SUPER user logging and Monitoring

Since SAP does not recommend using GRC Access Control to log actions performed using SUPER users such as SAP, DDIC, or other powerful id's, what tools are available?  When SAP, DDIC, or other powerful super users are used in your SAP environment.  Are these activities being logged?  Is anyone monitoring these activities?  Do you even use SUPER id's in your environment or assign access directly to your BASIS team?  Have you used GRC SPM or Virsa Firefighter to manage these users?  Are you using monitoring tools such as Cyber-Ark to log and monitor your BASIS team?  How do you ensure your management or audit team that all activities perfomed by SAP*, DDIC or other powerful SUPER users is logged and available for review?

> Since SAP does not recommend using GRC Access Control to log actions performed using SUPER users such as SAP*, DDIC, or other powerful id's, what tools are available?
Can you reference the source where SAP says that standard super users should not be logged?
SAP also says that standard users such as DDIC and SAP* are known targets of attack vectors(DoS attacks, password brute forcing, DB vulnerabilities...) so once having locked them down (see the other responses) it would make sense to monitor them for any events.
Cheers,
Julius

Similar Messages

  • Error handling, logging and monitoring business process

    I would like to know more about error handling, logging and monitoring in business process? Can someone give more information on this one?

    Chandran
    Please refer to following tutorials to understand each of these topics in detail:
    Validations:
    http://www.orafmwschool.com/validations/
    Exception Handling:
    http://www.orafmwschool.com/exception-handling/
    Fault Management Tutorial:
    http://www.orafmwschool.com/fault-management-tutorial/
    Business Activity Monitoring Tutorial:
    http://www.orafmwschool.com/bam-tutorial/
    You'll have to refer to Oracle documentation to understand more finer details.
    -Amjad.

  • IPS log and monitoring

    Hi, All
    Few Queries on Cisco IPS.!!!!
    1. Which are best tool for fetching cisco IPS logs??
    2. Where or Which directory Cisco Logs/Events are saved?
    3. I am only able to see today log but not able to view past any logs? what are possible cause?
    4. Any free-ware tool that fetch logs and events from cisco IPS?
    5. Cisco IPS express manager is free-ware or we need only cisco customer account?
    For any type of help.. Thanks
    Jignesh

    1. You can use IME (IPS Manager Express) to view all your IPS events.
    Here is the IME page for your reference:
    http://www.cisco.com/en/US/products/ps9610/index.html
    2. The logs on the IPS device itself has very small storage space and it wraps once the log is full, therefore if you have a lot of events triggered, you are only able to see the latest events.
    3. As per my above description.
    4. Cisco IME - it's free (no extra license is required to use IME).
    5. As long as you have CCO account, you should be able to download the IME software.
    Hope this helps.

  • I am using fieldpoint and labview to log and monitor the temperatur​es of my system. but i am not using Labview 6i with DSC, how can i do it??

    i am using fieldpoint 2.0 and labview 6i to monitor my system, but i think i don't have labview DSC.

    I have written a relatively large Fieldpoint application "just" using LV5.1 FDS, so it can be done.
    Fieldpoint can be seen as an external instrument, so you need to use the driver/vi's that comes with FP.
    I believe using DSC would only make the job easier for you.

  • How to monitor user logs,security logs,trace file,and performance monitori

    Hi guys,
    pls tel me how to monitor user logs,security logs,trace file,and performance monitoring.
    thanks
    regards
    kamal

    Hi,
    you can have a look in the Netweaver administration :
    http://<portal>:<port>/nwa
    Go to monitoring, Java system reports, etc..., you will find what you want.
    Fabien.

  • HT201303 Has anyone experienced being a victim of GNU Emacs Api Emulations hacking thru URL's - Feeds - Email - Redirect - Data Scrabling and more? We are unable to stop them because they are super users. They come back and do more damage. Help Please.

    We have been compromised within our businesses from an empolyee that was terminated with GNU Emac Api enulation program that has infiltrated all of our brand new Apple Computers. We made a decision to move to Mac's this year because of all our businesses being internet based and we are in several different platforms that require many different passcodes, email address, bank accounts, etc. It is not one seamless system that would address one email, password, bank account, etc.
    Eacy time we change one segment of our business unit to move to the next one to fix, we go back to check the previous one that we changed and they have already been in the accounts and changed them so that we have to redo them.
    The information is so broad and wide that the only way I know to ask this first questions - has anyone had this happen to them? We have seeked many avenues with law, experts, reformating our 2 momth old systems 2-3 times each and start over. They are the super users of this program and we can not get them out by changing passwords, accounts, etc. They have everything we do and make sure they keep changing it as we work on the next segment. They have cost our small business thousands of dollars already.
    I am a victim of something that even the local forenic authority is stumped because they don't know where to start. We are not a banking instutition or 100 million dollar company to get the help we need. We don't want to find hackers like they have done to us, we want to get them stopped and get us back on track to start getting our businesses rebuilt.
    Lots of stuff, but WE ARE BEGGING for HELP.
    Apple Support today spent 3 hours with us on the phone and our suppot representative was awesome, but they also said it was big and we need to reach out to the Apple community to see if they heard of anything like this crime. They are in the URL's, RSS Feeds and ghosting everything we do.
    I was told by our local Mac support that this was done by someone that was highly sophicated and they did not know many people that could do this type of damage. I can't image that someone in the Apple community would not know of someone that can assist. The one security company we contacted was around $25,000 to fix this aweful crime.
    We just want them stopped and put in jail so we can go back to business before it destoys us completely.  They even installed emacs on all of our Iphone and androids. WE are being taped, video recorded and eery key stroke is recored. They are only taking us down in middle America.
    Anyone have any ideas? Thank you.

    Hi AP_In_Surbiton,
    I am really sorry that you have had so much trouble getting your Caller ID up and going.  I'll be happy to help you out with this and get it working for you.
    Could you drop me in an email please? Use the 'contact us' form in my forum profile under the 'about me' section. You can find it by clicking on my username.
    Thx
    Craig
    BTCare Community Mod
    If we have asked you to email us with your details, please make sure you are logged in to the forum, otherwise you will not be able to see our ‘Contact Us’ link within our profiles.
    We are sorry but we are unable to deal with service/account queries via the private message(PM) function so please don't PM your account info, we need to deal with this via our email account :-)”
    td-p/30">Ratings star on the left-hand side of the post.
    If someone answers your question correctly please let other members know by clicking on ’Mark as Accepted Solution’.

  • Monitoring when users Log to resources remotely

    I'm trying to monitor when users access another computer in the domain remotely.  I check out the logs from the Domain Controller on event viewer (WindowsLogs) and it shows me some events where I can see that a user logged on a sepecific machine. 
    But when I run a test my logging in to a remote server I do not see an entry tha shows anything related to an access to the remote server.
    Is there anything I need to enable on the domain controller or any other logs I can take a look at?

    Hi,
    Have you configured audit policies on the Domain Controller?
    You can use ADUC to enable auditing, more information for you:
    HOW TO: Audit Active Directory Objects in Windows Server 2003
    http://support.microsoft.com/kb/814595
    Configuring Audit Policies
    http://technet.microsoft.com/en-us/library/dd277403.aspx
    Best Regards,
    Amy Wang

  • The report server has encountered a configuration error. Logon failed for the unattended execution account. (rsServerConfigurationError) Log on failed. Ensure the user name and password are correct. (rsLogonFailed) Logon failure: unknown user name or bad

    The report server has encountered a configuration error. Logon failed for the unattended execution account. (rsServerConfigurationError)
    Log on failed. Ensure the user name and password are correct. (rsLogonFailed)
    Logon failure: unknown user name or bad password 
    am using Windows integrated security,version of my sql server 2008R2
    I have go throgh the different articuls, they have given different answers,
    So any one give me the  exact soluction for this problem,
    Using service account then i will get the soluction or what?
    pls help me out it is urgent based.
    Regards
    Thanks!

    Hi Ychinnari,
    I have tested on my local environment and can reproduce the issue, as
    Vaishu00547 mentioned that the issue can be caused by the Execution Account you have configured in the Reporting Services Configuration Manager is not correct, Please update the Username and Password and restart the reporting services.
    Please also find more details information about when to use the execution account, if possible,please also not specify this account:
    This account is used under special circumstances when other sources of credentials are not available:
    When the report server connects to a data source that does not require credentials. Examples of data sources that might not require credentials include XML documents and some client-side database applications.
    When the report server connects to another server to retrieve external image files or other resources that are referenced in a report.
    Execution Account (SSRS Native Mode)
    If you still have any problem, please feel free to ask.
    Regards
    Vicky Liu
    Vicky Liu
    TechNet Community Support

  • How can I use firefox between windows 7 & windows XP on a network, where we are using Samba server. If a user logs on different workstation(and OS) with same account.

    we have a Linux fileserver with Samba share and have several users.
    The users tend to be in different locations and need to login at different workstations, sometimes the workstation may be WindowsXP and othertimes it is windows7.
    How can we use Firefox & Thunderbird in this situation.
    I find that Windows7 uses compressed files to store the location information.
    when a user logs on to win7 it creates a new account.

    we have a Linux fileserver with Samba share and have several users.
    The users tend to be in different locations and need to login at different workstations, sometimes the workstation may be WindowsXP and othertimes it is windows7.
    How can we use Firefox & Thunderbird in this situation.
    I find that Windows7 uses compressed files to store the location information.
    when a user logs on to win7 it creates a new account.

  • How can I get Firefox to run on a network with multiple users logging on with the same user name and password?

    I am trying to get Firefox running on a large network where I have multiple users that log on with the same user name and password. The problem is that when another user logs on to another computer the message comes up that their is already an instance of firefox running on that computer even though there really isn't. Only one instance can be run on the network at one time. I believe it is because firefox stores a shared profile as it thinks it is actually the same user even though it is being run on another computer. I repeat that each user that logs on uses the same user name and password but on different computers.

    I am trying to get Firefox running on a large network where I have multiple users that log on with the same user name and password. The problem is that when another user logs on to another computer the message comes up that their is already an instance of firefox running on that computer even though there really isn't. Only one instance can be run on the network at one time. I believe it is because firefox stores a shared profile as it thinks it is actually the same user even though it is being run on another computer. I repeat that each user that logs on uses the same user name and password but on different computers.

  • I receive an error stating user name and password are not valid on my ipad and iphone 3Gs when attempting to load email from my icloud account. When I log onto icloud from my Mac, it wont load the email either.

    One day, my ipad and iphone pick up my emails (.mac account) from icloud just fine. the next day, I recieved error messages that say my user name and password are not accurate. I removed the icloud program on both devices and added it back on to both devices and get the same message. I logged into icloud from my Mac and while I can log in, it times out when I select email and wont load the email there either. Any Suggestons?

    I am having the same problem; it started about 24-36 hours ago.
    I know my ID/PW combo are correct because I can access all other aspects of iCloud except mail.
    iPhone -- returns incorrect ID / Password
    iPad -- Same
    Mail.app on Mac -- returns incorrect password error
    icloud.com -- allows me to log in and use all functions accept mail.  When I try to use mail it stays on a white screen for about 60 seconds then returns a dialogue box that indicates a server error.
    I contacted Apple and they placed my iCloud account into something called "Troubleshooting" mode.  They generated a new strong password and sent it on to "Engineering."
    I suspect there are a small number ofo users like you who are affected with the same problem I am.  Too small a number for it to be reported as an outtage.  I suggest you call Apple and open a case to have your mail investigaged.
    Hope this helps...

  • Mapping and Monitoring all the User and the Field exits

    Hello Dears,
    Are possible, with the Solution Manager to map and monitor all the user and the field exists existing in my ECC6 Productivity Environment?
    Anyone has some documentation?
    Regards to all.
    FS.

    Hello Gurus,
    Someone has any information about this question?
    Regards to all.
    FS.

  • Autocomplete suggests my user ID and date of birth on the log in page of my savings account - how do I stop this?

    For the most part autocomplete is really helpful. However, when I log in to my savings account, my user ID and DOB are suggested, allowing anyone on my PC to view my account (a security code is required to carry out any transactions which does not appear to be autocompleted!) - how can I switch this off please? This has started since I reset Firefox (due to slowness, as recommended by Firefox). Thanks.

    Thank you jscher2000: all fixed now!

  • HT4314 I have tried to log into clash of clans on my iPad and it just keeps going to a new game rather than the one saved on my iPhone. I have been using the game centre and same user name and password ?

    I have tried to log into clash of clans on my iPad and it just keeps going to a new game rather than the one saved on my iPhone. I have been using the game centre and same user name and password ?

    I have the same problem.. EXACTLY. .  When phoning Apple Support they had trouble understanding my problem and couldnt find any type of solution. No one seems to take responsibility for GameCenter issues. The assistant escalated the problem but no one could find an answer. .
    The only idea was to set up a new apple id, hence a new GameCenter account. . But that would loose all the itunes data. Anyone got ideas ?

  • Deleting a request in ODS that has no request number and monitor log

    Hai All,
              I have a request that failed. It oesn't even have a request id and is not getting deleted. Even if I delete it, the trash can symbol appears onits side and then disappears but the request still satys. I changed the status to red and deleted. Still its not getting deleted. There is no log in monitor also. I have a lot of data in the ODS and cannot afford to delete all data and load. Is there any table in SAP where I cn go in and delete it or is there any other way around?

    Hello BI,
    Please check the job logs in SM37 and see what job log says for deleting ODS request at the end though the job finished successfully. See if the job is still running in SM51 at the backend on server. If so please stop that job. I doubt that the request is still running either in R3 or BW in the backend. That could be one reason why it sometimes doesn’t allow the request to be deleted.  
    Hope this helps,
    Bye,
    Naga.
    Message was edited by: Naga Timmaraju

Maybe you are looking for

  • Display filename in text field

    Hi, A simple question; how can I insert the pdf filename (without the file path) as a read only value in a text field. As this is not available as a Runtime property is there a script for this? Thanks! Sam

  • Seeburger AS2: Could not create deploy file

    Hello,   I am using Seeburger BIC mapper to do my EDI to XML conversion. When i try to generate the SDA file i get error as shown. Errors of Mapping See_E2X_ORDERS_UN_D97A : com.seeburger.bicmd.compile.JavaGenerationFailedException: Precompiler Error

  • Excise duty mapping in PO

    Dear Experts, I want to know, how to map the below scenario into sap. In the purchase order for capital good,  there should be a provision for taking 50 % of the excise duty in to GL accounts-( Excise duty input) for taking input credit up to 50 % an

  • Stop sound and start over without "pop"

    I need to be able to interrupt and restart a short (3-4 second) sound file while it's still playing. Seems simple enough, but with both SoundEngine and AudioServices it causing a "popping" sound as it restarts. Is there any way to avoid this? I tried

  • Using the java (tm) Icon...

    If you've made an application, can you use the JAVA icon (as in the left top corner of this page) in the aboutdialog of your application? Is it legal? thx, sjg