<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: security audit log in Application Development and Automation Discussions</title>
    <link>https://community.sap.com/t5/application-development-and-automation-discussions/security-audit-log/m-p/12379146#M1994082</link>
    <description>&lt;P&gt;&lt;A href="https://launchpad.support.sap.com/#/notes/1559742" target="test_blank"&gt;https://launchpad.support.sap.com/#/notes/1559742&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://launchpad.support.sap.com/#/notes/1411741" target="test_blank"&gt;https://launchpad.support.sap.com/#/notes/1411741&lt;/A&gt;&lt;/P&gt;&lt;P&gt;You need a S-USER to check notes&lt;/P&gt;</description>
    <pubDate>Wed, 28 Apr 2021 06:07:07 GMT</pubDate>
    <dc:creator>tom_wan</dc:creator>
    <dc:date>2021-04-28T06:07:07Z</dc:date>
    <item>
      <title>security audit log</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/security-audit-log/m-p/12379141#M1994077</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
  &lt;P&gt;We are monitoring security audit log and receiving the events "In program (event id:BUZ) " and "field content changed (event id:CUL)". Please provide the details about these events&lt;/P&gt;</description>
      <pubDate>Tue, 30 Mar 2021 12:23:14 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/security-audit-log/m-p/12379141#M1994077</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2021-03-30T12:23:14Z</dc:date>
    </item>
    <item>
      <title>Re: security audit log</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/security-audit-log/m-p/12379142#M1994078</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;looks to me that someone changed a value in a debugging session. As this is critical from security point of view it is usually logged in the Security Audit Log.&lt;/P&gt;</description>
      <pubDate>Tue, 30 Mar 2021 16:11:34 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/security-audit-log/m-p/12379142#M1994078</guid>
      <dc:creator>jmodaal</dc:creator>
      <dc:date>2021-03-30T16:11:34Z</dc:date>
    </item>
    <item>
      <title>Re: security audit log</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/security-audit-log/m-p/12379143#M1994079</link>
      <description>&lt;P&gt;I agree with your conclusion.&lt;/P&gt;&lt;P&gt;Refer to &lt;A href="https://launchpad.support.sap.com/#/notes/539404" target="_blank"&gt;SAP Note 539404&lt;/A&gt; for details.&lt;/P&gt;</description>
      <pubDate>Mon, 12 Apr 2021 19:39:50 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/security-audit-log/m-p/12379143#M1994079</guid>
      <dc:creator>Peter</dc:creator>
      <dc:date>2021-04-12T19:39:50Z</dc:date>
    </item>
    <item>
      <title>Re: security audit log</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/security-audit-log/m-p/12379144#M1994080</link>
      <description>&lt;P&gt;With Audit Log(SM19/SM20) or System Log(SM21), "critical" activities of debugger will be recorded. This is explained in notes:&lt;/P&gt;&lt;P&gt;1559742 - Insufficient Logging of Debugger Activities&lt;/P&gt;&lt;P&gt;1411741 - Evaluating debugger events in audit log&lt;/P&gt;</description>
      <pubDate>Tue, 13 Apr 2021 01:12:53 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/security-audit-log/m-p/12379144#M1994080</guid>
      <dc:creator>tom_wan</dc:creator>
      <dc:date>2021-04-13T01:12:53Z</dc:date>
    </item>
    <item>
      <title>Re: security audit log</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/security-audit-log/m-p/12379145#M1994081</link>
      <description>&lt;P&gt;ho can i access these notes?&lt;/P&gt;</description>
      <pubDate>Wed, 28 Apr 2021 05:43:32 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/security-audit-log/m-p/12379145#M1994081</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2021-04-28T05:43:32Z</dc:date>
    </item>
    <item>
      <title>Re: security audit log</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/security-audit-log/m-p/12379146#M1994082</link>
      <description>&lt;P&gt;&lt;A href="https://launchpad.support.sap.com/#/notes/1559742" target="test_blank"&gt;https://launchpad.support.sap.com/#/notes/1559742&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://launchpad.support.sap.com/#/notes/1411741" target="test_blank"&gt;https://launchpad.support.sap.com/#/notes/1411741&lt;/A&gt;&lt;/P&gt;&lt;P&gt;You need a S-USER to check notes&lt;/P&gt;</description>
      <pubDate>Wed, 28 Apr 2021 06:07:07 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/security-audit-log/m-p/12379146#M1994082</guid>
      <dc:creator>tom_wan</dc:creator>
      <dc:date>2021-04-28T06:07:07Z</dc:date>
    </item>
    <item>
      <title>Re: security audit log</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/security-audit-log/m-p/12379147#M1994083</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;why these events are critical?&lt;/P&gt;&lt;P&gt;what is " In program (event id:BUZ)" ? Is it indicates the execution?&lt;/P&gt;&lt;P&gt;I have not get the correct idea about these events&lt;/P&gt;</description>
      <pubDate>Fri, 30 Apr 2021 11:25:49 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/security-audit-log/m-p/12379147#M1994083</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2021-04-30T11:25:49Z</dc:date>
    </item>
    <item>
      <title>Re: security audit log</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/security-audit-log/m-p/12379148#M1994084</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;changing a field value in a debugging session can be used, for example, to bypass authorization checks.&lt;/P&gt;&lt;P&gt;Changing the value of SY-SUBRC to 0 after an AUTHORITY-CHECK statement would allow the program to continue even if the necessary authorization is not given. Self-assignment of SAP_ALL would also be possible. Therefore it is critical and to be logged in the Security Audit Log.&lt;/P&gt;</description>
      <pubDate>Fri, 30 Apr 2021 13:54:34 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/security-audit-log/m-p/12379148#M1994084</guid>
      <dc:creator>jmodaal</dc:creator>
      <dc:date>2021-04-30T13:54:34Z</dc:date>
    </item>
  </channel>
</rss>

