ARQ: "No Provisioning log available" message in Access Request

Hi,
I am facing a problem wherein, a request is duly provisioned and closed. However, in email notification, I get below message:
Hi XXX,
The Request number : 123 , has been processed by XYZ and the Request is Closed. The details are as follows:
No Provisioning log available
I checked and noticed that, request is duly closed and user is either created/modified in the target system properly. I maintained variable
%PROVISIONING% in the email body but still I am not getting the provisioning details.
The document is active and working absolutely fine in Development system. But here I am not sure why this is not working.
Can anybody help me determine what I am missing?
Regards,
Faisal

Hi Claudio,
Thanks for your reply.
I am on SP#14 and it seems to be applicable and I can try this. Just before doing so, I would like to inform you that this is working in Development system (same settings) but not in QA. To the best of my knowledge, the configuration is same and no modifications have been done in QA alone.
Still I am facing this problem. Do  you think if I implement this in Development system, the existing configurations will not be corrupted?
Also, please see below screen I got from GRFNMW_DBMONITOR_WD tcode
From this I can see, the value in variable "PROVISIONING"  is same as I am receiving in email notification. But not sure if why this is not getting updated. Where as in development, I could see values for this variable properly.
Any suggestion?
Regards,
Faisal

Similar Messages

  • No provisioning logs available

    Hi,
    I am on GRC 10.0 SP14, and configuring GRC with CUA setup. However, have run into an issue
    We have the CUA on Solution Manager, so all the ARM requests are going through CUA, if the user has access to Solman, I mean if the user has a role assigned for SOLMAN system or has SOLMAN added in the systems tab of SU01 everything works fine.
    However, if the user does not have access to the SOLMAN system or does not have SOLMAN added in the system tab, GRC does not update the user and gives a message "No provisioning logs available"
    It is forcing us to create the user in SOLMAN which is totally useless for us.
    Need your help in addressing it.
    Best Regards,
    Silver

    Hi Silver,
    you do not need to create a SOLMAN account.
    In your CUA settings - is CUA marked as global system (active)? Is so, please unmark it there and put individual list of system on second tab (CUA model distribution). It should work,
    Let me know,
    regards,
    Filip

  • ARQ: User details fields mappings problem in Access Request

    Dear All,
    My "User Search Data Sources" are: HR system and LDAP (in this order) and
    "User Details Data Sources" are: HR system, LDAP, GRC Production system and ERP Development system (in this order)
    I could search for the users in HR and LDAP systems correctly. However, the problems I am facing are:
    1. For some users, First Name, Last Name and Email id fields are not getting mapped. Though they are correctly shown in search screen of ARQ. This
        behavior is sporadic and not sure why this is not mapped for some of the users only. But for other users, they are getting mapped correclty!
    2. For some other users selected users from the search result, First Name, Last Name and Email id fields are correctly mapped. However, "Manager" field is empty and not mapped! Though they are correctly maintained in HR system.
    Any idea why this is behaving like this and how to solve this?
    Please advise.
    REgards,
    Faisal

    Hi,
    I could figure out something.
    I have below hierarchy in Active Directory:
    1. OU=Unit1,OU=ABC,DC=123,DC=COM
    2. OU=Unit2, OU=XYZ,DC123,DC=COM
    Unit1 and Unit2 are peers, fall under DC "123" and contain different sub-nodes and users. What is happening is that, if a user and his manager are from same OU (Unit1 for example), it is pulled appropriately.
    In case if a user is in Unit1 and manager is in Unit2, then in this case, manager first and last name is pulled and Manager id field is not filled.
    I could only maintain one of the above entries in LDAP tcode. I dont know how I can maintain peer-OUs in LDAP!
    When I maintained like this:
    OU=Unit1,OU=ABC,DC=123,DC=COM;OU=Unit2, OU=XYZ,DC123,DC=COM
    It give me error: "Entry does not exist".
    It is looking for only one node at at time but can not traverse in multiple peer nodes.
    CAn anyone suggest me on this?
    Regards,
    Faisal

  • GRC Access requests - Audit Log

    Dear All, GRC access requests is noticed with Provisioning failed messages. Access Request Audit Log is displayed with " Log on Failed / CPI - CALL: ThSAPCMRCV " message ( Screen shot enclosed ). Could you please share an insight on these messages and it's resolution. Thanks raj 

    Dear Raj,
    please check with your basis team if the connection to the system works. Basically it seems like you have a connection error as the log on does not work.
    Regards,
    Alessandro

  • Provisioning log is not available on Access request type Change Account

    Hi,
    So I have and issue when I try to submit a request to add a role to a user and I'm trying to understand what could be the reason for it.  Basically I have a workflow that works perfectly for a "Change Request".  I can see that all the steps are executed and then at the end of the request when is suppose to do the actual role assignment I see the message "Provisioning log is not available" then the approval path is finish and the request is closed but when I take a look at the user in the back end the role is not assign.  In terms of access I have try giving SAP_ALL to WF-Batch, nothing shows in Yellow or Red on SLG1 and in SPRO->AC-> User Provisioning -> Define request Type I see "Change Account" with SAP_GRAC_ACCESS_REQUEST.  What else can I do to troubleshoot this error?
    Note: I when back to the  to the AC 10.0 Pre-Implementation From Post-Installation to First Access Request and everythings looks right in terms of the AC Configuration settings.

    Hi Jonathan,
    In my question I was referring to SPRO - GRC/access control/user provisioning / maintain provisioning settings. Those need to be setup (min. global provisioning settings) in order to have role being assigned to user at the end of path.
    Change account option you can see under request type is referring to change user master data(e.g. password/ account validity / details).
    Is this system maintain by CUA? If so settings have to be different (see CUA settings in SPRO)
    I would recommend moving to SP14 as in SP13 there were many bugs, by the way I believe the worst SP ever since beginning of AC is SP13 (maybe due to number), as it destroys many working functionality.
    Filip         

  • GRC 10.1 Access Request - Provisioning Logs Not Available

    Hello guys,
    I am currently running into an issue with the user provisioning logs, the Request Approval notification which is sent to the user are at the end of an approved access request are as below and the Provisioning Logs tab is throwing a timeout error when opened.
    "Hi Varsha Upadhyay (B001193),
    The Request number : 26 , has been processed and the Request is Closed. The details are as follows:
    Provisioning failed; check provisioning log for details.
    Kind regards,
    Access Control Administrator "
    I have checked the table 'GRACREQPROVLOG'  and I see the logs available in the table, When I open the logs for a particular request no I see the below error message under the 'Prov Message' field
    "Type conflict when calling a function module (field length)"
    Similarly in SLG1, I find the following message at the end of each provisioning task that has taken place at the end of a request being approved.
    "Error in RFC; 'Type conflict when calling a function module (field length)'.
    I made sure I gave SAP_ALL to all the RFC ID's and also the WF-BATCH ID's, and the integration scenarios are also defined correctly for all the target system.
    It seems that this error is just preventing the provisioning details from being displayed in the email or in the Provisioning logs, but the user provisioning has actually taken place as expected (viewed in SU01).
    So i'm wondering even after provisioning has actually taken place successfully, why would this error occur. Does anyone know the source for this error message, please let me know what am I missing?

    Hi Narsimha,
    The error seems to be associated with wrong type being passed as a parameter to a function module.
    Can you check the field mapping for your connectors in SPRO? There might be a mismatch happenning there.
    Thanks
    Sammukh

  • ARQ: Default Role Provisioning Problem in Access Request???

    Hi,
    This Business Scenario is very common to have default role(s) assigned to a User at the back end system. So I have the same requirement. In achieving this, I followed below thread here:
    MSMP Issue - GRC 10
    I have also followed the note#1616092  for configuring the Default Roles.
    I have performed below activities:
    1. Param#2009 = YES
    2. Param#2010 = 001
    3. Param#2011 = REQUEST
    4. Param#2013 = SYSTEM
    5. Param#2038 = YES
    6. Imported a test role and NO ROLE OWNER is maintained.
    7.In NWBC->-AM->RM, I maintained a test role as a default.
    Now when I raise a request, application is successfully adding the default role to the request. However, the problem I am facing is that, one Manager approves the request, it is getting failed.
    The Audit Log says that, the STAGE is "Completed" but I could also see "No Agent Found, Cancelling path XYZ (in stage no. 002- GRAC_ROLEOWNER)
    May I know what I am missing here? Why I am getting error and how can I resolve it?
    Please advise.
    Regards,
    Faisal

    Hi Faisal,
    sorry for late resposne I was away traveling.
    default roles are being added by default to access request
    Yes, these roles are added to the access request.
    FN: OK
    and this roles are following your normal paths which I guess assumes manager and role owner.
    How such roles (not having role owner) will follow the normal path Manager->Role Owner if we are enabling routing (Rule ID: GRAC_MSMP_ROUTE_NO_ROLEOWNER) at manager stage level? Can you please help me understand this?
    FN: OK If you enable routing it will go to routing path. I have understood your post as you put in question the behavior of default roles and my point was - they act exacly the same like regular roles.
    - request is going to detour path
    Does it answer my question?
    FN: My point was default roles like all other will go to detur path (assuming you setup it globaly)
    Deafault roles can have separate path (in my case) where only supervisor is approving it.
    Instead of "GRAC_MSMP_ROUTE_NO_ROLEOWNER"  I believe we can have our own rule to have a separate path for such default roles based upon business requirement. Correct me, if required.
    FN; correct
    It was design in way that initiator rule based on role crtivality is sending this rule to separate path without role owner.
    Again, I believe you have enabled your custom rule here to achieve your business requirement instead standard rule id.
    correct
    If you do not have separate path - this role like any other will follow standard path you have.
    Here, I had used a stage called "ZNO_STAGE_PATH" for routing the system line item, which does not have any owner. I used the same path ID for "GRAC_MSMP_ROUTE_NO_ROLEOWNER"Rule ID and it is working fine as of now.
    FN: good
    My question is that, do you think if I don't use "ZNO_STAGE_PATH" as Path ID for "GRAC_MSMP_ROUTE_NO_ROLEOWNER" Rule ID, should it follow the standard Manager->Role Owner path and these default roles get approved and assigned automatically?
    FN: You should use the path ZNO_STAGE_PATH as path ID for routing rule.
    If the role does not have role owner it will not allow you the even get to Role Onwer stage - request will be detured.
    My point from the begining was - instead of using the routing rule - in our case we used separate path for default roles without role owner:) only consisted with manager stage. Again your approach is different but also will work.
    Then which Path ID should I use for "GRAC_MSMP_ROUTE_NO_ROLEOWNER" Rule ID, as it is mandatory?
    Should I use my current path for New/Change Account where at Manager level this was routed due to non availability of role owner?
    Are you asking for default roles?
    Please advise.
    Regards,
    Faisal

  • SP 2010 - Getting "An unexpected error has occurred. " message when accessing Sharepoint site after windows update - Windows 7 Home Premium

    Hi,
    I am new to SP 2010. I have installed Share point 2010 server (trial version) on my Windows 7 Home Premium Laptop by following the below link.
    http://msdn.microsoft.com/en-us/library/ee554869%28office.14%29.aspx
    Everything went fine and was able to see the new sharepoint site after completing configuration wizard. SP2010 Central Admin also worked fine.
    However, after windows update, sharepoint site is not working. I was able to see the site working for more than a day before windows update. SP2010 Central Admin is still working. Executed "PSCONFIG" after
    update but still no good.
    I saw a warning "The Security Token Service is not available" in Central Admin and did some research to fix the issue but nothing worked. 
    Hotfix
    I believe I have all hotfixes mentioned in the forums. Here is the list.
    Windows6.1-KB976462-v2-x64
    Windows6.1-KB982307-x64
    Synchronization
    Windows6.1-KB974405-x64
    MSChart
    SQLSERVER2008_ASADOMD10
    381569_intl_x64_zip
    Windows6.1-KB976462-v2-x64
    Event Viewer
     I can see following log in Event Viewer when accessing site home page.
    Event ID:      8306
    Task Category: Claims Authentication
    Level:         Error
    Website response
    http://localhost:32843/ - "HTTP Error 503. The service is unavailable." 
    http://localhost:32843/Topology/Topology.svc - Works fine
    http://localhost:32843/SecurityTokenServiceApplication/securitytoken.svc - Returns following error. I am unable to see windows authentication in both Windows Features (under IIS -> WWW services -> Security) and IIS website (SharePoint Web Services
    -> IIS -> Authentication).
    HTTP Error 500.0 - Internal Server Error
       Module "WindowsAuthenticationModule" could not be found
    I even tried to uninstall Sharepoint and re-install the same. It worked even second time until it went thro' windows update. App pools are running and Websites are up and running in IIS.
    Can anyone please help me to fix this issue? 
    Thanks

    Hi Henrik,
    Here is the log info.
      <EventID>8306</EventID> 
      <Version>14</Version> 
      <Level>2</Level> 
      <Task>47</Task> 
      <Opcode>0</Opcode> 
      <Keywords>0x4000000000000000</Keywords> 
      <Execution ProcessID="8436" ThreadID="8812" /> 
      <Channel>Application</Channel> 
      <Security UserID="S-1-5-20" /> 
    The content type text/html; charset=utf-8 of the response message does not match the content type of the binding (application/soap+msbin1). If using a custom encoder, be sure that the IsContentTypeSupported method is implemented properly. The first 1024
    bytes of the response were: '<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml"> <head> <title>IIS 7.5 Detailed Error - 500.0 - Internal
    Server Error</title> <style type="text/css"> <!-- body{margin:0;font-size:.7em;font-family:Verdana,Arial,Helvetica,sans-serif;background:#CBE1EF;} code{margin:0;color:#006600;font-size:1.1em;font-weight:bold;} .config_source code{font-size:.8em;color:#000000;}
    pre{margin:0;font-size:1.4em;word-wrap:break-word;} ul,ol{margin:10px 0 10px 40px;} ul.first,ol.first{margin-top:5px;} fieldset{padding:0 15px 10px 15px;} .summary-container fieldset{padding-bottom:5px;margin-top:4px;} legend.no-expand-all{padding:2px 15px
    4px 10px;margin:0 0 0 -12px;} legend{color:#333333;padding:4px 15px 4px 10px;margin:4px 0 8px -12px;_margin-top:0px; border-top:1px solid #EDEDED;border-left:1px solid #EDEDED;border-right:1px solid #969696; border-bottom:1px solid #969696;background:#E7ECF0;font-weight:bold;f'.
    I would like to let you know that I am getting following message when accessing the below link.  I am unable to see windows authentication in both Windows Features (under IIS -> WWW services -> Security)
    and IIS website (SharePoint Web Services -> IIS -> Authentication).
    http://localhost:32843/SecurityTokenServiceApplication/securitytoken.svc
    HTTP Error 500.0 - Internal Server Error
       Module "WindowsAuthenticationModule" could not be found
    Regards

  • FileServer Resource Failed - No storage is available message.

    1st node: TSMCTN (Working Fine)
    2nd node: TSMCTADM (FileServer-(TSMCTNADM)(Cluster Disk 3) Failed)
    First attempt, I try to delete File Server Resource without CAP (Client Access Point), it give me the network name "hostname+FQDN" is already in used
    in the network. 
    2nd I tried deleted CAP and adding back File Server Resource, it still give me the same error message as above.
    3rd, I'm Added back CAP and I tried to use other CAP name when adding a File Server resource in HA wizard, is working fine, but in add storage wizard selection, it prompt me no storage is available message.
    Question I have is -
    1.) Is there a correct steps for Adding a File Server resources in Failover cluster manager? e.g. 1st CAP, 2nd File Server, 3rd Disk Drives...

    Hi Umesh, thanks for your tips, but it does not help me on that. It still prompted " there are no available disks in the cluster "
    Let me elaborate more about this;
    In Storage at Failover Cluster Manager, I have four cluster disks is Online.
    Disk Witness in Quorum
    Cluster Disk 1 = Online
    TSMCTN
    Cluster Disk 2 = Online
    TSMCTNADM
    Cluster Disk 3 = Online
    Cluster Disk 4 = Online
    My question here is, I have a problem to add back File Server resource in tsmctnadm cluster node due to no storage available, is that mean I have to de-attached Cluster Disk 3/4 and Remove from Tsmctnadm cluster in order to get back my file server resource
    and then later add back?

  • CIMC on C210 server throws Error 2001: Service not available message

    I am trying to configure vmware on a brand new C210 server for the first time and the directions say to access the CIMC and load the vmware media. Sounds easy enough except every time I go to the CIMC webpage I recieve an " error 2001: Service not available"  message on every page I go to and none of the server info fields are populated. If I try to make any changes and save my settings the same message pops up and no changes are saved. Almost like the CIMC doesn't recognize the server or hardware. I ran the host update utility just now and upgraded the firmware for everything to the latest version but still no progress. Anyone have this happen or know how I can fix this?
    Thanks in advance!
    Jess

    I got it working on one of the servers, and havent tried the same solutions on any other server.
    What i did was manually adding an IP adress to the management IP, then save the config before rebooting. After rebooting i put it back to get IP from DHCP, and saved the config. After a secound reboot i was able to use the mangement interface without the 2001 error.
    I'm not sure if it will work on the rest of the servers, but it's worth a try
    Regards
    Alex

  • I have reset my email password &now when I sign on I receive "yahoo server is not available" message.

    I have reset my email password &amp;now when I sign on I receive "yahoo server is not available" message.

    Welcome to the Apple Community Michael.
    Firstly, you need to change your details with Apple,  Start here, change your country if necessary and go to manage your account. You may have already done this.
    In order to change your Apple ID or password for your iCloud account on your iOS device, you need to delete the account from your iOS device first, then add it back using your updated details. (Settings > iCloud, scroll down and hit "Delete Account")
    Providing you are simply updating your existing details and not changing to another account, when you delete your account, all the data that is synced with iCloud will also be deleted from the device (but not from iCloud), but will be synced back to your device when you login again.
    In order to change your Apple ID or password for your iCloud account on your computer, you need to sign out of the account from your computer first, then sign back in using your updated details. (System Preferences > iCloud, click the sign out button)
    In order to change your Apple ID or password for your iTunes account on your iOS device, you need to sign out from your iOS device first, then sign back in using your updated details. (Settings > iTunes & App store, scroll down and tap your ID)
    If you are using iMessages or FaceTime, you will also need to log out and into your ID there too.

  • Logging browser type in access.log

    Can weblogic log the browser type such as Apache and Stronghold support? The
    documentation does not mention it but I cannot imagine weblogic lacking this
    functionality.
    Thanks,
    Chuck
    Chuck Carson Sr. Systems Engineer
    [email protected] Change.com
    (858) 720-5040 Solana Beach, CA

    But the servlet which inspects User-Agent property will not be able to log
    every single access which is recorded in the access.log; only those which
    ask for the servlet itself.
    So, if a browser requests your index.html and index.html does not involve
    calling a servlet in order for it to be displayed in the browser, you won't
    be able to log the browser type which requested the page.
    Is the logging within WL going to be enhanced to be more than the current
    and very basic ) implementation?
    "JohnH" <[email protected]> wrote in message
    news:[email protected]..
    You can use the servlet api to retrieve the User-Agent request header toget the
    os and browser type/version. Not quite sure if you can intergrate thisinto the
    access log though. But it can easily be logged elsewhere.
    JohnH
    Chuck Carson wrote:
    Can weblogic log the browser type such as Apache and Stronghold support?
    The
    documentation does not mention it but I cannot imagine weblogic lackingthis
    functionality.
    Thanks,
    Chuck
    Chuck Carson Sr. Systems Engineer
    [email protected] Change.com
    (858) 720-5040 Solana Beach, CA

  • I am getting a Mobile Network Not Available message when trying to make phone calls

    I am getting a Mobile Network Not Available message after phone was drained for a few days. Texting works, internet works, I just cannot make calls.

    Statosphere II
    I've reset most everything, taken out battery/replaced, also set up roaming (all)
    Can't check voicemail either
    Thank you!

  • I am trying to download itunes and keep getting an error message cannot access network location %appdata%

    I am trying to download itunes to windows 7 and keep getting the error message "cannot access network location $APPDATA%\." I have contacted an Apple advisor and was not able to resolve the problem. What to do?

    Since this a problem pertaining to the iTunes application, you might have better luck posting this in the iTunes forum.
    https://discussions.apple.com/community/itunes
    B-rock

  • How to hide the report "No data available" message

    Hi,
    When there are no results from a query execution I would like to hide or at least replace by 0 the "No data available" message.
    I'm working on BI 7 and the query is included in a web template that has a button to export to excel and the objective is that this message doesn't appear in the exported file.
    Do you know if this is possible? If yes please tell me how to do it.
    Regards,
    Ana

    Hi,
    Thanks for your answer.
    I will explain my issue a little bit further.
    I'm working in BI 7 and I create a web template that contains five queries and a button to export all the queries results to an excel file.
    So when executing the query in the portal, depending on the selection criteria inserted some of the queries show the message "No data available" and using the button to export to excel the generated file include that message too. It would be preferable to delete the message in the web and in the excel file, but we need to replace at least in the excel file.
    I don't know if this is possible with some script so if you have some export script example please post it here.   
    If there is some way that when no records exists return zero I think that with a formula I can hide the result but I don't know how to get the 0 value....
    If you can help in some way I would be very grateful.
    Regards,
    Ana

Maybe you are looking for

  • Problem with Displaying MDX in RSCRM_REPORT

    I have read forum messages that the RSCRM_REPORT or RSCRM_BAPI can display a query's MDX statement. I'd tried to enable the "Display MDX Statement" menu option in both transactions.  All I can see is an empty MDX pane at the bottom of screen with men

  • Aggregated Spatial Network Model

    Hi, everyone The paper posted is intended for audiences specializing in GIS and Utility Engineering. Please contact me if interested http://matchlogics.dyndns.org/MatchLogicsNew/Articles/Aggregated%20Spatial%20Network%20Model.pdf

  • Set position of dialogbox depending on screen resolution

    Hi, Could you tell me how I can set the position of a dialogbox container (CL_GUI_DIALOGBOX_CONTAINER)depending on the current screen resolution? Thank you for your help, Fabian

  • OSX mail (Mavericks) fetches even though it's set to manual.

      This is only on my MBP; the iMac works as expected.  ???

  • Usage meter change?

    Can anyone help me with this? My usage about a half hour ago showed 3 hours, 33 minutes. I just checked it again, just kind of randomly, and it shows the usage at 1 hour 45 minutes! I restarted the phone, but it didn't change and am charging it now.