<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Security audit log for user specific and table in DevOps and System Administration Forum</title>
    <link>https://community.sap.com/t5/devops-and-system-administration-forum/security-audit-log-for-user-specific-and-table/m-p/12683837#M2293</link>
    <description>&lt;P&gt;Hi  @&lt;SPAN class="mention-scrubbed"&gt;cravisap&lt;/SPAN&gt; , &lt;/P&gt;&lt;P&gt;What you want to achieve is not possible by security audit log (standard) events only. I'd either require:&lt;/P&gt;&lt;P&gt;1. A correlation of security audit log events with events recorded in DBTablog (Table change log - requires the table to be activated for logging). For example: SAL Event -&amp;gt; User starts SE16N and subsequentially DU9 event for the loaded table and susequential record edits for the table. This is one of many possible use cases with different possible event sources. &lt;/P&gt;&lt;P&gt;2. Implement BAdIs and user exists where necessary to log custom SAL events as per note 1941568.&lt;/P&gt;&lt;P&gt;3. Adressing such events on the user's endpoints for example with EDR tooling&lt;/P&gt;&lt;P&gt;4. A combination of 1 too 3&lt;/P&gt;&lt;P&gt;Certain SAP security solution and service providers (like us at &lt;A href="https://www.no-monkey.com/" target="_blank"&gt;NO MONKEY&lt;/A&gt; ) provide consultancy and training for such detection scenarios and can guide through the process of implementing such capabilities. &lt;/P&gt;&lt;P&gt;As a general advice: Start with understanding and model your threats and attack surface first to decide on a meaningful prioritization to implement detection capabilities. &lt;/P&gt;&lt;P&gt;BR&lt;/P&gt;&lt;P&gt;Marco&lt;/P&gt;</description>
    <pubDate>Tue, 11 Apr 2023 09:56:41 GMT</pubDate>
    <dc:creator>marco_hammel2</dc:creator>
    <dc:date>2023-04-11T09:56:41Z</dc:date>
    <item>
      <title>Security audit log for user specific and table</title>
      <link>https://community.sap.com/t5/devops-and-system-administration-forum/security-audit-log-for-user-specific-and-table/m-p/12683833#M2289</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
  &lt;P&gt;I would like to activate the security audit log for a set of tables user specific. Is it possible in SM19? If yes, which option i would need to select.&lt;/P&gt;
  &lt;P&gt;Does it capture the changes in DBTABLOG or any other table available?&lt;/P&gt;</description>
      <pubDate>Mon, 10 Apr 2023 01:34:18 GMT</pubDate>
      <guid>https://community.sap.com/t5/devops-and-system-administration-forum/security-audit-log-for-user-specific-and-table/m-p/12683833#M2289</guid>
      <dc:creator>former_member850355</dc:creator>
      <dc:date>2023-04-10T01:34:18Z</dc:date>
    </item>
    <item>
      <title>Re: Security audit log for user specific and table</title>
      <link>https://community.sap.com/t5/devops-and-system-administration-forum/security-audit-log-for-user-specific-and-table/m-p/12683834#M2290</link>
      <description>&lt;P&gt;Hello &lt;SPAN class="mention-scrubbed"&gt;cravisap&lt;/SPAN&gt;,&lt;/P&gt;&lt;P&gt;Please check transaction AUT10 if it's works for you.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Neeraj Jain &lt;/P&gt;</description>
      <pubDate>Mon, 10 Apr 2023 01:49:19 GMT</pubDate>
      <guid>https://community.sap.com/t5/devops-and-system-administration-forum/security-audit-log-for-user-specific-and-table/m-p/12683834#M2290</guid>
      <dc:creator>Neeraj_Jain1</dc:creator>
      <dc:date>2023-04-10T01:49:19Z</dc:date>
    </item>
    <item>
      <title>Re: Security audit log for user specific and table</title>
      <link>https://community.sap.com/t5/devops-and-system-administration-forum/security-audit-log-for-user-specific-and-table/m-p/12683835#M2291</link>
      <description>&lt;P&gt;Hi Neeraj,&lt;/P&gt;&lt;P&gt;Thank you for sharing the information. I do not have AUT10 tcode in my system. I am using SAP BW on oracle system.&lt;/P&gt;&lt;P&gt;I tried to check the data in SCU3 which would display all the data logs especially what data has been changed.&lt;/P&gt;&lt;P&gt;I want to capture the log data for a user specific for a list of tables. For instance, i have 100 users with 1000 tables.&lt;/P&gt;&lt;P&gt;I want to capture USER10 manual activity on TABLE05 data. I dont want to capture all the users information. How to configure it.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Apr 2023 02:13:43 GMT</pubDate>
      <guid>https://community.sap.com/t5/devops-and-system-administration-forum/security-audit-log-for-user-specific-and-table/m-p/12683835#M2291</guid>
      <dc:creator>former_member850355</dc:creator>
      <dc:date>2023-04-10T02:13:43Z</dc:date>
    </item>
    <item>
      <title>Re: Security audit log for user specific and table</title>
      <link>https://community.sap.com/t5/devops-and-system-administration-forum/security-audit-log-for-user-specific-and-table/m-p/12683836#M2292</link>
      <description>&lt;P&gt;Please refer below SAP help link if it works:&lt;/P&gt;&lt;P&gt;&lt;A href="https://help.sap.com/docs/SAP_NETWEAVER_740/56bf1265a92e4b4d9a72448c579887af/6c57bf393b57ac22e10000000a11402f.html?locale=en-US" target="test_blank"&gt;https://help.sap.com/docs/SAP_NETWEAVER_740/56bf1265a92e4b4d9a72448c579887af/6c57bf393b57ac22e10000000a11402f.html?locale=en-US&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Apr 2023 02:18:33 GMT</pubDate>
      <guid>https://community.sap.com/t5/devops-and-system-administration-forum/security-audit-log-for-user-specific-and-table/m-p/12683836#M2292</guid>
      <dc:creator>Neeraj_Jain1</dc:creator>
      <dc:date>2023-04-10T02:18:33Z</dc:date>
    </item>
    <item>
      <title>Re: Security audit log for user specific and table</title>
      <link>https://community.sap.com/t5/devops-and-system-administration-forum/security-audit-log-for-user-specific-and-table/m-p/12683837#M2293</link>
      <description>&lt;P&gt;Hi  @&lt;SPAN class="mention-scrubbed"&gt;cravisap&lt;/SPAN&gt; , &lt;/P&gt;&lt;P&gt;What you want to achieve is not possible by security audit log (standard) events only. I'd either require:&lt;/P&gt;&lt;P&gt;1. A correlation of security audit log events with events recorded in DBTablog (Table change log - requires the table to be activated for logging). For example: SAL Event -&amp;gt; User starts SE16N and subsequentially DU9 event for the loaded table and susequential record edits for the table. This is one of many possible use cases with different possible event sources. &lt;/P&gt;&lt;P&gt;2. Implement BAdIs and user exists where necessary to log custom SAL events as per note 1941568.&lt;/P&gt;&lt;P&gt;3. Adressing such events on the user's endpoints for example with EDR tooling&lt;/P&gt;&lt;P&gt;4. A combination of 1 too 3&lt;/P&gt;&lt;P&gt;Certain SAP security solution and service providers (like us at &lt;A href="https://www.no-monkey.com/" target="_blank"&gt;NO MONKEY&lt;/A&gt; ) provide consultancy and training for such detection scenarios and can guide through the process of implementing such capabilities. &lt;/P&gt;&lt;P&gt;As a general advice: Start with understanding and model your threats and attack surface first to decide on a meaningful prioritization to implement detection capabilities. &lt;/P&gt;&lt;P&gt;BR&lt;/P&gt;&lt;P&gt;Marco&lt;/P&gt;</description>
      <pubDate>Tue, 11 Apr 2023 09:56:41 GMT</pubDate>
      <guid>https://community.sap.com/t5/devops-and-system-administration-forum/security-audit-log-for-user-specific-and-table/m-p/12683837#M2293</guid>
      <dc:creator>marco_hammel2</dc:creator>
      <dc:date>2023-04-11T09:56:41Z</dc:date>
    </item>
  </channel>
</rss>

