Completing the following procedures allows you to audit the events that occur in the SAP system. These events can be security events, or provisioning events that are a result of the Identity Manager drivers.
Each of the use cases requires that auditing be enabled. Use the following procedures to enable auditing for your SAP environment.
The procedures assume the following items have been completed:
Sentinel 6.1 is installed and configured. For more information, see the Sentinel 6.1 Installation Guide.
Identity Manager 3.6 is installed and configured. For more information, see the Identity Manager 3.6.1 Installation Guide.
Complete the following steps to enable the SAP server for auditing. These steps must be completed on each server you want to audit.
Shut down the SAP instance through the SAPMMC.
Edit the SAP profile <SID>_<INSTANCE_NAME>_<SERVER_NAME>.
For example: DMO_DVEBMGS01_sapserver
UNIX System: /usr/sap/<SID>/SYS/profile
Windows NT System: X:\usr\sap\<SID>\SYS\profile
Do not modify a SAP profile file with a .1 or .2 extension. These are the backup files.
Add the following parameters to the SAP profile file:
(Conditional) Modify the following parameters to the SAP profile if you are using the SAP ABAP trial version to increase memory allocation to the CCMS alert system. The CCMS alert system is disabled by default.
Start the SAP instance through the SAPMMC.
Log in to SAP.
Specify the SAP transaction SM19, then select
from the toolbar.In transaction SM19, click the
tab.Click the
icon to add additional events to Filter 1.Select
to activate the filter.Select all event types, such as logon and master record change.
By default, only System events are selected.
Click the
icon to save and distribute the changes to your SAP servers.Load the
> monitor via transaction RZ20:Run transaction RZ20.
Expand the SAP CCMS Monitor Templates node, then select the Security Monitor set.
Right-click the Security Monitor set, then click
.Repeat Step 1 through Step 8 for each SAP server that you want to enable auditing for.
The SAP CCMS Collector and the SAP XAL Connector need to be added to the Event Source Manager once. The SAP CCMS Collector and the SAP XAL Connector are then displayed as options to select during the configuration procedures.
To import the SAP CCMS Collector and the SAP XAL Connector:
Download the SAP CCMS Collector (SAP_CCMS_6.1r1.clz.zip) from the Sentinel 6.1 download Web site to the server where the Sentinel Control Center is running.
Download the SAP XAL Connector (sap_connector.zip)from the Sentinel 6.1 download Web site to the server where the Sentinel Control Center is running.
Log in to the Sentinel Control Center.
Select
> , then select > .Browse to and select the SAP CCMS Collector SAP_CCMS_6.1r1.clz.zip file, then click .
Follow the remaining prompts, then click
.Repeat steps Step 4 through Step 6, except browse to and select the SAP XAL Connector sap_connector.zip file.
The SAP Java Connector 3 (JCO) library files must be added to the Sentinel server for the SAP XAL Connector to work.
Download the SAP JCO3 library files from the SAP Service Market Place Web site.
The SAP XAL Connector only supports version 3 of the JCO library files. These files are:
sapjco3.jar
Native libraries:
Linux/UNIX: libsapjco3.so
Windows: sapjco3.dll
Log in to the Sentinel Control Center.
(Conditional) If you have more than one Connector, select the Connector, then proceed to the next step.
Select
> , then select the icon .Browse to and select the native library file for your platform.
Repeat Step 4 for the sapjco3.jar file.
For each SAP XAL Connector, you must have one SAP CCMS Collector.
In the Event Source Management live view, right-click the Collection Manager, then click
.Select
in the vendor column.Select
in the column, then click .Select
and for the Collector script, then click .Configure the SAP CCMS Collector for your needs by using the following information:
Click
.Complete the configuration of the SAP CCMS Collector with the following information:
Name: Specify a name for this Collector.
Run: Select whether the Collector is started whenever the Collector Manager is started.
Alert if no data received in specified time period: (Optional) Select this option to send the No Data Alert event to Sentinel if data is not received by the collector in the specified time period.
Limit Data Rate: (Optional) Select this option to set a maximum limit on the rate of data the collector sends to Sentinel. If the data rate limit is reached, Sentinel throttles back on the source in order to limit the flow of data.
Set Filter: (Optional) Specify a filter on the raw data passing through the collector.
Trust Event Source Time: (Optional) Select this option if you trust the Event Source server’s time.
Click
to save the Collector.The SAP XAL Connector can connect to more than one SAP Application.
In the Event Source Management live view, right-click the SAP CCMS Collector, then select
.Select
from the list of installed Connectors, then click .Configure the Connector by specifying the following information:
Name: Specify the name of the Connector to display.
Run: (Optional) Select this option to start the Connector when the Collector Manager starts.
Alert if no data received in specified time period: (Optional) Select this option to send a No Data Alert event to Sentinel if no data is received by the Connector in the specified time period. There is also an option to resend the alert if multiple time periods pass without receiving data from the Connector.
Limit Data Rate: (Optional) Specify the maximum limit on the rate of data this connector can send to Sentinel. If the data limit is reached, Sentinel begins to throttle back on the source in order to limit the flow of data.
Set Filter: (Optional) Specify a filter on the raw data passing through this connector.
Save Raw Data to a file: (Optional) Saves the raw data passing through the Connector to a file for further analysis.
Click
to save the configuration.You must configure one or more event sources for the SAP XAL Connector to poll for SAP system alerts.
In the Event Source Management live view, right-click the SAP XAL Connector, then select
.Specify the Connector parameters for the desired SAP server.
Host Name: Specify the DNS name or IP address of the SAP server that is polled for SAP system alerts.
System Number: Specify the system number of the SAP server.
Client Number: Specify the client number of the SAP server.
User Name: Specify the username of a user with sufficient authorization to perform CCMS administration. This involves the collection and completion of system alerts. It is recommended that a Communication (CPIC) User account be utilized.
Password: Specify the password of the CCMS administrative user.
Language: Specify the two-letter language code. The default is EN for English.
Click
.Specify a monitor set followed by the forward-slash-separated path to the desired monitor object. The default monitor set and object are
.The default monitor path is the most commonly used for system alerts that are related to system auditing.
Click
.Specify a name for the SAP server to be displayed as an event source in the Event Source Manager.
This allows you to identify each SAP server in the Event Source Manager.
Click
.Click
to save the configuration for the new event source object.Right-click the new SAP event source object, then click
to start the event source object.Repeat Step 1 through Step 8 for each SAP server you want to monitor through the same connector.