<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Multiple Users for Authorization Trace in Application Development and Automation Discussions</title>
    <link>https://community.sap.com/t5/application-development-and-automation-discussions/multiple-users-for-authorization-trace/m-p/11025537#M1898237</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Greetings Julius,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for the suggestion.&lt;/P&gt;&lt;P&gt;Though, kindly clarify the statement "&lt;EM&gt;y&lt;/EM&gt;&lt;SPAN style="color: #333333; font-size: 12px;"&gt;&lt;EM&gt;ou can also mask names. eg. RFC*&lt;/EM&gt;"? &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Did you mean using wildcard(s) on the &lt;EM style="font-size: 12px; color: #333333; background: #ffffff;"&gt;Trace Options&lt;/EM&gt;? Or had you implemented a logic in your custom program to mask the user name?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Thank you.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 23 Apr 2015 06:30:56 GMT</pubDate>
    <dc:creator>former_member456858</dc:creator>
    <dc:date>2015-04-23T06:30:56Z</dc:date>
    <item>
      <title>Multiple Users for Authorization Trace</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/multiple-users-for-authorization-trace/m-p/11025535#M1898235</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Greetings!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would like to inquire if there are alternate transaction(s) or program(s) to enable authorization trace for multiple users. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Currently, we are looking at transaction &lt;EM&gt;STAUTHTRACE&lt;/EM&gt;, and it seems that it only allows single user in the &lt;EM&gt;Trace Options&lt;/EM&gt;. We found that an option to derive for select users is by setting them on the &lt;EM&gt;Restrictions for the Evaluation&lt;/EM&gt; screen and leaving the field &lt;EM&gt;Trace for user only&lt;/EM&gt; as blank. However, this is not the desired approach. If possible, the authorization trace should only be performed for the select users.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 Apr 2015 07:39:02 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/multiple-users-for-authorization-trace/m-p/11025535#M1898235</guid>
      <dc:creator>former_member456858</dc:creator>
      <dc:date>2015-04-22T07:39:02Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Users for Authorization Trace</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/multiple-users-for-authorization-trace/m-p/11025536#M1898236</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In addition to all user and single fully qualified user names, you can also mask names. eg. RFC*&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But there are no select-options for lists.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We had the same challenges and developed our own programs for it to support select-options for lists and patterns which can also mask character sets within the user names. Eg. *RFC*. I could not find any way to do it in ST01.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Julius&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 Apr 2015 20:12:04 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/multiple-users-for-authorization-trace/m-p/11025536#M1898236</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2015-04-22T20:12:04Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Users for Authorization Trace</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/multiple-users-for-authorization-trace/m-p/11025537#M1898237</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Greetings Julius,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for the suggestion.&lt;/P&gt;&lt;P&gt;Though, kindly clarify the statement "&lt;EM&gt;y&lt;/EM&gt;&lt;SPAN style="color: #333333; font-size: 12px;"&gt;&lt;EM&gt;ou can also mask names. eg. RFC*&lt;/EM&gt;"? &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Did you mean using wildcard(s) on the &lt;EM style="font-size: 12px; color: #333333; background: #ffffff;"&gt;Trace Options&lt;/EM&gt;? Or had you implemented a logic in your custom program to mask the user name?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Thank you.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Apr 2015 06:30:56 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/multiple-users-for-authorization-trace/m-p/11025537#M1898237</guid>
      <dc:creator>former_member456858</dc:creator>
      <dc:date>2015-04-23T06:30:56Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Users for Authorization Trace</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/multiple-users-for-authorization-trace/m-p/11025538#M1898238</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jon,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In &lt;EM&gt;STAUTHTRACE&lt;/EM&gt; this option is available for evaluation of trace, you can mention the selected users please refer the below screen.&lt;/P&gt;&lt;P&gt;&lt;IMG class="migrated-image" src="https://community.sap.com/legacyfs/online/storage/attachments/storage/7/jiveimages/690871" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can look for long term trace by activating param auth/authorization_trace with value F. refer sap note 1854561.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks-&lt;/P&gt;&lt;P&gt;Guru&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Apr 2015 07:22:39 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/multiple-users-for-authorization-trace/m-p/11025538#M1898238</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2015-04-23T07:22:39Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Users for Authorization Trace</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/multiple-users-for-authorization-trace/m-p/11025539#M1898239</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Greetings Guru,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for the suggestion.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, the desired approach is to designate select users &lt;SPAN style="text-decoration: underline;"&gt;before&lt;/SPAN&gt; activating the trace. This is to reduce the resource being consumed in the memory while the trace is active.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I believe the User select-option under &lt;EM&gt;Restrictions for the Evaluation&lt;/EM&gt; is to filter the trace results after evaluation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Apr 2015 08:07:42 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/multiple-users-for-authorization-trace/m-p/11025539#M1898239</guid>
      <dc:creator>former_member456858</dc:creator>
      <dc:date>2015-04-23T08:07:42Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Users for Authorization Trace</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/multiple-users-for-authorization-trace/m-p/11025540#M1898240</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Exactly. You can mask the end of the name in the field. Eg. RFC* will trace all users who's names start with RFC.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But you cannot create patterns (eg. *RFC* = all names which contain pattern RFC) and you cannot list names (no select-options nor intervals available). This part we solved with our own program.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Julius&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 24 Apr 2015 09:59:34 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/multiple-users-for-authorization-trace/m-p/11025540#M1898240</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2015-04-24T09:59:34Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Users for Authorization Trace</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/multiple-users-for-authorization-trace/m-p/11025541#M1898241</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jon,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if you want to go up to 5 users, please consider activating param auth/authorization_trace. Once you will activate param with value F, you need to go in STUSOBTRACE and specify up to 5 users. system will trace the activity of only those users which you will specify here in STUSOBTRACE.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks-&lt;/P&gt;&lt;P&gt;Guru&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 24 Apr 2015 11:55:18 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/multiple-users-for-authorization-trace/m-p/11025541#M1898241</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2015-04-24T11:55:18Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Users for Authorization Trace</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/multiple-users-for-authorization-trace/m-p/11025542#M1898242</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Greetings Guru,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How will the activation trace be activated? Is it through a different transaction code?&lt;/P&gt;&lt;P&gt;As per checking in STUSOBTRACE, there are no buttons/options to activate the trace.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 24 Apr 2015 14:32:13 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/multiple-users-for-authorization-trace/m-p/11025542#M1898242</guid>
      <dc:creator>former_member456858</dc:creator>
      <dc:date>2015-04-24T14:32:13Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Users for Authorization Trace</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/multiple-users-for-authorization-trace/m-p/11025543#M1898243</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I suspect the guru meant the "change filter" button and misunderstood it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The system level auth/authorization_trace is not a detailed user based trace. It is a collector mechanism for the transaction contexts to write entries into table USOBT_AUTHVALTRC to record which objects were checked with check values in a transaction. SAP uses it to propose values for SU22. SAP developers process it in transaction CHECKMAN. If maintained / transfered, then they land in SU24 when you process SU25 steps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SAP released parts of this for customers as well to record "original data" for the customer system, but you will be given a warning about paralyzing the system if you turn it on because at every AUTHORITY-CHECK statement it compares the check data in the kernel to the application table. So it is ok for DEV and QAS systems to collect data for SU24, but for larger PROD systems you should be very careful (I do not recommend doing it in PROD).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Julius&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 24 Apr 2015 20:42:15 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/multiple-users-for-authorization-trace/m-p/11025543#M1898243</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2015-04-24T20:42:15Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Users for Authorization Trace</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/multiple-users-for-authorization-trace/m-p/11025544#M1898244</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Greetings Julius,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for the clarification.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As per checking the code for &lt;EM&gt;STAUTHTRACE&lt;/EM&gt;, it seems it uses system functions to perform the trace (C_SET_SWITCH, C_SET_USER, C_SET_MOD_TIME). If I understood correctly, &lt;SPAN style="font-size: 13.3333330154419px;"&gt;C_SET_USER determines the user which the trace will be performed.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We then tried to create a custom version of the program by enabling addition of multiple users in Trace Options.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;As per checking the code, the variable which will contain the user for tracing has a type of CHAR12, which means it may not be able to contain all the set users on the Trace Options. A loop statement was the approach used to enable the passing of all users. However, it was observed that the system function stops the trace for the current user once a new user has been set. Thus, the trace will remain active only to the latest user.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;As the possible users for tracing don't have a definite pattern, using wildcards seems an improbable approach.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With this, kindly advice accordingly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Apr 2015 03:49:21 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/multiple-users-for-authorization-trace/m-p/11025544#M1898244</guid>
      <dc:creator>former_member456858</dc:creator>
      <dc:date>2015-04-27T03:49:21Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Users for Authorization Trace</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/multiple-users-for-authorization-trace/m-p/11025545#M1898245</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You should be careful calling kernel functions directly. The lights could unexpectedly dim and the neighbour's cat might fall over stone dead if you get a parameter wrong..&amp;nbsp; &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We used a different approach (not these C-kernel functions, for the above reasons) but it is a commercial product so it would be inappropriate to wave it around in SCN discussions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You are however welcome to contact me via my Business Card if you are interested.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Julius&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Apr 2015 06:27:56 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/multiple-users-for-authorization-trace/m-p/11025545#M1898245</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2015-04-27T06:27:56Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Users for Authorization Trace</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/multiple-users-for-authorization-trace/m-p/11025546#M1898246</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jon,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can use ST01 and filter with program or transaction instead of multiple users.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;BR /&gt;Kavitha Rajan.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Apr 2015 15:45:35 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/multiple-users-for-authorization-trace/m-p/11025546#M1898246</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2015-04-27T15:45:35Z</dc:date>
    </item>
  </channel>
</rss>

