Fire Fighter Logs details in /n/virsa/vfat

Hi,
When i see the Fire Fighter logs through the Tcode /n/virsa/vfat, i am just able to know what tcode was used by a particular user and at what time and date.
Now if he has used SE38, i do not get the information of what report or program did he run in SE38. Similarly for SE16n I will not have the information of what table was used and modified.
So is it possible to know the complete details of the activity that user has done throught the FIreFighter.
Please help.
Regards
Anubhav

In the case of SE16 you can see the generated selection-screen program for that table being submitted both in STAD if you are fast enough (i.e. before the aggregation takes place) and in the security audit log (SM20N - which is actually the correct tool to rely on). They will show reports from SA38 etc as well.
However SE16N does not generate and submit report type programs so you cannot know which table was accessed. The only little "skidmark" it will leave behind is the memory id entries of the tabname selection parameter and SQL performance traces, but GRC does not access this data and it is unreasonable to assume that the history of these memory ids has been activated on the server side.
If worst comes worse you will be able to find out the table though - latest with a thumb-screw or bamboo under the finder nails... 
Cheers,
Julius

Similar Messages

  • Change History in Fire Fighter Log Report.

    Hi Experts,
    Changes made by fire fighters were not recorded in the fire fighter log reports.I have gone thru a thread in the forum,there was mentioned that the issue had been reported to the SAP.Please let me know, if there is any update on the issue from SAP.
    Thanks,
    Mukesh

    FF Logs can be recorded when the changes done with FF id. Without FF id no Support / IT user should be allowed.
    If you want to change the configuration it has to be done via FireFigher only. Otherwise you get the log from SM20, if its been configured.

  • Fire FIghter Log Issue

    Hi Gurus,
    I have an issue with Fire fighter Log Job...I have Scheduled the Job...ZFATBAK with a period One hour....
    When i tried to look at the Log in Fire Fighter tool...It has the below message...
    BACKGROUND JOB WAS NOT SCHEDULED/LOG & FILE NOT YET GENERATED.
    Please help ...

    Hi,
    Guess I try to help you here. Can you please check the following;
    1.FATBAK job ? ( Via SM37)
    2. Go to the configuration table in the FF (Logon to FF and one of the tabs--)
    Please let meknw the what you see.
    Thanks

  • Approve multiple Fire Fighter logs in once

    Dear all,
    we had to start the program GRAC_EAM_LOG_SYNC_TIMEBASED to start the FF-Log creation and the e-mail notification for the FF-Controller.
    The result is that there are more then 400 FF-logs are to check/approve now.
    Does someone know a program to approve these log in an masse change?
    BR
    Melanie

    Hi Denis,
    sorry for the late answer. We had Connection Problems between our Company and  SCN.
    Here the steps how Í could execute the Report for FF-logs which were not created, but must be there.
    IF you will see the FF-log approval file via UI -> Access Management ->Search Request -> Switch selection criteria "Proces ID" to "Firefighter Log Report Review Log Worflow".
    Meanwhile wie have created a Job that runs every night with this program
    Hope this will help you!
    BR Melanie

  • Fire Fighter Table Log

    Hi Gurus,
    I have to give the fire fighter log for the audit....When i look into the fire fighter log table
    Till the first step of firefighting Loggin in as Fire fighter is recordd on the Fire fighter id...But later all the activities has been Encrpted
    ylTCyMUOWnb     
    ylTCyMUOWnb     
    ylTCyMUOWnb     
    ylTCyMUOWnb     
    ylTCyMUOWnb     
    Firefighter                   THis is the first Step as fire fighter later the  field has been encrypted....
    Please let me know ...

    Hi Raghav,
       You can not download FF logs directly from the table as they are encrypeted. There are couple of ways to download FF logs.
    1) You can download FF logs in text format from FF. Go to
    FF -> Administration -> Archive -> Delete/Download Log.
    2) If you have implemented web functionality of FF (SPM), you can download any of the logs directly from web tool.
    Regards,
    Alpesh

  • Generate detailed log of usage in Fire Fighter

    Hi,
    We have recently configured the FFIDs. I am able to view FF-Id, time, activity, reason, T Codein the log report. However, I am not able to view detailed changes that were executed in the system using the FF ID.
    Can anyone help us.
    With best regards,
    Adarsha KG
    Edited by: Adarsha kg on Aug 1, 2008 8:24 AM
    Edited by: Adarsha kg on Aug 1, 2008 9:59 AM

    Hi Adarsha,
    Here is what i recommend if you want a detailed log of what fields the FF ID has changed/executed while running a particular tcode. You can view the Table change log details.
    1. Use tcode SCU3 ( Transaction table History)
    2. You can view the tables with Change recording activated
    3. You can Analyze the tables by clicking on Evaluate Logs
    4. You can give the date and time and evaluate the objects/tables
    5. You need to activate the logging of tables if not previously done.
    Hope this helps
    Regards,
    Kiran Kandepalli.

  • Fire Fighter is missed in the FF log sent to controllers

    Dear Experts,
    We are at SP10, and using role based Fire Fighter.
    We defined a FF role (e.g. FFrole001) and assigned this role to fire fighters.
    We are facing the following problem:
    If two fire fighters do the FF job at the same time, only one of fire fighters activity log will be sent to controllers for review.
    (Please note that the activity log of both fire fighters has been captured, we can find it in the /n/virsa/vfat.)
    Here is the detailed steps:
    1. The FF roles were assigned to two Fire Fighter at the same time
    2. Both of the Fire Fighters had performed some activities in system.
    3. FF activity log report captured the activities performed by the two Fire Fighters.
    4. But in the attachment in the email which was sent to FF controller, only one Fie Fighter was shown.
    Much appriciate if any one can help on this.
    Thanks!

    Hi Tang,
    Did you check the configuration settings for both the FF IDs.
    Also, as a trail and error, to isolate the issue, can you check using only the 2nd FF ID for which the log was not sent. Ensure that the 1st FF ID is not used. This way you can identify whether the issue is with the FF ID or the configuration.
    Regards,
    Raghu

  • Fire Fighter in Virsa

    Can someone please describe me how fire fighter works
    Thanks

    The only actions that are recorded are those of the firefighter ID. The firefighter ID does not record any other actions for any other users.
    A good example of what a fire fighter ID could be used for is Basis access. There are additonal tasks that a Basis person is allowed to perform in a non-Production system versus a Production system (as I am sure you are aware). There are times though that he/she may need elevated access to perform a critical task. At that point the firefighter ID is accessed and their actions recorded.
    As far as the type of access that you would assign, keeping with the same Basis person example, take a look at what you have defined for your Basis person(s) in your Production environment. Compare that access to what he/she has in QA (and/or Dev). The delta identified is the elevated access that may be required as baseline authorization for the firefighter ID. Of course this is only an example and you would have to tailor it to suite your requirements.
    Documents emailed.

  • SPM questions(Fire Fighter)

    Hello All,
    I had some questions on SPM(Fire fighter),please help me with this..
    For Critical transactions tab in /n/virsa/vfat--why we used it for,does it show header and footer log details..
    if we do not enter critical transactions will it still pull up critical history in FF logs.
    Second question-->Do we have setting of FF log history,can we pull the history of the user which is year old in FF log?
    Appreciate your responses.

    Hi,
    For Critical transactions tab in /n/virsa/vfat--why we used it for,does it show header and footer log details..
    if we do not enter critical transactions will it still pull up critical history in FF logs.
    The critical transactions that you maintain here will help you to generate a separate report that shows who and when any of the transaction codes were executed (and when they were executed). If you don't want to seperate the critical transactions, you can leave this blank.
    Do we have setting of FF log history,can we pull the history of the user which is year old in FF log?
    The logs will be available until they are archived.
    /VIRSA/ZFFUSERS - Table holds the Change logs (CLOG)
    /VIRSA/ZFFTNSLOG - Transaction Log (TLOG)
    Search in SE16, with /VIRSA/ZFF* to view the list of SPM tables.
    I recommend you to refer SAP Note 1041912 - Firefighter Best Practice Archiving Strategy that gives you the best solution to archive SPM logs.
    Hope this helps!!
    Regards,
    Raghu

  • Fire Fighter Report

    Hello Experts,
    I think I need some help on the Fire Fighter Reports.
    My ultimate goal is to get the list of Reason and activity used by the users during the months of January2012 and December2011.
    I was trying to execute the report "Reason/Activity Report" in SPM Tool Box in the transaction /n/virsa/vfat by giving the date range 01.01.2012 to 31.01.2012, i get the list but the column Reason Code is empty.
    I tried to view the table /virsa/ffreact in SE16.
    If i give input for FFKEY as 201112(December 2011), the result is "no table entries found for the specified key". But in the FF log report i can see users logged in during that period. Its the same case for the input *201201(January 2012).
    But if i give the input as 201202(February 2012), i get the list.
    Can anyone tell me the reason behind this.
    Best Rgds,
    Jaravuy

    Hi Jaravuy,
    Did you try to update the log?
    /n/virsa/vfat
    -->log information (F5)
    -->update (shift+F1)
    --> Choose a period where you are sure there has been activity
    Once you do this, you can try again.
    Best regards,
                   Félix

  • Ending a Session of a Fire Fighter ID

    Hi,
    One of my user has used the fire fighter yesterday and logged off.
    Now if he logs in to fire fighter using /n/virsa/vfat, the fire fighter id still shows that its being used by the same user ID.
    I have checked SM04 to end the users session.
    I can see the user ID logged in, but i cannot see the Fire Fighter ID in SM04.
    I clicked on the user ID and then clicked on the sessions, to find the transactions to end. But the transaction /n/virsa/vfat is not there.
    Then i tried in AL08 and it shows that the fire fighter ID is still active.
    And also there are not logs in SM12 for both user ID's
    But how can i end the fire fighter ID's session now.
    Best Rgds,
    jaravuy
    Edited by: jaravuy on Feb 17, 2012 3:09 PM

    I can see the user ID logged in, but i cannot see the Fire Fighter ID in SM04.
    Then i tried in AL08 and it shows that the fire fighter ID is still active.
    SM04 will show the list of users in the application server you are logged in. Check the application server in AL08 where the user is logged in. Then in SM51 you change your application server. Then in SM04 you will find the FF user. Here you need to kick off this user.
    Regards,
    Arpan Paik

  • Changes History Report in Fire Fighter

    Hi,
    We have assigned FF ID to end user. By using that FF ID,user did some changes.
    Ex: End user has used SU01 transaction and he has assigned SAP_ALL to his own id and some other users via FF ID.
    When we checked the Log Reports in FF 5.3, we are able to the see only transaction details which he has used. But we are unable to find the changes which he has done by using SU01.
    Please check and advice me how me can get that change history report in Fire Fighter.
    Thanks & Regards,
    KKRao.

    Hi Harleen,
    Retrieve Change Log option is already set as YES. But we are unable to get Changes History Report.
    Please advice to me.
    Thanks & Regards,
    KKRao

  • Fire Fighter Mail Notification

    Hi Gurus,
    I have an issue with fire fighter....if i am not wrong...When i add a firefighter id to a user id ...it should send a mail...Fore Fighter controller and owner with a link to approve and then they approve the access...then it will send the user access to the user.The above process is not happening with the fire fighter we using..
    The fire fighter owner and controller are just getting the logs...Please let me know how to config the initial mail notification.
    Thanks in advance
    Guru

    Hello Guru,
    When a user probably a Security Administrator assigns Firefighter ID to a Firefighter User there is no such provision of automated e-mail notification in Access Controls 5.2 - Firefighter SP level 5 with Patch 1. Which is at the moment latest available on SAP service market place.
    But you can take it another way. If you have an Honour of using Access Enforcer then you can create a dedicated workflow for Firefighter ID assignment. Where you can define different stages and approvers for all scenarios. Also this way you can intimate the requestor and approver about the status.
    In role expert, you can automate the default Virsa Firefighter, Owner, Administrator and controller roles for users.
    Still there is no such automated functionality which can let you automatically add users to Virsa Firefighter configuration tables and send an e-mail.
    What you can do is, after the approval of the firefighterID assignment your security guy can manually add users to these considered tables and finish the AE workflow notifying all the approvers and requestor.
    I hope i touched the whole scenario.
    If you still have doubts, let me know.
    Thanks & Regards,
    Amol Bharti

  • Fire fighter

    Guys,
    From my understanding the use of fire fighter is for emergency access in PRD. For that we can just create separate ID in sap system with almost sap_all authorization (not sap_all) and access PRD whenever there is a need.But why we need sap VIRSA fire fighter or SAP GRC super user privilege management?.

    Virsa Firefighter allows for tracking of who connects where, and what they do while connected. If you assign a generic SAP "super user", you loose these important tracking and auditing features... unless, of course, you create your own tracking system (for instance by activating a user exit upon login, demanding the person who logs in using the "super user" to identify him/herself and store some vital info such as time, date, ip address of the terminal used to connect and so on). Also, you'd need to turn security audit logging on.
    Firefighter gives you all of these security mechanisms in one package, one which tastes good to your auditors, too...
    Trond

  • Fire Fighter Roles

    Hi Gurus,
    I am in the process of designing Fire Fighter ROles for the Production process...
    Can any one please help me with the number of roles and Transactions that we use for the design process...
    How many Fire Fighter roles that we need and What are the Transactions.....?
    Thanks in advance
    Guru

    Hi Guru,
    The roles that need to be created for Firefighter ids are based on requirement from the Business process owners of the respective business modules ( example, SD, MM, PP, FICO ).
    Firefighter tool is designed to help you handle exceptional access requests appropriately.
    This tool is used to deal with emergency access requests. For example, when a Production support person needs to investigate an Urgent issue in Production system but does not have enough access. Then you need to assign the Firefighter id and the appropriate Firefighter role(s) to complete the emergency transactions.
    Virsa Firefighter for SAP enables super-users to perform emergency activities outside the parameters of their normal role, but to do so within a controlled, fully auditable environment. The application assigns a temporary ID that grants the super-user broad yet regulated access, and tracks and logs every activity the super-user performs using that temporary ID.
    So you need to consult your BPOs, Internal Audit team, Controllers and come up with the emergency transactions, authorizaton objects, programs, reports, tables and design the roles with appropriate naming conventions.Assign the Firefighter roles to the Firefight IDs in emergency in Production system.

Maybe you are looking for

  • How to delete pictures from ipod touch

    just want to know how can i delete photos from my itouch? and also how i can select what photos to be saved from my computer to ipod touch when it started to synchronize all the files.

  • Mail app will not open in my MacBook Air

    When I try running it, it simply collapses and will not let me click on any item of the menu. What can I do? If I log in with a different user it works, but not with my user. Please help!

  • Can we save our canvas as a .psd(photoshop) file? as we are saving with .jpg or .png format with the

                     I have 2-3 image in my canvas and i want to save it in .psd format means each image will act as a different layer when we will open the saved file in                  photoshop.                 Thanks & Regards,                 Parth

  • WLC2112 with Guest / Web-Auth and vlan

    Hi I'm trying to configure my WLC with guest SSID and vlan 10. The security is only set to Web-auth, and it is all working if the guest network is set to nativ vlan (1) But it seems that the http(s)://1.1.1.1/login.html is not reacheble from the gues

  • Construct dynamic menu through iteration of [for each]...

    Hi, I'm trying to create a menu based off a json file structure. Per the code below, I'm trying to build a menu structure that resembles the image below. In order to complete this piece of code, I'm trying to figure out what [mcMenuItem.y] and [mcLes