Shared Services Groups

Hi All,
How many groups we can create in Shared Services, is there any limit on number of groups in Shared Services?
We are using Hyperion system 9.3.1
Thanks & Regards

Hi,
I am not aware of a limit, the only sort of limit I have seen is down to active directory groups
"To ensure optimum performance, the number of groups present within the Group RDN should not exceed 10,000. If more groups are present, use a group filter to retrieve only the groups you want to provision."
Cheers
John
http://john-goodwin.blogspot.com/

Similar Messages

  • CSSimport.bat error: while migrating the Shared Services groups and users

    Hi,
    I am trying to migrate the shared services native users and group from 9.3.1(on server A) to 11.1.1.3(on server B)
    - I have taken the export in CSV format from 9.3.1 using CSSexport.bat.(export.csv) -Successful.
    - I have copied this on the 11.1.1.3 server and changed lil details like removing the admin user etc.
    - When I am trying the import this on 11.1.1.3, I am getting the below error:
    CSSimport importexport.properties2010-10-11 09:36:41,328 Attempting a import operation
    log4j:WARN No appenders could be found for logger (com.hyperion.css.common.CSSLogger).
    log4j:WARN Please initialize the log4j system properly.
    null
    Aborting program...
    - There are not log or error files geting generated - The only error recieved , is given above.
    - I have made the necessary changes to the impotexport.properties file on 11.1.1.3 before starting the CSSimport utility.
    Can you please let meknow what should I do to overcome this error.
    -thanks,
    Ankit

    First thing I would try would be on the 11.1.1.3, try and run an export, if it works then run the import on the same file, this way you will make sure you have the version 11 utility working.
    Once you have done that then you can move on to the 9.3.1 export file.
    Cheers
    John
    http://john-goodwin.blogspot.com/

  • Shared Services Group Provisioning

    Hi,
    I am using Hyperion Shared Services 9.3.1. I am running a script to provision users under one group.
    I am running it through importexport utility.
    . I have tested the script with 2 users and it has provisioned those. that means script is correct. My problem is this time, I am running the script to provision 200+ users in one group
    Is there a way I can check through logs how much its finished or how many users it has provisioned. I am going under that group in Shared services, over there its not showing those users.
    Please help me.
    Thanks in advance.
    Pankaj Mehta.

    Hi,
    In the property file you can enable tracing by specifing trace log file in ExportImport properties file. enable the following properties:
    importexport.enable.console.traces=true( Indicates whether trace information should be displayed in the console where the Import/Export utility is executed)
    importexport.trace.events.file=<LogFileLocation>( TraceLogFile)
    importexport.errors.log.file=<LogFileLocation>( errors during the operation is logged to this file)
    Hope this helps!
    Nra

  • How to extract external directory users from a shared services group from shared services RDBMS repository

    Hi,
    I have a security group in shared services, which has external directory users. I want to extract the list of users from shared services RDBMS repository using a SQL query. Please let me know if this is possible and from which table(s) I can query such list.
    Thanks...

    You need to use CSS_Groups, CSS_GROUP_MEMBERS and CSS_USERS tables in your Foundation DB. Something like below will give you these details:
    select b.Name  ,a.Name  from HYPFOUND.CSS_GROUPS b ,
    HYPFOUND.CSS_USERS a ,
    HYPFOUND.CSS_GROUP_MEMBERS c
    WHERE c.MEMBER_IDENTITY = a.IDENTITY_ID and
    c.GROUP_IDENTITY = b.IDENTITY_ID
    GROUP BY (b.Name,a.name)

  • Generate report to show all users and groups in Shared Services in EPM 11x

    Hi,
    Is there any way to generate a report (like a migration report or job status report) which can be generated through workspace/shared services 11.1.1.3 so that my admin can look at all the users and groups created. Something that I can view and probably print out? Any suggestions?
    ~Adeeba

    Yes, I knew this one. This basically shows me the users and groups assigned specific provision access. Is there any way to view a report that shows which users and groups have access to dimensions of an individual planning application?
    ~Adeeba

  • Error while adding users to a group created in shared services

    Hi All,
    I am using EPM 11.1.1.1.0.. When i log into SHared services as admin and create a group i get the following error when i try to add the user members to the group.
    "Servlet error: An exception occurred. The current application deployment descriptors do not allow for including it in this response. Please consult the application log for details."
    Can somebody please help....
    Regards.
    Alicia

    Hello Ritendra,
    i am also facing the same problem. i could not find some solution.
    if you got some solutions then please help me.
    i have installed oracle 9i as in W2K system.
    regards
    sudhir

  • Creation of Group in Shared Services

    Hi All,
    I am creating groups in Shared Services using Import export utility, to create a group I have given record like
    #group,,,,,,,
    id,provider,name,description,internal_id,,,
    Test.30.7202,Native Directory,Test.30.7202,,,,,
    But group is not getting created, when I checked the trace log file I found
    Trace...
         2010-06-09 15:28:20,822 Attempting a import operation
         2010-06-09 15:28:22,147 Import : Attempting to create group Test.30.7202
         2010-06-09 15:28:22,162 Import : Create group Test.30.7202 failed.
    Can you please someone explain, is there I missed any information?
    We are using Hyperion system 9.3.1
    Thanks in Advance

    Hi John,
    Thanks for the prompt response, its working fine without intenal id. One more issue, Now I am provisioning groups for Planning Application
    project_name     application_name     role_id     product_type     user_id     user_provider     group_id     group_provider
    HyperionPlanning     Testapp     Planner     HP-9.3.1               Test.30.7202     Native Directory
    Like the above, is there any syntax to provide access to Essbase "Server Access" (Minimum access to access to Essbase) and Business Rules?
    Thanks in Advance,

  • New group in Shared Services does not come up in projects?

    Hi All,
    I'm working on a system that has externalized security, and we use Hyperion Shared Services to add users to groups and assign filters to groups.
    I have just added a new group in the analkytic server in shared services, I have also provisioned it to have filter access of a particular DB.
    When I go to the projects folder and check the list of groups under the application, to look for this group so I could assign the filter, I dont find the group listed.
    Does anyone know what I am missing out on.
    Thanks in advance.
    Anindyo

    Hi John,
    I tried to delete the group and create a new group again:
    searched for the group, right clicked on it and clicked on Provision.
    Then I expanded the Analytic server tree to the left, selected server Access, and moved it using the arrow button.
    Then I expanded the DB name, there were "Provisioning Manager", "Application Manager" and "My Role".
    I expanded the Tree of "My Role" and found "Calc", "Filter" and "Read".
    I expanded the tree "Filter", and found Start/Stop Application.
    I selected "Filter" (not Start/Stop Application) and moved it to the second list on the right using the Arrow button.
    Then I clicked on the save button.
    Now I expanded the Projects Folder:
    Clicked on the DB to which I provisioned this group.
    It showed the list of users and groups to the right.
    I selected groups in the drop down.
    Clicked on refresh, but the new group does not appear.
    Please let me know if I missed out on anything.
    Thanks for the response,
    Regard,
    Anindyo

  • Unable to see assign users or groups option under a groupin Shared services

    I have a bizzare issue related to Shared services.
    In Application 1 (on PROD env), after I select the group, right-click and go to properties, under "group members" and "user members" tabs, I do not see the options to assign access to any of the existings groups (we have about 50+ groups). I can only view the existing users/groups, even though I have been given admin/proviosioning rights, while the other admin can assign access to the same application.
    While for Application 2 (on DEV) I am able to see all these options and I am able to assign users and groups to any of the groups. I do not see them as a browser issue, as I have opened both these links on the same IE window, but on different tabs.
    Unfortunately, I can't test App1 on TEST/DEV, as we do not have its copy on here, it is all on PROD and App2 is only on DEV.
    Any ideas?
    Thanks,
    Paul

    I would of thought it was provision related, can you try setting up another user as a test with the correct provisioning such as provisioning manager of the different product areas and see if the new user works.
    If it does then it points an issue with your account or the way it has been provisioned.
    Cheers
    John
    http://john-goodwin.blogspot.com/

  • Shared Services Application Groups

    Hi,
    We have the following application groups which I assume are default
    APS Servers
    Business Rules
    Default Application Group
    Essbase Studio Server
    Essbase Server
    File System
    Foundation
    Planning
    Reporting and Analysis
    I was playing with creating my own Application Groups in shared services and created my own one and then decided that I didn't have a use for it so I deleted it but it also deleted what I has added to it from the groups above. e.g
    Essbase Server Access
    Our Main Planning application
    Now I go back and try and provision for these I cannot find them anywhere!! How can I get them back??
    Cheers
    Luke

    John,
    Reconfigured the deploy to web server and cluster configuration for Planning, both successful yet if I go into Workspace the Navigate/Application does not appear. Forget if I see Planning or Scorecard I cannot even see the subbox 'application'
    JTS

  • Security Settings for two admin groups  with shared service

    Hi all,
    I use Essbase Administration Services 11.1.2 and Hyperion Shared Services Console 11.1.2.0.73 (Drop 17)
    Access Rights are granted via Groups in Hyperion Shared Service Console.
    We have two admin groups.
    AccessGroup 1: admin rights on some cubes (A) and read rights on all others (B).
    AccessGroup 2: admin rights on (B) and read rights on (A).
    If someone of AccessGroup 1 copies a cube of (A) – Fin_rep for example – wether AccessGroup 1 nor AccessGroup 2 can even see the cube (and i dont even mention admin rights) execpt the one who copied it.
    Settings in Shared Services Console:
    - Both groups have role "Create/delete application" and "AccessManager" (or something like that - german word is "Zugriffsberechtigungsmanager") on Essbase Cluster (our essbase server).
    - AccessGroup 1 has role "ApplicationManager" and "AccessManager" for all cubes which they should administrate (A)
    and role "Read" for all cubes with read only (B)
    - AccessGroup 2 has role "ApplicationManager" and "AccessManager" for all cubes which they should administrate (B)
    and role "Read" for all cubes with read only (A)
    I hope i can get some help with this topic.
    Thank you in advance,
    Best regards
    Bernd
    Edited by: 907705 on 07.02.2012 02:52

    Security will not copy over when you create new cube from old cube. You have to grant security to required groups using shared services or Maxl.

  • Planner provisioning for user groups lost in Shared services

    Hi All,
    Everything was fine. All of a sudden, no users were able to login in to planning.
    On investigation it was found that all the planner/planning provision to the groups is lost in the shared services.
    Digged into log for a while and couldnt find out any issues.
    What could be the reason we lost user group security provisioning only to planning?
    Could anyone please help on this?
    Regards,
    GG

    I used to have same experience every time migration happens from dev to UAT or prod etc.
    After migration, registering with shared service will be successful. When i try to sync, migrate user identities (provisionusers.cmd) from shared service all user group info vanishes in planning (Add/Edit access page). i.e hsp_access_control table is truncated or all rows are dropped.
    Then i have to set it up correctly. Guess this happens because usergroups have different id between different environments. When sync'g planning at target, it will not be able to recognize the wrong usergroup id of source system.
    My assumption:
    When provisionusers.cmd is run, planning fetches the usergroup provisioning information from shared services in to hsp_access_control planning repository table. could someone confirm the same?
    Is there any other way to overcome this issue recurring on every time migration happens?
    But the problem today was different: the provisioning is lost in the shared services itself which i havent witnessed so far. We didnt migrate recently, everything was file till 8 AM, but screwed around 8.10 AM. everything was up and running.
    Cheers,
    GG

  • Maximum length of security group name in Shared Services

    Hi All,
    We are about to migrate to a v11.1.2 Hyperion environment and would like to centralise our security management for our HFM\Planning\Essbase\etc applications to Hyperion Shared Services.
    We'd like to formulate the security group in a particular way so as to allow anyone to know exactly what Hyperion Product, application, role and entity access a security group grants access to ... just by looking at the security gorup name. Obviously, we'd like not to have too long\lengthy a security group name.
    As such, I would like to know if anyone has ever come across or knows of any limitations in the number of characters used to name security groups in HSS. If yes, what is the maximum number of characters which can be used to name a security group????
    Thanks in advance.
    JBM

    * If you are using a DB2 database, the user name must contain at least 8 characters. User names should not exceed 256 characters (Oracle and SQL Serve databases), and 1000
    characters (DB2).
    * Group name should have a maximum 256 characters. Group names should contain a minimum of 8 characters if Native Directory is hosted on DB2 databases.
    You may find more information in http://download.oracle.com/docs/cd/E17236_01/epm.1112/hss_admin.pdf
    HTH-
    Jasmine.

  • Security in shared services :not able to  assining filters to the group

    Hi all,
    Iam getting the problem with assigning the filters to goups and users in shared services (our security is sharedservices mode), i refreshed the security
    Its not showing any group for that cube ,,,, i gave the access to that group but iam not able to assign that filter to that group
    wen i right clik on that cube , its showing page canot displayed, can any one face this issue
    or any other utilitywe ahve to assighn filters to the group
    Even I tried with maxl grant access but no use,
    Plz help on this...
    Edited by: user8815661 on 26 avr. 2010 04:36

    If you're on Windows, edit the hosts file from: C:\WINDOWS\system32\drivers\etc & include the Essbase, Shared services servers

  • Shared Services 11.1.2 Unable to remove assigned user from a security group

    In Shared Services 11.1.2 - trying to remove a user from the assigned users list of a security group. Initially, I am able to remove the user and the assigned users total decreases by one - but when I relaunch the group properties - this user is still in there? The change does not hold. Any suggestions would be appreciated - thanks,
    Paul

    Hello Paul,
    Not sure if this is related to yours, but it might be worth having a look at the following articles on Oracle support --
    External users in EPM Shared Services (e.g. MSAD users) cannot be removed from Native groups if they have multiple IDs in the external user directory. [ID 1526569.1]
    Users from External User Directories Cannot be Removed from Native Groups [ID 1272309.1]
    Thanks,
    hyperionEPM
    Please mark answers as correct or helpful for others to find them easily.

Maybe you are looking for

  • I'm getting charged for a glitch in the Verizon system, how do I fix this?

    To Whom It May Concern: We have been a longtime and loyal Verizon Wireless customer and advocate. Up until yesterday, we could not imagine ever using any other company beside Verizon Wireless. However, we received our bill yesterday and were shocked

  • How do I reset or delete settings in the Messaging...

    How do I reset or delete settings in the Messaging section on a 6790?  I input something that I need to delete.

  • SAP Authentication - Entitlement systems

    Hi Team, We designed all the reports with one OLAP Connection, Its mapped to SAP - ECC Entitlement systems Now, we need one more report with data level filter for specific users. So, We are planning to achieve this at BW cube level for specific users

  • Access rules policies in Cisco Security Manager

    Hello! We've started to deploy CSM 3.01 on our network (currently we have about 20 ASA's and this list is going to have about a 100 devices). The point is that we haven't used CSM's Policy View tab to develop our security policy - we've deployed our

  • Pacman + -Syu = system freeze

    I cannot post console output because system freeze so i cannot cut& paste. My pacman output is localized so my translation may not be 100% accurate After i pacman -Syu i get a list of packages hit y they get downloaded then pacman is checking depende