<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Security audit log in Application Development and Automation Discussions</title>
    <link>https://community.sap.com/t5/application-development-and-automation-discussions/security-audit-log/m-p/12400549#M1995608</link>
    <description>&lt;P&gt;I have just used SM20 in a test system with two app servers:&lt;/P&gt;&lt;P&gt;&lt;IMG class="migrated-image" src="https://community.sap.com/legacyfs/online/storage/attachments/storage/7/attachments/1916712-sm20.jpg" /&gt;&lt;/P&gt;&lt;P&gt;As you can see above, the Name displays the application server name (I cut the first part of the names). One ends with "73x" and the other one ends with "75".&lt;/P&gt;&lt;P&gt;So, you know what app server was stopped and started.&lt;/P&gt;&lt;P&gt;Why they are stopped and started: most likely a maintenance happened, that required a system (or instance) restart.&lt;/P&gt;&lt;P&gt;In my example, I didn't select a specific instance, so SM20 read the Security Audit Logs from both instances.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Cris&lt;/P&gt;</description>
    <pubDate>Thu, 29 Apr 2021 17:47:38 GMT</pubDate>
    <dc:creator>cris_hansen</dc:creator>
    <dc:date>2021-04-29T17:47:38Z</dc:date>
    <item>
      <title>Security audit log</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/security-audit-log/m-p/12400543#M1995602</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
  &lt;P&gt;While monitoring Security Audit Logs events in ArcSight, the events "Application server started (Event id AUG)" and "Application Server Stopped (Event id AUH)" occurred with no IP address or host name. How will find which application is started or stopped?&lt;/P&gt;</description>
      <pubDate>Tue, 27 Apr 2021 06:33:03 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/security-audit-log/m-p/12400543#M1995602</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2021-04-27T06:33:03Z</dc:date>
    </item>
    <item>
      <title>Re: Security audit log</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/security-audit-log/m-p/12400544#M1995603</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;I think you should contact ArcSight support for this, as it is a 3rd party product.&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Tue, 27 Apr 2021 07:31:26 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/security-audit-log/m-p/12400544#M1995603</guid>
      <dc:creator>tom_wan</dc:creator>
      <dc:date>2021-04-27T07:31:26Z</dc:date>
    </item>
    <item>
      <title>Re: Security audit log</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/security-audit-log/m-p/12400545#M1995604</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;SAL files should be recorded per application server. That means that the entry you see is from the application server itself.&lt;/P&gt;&lt;P&gt;Read more about SAL in &lt;A href="https://blogs.sap.com/2014/12/11/analysis-and-recommended-settings-of-the-security-audit-log-sm19-sm20/" target="_blank"&gt;this SAP Community blog&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Cris&lt;/P&gt;</description>
      <pubDate>Tue, 27 Apr 2021 10:52:43 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/security-audit-log/m-p/12400545#M1995604</guid>
      <dc:creator>cris_hansen</dc:creator>
      <dc:date>2021-04-27T10:52:43Z</dc:date>
    </item>
    <item>
      <title>Re: Security audit log</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/security-audit-log/m-p/12400546#M1995605</link>
      <description>&lt;P&gt;Hello anonymous user, &lt;/P&gt;&lt;P&gt;sadly many log files produced by SAP systems like SAP NetWeaver or SAP HANA do not have all necessary details inside the log files themselves, which would be the baseline for an easy SIEM integration. Here for example you need to enrich the logs with the hostname on which the logs have been generated.&lt;/P&gt;&lt;P&gt;We would love to see more alignment when it comes to logging - both between the components of the same product as well as between different products. Wondering how SAP ETD for example handles this, but my assumption is that SAP spent some effort in log enrichment, correlation, etc. instead of healing the root causes.&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Joe Görlich&lt;/P&gt;</description>
      <pubDate>Tue, 27 Apr 2021 12:05:12 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/security-audit-log/m-p/12400546#M1995605</guid>
      <dc:creator>JoeGoerlich</dc:creator>
      <dc:date>2021-04-27T12:05:12Z</dc:date>
    </item>
    <item>
      <title>Re: Security audit log</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/security-audit-log/m-p/12400547#M1995606</link>
      <description>&lt;P&gt;We have more than one application server. How we will find the application server without IP/host name?&lt;/P&gt;&lt;P&gt;For what purpose, the application server started and stopped?&lt;/P&gt;</description>
      <pubDate>Tue, 27 Apr 2021 12:10:28 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/security-audit-log/m-p/12400547#M1995606</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2021-04-27T12:10:28Z</dc:date>
    </item>
    <item>
      <title>Re: Security audit log</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/security-audit-log/m-p/12400548#M1995607</link>
      <description>&lt;P&gt;On the SAP system you may configure the SAL log file name via profile parameter FN_AUDIT to include the hostname, the SID as well as the instance number. For example FN_AUDIT = audit_$(SAPSYSTEMNAME)_$(INSTANCE_NAME)_$(SAPLOCALHOST)_++++++++###### Then you may enrich the logs in your SIEM to include these values from the log file name during the import.&lt;/P&gt;&lt;P&gt;For this and for details like reasons for restarts of application servers please contact the responsible SAP administrators. &lt;/P&gt;&lt;P&gt;I also recommend to read the blogpost &lt;A href="https://blogs.sap.com/2014/12/11/analysis-and-recommended-settings-of-the-security-audit-log-sm19-sm20/" target="test_blank"&gt;https://blogs.sap.com/2014/12/11/analysis-and-recommended-settings-of-the-security-audit-log-sm19-sm20/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Including SAP security monitoring into the SOC/CDC is a highly valuable step, but this means also to train the analysts to 'speek' SAP. No offence!&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;P&gt;Joe Görlich&lt;/P&gt;</description>
      <pubDate>Wed, 28 Apr 2021 11:20:52 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/security-audit-log/m-p/12400548#M1995607</guid>
      <dc:creator>JoeGoerlich</dc:creator>
      <dc:date>2021-04-28T11:20:52Z</dc:date>
    </item>
    <item>
      <title>Re: Security audit log</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/security-audit-log/m-p/12400549#M1995608</link>
      <description>&lt;P&gt;I have just used SM20 in a test system with two app servers:&lt;/P&gt;&lt;P&gt;&lt;IMG class="migrated-image" src="https://community.sap.com/legacyfs/online/storage/attachments/storage/7/attachments/1916712-sm20.jpg" /&gt;&lt;/P&gt;&lt;P&gt;As you can see above, the Name displays the application server name (I cut the first part of the names). One ends with "73x" and the other one ends with "75".&lt;/P&gt;&lt;P&gt;So, you know what app server was stopped and started.&lt;/P&gt;&lt;P&gt;Why they are stopped and started: most likely a maintenance happened, that required a system (or instance) restart.&lt;/P&gt;&lt;P&gt;In my example, I didn't select a specific instance, so SM20 read the Security Audit Logs from both instances.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Cris&lt;/P&gt;</description>
      <pubDate>Thu, 29 Apr 2021 17:47:38 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/security-audit-log/m-p/12400549#M1995608</guid>
      <dc:creator>cris_hansen</dc:creator>
      <dc:date>2021-04-29T17:47:38Z</dc:date>
    </item>
    <item>
      <title>Re: Security audit log</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/security-audit-log/m-p/12400550#M1995609</link>
      <description>&lt;P&gt;Thank you for your reply,&lt;/P&gt;&lt;P&gt;We are analyzing security audit log in ArcSight SIEM. There are no field for application server's name.&lt;/P&gt;&lt;P&gt;The available details are attached here&lt;/P&gt;&lt;P&gt;&lt;A href="https://answers.sap.com/storage/temp/1916721-application-server.png"&gt;application-server.png&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 30 Apr 2021 04:04:22 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/security-audit-log/m-p/12400550#M1995609</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2021-04-30T04:04:22Z</dc:date>
    </item>
    <item>
      <title>Re: Security audit log</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/security-audit-log/m-p/12400551#M1995610</link>
      <description>&lt;P&gt;How do you forward the SAL logs from the SAP NetWeaver AS ABAP to your SIEM?&lt;/P&gt;</description>
      <pubDate>Fri, 30 Apr 2021 07:56:12 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/security-audit-log/m-p/12400551#M1995610</guid>
      <dc:creator>JoeGoerlich</dc:creator>
      <dc:date>2021-04-30T07:56:12Z</dc:date>
    </item>
    <item>
      <title>Re: Security audit log</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/security-audit-log/m-p/12400552#M1995611</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;We have no  idea about that and monitoring another organization's logs. we are new to the security audit log and monitoring another organization's logs.&lt;/P&gt;&lt;P&gt;There contains about 30+ servers for development, production and testing.&lt;/P&gt;&lt;P&gt;What is the difference between SAP ERP Central Component (ECC) and SAP NetWeaver AS ABAP ?&lt;/P&gt;</description>
      <pubDate>Fri, 30 Apr 2021 08:55:00 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/security-audit-log/m-p/12400552#M1995611</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2021-04-30T08:55:00Z</dc:date>
    </item>
  </channel>
</rss>

