<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Regd. Security Audit log in Application Development and Automation Discussions</title>
    <link>https://community.sap.com/t5/application-development-and-automation-discussions/regd-security-audit-log/m-p/7061899#M1503456</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The Security Audit Log does not have filter options for e.g. user groups. You just can use a generic name filter like "BS*" to identify business users. You can activate one profile only.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Perhaps you could rename the business users ... but this is not a good idea at all...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Another very weak workaround would be to work with different applications for both user groups which run different Security Audit Log settings. But any business user would be able to logon to the other application server. Therefore it's not a solution either. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-&amp;gt; I don't see a solution.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyway: In opposite to the system log, the Security Audit Log never gets overwritten. If you provide enought file space you could log everything.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kind regards&lt;/P&gt;&lt;P&gt;Frank Buchholz&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 07 Jul 2010 13:30:55 GMT</pubDate>
    <dc:creator>Frank_Buchholz</dc:creator>
    <dc:date>2010-07-07T13:30:55Z</dc:date>
    <item>
      <title>Regd. Security Audit log</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/regd-security-audit-log/m-p/7061893#M1503450</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have a requirement from business to activate Security audit log for all Business users. We have around 160 Business users but in SM19 I am able to set filters for only 10 users maximum.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also I tried creating 16 profiles and maintained 10 users each but still I was able to activate only one profile at a time.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I put * in the user tab then system starts logging for all users including our ESS users. But we don't want to log for ESS users as there are 1000+ ESS users which will affect the growth of the security log as well the performance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please suggest is there any way to enable security log only for around 160 users using SM19.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Nalla.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Jun 2010 05:58:11 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/regd-security-audit-log/m-p/7061893#M1503450</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2010-06-28T05:58:11Z</dc:date>
    </item>
    <item>
      <title>Re: Regd. Security Audit log</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/regd-security-audit-log/m-p/7061894#M1503451</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE&gt;&lt;CODE&gt;&lt;P&gt;But we don't want to log for ESS users as there are 1000+ ESS users which will affect the growth of the security log as well the performance.&lt;/P&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;P&gt;As per my understanding, security log will grow up to 100 MB. After that it will start overrighing it..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For performance, you can enable selective logging options in Filter setting, instead of all.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rajesh Narkhede&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Jun 2010 06:07:56 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/regd-security-audit-log/m-p/7061894#M1503451</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2010-06-28T06:07:56Z</dc:date>
    </item>
    <item>
      <title>Re: Regd. Security Audit log</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/regd-security-audit-log/m-p/7061895#M1503452</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear Rajeev,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your suggestion. But is there any way we can activate the security log only for 160 users.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Next point is related to file overwriting. I hope the maximum file size we can set is 2 GB. Do you mean to say even the file size to grow is 2 GB, the logs will be over written when it reaches a size of 100 MB.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;P&gt;Nalla.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Jun 2010 07:04:27 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/regd-security-audit-log/m-p/7061895#M1503452</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2010-06-28T07:04:27Z</dc:date>
    </item>
    <item>
      <title>Re: Regd. Security Audit log</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/regd-security-audit-log/m-p/7061896#M1503453</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&amp;gt; As per my understanding, security log will grow up to 100 MB. After that it will start overrighing it..&lt;/P&gt;&lt;P&gt;Your understanding is not correct. You can configure the max size and when reached the log stops recording.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If considered in the user naming convention, then a possible solution to this is changing the RZ10 parameter rsau/user_selection. Read the docs in RZ11 on what it does.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Otherwise, a carefull selection of what to log is the best option - such that successfull RFC logins and calls from ESS are not recorded, but other events and those required for the 160 are. This is certainly possible and anyway recommendable.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Julius&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Jun 2010 08:23:53 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/regd-security-audit-log/m-p/7061896#M1503453</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2010-06-28T08:23:53Z</dc:date>
    </item>
    <item>
      <title>Re: Regd. Security Audit log</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/regd-security-audit-log/m-p/7061897#M1503454</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the update. But rsau/user_selection will not help us because our user ids are similar to our employee ids and we cant use wild card option like RFC* or ESS*.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also in detailed selection option in SM19, i tried removing the RFC related options but still when our ESS users login, it is getting logged.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Our landscape is as below.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ECC 5.0 only Abap system. We have ITS system through which ESS users will login using the portal id. And user type for all users including ESS users is dialog.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there any way we can restrict using user group or licensing type? Will it be a minor development if I ask our ABAPER to create a Z Tcode similar to SU19 by including user group or is there any user exit which can help us to put restriciton on user group wise.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Nalla.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Jun 2010 13:15:55 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/regd-security-audit-log/m-p/7061897#M1503454</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2010-06-28T13:15:55Z</dc:date>
    </item>
    <item>
      <title>Re: Regd. Security Audit log</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/regd-security-audit-log/m-p/7061898#M1503455</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&amp;gt; Thanks for the update. But rsau/user_selection will not help us because our user ids are similar to our employee ids and we cant use wild card option like RFC* or ESS*.&lt;/P&gt;&lt;P&gt;I thought it worth mentioning, to consider for next time...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt; Also in detailed selection option in SM19, i tried removing the RFC related options but still when our ESS users login, it is getting logged.&lt;/P&gt;&lt;P&gt;Possibly it is logging the RFC call and not the RFC authentication. Try the other way around and filter out the successfull logins in SM20N.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt; Is there any way we can restrict using user group or licensing type? &lt;/P&gt;&lt;P&gt;No, not to my knowledge.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt; Will it be a minor development if I ask our ABAPER to create a Z Tcode similar to SU19 by including user group or is there any user exit which can help us to put restriciton on user group wise.&lt;/P&gt;&lt;P&gt;You can make the screen program glow in the dark in a Z-tcode, but the location where the log is &lt;STRONG&gt;written&lt;/STRONG&gt; is not accessible to you and that is where the music is. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The best option is to set a carefully chosen and tested filter in SM19 which covers your requirement without stopping the log, and then use SM20N to filter a subset of that.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can also define the selection methods and reaction methods in transaction RZ21 and then activate them in a monitoring template in RZ20. This way you are faster and will only see what you want.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can also do the same in Solution Manager for the managed systems and have a central monitoring and reaction from there. Then you are on the right track in my opinion.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Julius&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Jun 2010 18:06:02 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/regd-security-audit-log/m-p/7061898#M1503455</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2010-06-28T18:06:02Z</dc:date>
    </item>
    <item>
      <title>Re: Regd. Security Audit log</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/regd-security-audit-log/m-p/7061899#M1503456</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The Security Audit Log does not have filter options for e.g. user groups. You just can use a generic name filter like "BS*" to identify business users. You can activate one profile only.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Perhaps you could rename the business users ... but this is not a good idea at all...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Another very weak workaround would be to work with different applications for both user groups which run different Security Audit Log settings. But any business user would be able to logon to the other application server. Therefore it's not a solution either. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-&amp;gt; I don't see a solution.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyway: In opposite to the system log, the Security Audit Log never gets overwritten. If you provide enought file space you could log everything.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kind regards&lt;/P&gt;&lt;P&gt;Frank Buchholz&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Jul 2010 13:30:55 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/regd-security-audit-log/m-p/7061899#M1503456</guid>
      <dc:creator>Frank_Buchholz</dc:creator>
      <dc:date>2010-07-07T13:30:55Z</dc:date>
    </item>
  </channel>
</rss>

