Skip to content

Commit db94da8

Browse files
authored
Merge pull request #202266 from MSFTandrelom/andrelom-docs-update-2
redoing PR
2 parents bcb0b0b + 7f01d0b commit db94da8

20 files changed

+407
-184
lines changed

articles/sentinel/TOC.yml

Lines changed: 6 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -143,10 +143,8 @@
143143
href: microsoft-365-defender-sentinel-integration.md
144144
- name: Integrate SAP
145145
items:
146-
- name: Deployment overview
147-
href: sap/deployment-overview.md
148-
- name: Deployment prerequisites
149-
href: sap/prerequisites-for-deploying-sap-continuous-threat-monitoring.md
146+
- name: Solution overview
147+
href: sap/solution-overview.md
150148
- name: How-tos
151149
items:
152150
- name: Plan architecture
@@ -394,6 +392,10 @@
394392
items:
395393
- name: Deployment guide
396394
items:
395+
- name: Deployment overview
396+
href: sap/deployment-overview.md
397+
- name: Deployment prerequisites
398+
href: sap/prerequisites-for-deploying-sap-continuous-threat-monitoring.md
397399
- name: Prepare SAP environment
398400
href: sap/preparing-sap.md
399401
- name: Deploy data connector agent

articles/sentinel/sap/collect-sap-hana-audit-logs.md

Lines changed: 8 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -14,7 +14,7 @@ ms.date: 03/02/2022
1414
This article explains how to collect audit logs from your SAP HANA database.
1515

1616
> [!IMPORTANT]
17-
> The Microsoft Sentinel SAP solution is currently in PREVIEW. The [Azure Preview Supplemental Terms](https://azure.microsoft.com/support/legal/preview-supplemental-terms/) include additional legal terms that apply to Azure features that are in beta, preview, or otherwise not yet released into general availability.
17+
> The Microsoft Sentinel Threat Monitoring for SAP solution is currently in PREVIEW. The [Azure Preview Supplemental Terms](https://azure.microsoft.com/support/legal/preview-supplemental-terms/) include additional legal terms that apply to Azure features that are in beta, preview, or otherwise not yet released into general availability.
1818
1919
If you have SAP HANA database audit logs configured with Syslog, you'll also need to configure your Log Analytics agent to collect the Syslog files.
2020

@@ -51,25 +51,25 @@ If you have SAP HANA database audit logs configured with Syslog, you'll also nee
5151

5252
## Next steps
5353

54-
Learn more about the Microsoft Sentinel SAP solutions:
54+
Learn more about the Microsoft Sentinel Threat Monitoring for SAP solutions:
5555

56-
- [Deploy Continuous Threat Monitoring for SAP](deployment-overview.md)
57-
- [Prerequisites for deploying SAP continuous threat monitoring](prerequisites-for-deploying-sap-continuous-threat-monitoring.md)
56+
- [Deploy Threat Monitoring for SAP](deployment-overview.md)
57+
- [Prerequisites for deploying Threat Monitoring for SAP](prerequisites-for-deploying-sap-continuous-threat-monitoring.md)
5858
- [Deploy SAP Change Requests (CRs) and configure authorization](preparing-sap.md)
5959
- [Deploy and configure the SAP data connector agent container](deploy-data-connector-agent-container.md)
6060
- [Deploy SAP security content](deploy-sap-security-content.md)
61-
- [Deploy the Microsoft Sentinel SAP data connector with SNC](configure-snc.md)
61+
- [Deploy the Microsoft Sentinel Threat Monitoring for SAP data connector with SNC](configure-snc.md)
6262
- [Enable and configure SAP auditing](configure-audit.md)
6363

6464
Troubleshooting:
6565

66-
- [Troubleshoot your Microsoft Sentinel SAP solution deployment](sap-deploy-troubleshoot.md)
66+
- [Troubleshoot your Microsoft Sentinel Threat Monitoring for SAP solution deployment](sap-deploy-troubleshoot.md)
6767
- [Configure SAP Transport Management System](configure-transport.md)
6868

6969
Reference files:
7070

71-
- [Microsoft Sentinel SAP solution data reference](sap-solution-log-reference.md)
72-
- [Microsoft Sentinel SAP solution: security content reference](sap-solution-security-content.md)
71+
- [Microsoft Sentinel Threat Monitoring for SAP solution data reference](sap-solution-log-reference.md)
72+
- [Microsoft Sentinel Threat Monitoring for SAP solution: security content reference](sap-solution-security-content.md)
7373
- [Kickstart script reference](reference-kickstart.md)
7474
- [Update script reference](reference-update.md)
7575
- [Systemconfig.ini file reference](reference-systemconfig.md)

articles/sentinel/sap/configure-audit.md

Lines changed: 12 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
---
22
title: Enable and configure SAP auditing for Microsoft Sentinel | Microsoft Docs
3-
description: This article shows you how to enable and configure auditing for the Microsoft Sentinel Continuous Threat Monitoring solution for SAP, so that you can have complete visibility into your SAP solution.
3+
description: This article shows you how to enable and configure auditing for the Microsoft Sentinel Threat Monitoring solution for SAP, so that you can have complete visibility into your SAP solution.
44
author: MSFTandrelom
55
ms.author: andrelom
66
ms.topic: how-to
@@ -11,16 +11,16 @@ ms.date: 04/27/2022
1111

1212
[!INCLUDE [Banner for top of topics](../includes/banner.md)]
1313

14-
This article shows you how to enable and configure auditing for the Microsoft Sentinel Continuous Threat Monitoring solution for SAP, so that you can have complete visibility into your SAP solution.
14+
This article shows you how to enable and configure auditing for the Microsoft Sentinel Threat Monitoring solution for SAP, so that you can have complete visibility into your SAP solution.
1515

1616
> [!IMPORTANT]
17-
> The Microsoft Sentinel SAP solution is currently in PREVIEW. The [Azure Preview Supplemental Terms](https://azure.microsoft.com/support/legal/preview-supplemental-terms/) include additional legal terms that apply to Azure features that are in beta, preview, or otherwise not yet released into general availability.
17+
> The Microsoft Sentinel Threat Monitoring for SAP solution is currently in PREVIEW. The [Azure Preview Supplemental Terms](https://azure.microsoft.com/support/legal/preview-supplemental-terms/) include additional legal terms that apply to Azure features that are in beta, preview, or otherwise not yet released into general availability.
1818
>
1919
> We strongly recommend that any management of your SAP system is carried out by an experienced SAP system administrator.
2020
>
2121
> The steps in this article may vary, depending on your SAP sytem's version, and should be considered as a sample only.
2222
23-
Some installations of SAP systems may not have audit log enabled by default. For best results in evaluating the performance and efficacy of the Microsoft Sentinel Continuous Threat Monitoring solution for SAP, enable auditing of your SAP system and configure the audit parameters.
23+
Some installations of SAP systems may not have audit log enabled by default. For best results in evaluating the performance and efficacy of the Microsoft Sentinel Threat Monitoring solution for SAP, enable auditing of your SAP system and configure the audit parameters.
2424

2525
## Check if auditing is enabled
2626

@@ -73,7 +73,7 @@ Some installations of SAP systems may not have audit log enabled by default. For
7373

7474
### Recommended audit categories
7575

76-
The following table lists Message IDs used by the Continuous Threat Monitoring for SAP solution. In order for analytics rules to detect events properly, we strongly recommend configuring an audit policy that includes the message IDs listed below as a minimum.
76+
The following table lists Message IDs used by the Threat Monitoring for SAP solution. In order for analytics rules to detect events properly, we strongly recommend configuring an audit policy that includes the message IDs listed below as a minimum.
7777

7878
| Message ID | Message text | Category name | Event Weighting | Class Used in Rules |
7979
| - | - | - | - | - |
@@ -129,25 +129,25 @@ The following table lists Message IDs used by the Continuous Threat Monitoring f
129129

130130
## Next steps
131131

132-
Learn more about the Microsoft Sentinel SAP solutions:
132+
Learn more about the Microsoft Sentinel Threat Monitoring for SAP solutions:
133133

134-
- [Deploy Continuous Threat Monitoring for SAP](deployment-overview.md)
135-
- [Prerequisites for deploying SAP continuous threat monitoring](prerequisites-for-deploying-sap-continuous-threat-monitoring.md)
134+
- [Deploy Threat Monitoring for SAP](deployment-overview.md)
135+
- [Prerequisites for deploying Threat Monitoring for SAP](prerequisites-for-deploying-sap-continuous-threat-monitoring.md)
136136
- [Deploy SAP Change Requests (CRs) and configure authorization](preparing-sap.md)
137137
- [Deploy and configure the SAP data connector agent container](deploy-data-connector-agent-container.md)
138138
- [Deploy SAP security content](deploy-sap-security-content.md)
139-
- [Deploy the Microsoft Sentinel SAP data connector with SNC](configure-snc.md)
139+
- [Deploy the Microsoft Sentinel Threat Monitoring for SAP data connector with SNC](configure-snc.md)
140140
- [Collect SAP HANA audit logs](collect-sap-hana-audit-logs.md)
141141

142142
Troubleshooting:
143143

144-
- [Troubleshoot your Microsoft Sentinel SAP solution deployment](sap-deploy-troubleshoot.md)
144+
- [Troubleshoot your Microsoft Sentinel Threat Monitoring for SAP solution deployment](sap-deploy-troubleshoot.md)
145145
- [Configure SAP Transport Management System](configure-transport.md)
146146

147147
Reference files:
148148

149-
- [Microsoft Sentinel SAP solution data reference](sap-solution-log-reference.md)
150-
- [Microsoft Sentinel SAP solution: security content reference](sap-solution-security-content.md)
149+
- [Microsoft Sentinel Threat Monitoring for SAP solution data reference](sap-solution-log-reference.md)
150+
- [Microsoft Sentinel Threat Monitoring for SAP solution: security content reference](sap-solution-security-content.md)
151151
- [Kickstart script reference](reference-kickstart.md)
152152
- [Update script reference](reference-update.md)
153153
- [Systemconfig.ini file reference](reference-systemconfig.md)

articles/sentinel/sap/configure-snc.md

Lines changed: 11 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
11
---
2-
title: Deploy the Microsoft Sentinel SAP data connector with Secure Network Communications (SNC) | Microsoft Docs
2+
title: Deploy the Microsoft Sentinel Threat Monitoring for SAP data connector with Secure Network Communications (SNC) | Microsoft Docs
33
description: This article shows you how to deploy the **Microsoft Sentinel data connector for SAP** to ingest NetWeaver/ABAP logs over a secure connection using Secure Network Communications.
44
author: batamig
55
ms.author: bagol
@@ -8,16 +8,16 @@ ms.custom: mvc, ignite-fall-2021
88
ms.date: 05/03/2022
99
---
1010

11-
# Deploy the Microsoft Sentinel SAP data connector with SNC
11+
# Deploy the Microsoft Sentinel Threat Monitoring for SAP data connector with SNC
1212

1313
[!INCLUDE [Banner for top of topics](../includes/banner.md)]
1414

1515
This article shows you how to deploy the **Microsoft Sentinel data connector for SAP** to ingest NetWeaver/ABAP logs over a secure connection using Secure Network Communications (SNC).
1616

1717
> [!IMPORTANT]
18-
> The Microsoft Sentinel SAP solution is currently in PREVIEW. The [Azure Preview Supplemental Terms](https://azure.microsoft.com/support/legal/preview-supplemental-terms/) include additional legal terms that apply to Azure features that are in beta, preview, or otherwise not yet released into general availability.
18+
> The Microsoft Sentinel Threat Monitoring for SAP solution is currently in PREVIEW. The [Azure Preview Supplemental Terms](https://azure.microsoft.com/support/legal/preview-supplemental-terms/) include additional legal terms that apply to Azure features that are in beta, preview, or otherwise not yet released into general availability.
1919
20-
The Continuous Threat Monitoring for SAP data connector agent typically connects to an SAP ABAP server using an RFC connection, and a user's username and password for authentication.
20+
The Threat Monitoring for SAP data connector agent typically connects to an SAP ABAP server using an RFC connection, and a user's username and password for authentication.
2121

2222
However, some environments may require the connection be over an encrypted channel, and client certificates be used for authentication. In these cases you can use SAP Secure Network Communication for this purpose, and you'll have to take the appropriate steps as outlined in this article.
2323

@@ -182,26 +182,26 @@ For additional information on options available in the kickstart script, review
182182
183183
## Next steps
184184
185-
Learn more about the Microsoft Sentinel SAP solutions:
185+
Learn more about the Microsoft Sentinel Threat Monitoring for SAP solutions:
186186
187-
- [Deploy Continuous Threat Monitoring for SAP](deployment-overview.md)
188-
- [Prerequisites for deploying SAP continuous threat monitoring](prerequisites-for-deploying-sap-continuous-threat-monitoring.md)
187+
- [Deploy Threat Monitoring for SAP](deployment-overview.md)
188+
- [Prerequisites for deploying Threat Monitoring for SAP](prerequisites-for-deploying-sap-continuous-threat-monitoring.md)
189189
- [Deploy SAP Change Requests (CRs) and configure authorization](preparing-sap.md)
190190
- [Deploy and configure the SAP data connector agent container](deploy-data-connector-agent-container.md)
191191
- [Deploy SAP security content](deploy-sap-security-content.md)
192-
- [Deploy the Microsoft Sentinel SAP data connector with SNC](configure-snc.md)
192+
- [Deploy the Microsoft Sentinel Threat Monitoring for SAP data connector with SNC](configure-snc.md)
193193
- [Enable and configure SAP auditing](configure-audit.md)
194194
- [Collect SAP HANA audit logs](collect-sap-hana-audit-logs.md)
195195
196196
Troubleshooting:
197197
198-
- [Troubleshoot your Microsoft Sentinel SAP solution deployment](sap-deploy-troubleshoot.md)
198+
- [Troubleshoot your Microsoft Sentinel Threat Monitoring for SAP solution deployment](sap-deploy-troubleshoot.md)
199199
- [Configure SAP Transport Management System](configure-transport.md)
200200
201201
Reference files:
202202
203-
- [Microsoft Sentinel SAP solution data reference](sap-solution-log-reference.md)
204-
- [Microsoft Sentinel SAP solution: security content reference](sap-solution-security-content.md)
203+
- [Microsoft Sentinel Threat Monitoring for SAP solution data reference](sap-solution-log-reference.md)
204+
- [Microsoft Sentinel Threat Monitoring for SAP solution: security content reference](sap-solution-security-content.md)
205205
- [Kickstart script reference](reference-kickstart.md)
206206
- [Update script reference](reference-update.md)
207207
- [Systemconfig.ini file reference](reference-systemconfig.md)

articles/sentinel/sap/configure-transport.md

Lines changed: 11 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
---
22
title: Configure SAP Transport Management System to connect from Microsoft Sentinel | Microsoft Docs
3-
description: This article shows you how to configure the SAP Transport Management System in the event of an error or in a lab environment where it hasn't already been configured, in order to successfully deploy the Continuous Threat Monitoring solution for SAP in Microsoft Sentinel.
3+
description: This article shows you how to configure the SAP Transport Management System in the event of an error or in a lab environment where it hasn't already been configured, in order to successfully deploy the Threat Monitoring solution for SAP in Microsoft Sentinel.
44
author: MSFTandrelom
55
ms.author: andrelom
66
ms.topic: how-to
@@ -10,10 +10,10 @@ ms.date: 04/07/2022
1010

1111
[!INCLUDE [Banner for top of topics](../includes/banner.md)]
1212

13-
This article shows you how to configure the SAP Transport Management System in order to successfully deploy the Continuous Threat Monitoring solution for SAP in Microsoft Sentinel.
13+
This article shows you how to configure the SAP Transport Management System in order to successfully deploy the Threat Monitoring solution for SAP in Microsoft Sentinel.
1414

1515
> [!IMPORTANT]
16-
> The Microsoft Sentinel SAP solution is currently in PREVIEW. The [Azure Preview Supplemental Terms](https://azure.microsoft.com/support/legal/preview-supplemental-terms/) include additional legal terms that apply to Azure features that are in beta, preview, or otherwise not yet released into general availability.
16+
> The Microsoft Sentinel Threat Monitoring for SAP solution is currently in PREVIEW. The [Azure Preview Supplemental Terms](https://azure.microsoft.com/support/legal/preview-supplemental-terms/) include additional legal terms that apply to Azure features that are in beta, preview, or otherwise not yet released into general availability.
1717
1818
SAP's Transport Management System is normally already configured on production systems. However, in a lab environment, where CRs often haven't been previously installed, configuration may be required.
1919

@@ -72,30 +72,30 @@ The following steps show the process for configuring the Transport Management Sy
7272

7373
## Next steps
7474

75-
Now that you've configured the Transport Management System, you'll be able to successfully complete the `STMS_IMPORT` transaction and you can continue [preparing your SAP environment](preparing-sap.md) for deploying the Continuous Threat Monitoring solution for SAP in Microsoft Sentinel.
75+
Now that you've configured the Transport Management System, you'll be able to successfully complete the `STMS_IMPORT` transaction and you can continue [preparing your SAP environment](preparing-sap.md) for deploying the Threat Monitoring solution for SAP in Microsoft Sentinel.
7676

7777
> [!div class="nextstepaction"]
7878
> [Deploy SAP Change Requests and configure authorization](preparing-sap.md#import-the-crs)
7979
80-
Learn more about the Microsoft Sentinel SAP solutions:
80+
Learn more about the Microsoft Sentinel Threat Monitoring for SAP solutions:
8181

82-
- [Deploy Continuous Threat Monitoring for SAP](deployment-overview.md)
83-
- [Prerequisites for deploying SAP continuous threat monitoring](prerequisites-for-deploying-sap-continuous-threat-monitoring.md)
82+
- [Deploy Threat Monitoring for SAP](deployment-overview.md)
83+
- [Prerequisites for deploying Threat Monitoring for SAP](prerequisites-for-deploying-sap-continuous-threat-monitoring.md)
8484
- [Deploy SAP Change Requests (CRs) and configure authorization](preparing-sap.md)
8585
- [Deploy and configure the SAP data connector agent container](deploy-data-connector-agent-container.md)
8686
- [Deploy SAP security content](deploy-sap-security-content.md)
87-
- [Deploy the Microsoft Sentinel SAP data connector with SNC](configure-snc.md)
87+
- [Deploy the Microsoft Sentinel Threat Monitoring for SAP data connector with SNC](configure-snc.md)
8888
- [Enable and configure SAP auditing](configure-audit.md)
8989
- [Collect SAP HANA audit logs](collect-sap-hana-audit-logs.md)
9090

9191
Troubleshooting:
9292

93-
- [Troubleshoot your Microsoft Sentinel SAP solution deployment](sap-deploy-troubleshoot.md)
93+
- [Troubleshoot your Microsoft Sentinel Threat Monitoring for SAP solution deployment](sap-deploy-troubleshoot.md)
9494

9595
Reference files:
9696

97-
- [Microsoft Sentinel SAP solution data reference](sap-solution-log-reference.md)
98-
- [Microsoft Sentinel SAP solution: security content reference](sap-solution-security-content.md)
97+
- [Microsoft Sentinel Threat Monitoring for SAP solution data reference](sap-solution-log-reference.md)
98+
- [Microsoft Sentinel Threat Monitoring for SAP solution: security content reference](sap-solution-security-content.md)
9999
- [Kickstart script reference](reference-kickstart.md)
100100
- [Update script reference](reference-update.md)
101101
- [Systemconfig.ini file reference](reference-systemconfig.md)

0 commit comments

Comments
 (0)