You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/sentinel/sap/collect-sap-hana-audit-logs.md
+9-11Lines changed: 9 additions & 11 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -9,12 +9,10 @@ ms.date: 03/02/2022
9
9
10
10
# Collect SAP HANA audit logs in Microsoft Sentinel
11
11
12
-
[!INCLUDE [Banner for top of topics](../includes/banner.md)]
13
-
14
12
This article explains how to collect audit logs from your SAP HANA database.
15
13
16
14
> [!IMPORTANT]
17
-
> The Microsoft Sentinel Threat Monitoring for SAP solution is currently in PREVIEW. The [Azure Preview Supplemental Terms](https://azure.microsoft.com/support/legal/preview-supplemental-terms/) include additional legal terms that apply to Azure features that are in beta, preview, or otherwise not yet released into general availability.
15
+
> Microsoft Sentinel SAP HANA support is currently in PREVIEW. The [Azure Preview Supplemental Terms](https://azure.microsoft.com/support/legal/preview-supplemental-terms/) include additional legal terms that apply to Azure features that are in beta, preview, or otherwise not yet released into general availability.
18
16
19
17
If you have SAP HANA database audit logs configured with Syslog, you'll also need to configure your Log Analytics agent to collect the Syslog files.
20
18
@@ -51,25 +49,25 @@ If you have SAP HANA database audit logs configured with Syslog, you'll also nee
51
49
52
50
## Next steps
53
51
54
-
Learn more about the Microsoft Sentinel Threat Monitoring for SAP solutions:
52
+
Learn more about the Microsoft Sentinel Solution for SAP:
55
53
56
-
-[Deploy Threat Monitoring for SAP](deployment-overview.md)
57
-
-[Prerequisites for deploying Threat Monitoring for SAP](prerequisites-for-deploying-sap-continuous-threat-monitoring.md)
54
+
-[Deploy Microsoft Sentinel Solution for SAP](deployment-overview.md)
55
+
-[Prerequisites for deploying Microsoft Sentinel Solution for SAP](prerequisites-for-deploying-sap-continuous-threat-monitoring.md)
58
56
-[Deploy SAP Change Requests (CRs) and configure authorization](preparing-sap.md)
59
-
-[Deploy and configure the SAP data connector agent container](deploy-data-connector-agent-container.md)
57
+
-[Deploy and configure the container hosting the SAP data connector agent](deploy-data-connector-agent-container.md)
60
58
-[Deploy SAP security content](deploy-sap-security-content.md)
61
-
-[Deploy the Microsoft Sentinel Threat Monitoring for SAP data connector with SNC](configure-snc.md)
59
+
-[Deploy the SAP data connector with SNC](configure-snc.md)
62
60
-[Enable and configure SAP auditing](configure-audit.md)
63
61
64
62
Troubleshooting:
65
63
66
-
-[Troubleshoot your Microsoft Sentinel Threat Monitoring for SAP solution deployment](sap-deploy-troubleshoot.md)
64
+
-[Troubleshoot your Microsoft Sentinel Solution for SAP deployment](sap-deploy-troubleshoot.md)
67
65
-[Configure SAP Transport Management System](configure-transport.md)
68
66
69
67
Reference files:
70
68
71
-
-[Microsoft Sentinel Threat Monitoring for SAP solution data reference](sap-solution-log-reference.md)
72
-
-[Microsoft Sentinel Threat Monitoring for SAP solution: security content reference](sap-solution-security-content.md)
69
+
-[Microsoft Sentinel Solution for SAP data reference](sap-solution-log-reference.md)
70
+
-[Microsoft Sentinel Solution for SAP: security content reference](sap-solution-security-content.md)
Copy file name to clipboardExpand all lines: articles/sentinel/sap/configure-audit.md
+12-16Lines changed: 12 additions & 16 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -1,6 +1,6 @@
1
1
---
2
2
title: Enable and configure SAP auditing for Microsoft Sentinel | Microsoft Docs
3
-
description: This article shows you how to enable and configure auditing for the Microsoft Sentinel Threat Monitoring solution for SAP, so that you can have complete visibility into your SAP solution.
3
+
description: This article shows you how to enable and configure auditing for the Microsoft Sentinel Solution for SAP, so that you can have complete visibility into your SAP solution.
4
4
author: MSFTandrelom
5
5
ms.author: andrelom
6
6
ms.topic: how-to
@@ -9,18 +9,14 @@ ms.date: 04/27/2022
9
9
10
10
# Enable and configure SAP auditing for Microsoft Sentinel
11
11
12
-
[!INCLUDE [Banner for top of topics](../includes/banner.md)]
13
-
14
-
This article shows you how to enable and configure auditing for the Microsoft Sentinel Threat Monitoring solution for SAP, so that you can have complete visibility into your SAP solution.
12
+
This article shows you how to enable and configure auditing for the Microsoft Sentinel Solution for SAP, so that you can have complete visibility into your SAP solution.
15
13
16
14
> [!IMPORTANT]
17
-
> The Microsoft Sentinel Threat Monitoring for SAP solution is currently in PREVIEW. The [Azure Preview Supplemental Terms](https://azure.microsoft.com/support/legal/preview-supplemental-terms/) include additional legal terms that apply to Azure features that are in beta, preview, or otherwise not yet released into general availability.
18
-
>
19
15
> We strongly recommend that any management of your SAP system is carried out by an experienced SAP system administrator.
20
16
>
21
17
> The steps in this article may vary, depending on your SAP sytem's version, and should be considered as a sample only.
22
18
23
-
Some installations of SAP systems may not have audit log enabled by default. For best results in evaluating the performance and efficacy of the Microsoft Sentinel Threat Monitoring solution for SAP, enable auditing of your SAP system and configure the audit parameters.
19
+
Some installations of SAP systems may not have audit log enabled by default. For best results in evaluating the performance and efficacy of the Microsoft Sentinel Solution for SAP, enable auditing of your SAP system and configure the audit parameters.
24
20
25
21
## Check if auditing is enabled
26
22
@@ -73,7 +69,7 @@ Some installations of SAP systems may not have audit log enabled by default. For
73
69
74
70
### Recommended audit categories
75
71
76
-
The following table lists Message IDs used by the Threat Monitoring for SAP solution. In order for analytics rules to detect events properly, we strongly recommend configuring an audit policy that includes the message IDs listed below as a minimum.
72
+
The following table lists Message IDs used by the Microsoft Sentinel Solution for SAP. In order for analytics rules to detect events properly, we strongly recommend configuring an audit policy that includes the message IDs listed below as a minimum.
77
73
78
74
| Message ID | Message text | Category name | Event Weighting | Class Used in Rules |
79
75
| - | - | - | - | - |
@@ -129,25 +125,25 @@ The following table lists Message IDs used by the Threat Monitoring for SAP solu
129
125
130
126
## Next steps
131
127
132
-
Learn more about the Microsoft Sentinel Threat Monitoring for SAP solutions:
128
+
Learn more about the Microsoft Sentinel Solution for SAP:
133
129
134
-
-[Deploy Threat Monitoring for SAP](deployment-overview.md)
135
-
-[Prerequisites for deploying Threat Monitoring for SAP](prerequisites-for-deploying-sap-continuous-threat-monitoring.md)
130
+
-[Deploy Microsoft Sentinel Solution for SAP](deployment-overview.md)
131
+
-[Prerequisites for deploying Microsoft Sentinel Solution for SAP](prerequisites-for-deploying-sap-continuous-threat-monitoring.md)
136
132
-[Deploy SAP Change Requests (CRs) and configure authorization](preparing-sap.md)
137
-
-[Deploy and configure the SAP data connector agent container](deploy-data-connector-agent-container.md)
133
+
-[Deploy and configure the container hosting the SAP data connector agent](deploy-data-connector-agent-container.md)
138
134
-[Deploy SAP security content](deploy-sap-security-content.md)
139
-
-[Deploy the Microsoft Sentinel Threat Monitoring for SAP data connector with SNC](configure-snc.md)
135
+
-[Deploy the SAP data connector with SNC](configure-snc.md)
140
136
-[Collect SAP HANA audit logs](collect-sap-hana-audit-logs.md)
141
137
142
138
Troubleshooting:
143
139
144
-
-[Troubleshoot your Microsoft Sentinel Threat Monitoring for SAP solution deployment](sap-deploy-troubleshoot.md)
140
+
-[Troubleshoot your Microsoft Sentinel Solution for SAP deployment](sap-deploy-troubleshoot.md)
145
141
-[Configure SAP Transport Management System](configure-transport.md)
146
142
147
143
Reference files:
148
144
149
-
-[Microsoft Sentinel Threat Monitoring for SAP solution data reference](sap-solution-log-reference.md)
150
-
-[Microsoft Sentinel Threat Monitoring for SAP solution: security content reference](sap-solution-security-content.md)
145
+
-[Microsoft Sentinel Solution for SAP data reference](sap-solution-log-reference.md)
146
+
-[Microsoft Sentinel Solution for SAP: security content reference](sap-solution-security-content.md)
Copy file name to clipboardExpand all lines: articles/sentinel/sap/configure-snc.md
+15-20Lines changed: 15 additions & 20 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -1,23 +1,18 @@
1
1
---
2
-
title: Deploy the Microsoft Sentinel Threat Monitoring for SAP data connector with Secure Network Communications (SNC) | Microsoft Docs
3
-
description: This article shows you how to deploy the **Microsoft Sentinel data connector for SAP** to ingest NetWeaver/ABAP logs over a secure connection using Secure Network Communications.
4
-
author: batamig
5
-
ms.author: bagol
2
+
title: Deploy the Microsoft Sentinel for SAP data connector with Secure Network Communications (SNC) | Microsoft Docs
3
+
description: This article shows you how to deploy the Microsoft Sentinel for SAP data connector to ingest NetWeaver/ABAP logs over a secure connection using Secure Network Communications.
4
+
author: limwainstein
5
+
ms.author: lwainstein
6
6
ms.topic: how-to
7
7
ms.custom: mvc, ignite-fall-2021
8
8
ms.date: 05/03/2022
9
9
---
10
10
11
-
# Deploy the Microsoft Sentinel Threat Monitoring for SAP data connector with SNC
11
+
# Deploy the Microsoft Sentinel for SAP data connector with SNC
12
12
13
-
[!INCLUDE [Banner for top of topics](../includes/banner.md)]
13
+
This article shows you how to deploy the **Microsoft Sentinel for SAP** data connector to ingest NetWeaver/ABAP logs over a secure connection using Secure Network Communications (SNC).
14
14
15
-
This article shows you how to deploy the **Microsoft Sentinel data connector for SAP** to ingest NetWeaver/ABAP logs over a secure connection using Secure Network Communications (SNC).
16
-
17
-
> [!IMPORTANT]
18
-
> The Microsoft Sentinel Threat Monitoring for SAP solution is currently in PREVIEW. The [Azure Preview Supplemental Terms](https://azure.microsoft.com/support/legal/preview-supplemental-terms/) include additional legal terms that apply to Azure features that are in beta, preview, or otherwise not yet released into general availability.
19
-
20
-
The Threat Monitoring for SAP data connector agent typically connects to an SAP ABAP server using an RFC connection, and a user's username and password for authentication.
15
+
The SAP data connector agent typically connects to an SAP ABAP server using an RFC connection, and a user's username and password for authentication.
21
16
22
17
However, some environments may require the connection be over an encrypted channel, and client certificates be used for authentication. In these cases you can use SAP Secure Network Communication for this purpose, and you'll have to take the appropriate steps as outlined in this article.
23
18
@@ -182,26 +177,26 @@ For additional information on options available in the kickstart script, review
182
177
183
178
## Next steps
184
179
185
-
Learn more about the Microsoft Sentinel Threat Monitoring for SAP solutions:
180
+
Learn more about the Microsoft Sentinel Solution for SAP:
186
181
187
-
- [Deploy Threat Monitoring for SAP](deployment-overview.md)
188
-
- [Prerequisites for deploying Threat Monitoring for SAP](prerequisites-for-deploying-sap-continuous-threat-monitoring.md)
182
+
- [Deploy Microsoft Sentinel Solution for SAP](deployment-overview.md)
183
+
- [Prerequisites for deploying Microsoft Sentinel Solution for SAP](prerequisites-for-deploying-sap-continuous-threat-monitoring.md)
189
184
- [Deploy SAP Change Requests (CRs) and configure authorization](preparing-sap.md)
190
-
- [Deploy and configure the SAP data connector agent container](deploy-data-connector-agent-container.md)
185
+
- [Deploy and configure the container hosting the SAP data connector agent](deploy-data-connector-agent-container.md)
191
186
- [Deploy SAP security content](deploy-sap-security-content.md)
192
-
- [Deploy the Microsoft Sentinel Threat Monitoring for SAP data connector with SNC](configure-snc.md)
187
+
- [Deploy the Microsoft Sentinel Solution for SAP](configure-snc.md)
193
188
- [Enable and configure SAP auditing](configure-audit.md)
194
189
- [Collect SAP HANA audit logs](collect-sap-hana-audit-logs.md)
195
190
196
191
Troubleshooting:
197
192
198
-
- [Troubleshoot your Microsoft Sentinel Threat Monitoring for SAP solution deployment](sap-deploy-troubleshoot.md)
193
+
- [Troubleshoot your Microsoft Sentinel Solution for SAP deployment](sap-deploy-troubleshoot.md)
199
194
- [Configure SAP Transport Management System](configure-transport.md)
200
195
201
196
Reference files:
202
197
203
-
- [Microsoft Sentinel Threat Monitoring for SAP solution data reference](sap-solution-log-reference.md)
204
-
- [Microsoft Sentinel Threat Monitoring for SAP solution: security content reference](sap-solution-security-content.md)
198
+
- [Microsoft Sentinel Solution for SAP data reference](sap-solution-log-reference.md)
199
+
- [Microsoft Sentinel Solution for SAP: security content reference](sap-solution-security-content.md)
Copy file name to clipboardExpand all lines: articles/sentinel/sap/configure-transport.md
+11-16Lines changed: 11 additions & 16 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -1,19 +1,14 @@
1
1
---
2
2
title: Configure SAP Transport Management System to connect from Microsoft Sentinel | Microsoft Docs
3
-
description: This article shows you how to configure the SAP Transport Management System in the event of an error or in a lab environment where it hasn't already been configured, in order to successfully deploy the Threat Monitoring solution for SAP in Microsoft Sentinel.
3
+
description: This article shows you how to configure the SAP Transport Management System in the event of an error or in a lab environment where it hasn't already been configured, in order to successfully deploy the Microsoft Sentinel Solution for SAP.
4
4
author: MSFTandrelom
5
5
ms.author: andrelom
6
6
ms.topic: how-to
7
7
ms.date: 04/07/2022
8
8
---
9
9
# Configure SAP Transport Management System to connect from Microsoft Sentinel
10
10
11
-
[!INCLUDE [Banner for top of topics](../includes/banner.md)]
12
-
13
-
This article shows you how to configure the SAP Transport Management System in order to successfully deploy the Threat Monitoring solution for SAP in Microsoft Sentinel.
14
-
15
-
> [!IMPORTANT]
16
-
> The Microsoft Sentinel Threat Monitoring for SAP solution is currently in PREVIEW. The [Azure Preview Supplemental Terms](https://azure.microsoft.com/support/legal/preview-supplemental-terms/) include additional legal terms that apply to Azure features that are in beta, preview, or otherwise not yet released into general availability.
11
+
This article shows you how to configure the SAP Transport Management System in order to successfully deploy the Microsoft Sentinel Solution for SAP.
17
12
18
13
SAP's Transport Management System is normally already configured on production systems. However, in a lab environment, where CRs often haven't been previously installed, configuration may be required.
19
14
@@ -72,30 +67,30 @@ The following steps show the process for configuring the Transport Management Sy
72
67
73
68
## Next steps
74
69
75
-
Now that you've configured the Transport Management System, you'll be able to successfully complete the `STMS_IMPORT` transaction and you can continue [preparing your SAP environment](preparing-sap.md) for deploying the Threat Monitoring solution for SAP in Microsoft Sentinel.
70
+
Now that you've configured the Transport Management System, you'll be able to successfully complete the `STMS_IMPORT` transaction and you can continue [preparing your SAP environment](preparing-sap.md) for deploying the Microsoft Sentinel Solution for SAP in Microsoft Sentinel.
76
71
77
72
> [!div class="nextstepaction"]
78
73
> [Deploy SAP Change Requests and configure authorization](preparing-sap.md#import-the-crs)
79
74
80
-
Learn more about the Microsoft Sentinel Threat Monitoring for SAP solutions:
75
+
Learn more about the Microsoft Sentinel Solution for SAP:
81
76
82
-
-[Deploy Threat Monitoring for SAP](deployment-overview.md)
83
-
-[Prerequisites for deploying Threat Monitoring for SAP](prerequisites-for-deploying-sap-continuous-threat-monitoring.md)
77
+
-[Deploy Microsoft Sentinel Solution for SAP](deployment-overview.md)
78
+
-[Prerequisites for deploying Microsoft Sentinel Solution for SAP](prerequisites-for-deploying-sap-continuous-threat-monitoring.md)
84
79
-[Deploy SAP Change Requests (CRs) and configure authorization](preparing-sap.md)
85
-
-[Deploy and configure the SAP data connector agent container](deploy-data-connector-agent-container.md)
80
+
-[Deploy and configure the container hosting the SAP data connector agent](deploy-data-connector-agent-container.md)
86
81
-[Deploy SAP security content](deploy-sap-security-content.md)
87
-
-[Deploy the Microsoft Sentinel Threat Monitoring for SAP data connector with SNC](configure-snc.md)
82
+
-[Deploy the Microsoft Sentinel Solution for SAP data connector with SNC](configure-snc.md)
88
83
-[Enable and configure SAP auditing](configure-audit.md)
89
84
-[Collect SAP HANA audit logs](collect-sap-hana-audit-logs.md)
90
85
91
86
Troubleshooting:
92
87
93
-
-[Troubleshoot your Microsoft Sentinel Threat Monitoring for SAP solution deployment](sap-deploy-troubleshoot.md)
88
+
-[Troubleshoot your Microsoft Sentinel Solution for SAP deployment](sap-deploy-troubleshoot.md)
94
89
95
90
Reference files:
96
91
97
-
-[Microsoft Sentinel Threat Monitoring for SAP solution data reference](sap-solution-log-reference.md)
98
-
-[Microsoft Sentinel Threat Monitoring for SAP solution: security content reference](sap-solution-security-content.md)
92
+
-[Microsoft Sentinel Solution for SAP data reference](sap-solution-log-reference.md)
93
+
-[Microsoft Sentinel Solution for SAP: security content reference](sap-solution-security-content.md)
0 commit comments