BW Performance & troubleshooting role

Dear SDN!
I would like to know is it advisable for an rather inexperienced certified BW person to be deployed solo to a major customer who needs someone experienced to look into the cause of the BW performance and other problems experienced by users and within the system itself?
I reckon this calls for skills in BW360, not part of BW solution scope. As you know my technical background, I may be able to provide some value but as this is BW, and performance characteristic is different than R/3, would it be advisable to be gungho and accept such an assignment solo? Client has its BW support but not able to solve the problems.
Also, what are usually the causes for BW performance issues and cause customers to be unhappy? Appreciate also if you experts could advice on what are the functional aspects to look into or that I should know when handling such issues.
My gut feeling is I don't feel comfortable about this assignment as I would be deployed overseas on contract.
I have mentioned in interview that I am looking for a junior bw role and prefers functional activities. But this is what I get. Being alone in a faraway land without own company people to leverage on seems daunting to me.
Seeking your advice / comments.
bworbust

Hi ,
Before you prepare to travel my suggestion is to go thruogh the implementations that had already gone live because it gives you enough experience to handle the things .You are a certified professional use that experience in the implementations and dont forget that we(SDNer's) are always there to help you.
Regarding the performance issues some of our Experts wrote..
INDEXEs  : The indexes that are created in the fact table for each dimension allow you to easily find and select the data
see http://help.sap.com/saphelp_nw04/helpdata/en/80/1a6473e07211d2acb80000e829fbfe/content.htm
COMPRESSION :  when you load data into the InfoCube, each request has its own request ID, which is included in the fact table in the packet dimension.
This (besides giving the possibility to manage/delete single request) increases the volume of data, and reduces performance in reporting, as the system has to aggregate with the request ID every time you execute a query. Using compressing, you can eliminate these disadvantages, and bring data from different requests together into one single request (request ID 0).
This function is critical, as the compressed data can no longer be deleted from the InfoCube using its request IDs and, logically, you must be absolutely certain that the data loaded into the InfoCube is correct.
see http://help.sap.com/saphelp_nw04/helpdata/en/ca/aa6437e7a4080ee10000009b38f842/content.htm
PARTITIONS :  by using partitioning you can split up the whole dataset for an InfoCube into several, smaller, physically independent and redundancy-free units. Thanks to this separation, performance is increased when reporting, or also when deleting data from the InfoCube.
see http://help.sap.com/saphelp_nw04/helpdata/en/33/dc2038aa3bcd23e10000009b38f8cf/content.htm
Additionally you can see a lot in service.sap.com/bw -> Performance.
You can also find the detailed hardware and tests in a white paper on www.sap.com/bi -> Brochures and Whitepapers -> Scalability with SAP Business Information Warehouse
Hope it helps you......
Regards
Lisa

Similar Messages

  • Network Performance Troubleshooting?

    Greetings all,
    I have a new Sun X4240 server installed as an enterprise backup media server and it's suffering terrible network performance to our new Exagrid disk storage backup appliance. The shares on the Exagrid are mounted as NFS3 shares on the server. If I cable the server directly to the Exagrid appliance, I get a reasonable 450-500 Mb/s on a simple copy from local disk to the NFS share. When I connect them back into our Cisco switch, the performance on the same copy drops to well under 20 Mb/s. A Windows server on the same switch sending traffic to CIFS shares on the Exagrid is performing quite well.
    Does anyone have any ideas how to start troubleshooting this problem? Any other recommendations? Anything will be very welcome!
    Sun X4240, Solaris 10 05/09 X64
    Cisco Catalyst 4506, Supervisor II+ version 12.2(46), (cat4500-ipbasek9-mz.122-46.SG.bin)
    WS-X4548-GB-RJ45 (48 port 10/100/1000BaseT module)
    Many thanks,
    Tim

    I tried forcing the port settings but that still didn't work. In the end it turned out to be a problem with the code on the Cisco router. We tried a different, much cheaper Cisco router and it worked great.

  • Oracle 10g tools for performance/troubleshooting

    Hi
    I want to find some tools for moniting the performance and troublesooting. Any suggest? OEM tuning pack, statspack...etc
    Thanks

    Different tools for different troubles. What trouble are you trying to shoot?
    For general information, try the Performance Tuning guide.

  • JSP Performance Troubleshooting

    I am running into some performance problems with my JSP application. We are using JRun as the server. My page is executing a stored procedure in SQL Server, storing the data from the resultset in an arraylist of objects that I created to store the data and displaying the data in increments of 50 in an html page. I store the arraylist as a session attribute.
    In one particular example the resultset is 278 records. The stored procedure takes about a second to run using the Query Analyzer. The page takes several minutes to display.
    Does anyone know where I should begin to look to improve the performance of this page? I could post the code from the page, but I didn't want to just throw that out there without a specific question about it.
    Thanks for your time.
    Matt

    If you are facing this problem for large amount of records that you are trying to retrive and trying to do tha pagination in jsp then you may also think in this following way to to improve performance.
    I'm not sure how far it will be useful for you but its just my idea.
    1.First dont keep the ArrayList object in session.
    2.dont retrive all records and retrive only current page rows from database that you want to display on the jsp
    3.when you click next for pagination again retrive only current page rows.
    let me know if you need more info

  • How do I use one filed to perform two roles?

    JDeveloper 10.1.3.2, ADF Faces, ADF BC app.
    I have a situation where one field needs to supply a database value and a web service parameter. I have the data controls for both. Currently I also have both on the page, with the same data entered in both, and when I do a submit they both do the correct job; the data is commited, and the web service executes and returns the expected values to the next page.
    How can I either:
    - combine them into the same field
    - have one default to the value of the other as soon as focus leaves it

    Hi,
    in the binding layer, you reference e.g the value of the attribute binding of the database field by the attribute binding of the WebService field. This way, editing the database field automatically populates the WebService field
    Frank

  • Troubleshooting and Introduction for Exchange 2007/2010 AutoDiscover - Details about "Test E-mail AutoConfiguration"

    AutoDiscover is a new feature in Exchange 2007, to provide access to Microsoft Exchange features (OAB, Availability service, UM) for Outlook 2007
    clients or later.
    We can determine whether problems related to AutoDiscover via OWA.
    For example:
    OOF is not working in Outlook Client but it is working in OWA.
    When we realized this issue is not related to Outlook Client side and network side after performing some troubleshooting steps, it should be something
    abnormal on AutoDiscover.
    There is a common tool to check AutoDiscover in Outlook, Test E-mail AutoConfiguration.
    Today, we will introduce AutoDisocver and “Test E-mail AutoConfiguration” in details. Hope it is helpful for AutoDiscover troubleshooting and self-learning.
    1. Differences between “Test E-mail AutoConfiguration” and other tools
    The “Test-OutlookWebServices” cmdlet allows us to test the functionality of the following services:
    Autodisocver
    Exchange Web Services
    Availability Service
    Offline Address Book
    When we run “Test-OutlookWebServices”, it returns all the web services’ states.
    However, some information are useless for some scenarios.
    For example:
    We just want our Exchange 2010 Server working internally. So it is unnecessary to enable Outlook Anywhere.
    However, when we run “Test-OutlookWebServices”, it returns Outlook Anywhere errors because the Outlook Anywhere does not need to been enabled.
    In contrast, using “Test E-mail Autodiscover” is more intuitive.
    If there is any problems, it will return error code from the test result, like 0x8004010F etc. We can do some research from TechNet articles or MS
    KBs.
    Although it is difficult to say where the specific problem is just via the error codes, we can combine with IIS logs to perform troubleshooting and
    find the root of problem.
    2. How to use “Test E-mail AutoConfiguration” Tool
    a. Open Outlook, we can find there is an Outlook Icon at the right bottom of System tray. Holding down “Ctrl” button and right click the Outlook Icon, we will see “Test E-mail
    AutoConfiguration” option. Please see Figure 01.
    Figure 01
    b. Click “Test E-mail AutoCofiguration” and input user name, uncheck the “Use Guessmart” and “Secure Guessmart Authentication” checkboxes, then click “Test”. Please see
    Figure 02.
    Figure 02
    c. “Test E-mail AutoConfiguration” result panel and log panel. Please see Figure 03 and Figure 04.
    Figure 03
    Figure 04
    3. How to understand “Test E-mail AutoConfiguration” result
    According to the Figure 03, we found there are many URLs in the “Test E-mail AutoConfiguration” result panel. Let us understand the details of these
    URLs.
    If we these URLs are not the correct ones, we can re-setting or re-creating them via commands.
    - Internal OWA URL:
    https://vamwan310.vamwan.com/owa/
    OWA internal access.
    - External OWA URL:
    https://mail.vamwan.com/owa/
    OWA external access.
    - Availability service URL:
    https://vamwan310.vamwan.com/EWS/Exchange.asmx
    Free/Busy, OOF and meeting suggestions.
    - OOF URL:
    https://vamwan310.vamwan.com/EWS/Exchange.asmx
    Out of Office access.
    - OAB URL:
    https://vamwan310.vamwan.com/OAB/023ef307-b18a-4911-a52c-de26700f6173/
    OAB access.
    - Exchange Control Panel URL:
    https://vamwan310.vamwan.com/ecp/
    ECP access.
    4. AutoDiscover Tips
    - AutoDiscover Service itself is a web application running on the AutoDiscover virtual directory (not a server service) designed to provide connection information to various
    clients.
    - The AutoDiscover service is automatically installed and configured when CAS role is added to any Exchange Server.
    - AutoDisocver virtual directory is created in IIS within the Default Web Site.
    - A Sercive-Connection-Point (SCP) object is created in AD.
    - The SCP contains a URL to the AutoDiscover service. This is for intranet clients so they do not have to use DNS to locate the AutoDiscover service.
    - In AD this object is located at the following location:
    DC=<domain>, CN=Configuration, CN=Services, CN=Microsoft Exchange, CN=First Organization, CN=Administrative Groups, CN=Exchange Administrative
    Group, CN=Servers, CN=<CAS Name>, CN=Protocols, CN=AutoDiscover, CN=<CAS Name>
    - Setup creates the AutoDiscover URL based on the following structure:
    <CASNetbiosName>.domain.com/AutoDiscover/AutoDiscover.xml
    If a PKI certificate is not already present, a self-signed certificate is installed on the Default Web Site. 
    To help allow this certificate pass the Issues to test it is set up with a Subject Alternative Name containing urls.
    If a PKI certificate is present, that certificate is utilized and configured for use in IIS.
    The Outlook Provider is used to configure separate settings for the Exchange PRC protocol (internal to network), Outlook Anywhere (Exchange HTTP protocol), and WEB:
    EXCH, EXPR, WEB
    The
    EXCH and EXPR setting are vital for the proper configuration of Outlook.
    5. AutoDiscover Workflow
    General Process flow:
    There are various components surrounding the AutoDiscover Service and all are necessary to complete a request. Including IIS, AutoDiscover service
    itself, the provider, and AD.
    a.
    Client constructs service URL and submits Autodiscover Request. First attempt to locate the SCP object in AD. So, DNS is not needed.
    b.
    IIS Authenticates User.
    c.
    Is the Autodiscover service in the appropriate forest?
    + If YES.
        1)
    Parse/Validate Request
        2)
    Is there a provider that can service the Request?
    ++ If YES
          a)
    Config provider processes request and returns config settings.
          b)
    Return config setting to client
    ++ If NO
    Inform client we cannot process request
    + If NO.
    Redirect client to Autodiscover service in the appropriate forest.
    Methods to find Autodiscover services: SCP and DNS
    Domain-joined
    a. Find SCP first.
    The SCP contains the URL to the AutoDiscover service.
    URL: https://CAS01.contoso.com(CAS’ FQDN)/AutoDiscover/AutoDiscover.xml
    If more than one SCP object is found in AD (it means there are multiple CAS servers in the Exchange organization), Outlook client will choose one of the SCP entries that
    are in the same site to obtain the AutoDisocover URL.
    b. If we cannot find SCP object, then Outlook client will use DNS to locate AutoDiscover.
    Outlook parses out the domain (SMTP suffix) via your EmaiAddress, then attempts to connect to the predetermined order of URLs via the suffix.
    For example: If my email address is
    [email protected]
    Outlook tries POST commands to the following order of URLs:
    https://contoso.com/autodiscover/autodiscover.xml
    https://autodiscover.contoso.com/autodiscover/autodiscover.xml
    NOTE: The URLs above is by design, hardcode
    and cannot be changed.
    c.
    If those fail, Outlook tries a simple redirect to another URLs in IIS:
    http://contoso.com/autodiscover/autodiscover.xml
    http://autodiscover.contoso.com/autodiscover/autodiscover.xml
    If none of these URLs work then DNS is most likely not set up correctly.
    We can test that by pinging one of the above URLs.
    If that is successful, we must ensure the URLs contoso.com or autodiscover.contoso.com are actually pointing to the CAS server.
    If the ping fails then there is a chance that DNS is not set up correctly so be sure to check that the URLs are even registered.
    NOTE: If contoso.com is a non-CAS server,
    we should add a Host record with just AutoDiscover. And point that entry to your CAS server that is running AutoDiscover.
    d.
    If still failed, we can use DNS SRV lookup for _autodiscover._tcp.contoso.com, then “CAS01.contoso.com” returned. Outlook will ask permission from the user to continue
    with AutoDiscover to post to https://CAS01.contoso.com/autodiscover/autodiscover.xml
    Non-Domain-joined
    It first tries to locate the Autodiscover service by looking up the SCP object in AD. However the client is unable to contact AD, it tries to locate
    the Autodiscover service by using DNS.
    Then, same as step b, c, d in
    Domain-joined scenario.
    6. How to change the AutoDiscover
    service location order forcibly?
    By default, Outlook client locates AutoDiscover service in that order above.
    We can also change the order forcibly.
    a.
    If we want to locate AutoDiscover service via one of the autodiscover URLs, please running following command in EMS:
    Set-ClientAccessServer -identity <servername> -AutodiscoverServiceInternalUri https://autodiscover.contoso.com/autodiscover/autodiscover.xml(URL
    that you want)
    b. If we want to locate AutoDiscover service via
    SRV record, please follows this KB to set up SRV:
    http://support.microsoft.com/kb/940881
    7. How to check AutoDiscover Healthy
    a. We should make sure the AutoDiscover
    is healthy before using AutoDiscover to perform troubleshooting.
    b.
    We can browse following URL in IE explorer:
    https://autodiscover.vamwan.com/autodiscover/autodiscover.xml
    If it returns “code 600”, that means AutoDiscover is healthy.
    Screenshot as below:
    c. AutoDiscover itself returns errors to the requesting client if the incoming request does not contain the appropriate information to complete a
    request.
    The following table explains the possible errors that could be returned.
    Error   Value
    Description  
    600
    Mailbox not found and a   referral could not be generated.
    601
    Address supplied is not   a mailbox. The provided email address is not something a client can connect to.   It could
    be a group or public folder.
    602
    Active Directory error.
    603
    Others.
    The 600 “Invalid Request” error is returned because a user name was not passed to the service. That is OK for this test because this does confirm
    the service is running and accepting requests.
    d.
    If AutoDiscover service is not working well, I suggest re-building the AutoDiscover Virtual Directory for testing.
    Steps as below:
    1) Running following command in EMS to remove the AutoDiscover VD (we cannot delete it via EMC):
    Remove-AutodiscoverVirtualDirectory -Identity "CAS01\autodiscover(autodiscover.contoso.com)"
    Please refer:
    http://technet.microsoft.com/en-us/library/bb124113(v=exchg.141).aspx 
    2)
    Running following command in EMS to verify whether we have removed the AutoDisocver VD successfully:
    Get-AutodiscoverVirtualDirectory | FL
    Please refer:
    http://technet.microsoft.com/en-us/library/aa996819(v=exchg.141).aspx
    3)
    Running following command in EMS to re-creating a new AutoDiscover VD:
    New-AutodiscoverVirtualDirectory -Websitename <websitename> -BasicAuthentication:$true -WindowsAuthentication:$true
    Please refer:
    http://technet.microsoft.com/en-us/library/aa996418(v=exchg.141).aspx
    8. Common issues
    a. Outlook Disconnection
    Issue and Troubleshooting
    Issue:
    Sometimes the Outlook clients cannot connect to the Exchange server after migrating to a new Exchange server or changing to new CAS. The Outlook clients
    always connect to the old CAS server.
    Troubleshooting:
    To solve this issue, we should change the SCP via following command:
    Set-ClientAccessServer -Identity
    <var>CAS_Server_Name</var> -AutodiscoverServiceInternalUri
    https://mail.contoso.com(newCAS’FQDN)/autodiscover/autodiscover.xml
    b. Autodiscover
    Certificate issue
    Tips on Certificate:
    Exchange requires a certificate to run an SSL protocol such as HTTPS. We can use the certificate that supports subject alternate names (SAN) in Exchange.
    This is to allow the certificate to support resources that have different names, such as Outlook Anywhere and the Autodisocver Web application.
    Issue and Troubleshooting
    Issue:
    We receiver the Certificate Principal Mismatch error when we use a SAN certificate.
    Troubleshooting:
    1) Please determine the FQDN that the client
    uses to access the resource. Steps as below:
    OutlookàToolsàAccount
    SettingsàE-mailàclick
    the Exchange accountàChangeàMore
    SettingsàConnectionàExchange
    Proxy Settingsànote the FQND that list in the
    Only connect to proxy servers that have this principal name in their certificate box.
    2)
    Please using EMS to determine the value for the CerPrincipalName attribute: Get-OutlookProvider
    This command returns the result for the EXPR name.
    3)
    Please re-setting the CertPrincipalName attribute to match the FQDN via following command:
    Set-OutlookProvider EXPR –CertPrincipalName: “msstd:<FQDN the certificate is issued to>”
    9. Resource for reference:
    Autodiscover and Exchange 2007
    http://technet.microsoft.com/en-us/library/bb232838(v=exchg.80).aspx
    White Paper: Understanding the Exchange 2010 Autodiscover Service
    http://technet.microsoft.com/en-us/library/jj591328(v=exchg.141).aspx
    Certificate Principal Mismatch
    http://technet.microsoft.com/en-us/library/aa998424(v=exchg.80).aspx
    Please click to vote if the post helps you. This can be beneficial to other community members reading the thread.

    HI,
     I get following?  when run the test?  user is login to Domain A but accessing exchange in Domain B?

  • How to find cause of db performance problem??

    Hi,
    I am facing continuous performance issues with our database and for that I want to know how I can get information about the following points:
    1- How to find most accessed table(s) or tables with highest hits or top queries is accessing which table(s)?
    2- What indication can tell that a particular table need to be rebuilt?
    3- When to rebuild indexes? and how to know that an indexed need to be rebuilt?
    Your prompt reply is highly appreciated
    Thanks,
    Younis

    Hi,
    a good starting point for investigating poor database performance is AWR (if you have a license for that) or statspack (if you don't). If you need help interpreting it, you can refer to J. Lewis's series on statspack reports (also applies to AWR):
    http://jonathanlewis.wordpress.com/2011/03/09/statspack-reports/
    I have also made a few blog posts on this topic, see http://savvinov.com/tag/awr/
    Regarding your other questions -- countrary to popular belief, rebuilding indexes or tables is seldom helpful. More often, performance problems are caused by bad execution plans (side effects of bind peaking, inaccurate statistics, correlated predicates etc.), data design issues, bad coding practices, not using bind variables etc.
    Database performance topic is a huge topic and obviously cannot fit into a discussion thread. Christian Antognini's book "Oracle Performance Troubleshooting" can provide you a gentle introduction into performance tuning, provided you already have good familiarity with Oracle architecture.
    Or, if you want help with your particular problem, post your AWR report here and briefly describe what your users are unhappy about -- there is a good chance that you get valuable feedback from several renowned experts.
    Good luck!
    Best regards,
    Nikolay

  • SOD Detour in Role Approval Workflow possible?

    Hello GRC Experts,
    we have implemented an Access Request Approval Workflow with a Detour Rule (GRAC_MSMP_DETOUR_SODVIOL).
    The second workflow we are working at is the Role Approval Workflow. Is it possible to use the SOD Detour Rule also in Role Approval Workflow? I didnt find the SOD Detour Rule in the MSMP Role Approval Workflow.
    We would like to implement a following Scenario:
    if the role contains an SOD the request should take Path 1 and if not Path 2.
    Is it in MSMP Standard possible or should we use BRF+ for creating a Detour Rule?
    Thanks,
    Best Regards
    Sabrina

    Hi Sabrina,
    For Access Request workflow, we generally use GRAC_MSMP_DETOUR_SODVIOL to implement routing rule(based on detour condition - risk found). Purpose of same (if I am not mistaken) is to through the request to another level of approver wherein mitigation monitor agent reviews the mitigation performed by role owner stage and approve/reject the request.
    But, when we create a role same is not the condition as we do not mitigate role level risk thus no need to go for mitigation monitor stage. May be you have some business scenario, if you can let us know will be gr8.
    For the rule ID, did you try adding the rule ID ?(you may already know, still would like to cross check with you).
    GRAC_MSMP_DETOUR_SODVIOL under list of rules for "
    Role Approval Workflow" In the screenshot you have shown, just click on ADD feed -
    Rule ID -GRAC_MSMP_DETOUR_SODVIOL.
    Rule description - same as Access request.
    Rule type - Function module based
    rule kind - routing rule.
    Add this and check if it works and let us know the result too.
    Regards,
    Nishant

  • Performance counters for SQL database

    I have this need to carry out a performance test on our SQL database. What are the counters that I need to check and are there any tools that would assist me on this?
    mayooran99

    Hello,
    Please refer to the following series of articles.
    n  Beginners
    http://blogs.msdn.com/b/john_daskalakis/archive/2013/10/07/how-to-troubleshoot-sql-server-performance-issues-with-simple-tools-part-1-how-to-collect-a-detailed-perfmon-trace.aspx
    http://blogs.msdn.com/b/john_daskalakis/archive/2013/10/14/how-to-troubleshoot-sql-server-performance-issues-with-simple-tools-part-2-how-to-analyze-the-perfmon-trace-and-detect-io-bottlenecks.aspx
    http://blogs.msdn.com/b/john_daskalakis/archive/2013/10/21/how-to-troubleshoot-sql-server-performance-issues-with-simple-tools-part-2-how-to-analyze-the-perfmon-trace-and-detect-sql-server-performance-issues.aspx
    http://blogs.msdn.com/b/john_daskalakis/archive/2013/10/30/how-to-troubleshoot-sql-server-performance-issues-with-simple-tools-part-3-the-profiler.aspx

    n  Advanced
    http://blogs.msdn.com/b/john_daskalakis/archive/2013/11/04/specialized-performance-troubleshooting-part-1-how-to-troubleshoot-forwarded-records.aspx
    http://blogs.msdn.com/b/john_daskalakis/archive/2013/11/11/specialized-performance-troubleshooting-part-2-how-to-troubleshoot-memory-problems-in-sql-server.aspx
    http://blogs.msdn.com/b/john_daskalakis/archive/2013/11/18/specialized-performance-troubleshooting-part-3-how-to-identify-storage-issues-at-a-sql-server-box.aspx
    Hope this helps.
    Regards,
    Alberto Morillo
    SQLCoffee.com

  • User Roles in XI

    Hi,
    I would like to restricted my users to access some objects in IR so, i tryed  with the follwoing blog but,
    /people/michal.krawczyk2/blog/2005/05/25/xi-how-to-add-authorizations-to-repository-objects
    when i click the change button in the repository objtct its not performing perticular role.
    i was configured ExchangeProfile parametes and created new user and its roles.
    Would you tell where i done mistake. according to This Blog.
    Thanks
    Mahesh

    Hi,
    Role:   SAP_XI_Developer
    u2022     SAP_XI_DEVELOPER (Composite)
    u2022     SAP_SLD_DEVELOPER
    u2022     SAP_XI_DEMOAPP
    u2022     SAP_XI_DEVELOPER_ABAP
    u2022     SAP_XI_DEVELOPER_J2EE
    Notes:
    No access to the Administration of the XI Tools URL,
       ABAP
     SXI_CACHE to view the cache but not refresh it
     SXMB_MONI
     SPROXY
     SXMB_IFR
     SXMB_ADM
     SLDCHECK
     SLDAPICUST
    SLD
     create/change Technical /Business System
     create Software Catalog (Product/Software Component Version)
     create/change Development (Name Reservation, Content Browser, Class Browser).
    REPOSITORY
     import SWCV (Software Component Version) from SLD
     create new namespace under a SWCV
     create/change new or existing Integration Scenarios and Integration Processes because the Software Component cannot be changed
     create/change new or existing Interface Objects because the Software Component cannot be changed
     create/change new or existing Mapping Objects because the Software Component cannot be changed
     create/change new or existing Adapter Objects
    DIRECTORY
     transfer integration scenario from Repository
     create/change Party
     create/change Service Without Party
     create/change Service Receiver Determination
     create/change Service Interface Determination
     create/change Service Sender Agreement
     create/change Service Receiver Agreement
          RWB
     Component Monitoring
     Message Monitoring
     Performance Monitoring
     Alert Configuration
     Alert Inbox
     Cache Monitoring     Role:   SAP_XI_Configurator
    u2022     SAP_XI_CONFIGURATOR (Composite)
    u2022     SAP_SLD_CONFIGURATOR
    u2022     SAP_XI_BPE_CONFIGURATOR_ABAP
    u2022     SAP_XI_CONFIGURATOR_ABAP
    u2022     SAP_XI_CONFIGURATOR_J2EE
    u2022     SAP_XI_DEMOAPP
    Notes:
    No access to the Administration of the XI Tools URL
       ABAP
     SXI_CACHE to view the cache but not refresh it
     SXMB_MONI
     SPROXY
     SXMB_IFR
     SXMB_ADM
     SLDCHECK
     SLDAPICUST
    SLD
     create/change Technical /Business System
     create Software Catalog (Product/Software Component Version)
     create/change Development (Name Reservation, Content Browser, Class Browser).
    REPOSITORY
     import SWCV (Software Component Version) from SLD
     create new namespace under a SWCV
     create/change new or existing Integration Scenarios and Integration Processes because the Software Component cannot be changed
     create/change new or existing Interface Objects because the Software Component cannot be changed
     create/change new or existing Mapping Objects because the Software Component cannot be changed
     create/change new or existing Adapter Objects
            DIRECTORY
     transfer integration scenario from Repository
     create/change Party
     create/change Service Without Party
     create/change Service Receiver Determination
     create/change Service Interface Determination
     create/change Service Sender Agreement
     create/change Service Receiver Agreement
           RWB
     Component Monitoring
     Message Monitoring
     Performance Monitoring
     Alert Configuration
     Alert Inbox
     Cache Monitoring
    Role:  SAP_XI_ADMINISTRATOR
    u2022     SAP_XI_ADMINISTRATOR (Composite)
    u2022     SAP_ALM_ADMINISTRATOR
    u2022     SAP_ALM_CUSTOMIZER
    u2022     SAP_SLD_ADMINISTRATOR
    u2022     SAP_XI_ADMINISTRATOR_ABAP
    u2022     SAP_XI_ADMINISTRATOR_J2EE
    u2022     SAP_XI_BPE_ADMINISTRATOR_ABAP
    u2022     SAP_XI_DEMOAPP
    Notes: Has access to the Administration of the XI Tools URL (This should be Basis Only)
    ABAP
    u2022         Has access to SXI_CACHE to view the cache but not refresh it
    u2022         Has access to SXMB_ADM
    u2022         Has access to SXMB_MONI
    u2022         Has access to SPROXY
    u2022         Has access to SXMB_IFR
    u2022         Has access to SLDCHECK
    u2022         Has access to SLDAPICUST
    SLD
    u2022         Can create/change Technical /Business System
    u2022         Can create/delete Software Catalog (Product/Software Component Version)
    u2022         Can create/change Development (Name Reservation, Content Browser, Class Browser).
    REPOSITORY
    u2022         Can import SWCV (Software Component Version) from SLD and delete from Repository
    u2022         Can create new namespace under a SWCV
    u2022         Can create/change new or existing Integration Scenarios and Integration Processes
    u2022         Can create/change new or existing Interface Objects
    u2022         Can create/change new or existing Mapping Objects
    u2022         Can create/change new or existing Adapter Objects
           DIR
    u2022         Can transfer integration scenario from Repository
    u2022         Can create/change Party
    u2022         Can create/change Service WithoutParty
    u2022         Can create/change Service Receiver Determination
    u2022         Can create/change Service Interface Determination
    u2022         Can create/change Service Sender Agreement
    u2022         Can create/change Service Receiver Agreement
                                                                                    RWB
    u2022         Can access Component Monitoring
    u2022         Can access Message Monitoring
    u2022         Can access Performance Monitoring
    u2022         Can access Alert Configuration
    u2022         Can access Alert Inbox
    u2022         Can access Cache Monitoring     Role:   SAP_XI_CONTENT_ORGANIZER
    u2022     SAP_XI_CONTENT_ORGANIZER (Composite)
    u2022     SAP_SLD_ORGANIZER
    u2022     SAP_XI_CONTENT_ORGANIZER_ABAP
    u2022     SAP_XI_CONTENT_ORGANIZER_J2EE
    Notes:    No access to the Administration of the XI Tools URL
    ABAP
    u2022         No access to SXI_CACHE
    u2022         No access to SXMB_ADM
    u2022         No access to SXMB_MONI
    u2022         No access to SPROXY
    u2022         Has access to SXMB_IFR
    u2022         No access to SLDCHECK
    u2022         No access to SLDAPICUST
    SLD
    u2022         Can create/change Technical /Business System
    u2022         Can create/delete Software Catalog (Product/Software Component Version)
    u2022         Can create/change Development (Name Reservation, Content Browser, Class Browser).
             REPOSITORY
    u2022         Can import SWCV (Software Component Version) from SLD and delete from Repository
    u2022         Can create new namespace under a SWCV
    u2022         Can create/change new or existing Integration Scenarios and Integration Processes
    u2022         Can create/change new or existing Interface Objects
    u2022         Can create/change new or existing Mapping Objects
    u2022         Can create/change new or existing Adapter Objects
           DIR
    u2022         Can transfer integration scenario from Repository
    u2022         Can create/change Party
    u2022         Can create/change Service WithoutParty
    u2022         Can create/change Service Receiver Determination
    u2022         Can create/change Service Interface Determination
    u2022         Can create/change Service Sender Agreement
    u2022         Can create/change Service Receiver Agreement
                                                                                    RWB
    u2022         Can access Component Monitoring
    u2022         Can access Message Monitoring
    u2022         Can access Performance Monitoring
    u2022         Can access Alert Configuration
    u2022         Can access Alert Inbox
    u2022         Can access Cache Monitoring
    Role:  SAP_XI_DISPLAY_USER
    u2022     SAP_XI_DISPLAY_USER (Composite)
    u2022     SAP_SLD_GUEST
    u2022     SAP_XI_DISPLAY_USER_ABAP
    u2022     SAP_XI_DISPLAY_USER_J2EE
    Notes: No access to the Administration of the XI Tools URL
    ABAP
    u2022         Has access to SXI_CACHE but cannot refresh cache
    u2022         Has display access to SXMB_ADM
    u2022         Has access to SXMB_MONI
    u2022         Has access to SPROXY
    u2022         Has access to SXMB_IFR
    u2022         Has access to SLDCHECK
    u2022         No access to SLDAPICUST
    SLD
    u2022         Cannot create/change Technical /Business System
    u2022         Cannot create/delete Software Catalog (Product/Software Component Version)
    u2022         Cannot create/change Development (Name Reservation, Content Browser, Class Browser).
    REP
    u2022         Cannot import SWCV (Software Component Version) from SLD and delete from Repository
    u2022         Cannot create new namespace under a SWCV
    u2022         Cannot create/change new or existing Integration Scenarios and Integration Processes
    u2022         Cannot create/change new or existing Interface Objects
    u2022         Cannot create/change new or existing Mapping Objects
    u2022         Cannot create/change new or existing Adapter Objects
           DIR
    u2022         Cannot transfer integration scenario from Repository
    u2022         Cannot create/change Party
    u2022         Cannot create/change Service WithoutParty
    u2022         Cannot create/change Service Receiver Determination
    u2022         Cannot create/change Service Interface Determination
    u2022         Cannot create/change Service Sender Agreement
    u2022         Cannot create/change Service Receiver Agreement                                                                               
    RWB
    u2022         Can access Component Monitoring
    u2022         Can access Message Monitoring
    u2022         Can access Performance Monitoring
    u2022         Can access Alert Configuration
    u2022         Can access Alert Inbox
    u2022         Can access Cache Monitoring     Role:   SAP_XI_MONITOR
    u2022     SAP_XI_MONITOR (Composite)
    u2022     SAP_SLD_GUEST
    u2022     SAP_XI_BPE_MONITOR_ABAP
    u2022     SAP_XI_DEMOAPP
    u2022     SAP_XI_MONITOR_ABAP
    u2022     SAP_XI_MONITOR_J2EE
    Notes: No access to the Administration of the XI Tools URL
    ABAP
    u2022         Has access to SXI_CACHE and refresh cache
    u2022         No access to SXMB_ADM
    u2022         Has access to SXMB_MONI
    u2022         Has access to SPROXY
    u2022         Has access to SXMB_IFR
    u2022         No access to SLDCHECK
    u2022         No access to SLDAPICUST
    SLD
    u2022         Cannot create/change Technical /Business System
    u2022         Cannot create/delete Software Catalog (Product/Software Component Version)
    u2022         Cannot create/change Development (Name Reservation, Content Browser, Class Browser).
    REP
    u2022         Cannot import SWCV (Software Component Version) from SLD and delete from Repository
    u2022         Cannot create new namespace under a SWCV
    u2022         Cannot create/change new or existing Integration Scenarios and Integration Processes
    u2022         Cannot create/change new or existing Interface Objects
    u2022         Cannot create/change new or existing Mapping Objects
    u2022         Cannot create/change new or existing Adapter Objects
           DIR
    u2022         Cannot transfer integration scenario from Repository
    u2022         Cannot create/change Party
    u2022         Cannot create/change Service WithoutParty
    u2022         Cannot create/change Service Receiver Determination
    u2022         Cannot create/change Service Interface Determination
    u2022         Cannot create/change Service Sender Agreement
    u2022         Cannot create/change Service Receiver Agreement                                                                               
    RWB
    u2022         Can access Component Monitoring
    u2022         Can access Message Monitoring
    u2022         Can access Performance Monitoring
    u2022         Can access Alert Configuration
    u2022         Can access Alert Inbox
    u2022         Can access Cache Monitoring

  • Structural role assignment in SRM

    Hi all,
    This is my first post, I hope I will find an answer to my question.
    We are about to implement SRM and our security strategy is to use the structure to assign the roles to the position and to the org unit. We did this in our ECC system and it works as expected, however in SRM the relationship between the employees and the user ID via Infotype 0105 doesn't exist. In the SRM structure the relation is with the BP, does anyone know if there is a program like PFCG_TIME_DEPENDENCY in SRM to update the users roles base on their position assignment.
    I tried many things like USER_GEN, BBP_BP_OM_INTEGRATE but it doesn't seem to do what I'm looking for. Also, does anyone know what is the purpose of attribut role. I tried to assign role to this attribut but it seems useless.
    Thanks,

    Hi regarding  SRM indirect role assignment,
    Are you using organizational management /structure from HR or you have built/configured the OM/sturcture  in SRM?
    are  you taking a simple PFCG role and performing indirect role assignment to a position.
    BP configuration needs to be done , I remember the configurator assigning roles when doing that, I dont remember how the position was linked from BP?
    BP documentation for SRM
    http://help.sap.com/saphelp_srm50/helpdata/en/5d/55b158638111d2b408006094b92d37/frameset.htm
    I forgot to ask?
    Did you check if an userid is mapped to the position ( Meaning the test user )
    Please check the below link for related  information
    SRM - ppoma_bbp: how to link central person with the position
    Edited by: Franklin Jayasim on Jul 28, 2010 10:23 PM

  • Role level mitigating controls not affecting position level reports

    Hi,
    Here's the problem we're having with mitigating controls:
    When I assign a mitigating control to a role, it correctly mitigates the risk when we perform a role level SoD analysis.  However, when we perform a position level analysis, the same role shows up again in the report as not mitigated.  Anyone else running into this issue?  We are on CC5.2 with SP4.  Is this fixed in later SPs?
    Simple Example:
    Role ABC has conflicting tcodes FBV0 and FBVB.  We applied a mitigating control to this role and it doesn't show up anymore on the role level reports.
    When running the position level SoD analysis, position number 50010000 contains role ABC and the same conflict shows up again even though the conflict is entirely within Role ABC and not with other roles that are in position 50010000.
    Thanks,
    Robert

    All,
    I opened a customer message with SAP and it seems that this issue is a limitation with CC 5.2  Mitigating at the role level will will not follow through to the position level reports.  However, it seems that it will follow through to the user level as long as you have configured it under the Configuration->Additional Options tab.  There is a setting there that will allow rule level mitigating controls to take affect at the user level.
    Thanks,
    Robert

  • Unable to perform indirrect user assignment reconciliation

    Hello,
              I have created an indirect role assignment (position based) in PFCG through the organizational management tab. But when i trigger the reconcilliation, the status shows up as complete (green) but when i go one step back to the user tab, the system pops up a message saying the assignment is not complete. The assignment does not work. Can you please suggest if i am missing something.
    Just to be sure, i have run the user master reconciliation as well but this not help.
    Regards,
    Prashant

    Hi,
    Have you checked if user has a active personnel number with a valid IT0105 subtype 0001 assigned?
    Also try reconciling the user's position via report RHPROFL0
    PS: You can also perform indirect role assignment ( to user's position) via transactions PO13 or PP01 via OM infotype 1001 and relationship B007
    Thanks,
    Sandipan

  • ERM overwrites backend role without warning.

    We are on version 5.3 - SP13.
    I have uploaded roles to our ERM installation. The upload was performed with the bulk download file collected via the /VIRSA/RE_DNLDROLES - program in backend in combination with the role information file which we have maintained with relevant role attribute data. The Org-level file is not relevant for us since our security concept does not include derived roles.
    When we took the tool into use we discovered that even though the upload was completed successfully there are examples of roles which are created with non-identical content (authorization objects and field values) from the actual backend roles.
    When we started performing changes to those roles, not identical in ERM and backend, via ERM, the system did not give a warning of the inconsistency but just directly overwrote the backend role with the incorrect ERM version of the role. 
    Anyone else with experience with the same error?

    Thanks Raghu and Frank for your replies!
    What I did was:
    1. Yes: I imported roles into ERM.
    I made the assumption that the roles would be created correctly contentwise in ERM since the upload is done from a file which is directly downloaded from the backend system. I probably have some issues in this department as you have both already pinpointed.
    Maybe the lack of including the OrgData file in the upload is the source for the error...?
    Sorry about my stupid question Raghy, but how do I maintain the Org Data file? I see that the data columns are:
    Rolename - Derived Org Level - From value - To value
    Do I really have to maintain this manually when I do not have derived roles....?
    (I see that there is a lot of org level values included in the system already from the initial upload.)
    Do you have any general advise on how I can easily verify that my roles are created with correct content in ERM compared with the backend system?
    2. Yes/No: I agree that if you generate a role from ERM, then you must know what you do and expect the backend role to be overwritten.
    What I did was that I opened PFCG from ERM to make changes to the role.
    I have in earlier test scenarios received a system messages at this point in the process asking me if I really want to overwrite the backend role. To my understanding this message is supposed to appear in any case when the ERM role is different from the backend role. Then I have the possibility to cancel the opening of PFCG and synchronize the role from backend to ERM before I continue with actually opening PFCG and performing the role changes.
    I do not know why I get this message sometimes, but not always.....
    Best regards
    Kari

  • Portal role/ group provisioning via CUP

    HI Gurus,
    We are planing to perform portal role (EP 7 )provisioning via CUP. Is there any config guide available for this which we can follow.
    Thanks
    Ani

    This guide might be of help:
    http://www.sdn.sap.com/irj/bpx/go/portal/prtroot/docs/library/uuid/502a14db-6261-2c10-22b5-95117ab0e5ed
    Regards,
    Luis

Maybe you are looking for

  • My app store doesn't download anything i don't know how to fix this problem

    my app store doesn't download anything i don't know how to fix this problem

  • Since updating my computer i cannot install or open itunes, help!!!

    Since updating important installations on my computer i cannot open itunes. I unistalled it after hours of trying and now i can even install the software. very frustrated and confused can anyone help??

  • PI sheet function module call

    Hi, we are using PI sheets for process orders. Let us say, there are four fields on PI sheet for which data needs to be entered. user enters data in first three fields. For the last field (i.e 4th field), value is based on first field and another val

  • Install On Windows Server 2003

    I download Oracle 9i release 2 for windows server 2003 from http://otn.oracle.com/software/products/oracle9i/htdocs/win2k3soft.html. After extracting the zip files I dont see an install files. The files that I downloaded look like they are for a patc

  • Application unable to connect to databse after some time

    The problem we are facing is that after some time the application seems to be unable to connect to the database. The only way we have been able to clear the issue is by re starting the application servers. Below is the information I see in my logs an