Automate HFM Security extract?

Hi,
HFM Security can be extracted in below methods
1. In workspace > Extract Tasks> Extract Security
2. In Shared service > Application Groups > Rt Click on App Name> Assign Access control > Security Reports
Please let me know if any another ways to Extract security reports.
Can we make Automate the "extracting security reports"?
Thanks in Advance.
Regards,
AVSR

Overview: create a migration definition file for HFM (migrating what information you need, in your case it would be security)... save the file, don't execute. Using cmd prompt, run the LCM utility.bat, supplying it with the information needed as well as the migration file. Automate it by creating a batch file to run your migration file and the utility. Schedule the batch file in task scheduler and it will run whenever needed.
Search for it on the oracle knowledgebase. Theres a lot of info on LCM there.

Similar Messages

  • Role Access : SS Provision Report vs Workspace Security Extract

    Is this normal, we are using EPM 11.1.2 Classic Metadata.
    I Setup a user 123049, provisioned him HFM access to "Reserved" only.
    I also add the same user to a native group called FM_Loc_Reviewer which has provision access to 7 Roles: Approve JE ,Consolidate,Create JE, Load Excel Data, Post JE, Reviewer 1 and Save System Report on Server.
    When i extract security from workspace it has user, 123049 showing up with the combined provision of his id and the group he belongs to. Is this a te way it is suppose to be? In HFM 4.02 it would only show his access
    Thanks
    From Shared Services:
    User@Directory     Role     Inheritance Information
    123049@CompanyA     Approve Journals     FM_Loc_Reviewer
    123049@CompanyA     Consolidate     FM_Loc_Reviewer
    123049@CompanyA     Create Journals     FM_Loc_Reviewer
    123049@CompanyA     Load Excel Data     FM_Loc_Reviewer
    123049@CompanyA     Post Journals     FM_Loc_Reviewer
    123049@CompanyA     Reserved     -
    123049@CompanyA     Reviewer 1     FM_Loc_Reviewer
    123049@CompanyA     Save System Report On Server     FM_Loc_Reviewer
    From Security Extract:
    !ROLE_ACCESS     
    Reviewer 1     123049@CompanyA
    Reserved     123049@CompanyA
    Save System Report On Server 123049@CompanyA
    Create Journals     123049@CompanyA
    Approve Journals     123049@CompanyA
    Load Excel Data     123049@CompanyA
    Consolidate     123049@CompanyA
    Post Journals     123049@CompanyA
    Edited by: user13116744 on Nov 17, 2010 9:58 AM

    This is a sample on the way it looks in mine.... we are using EPM 11.1.3 Classic Metadata
    !ROLE_ACCESS
    Provisioning Manager;admin@mycompany
    Application Administrator;admin@mycompany
    Reviewer 1;myuser@Native Directory
    Reviewer 2;myuser@Native Directory
    Reviewer 1;myuser2@Native Directory
    Reviewer 3;myuser2@Native Directory
    Read Journals;myuser3@Native Directory

  • HFM Security Access

    I have a query on HFM security which I have got from the business.
    1)     Change Doris and Jeanie access to read/display only in HFM production. We should have access to display all data in HFM. – I was not sure which access should I give to get this requirement.
    2)     In Process Management, Please provide “Start”, “Signoff”, “Approve”, “Reject”, “Publish” in process management for Rob Sage, Debbie Indrieri and Doris Lai. Also, Please provide “Promote” and “Submit” Access to Elisa Ha and Jaime Akiyama. – Shall I give Review Supervisor for Rob Sage, Debbie and Doris for this access and not sure which one should I give for Elisa and Jaime.
    Kindly help me in this regards.

    I don't use process management so I will not attempt to answer that part of your question.
    In regards to the first part, you need to go into Shared Services and assign those users the Read permission for the required security classes. For instance, if all entities are tied to a class called ALLENTITIES, you could go into Shared Services, click on projects, click on the project that holds your application, and then click on the application you are managing. Then you would search for the users/groups in question and add them to the selected list, next you would select the classes you want to assign them access to (i.e. ALLENTITIES). On the next screen you will see a grid with users/groups and classes. Go to the cells and set the Access Rights to read. (Be sure to hit the SAVE button when done)
    Alternatively, you can do a security extract from the application, make the updates in the security file, and load that back to the system.

  • HFM security Class

    Hello Guys,
    I've to create around 3500 security classes and same number for the HSS roles I'm wondering if there is a way to bulk upload from a txt or a csv file rather than create everityng manually.
    Thanks
    Fran

    That's right: HFM's security extract has four sections: users/Groups, Security Classes, User/Group Role assignments, and User/Group class access. This can be easily coded outside of HFM and then loaded into the HFM application directly. Please note that security can only be loaded in Merge mode, so if you need to remove a user's access, you must do so from within Shared Services. Do not use the "Clear all security" mode unless you plan to rebuild the application entirely.
    --Chris                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               

  • HFM Security Issue - User can submit a journal by by-passing the approval step even though they are not an admin.

    Hi All,
    I was wondering if anyone could help me with a HFM security issue on HFM 11.1.2.3 we are facing please?
    The problem is that a user can by-pass the journal approval stage and post directly after submitting if Custom4 access control=All is selected.
    If any of the other access controls (None, Read, Promote) for custom 4 are selected, the first two steps of the process are possible -
    input and approval of the journal are possible but final posting of the journal is not and returns an error that says:
    "User does not have the access right to perform this journal task"
    The options I have thought for a workaround are as follows:
    1.       1. Set up a 3rd user called data poster and remove submit journal role from user 1 (data inputter)
    2.       2. Put in place process control and use the various review levels (could be quite time consuming given there is no time left for development)
    Have anyone experienced this before and come up with a quick way of resolving this please? It would be very much appreciated.
    We have two types of users who are associated with groups in HFM and have the appropriate roles assigned to them to complete their tasks,
    they are:
    1. A data Inputter (who inputs base data and journals, who has access to create and submit journals)
    2.   2. A data reviewer (who approves journals)
    The process is as follows:
    1.       1. Logon as Data inputter to submit the journals
    2.       2. Logon as Data reviewer to approve the journals
    3.       3. Logon as Data inputter to post the Journals
    We are using the custom 4 member to identify different adjustment types. At the moment we are able to set it up in such a way whereby Steps 1 and 2 can be completed
    but once it comes back to step 3, we get an error as follows:
    "User does not have the access right to perform this journal task"
    (This error comes about when the access control on custom 4 is set to None, Read, Promote)
    Custom 4 Access Rights looks as follows:
    C4_ADJ01
    C4_ADJ02
    C4_ADJ03
    C4_ADJ04
    HFMDefault
    Read
    Read
    Read
    Read
    HFMLoad
    All
    Promote
    None
    Read
    HFMReview
    Read
    All
    All
    All
    When Custom 4=C4_ADJ01 all 3 steps can be completed but it by-passes step 2 (journal approval).
    For all other Custom 4 we complete steps 1 and 2 successfully but not step 3 due to access issues.
    Roles for the groups that users assigned look like the following:
    Test User Name
    Test User Name
    Access Rights
    1
    Base Data input/Journal Data input
    test_HFMLoad
    Reviewer 1
    Review Supervisor
    Create Journals
    Read Journals
    Database Management
    Enable write back in Web Grid
    Load Excel Data
    Generate Recurring
    Post Journals
    Create Unbalanced Journals
    Manage Templates
    Data Form Write Back from Excel
    Consolidate
    2
    Data Reviewer
    test_HFMReview
    Reviewer 1
    Review Supervisor
    Create Journals
    Read Journals
    Database Management
    Approve Journals
    Consolidate
    Reviewer 2
    Generate Recurring
    Manage Templates
    Create Unbalanced Journals
    Any help or advice would be much appreciated.
    Thanks in advance,
    M.

    Hi All,
    I was wondering if anyone could help me with a HFM security issue on HFM 11.1.2.3 we are facing please?
    The problem is that a user can by-pass the journal approval stage and post directly after submitting if Custom4 access control=All is selected.
    If any of the other access controls (None, Read, Promote) for custom 4 are selected, the first two steps of the process are possible -
    input and approval of the journal are possible but final posting of the journal is not and returns an error that says:
    "User does not have the access right to perform this journal task"
    The options I have thought for a workaround are as follows:
    1.       1. Set up a 3rd user called data poster and remove submit journal role from user 1 (data inputter)
    2.       2. Put in place process control and use the various review levels (could be quite time consuming given there is no time left for development)
    Have anyone experienced this before and come up with a quick way of resolving this please? It would be very much appreciated.
    We have two types of users who are associated with groups in HFM and have the appropriate roles assigned to them to complete their tasks,
    they are:
    1. A data Inputter (who inputs base data and journals, who has access to create and submit journals)
    2.   2. A data reviewer (who approves journals)
    The process is as follows:
    1.       1. Logon as Data inputter to submit the journals
    2.       2. Logon as Data reviewer to approve the journals
    3.       3. Logon as Data inputter to post the Journals
    We are using the custom 4 member to identify different adjustment types. At the moment we are able to set it up in such a way whereby Steps 1 and 2 can be completed
    but once it comes back to step 3, we get an error as follows:
    "User does not have the access right to perform this journal task"
    (This error comes about when the access control on custom 4 is set to None, Read, Promote)
    Custom 4 Access Rights looks as follows:
    C4_ADJ01
    C4_ADJ02
    C4_ADJ03
    C4_ADJ04
    HFMDefault
    Read
    Read
    Read
    Read
    HFMLoad
    All
    Promote
    None
    Read
    HFMReview
    Read
    All
    All
    All
    When Custom 4=C4_ADJ01 all 3 steps can be completed but it by-passes step 2 (journal approval).
    For all other Custom 4 we complete steps 1 and 2 successfully but not step 3 due to access issues.
    Roles for the groups that users assigned look like the following:
    Test User Name
    Test User Name
    Access Rights
    1
    Base Data input/Journal Data input
    test_HFMLoad
    Reviewer 1
    Review Supervisor
    Create Journals
    Read Journals
    Database Management
    Enable write back in Web Grid
    Load Excel Data
    Generate Recurring
    Post Journals
    Create Unbalanced Journals
    Manage Templates
    Data Form Write Back from Excel
    Consolidate
    2
    Data Reviewer
    test_HFMReview
    Reviewer 1
    Review Supervisor
    Create Journals
    Read Journals
    Database Management
    Approve Journals
    Consolidate
    Reviewer 2
    Generate Recurring
    Manage Templates
    Create Unbalanced Journals
    Any help or advice would be much appreciated.
    Thanks in advance,
    M.

  • Monitoring HFM security

    I am using Hyperion 11.1.2.1. and want to monitor some HFM security.
    Is there any way we can find that :
    how many number of users are currently accessing a particular HFM Application and can identify them with their user-details and login-details whenever required ?
    how many number of users are currently accessing the whole HFM Application(Schema) and can identify them with their user-details and login-details whenever required ?
    -----Sunny

    Hi Sunny,
    As the subject was about HFM Security i have given you the query or details which i was aware about HFM.
    1.I mean to say for the tables i have listed in the query there are other columns as well so if you want to get more details then you can select which are all the columns you would require and add them accordingly in the query.
    2.Yeah its possible to get the details about user connected to application even. here is the query you need to change for this as below
    select h.sservername,h.sappname,s.susername,to_char((to_date('01/1900','MM/YYYY')+h.dstarttime-2),'DD/MM/YYYY hh24:mi:ss'),h.lactivitycode,h.sactivitydesc
    from hsv_users_on_system h,hsv_activity_users s
    where h.luserid in s.luserid
    order by sservername
    Also as you were asking for Historical/past login times & details here is the below query which will help you in analysing the things better with activity they did and time they logged in and carried out activity.
    select g.servername,g.appname,to_char((to_date('01/1900','MM/YYYY')+g.starttime-2),'DD/MM/YYYY hh24:mi:ss'),to_char((to_date('01/1900','MM/YYYY')+g.endtime-2),'DD/MM/YYYY hh24:mi:ss'),g.strdescription,s.susername
    from Appname_task_audit g,hsv_activity_users s
    where g.activityuserid in s.luserid (optional if you want to search excluding admin id then you can add this line to existing query at the end [and s.susername not like '%admin%'])
    As the audit logs are specific to applications you need to replace "appname" in the query with your application name for which you wanted to check audit.
    Ex: if your application name is abcd then your query should be something like this
    select g.servername,g.appname,to_char((to_date('01/1900','MM/YYYY')+g.starttime-2),'DD/MM/YYYY hh24:mi:ss'),to_char((to_date('01/1900','MM/YYYY')+g.endtime-2),'DD/MM/YYYY hh24:mi:ss'),g.strdescription,s.susername
    from abcd_task_audit g,hsv_activity_users s
    where g.activityuserid in s.luserid (optional if you want to search excluding admin id/any specific user  then you can add this line/change  existing query at the end [and s.susername not like '%admin%'])
    Hope this helps !!!!
    Thanks
    Amith

  • HFM Data Extract in Task Flow ??

    HI,
    I have a couple of clarification on HFM Data extract in HFM Task flow,
    1) Is Data extraction possible for the predefined accounts in HFM task flow? – in which Accounts & other dimesion memebers needs to be pre-defined so that just on execution of the task flow, HFM needs to extract the data into a text file (i.e., It should not prompt to select the Accounts (as well as other dimension members) each time we extract)
    2) For Data extract purpose, we need some of the HFM members in a different name. So, we planned to create a alias table. In data extraction, Is it possible to select the member names from an custom alias table?
    3) We have to define a specific set of Account values as negative in the extracted data file which is actually positive in HFM. Also, In the extracted data file, We need to have the Account member name same as the existing HFM Account name.
    a.     For instance,
    In HFM:
    Account Member Name in HFM: VUK
    Account Value: 1000
    In the Extracted data file:
    Account Member Name in data file: VUK
    Account Value: -1000
    Is this feasible? If yes, can you explain a bit in detail (like how we can implement this in HFM)
    Thanks,
    Siva

    HI,
    I need a help in HFM Data extraction.
    We use four custom dimensions and our requirement is to get the data extract for the custom members which we need(we need only parent members in custom dimensions).
    But, by default, HFM extracts the data for all base custom members(and not for any parent custom members) - which we dont wish to have.
    Is there any possiblty to extract the data by choosing the custom members for which we need data ??
    Our's is a classic HFM Application in 9.3.1. (in Oracle DB)
    Your response will be highly appreciated !!!
    Thanks,
    Siva

  • HFM Security Class Java API

    Dear All,
    I'm trying to get HFM Security Class info using Java APIs. Recently I was able to connect to the Hyperion Shared Services using the hyperion css.jar java file. Is there a similar jar to access the Security classes and get users, groups and vice versa?
    Any examples would be great as well.

    Thanks for the reply. I was hoping this was not the case...
    In 9.2 I used these objects but I was hoping to move away from this and use provided API's.
    I'm using c# to talk to the object which I expose to java using web services so I guess that is what I'll be using!!!
    Cheers,

  • HFM Security Class and Security

    Hi All my Peers,
    Can any one explain me What is the difference between Security Class and Security

    No offense, but if you don't understand these concepts well enough, your CV should probably be sent a far distance if you are trying to get an experienced consulting position. Understanding security is an important piece to the puzzle, especially when dealing with large amounts of financial data.
    With that said.......
    Security - Generally speaking, the goal of security is to control access to data, objects, programs, etc. In the Hyperion sense, security is managed in multiple different ways :
    - Program Access : Only users who are linked to Hyperion's Shared Services AND have the proper provisioned rights can open a program. (i.e. HFM, Reports, Workspace, FDM, etc, etc, etc.)
    - Provisioning : There are different types of rights per program that a user can have. Provisioning is the act of assigning these rights. (i.e. HFM has multiple rights such as Appliation Administrator, Default, Provisioning Manager, etc.)
    - Data / Object Access : Even if you have the right to enter the program, there is generally another layer of security which controls what you can do. For instance, inside of HFM, you can configure security for objects such as Data Forms and Data Grids. Furthermore, you can limit the user's ability to change or view data for specific entities, accounts, as well as other dimensions.
    - Security Classes : The security classes that you assign in the metadata are used during the act of assigning the Data / Object access controls. Users (and Groups) and assigned View Only, All (Read/Write), or None access to HFM Security Classes.
    This is a ridiculously high level overview. To get a much better understanding, I strongly recommend that you read the product documentation for the specific products you are using. If you are using 11.1.2.1 / HFM, here are a couple of documents that are of value :
    http://docs.oracle.com/cd/E17236_01/epm.1112/hfm_admin.pdf - Administrators guide which has a section on security.
    http://docs.oracle.com/cd/E17236_01/epm.1112/hfm_user.pdf - Users' guide which talked to security in terms of forms/ grids
    General System 11 doc : http://docs.oracle.com/cd/E17236_01/nav/portal_5.htm
    Hope that helps

  • HFM security roles to perform only Extract tasks

    Hello,
    Could any one please tell me what roles I need to give for a user so that he can only perform extract tasks?
    I gave him Extended analytica and advanced user roles.
    But I could see Extract data and Extract journal tasks but not the rest of them.
    I am using HFM 9.3.1.
    Thanks
    Hemanth

    I have provisioned a new native user ID w/ extended analytics and default access but get this error message when running EA from application:
    (-2147208192) (An unknown error has occurred in the HsvData object.)
    Does anyone know what additional security should be provisioned?

  • HFM Application Extract Metadata fails in workspace Web 11.1.2.1

    Hi,
    Problem Description: Extracting Metdata throwing error in HFM Web workspace below is the error details.
    %0
    Show Details:
    Error Reference Number: {BF83D4D3-4C21-4708-B1D6-923288DAB44F}
    Num: 0x800412c4;Type: 0;DTime: 4/16/2012 4:43:45 PM;Svr: HFM server;File: CHITRegistryWrapper.cpp;Line: 52;Ver: 11.1.2.1.000.3082;
    Num: 0x800412c4;Type: 0;DTime: 4/16/2012 4:43:45 PM;Svr: HFM server;File: CHFMwHITRegistry.cpp;Line: 128;Ver: 11.1.2.1.000.3082;
    I had gone through the Doc ID 1156915.1 and followed the steps to troubleshoot the issue. Unfortunately it did not work us issue still exist .Please advice
    Thank you
    Edited by: 877997 on May 1, 2012 9:15 AM

    Ok, sorry for all the questions in advance, but just trying to narrow this down. Are you able to extract other items from the web, i.e. rules, security, member lists, etc.?

  • HFM Security Report Automation?

    Is there a way to automate the running of the HFM (Hyperion Financial Management) Security Report in Shared Services.?
    version: 11.1.2.0
    Is this possible with using Task Automation? ---> If yes please provide details
    If this possible using other reporting tools like HFR, web analysis..etc ---> This is not recommended
    If any other way, Please provide details.
    Thanks All!!
    Regards,
    AVSR

    I think the best way to produce custom security files is using the HFM API. You can use this to report on group memberships and roles and class access. You can read all about it in the Web Developer's Guide Chapter 10. The chapter starts:
    The HFMwSecurity type library contains the HFMwSecurity component. This component
    provides methods that enumerate an application’s security classes, indicate whether a user has
    rights to perform a given task, and return other types of security information.
    I have seen these used to great effect.

  • Automate HFM Task Audit Export

    I am trying to find a way to export the daily task audit info and email it to our auditors on a nightly basis. I figure if I can find out which table in the HFM database contains this audit info I can write something to automatically export it. Does anyone know where I can find this audit task data? I have searched tables in the HFM database and I am unable to determine this.
    Thanks in advance
    HFM Version 11.1.2.2
    DB SQL Server 2008 R2

    Hi there,
    Check the Consultant Tools that are installed with HFM. There is a quite simple tool which allows you to extract the task and data audit without any effort at all.
    Regards,
    Thanos

  • HFM Security Access Edit Logs - Audit

    I have been asked by our internal audit group to provide logs of when users access within HFM have been edited (i.e. added, changed roles, added to groups, etc.). Is there anyone else that has received this request, and more importantly how have you met this request (logs in the system, etc)?
    The only way I have been able to track this is offline via spreadsheets.
    Any/all advice is appreciated.
    Thanks.
    LJ
    Edited by: user8357096 on Mar 23, 2010 7:28 AM

    I have had a couple clients ask for something like this. At least now with user provisioning you can get reports of what the security was, like a snapshot. Then compare it to another time. But this will only tell you part of the story. If you are using groups for example, it possible a user gets added to one group then removed. You would not have access to that change in HFM, it would keep no record of it.
    I would recommend taking and extract and report and archiving them to reference.

  • HFM Security file load error

    Hi All
    I am facing an error while loading the security file in Hyperion Financial Management which reads as:
    The specified item already exists.
    Show Details:
    Error Reference Number: {8D871273-18BC-4103-BF90-8196E3BFAFFC}
    Num: 0x8004021f;Type: 0;DTime: 5/26/2009 12:56:09 AM;Svr: BHIHYPDVH24;File: CHsvSecurityAccess.cpp;Line: 2856;Ver: 9.2.0.0.1380;
    Num: 0x8004021f;Type: 0;DTime: 5/26/2009 12:56:09 AM;Svr: BHIHYPDVH24;File: CHsvSecurityLoadACM.cpp;Line: 2034;Ver: 9.2.0.0.1380;
    Num: 0x8004021f;Type: 0;DTime: 5/26/2009 12:56:09 AM;Svr: BHIHYPDVH24;File: CHsvSecurityLoadACM.cpp;Line: 377;Ver: 9.2.0.0.1380;
    Num: 0x8004021f;Type: 0;DTime: 5/26/2009 12:56:09 AM;Svr: BHIHYPDVH24;File: CHsvSecurityLoadACV.cpp;Line: 209;Ver: 9.2.0.0.1380;
    Has anyone seen this error before? Please let me know the resolution or the cause atleast.
    Thanks in advance
    Rahul

    Hi Thanos,
    Thanks for the reply!!
    Yes, I tried extracting some ownership data for the years 2013 and 2012 and I was successful in loading the data back.
    I extracted the 2013 ownership data updated the year to 2014 and month to Jan and try to load it back then I am getting these errors.. same with for year 2015 and future years..
    The format of the load file looks correct as I was able to load for previous years with the updated ownership data with no errors..
    I killed the HFM process on the app server and tried to load it back but still could not succeed.
    Any suggestions.. please help...
    Thanks again!!

Maybe you are looking for

  • Why can't I use face time with my phone on ios 6?

    Since I updated to ios 6 I can't use my phone number to receive or make face time calls.  I have also lost the use of my primary email address (as it is different to my apple I'd) on face time  too, it says error already in use.  Can anyone help????

  • Link to url using open window

    Hellow to everybody, is it posible to make a get Url action, using a the java script open window, to open this url on a small size, Thanks, David

  • Everything displayed on my ipod is twice its size. what do i do to get everything back to normal?

    everything displayed on my ipod touch is twice the normal size! what do i do to restore back to its normal size?

  • BC4J, OC4J and solaris

    We are developing an JSP application with JDeveloper9i candidate, using BC4J and JBO tags. It works well over Windows NT. Now, we need to deploy that application over Sun Solaris. How I can do that ???. How I install bc4j 5.0 library ?

  • How to Read Outbound Email Activity

    Hello All, I want to read Outbound Email Activity data dynamically after clicking on Sent button. Is there any function module like crm_order_read to read activities, for Outbound Email also. Please suggest me some solution. Regards, Sanjani