
|**Permissions in****Microsoft Entra**|You must have permissions in Microsoft Entra ID required to create app registrations. This permission can be obtained through membership of built-in Microsoft Entra ID role:<br><br>- Application Developer.|Required |
94
+
|**Read permissions to shared keys for the workspace**| TBD DESCRIPTION OF THIS. The linked bookmark doesn't go anywhere. For more information, see [Install Log Analytics agent on Windows computers](/azure/azure-monitor/platform/agent-windows#obtain-workspace-id-and-key). | Required |
95
+
|**Permissions in Microsoft Entra**|You must have permissions in Microsoft Entra ID required to create app registrations. This permission can be obtained through membership of built-in Microsoft Entra ID role:<br><br>- Application Developer.|Required |
95
96
96
97
## SAP prerequisites for the agentless data connector
97
98
98
99
We recommend that your **SAP BASIS** team verify and ensure SAP system prerequisites. We strongly recommend that any management of your SAP system is carried out by an experienced SAP system administrator.
99
100
100
101
| Prerequisite | Description |
101
102
| ---- | ----------- |
102
-
|**Supported SAP versions**| The **Agentless** solution supports SAP NetWeaver systems with [SAP_BASIS versions 750](https://userapps.support.sap.com/sap(bD1kZSZjPTAwMQ==)/support/pam/pam.html?smpsrv=https%3a%2f%2fwebsmp201.sap-ag.de#ts=60&s=netweaver%207.5&o=most_viewed%7Cdesc&st=l&rpp=20&page=1&pvnr=73554900100900000414&pt=g%7Cd) and above. |
103
+
|**Supported SAP versions**| The **Agentless** solution supports SAP NetWeaver systems with [SAP_BASIS versions 750](https://userapps.support.sap.com/sap(bD1kZSZjPTAwMQ==)/support/pam/pam.html?smpsrv=https%3a%2f%2fwebsmp201.sap-ag.de#ts=60&s=netweaver%207.5&o=most_viewed%7Cdesc&st=l&rpp=20&page=1&pvnr=73554900100900000414&pt=g%7Cd) and above. <br><br>Change Docs logs running on Sybase aren't supported. If you're using Sybase, we recommend that you customize your system to turn off ingestion for Change Docs logs. For more information, see [Customize your SAP agentless data connector for Microsoft Sentinel (Preview)](configure-agentless.md).|
103
104
|**SAP environment**| Your SAP environment must have: <br><br> The **RSAU_API_GET_LOG_DATA** function module, remote enabled on your SAP System. For more information, see the [SAP documentation](https://me.sap.com/notes/3054326/E). <br>An SAP BTP Subaccount with following services enabled: <br> - SAP Integration Suite <br>- SAP Process Integration Runtime <br>- Cloud Foundry Runtime<br> For more information, see the [SAP documentation](https://help.sap.com/docs/sap-hana-spatial-services/onboarding/creating-subaccount-on-sap-business-technology-platform-sap-btp). [Trial accounts](https://developers.sap.com/tutorials/hcp-create-trial-account.html) are supported.<br><br>The [SAP Cloud Connector](https://help.sap.com/docs/connectivity/sap-btp-connectivity-cf/installation?locale=en-US) deployed <br><br>SAP NetWeaver version 7.5 or higher|
104
105
|**SAP roles and permissions**| You must have the following roles in your SAP systems: <br><br>**In SAP NetWeaver 7.5+**: SAP Netweaver Administrator <br><br>**In SAP BTP, all of the following roles**:<br>- Subaccount administrator <br>- Integration Provisioner <br>- PI_Administrator <br>- PI_Integration_Developer <br>- PI_Business_Expert|
0 commit comments