cancel
Showing results for 
Search instead for 
Did you mean: 

SAP GRC 10 EAM Log Issue

Former Member
0 Kudos

Hi Experts,

I am configuring SAP GRC10 EAM for my client. I am running into an issue where not all FFID log information is being captured. The only information that is currently showing in the Consolidated Log Report are the security transaction codes that have been accessed and security changes that have been made (adding/removing roles from a user master record). The Firefighter Log Summary Report shows that the ID was being used and logged in with (shows reason code and time of login). The Reason Code and Activity Report also shows that the ID was being used and logged in with (shows reason code and time of login). The Transaction Log and Session Details does show any information. This is only happening in our QA ECC environment (as it is capturing all relevant information in our development environment).

Please see below for system information:

  • I have set the GRAC_SPM_LOG_SYNC_UPDATE job to run every 10 minutes for the QA ECC system; also, I am running the sync on in NWBC prior to generating the reports.
  • I have set the GRAC_ACTION_USAGE_SYNC job to run nightly for the QA ECC system. I have also ran this
  • I have set the following parameters in the GRC system:
    • 4003 - Yes
    • 4004 - Yes
    • 4005 - Yes
    • 4006 - Yes
  • I have set the following parameters for the plugin in the GRC system:
    • 1000, 1, QECCLNT500
    • 1001, 0, DGRCLNT100
    • 1089, 1, 1
    • 1090, 4, EG100_0000
  • The CDHDR and CDPOS tables are only showing the change updates for security updates when filtered on the fire fighter IDs
  • STAD is empty
  • SM19 filters have been set to * for all selections
  • SM21 is showing entries
  • SM20 is showing empty
  • SM49 is showing entries
  • Timezones are in sync
  • The following parameters in RSPARAM have been set:
    • rsau/max_diskspace/local - 100M

    • rsau/enable - 1

Would this be an issue on the GRC side or the ECC side? If on the ECC side, how would I be able to fix this issue? Any information would help! Thanks.

Paul

Accepted Solutions (1)

Accepted Solutions (1)

cchawla
Discoverer
0 Kudos

Paul,

Your SM20 logs should show the t-codes executed.

As you are on SP13 then you already have fix provided in sap note 1775432 but you will need to check the additional authorizations required for RFC user as mentioned in this note.

CJ

Former Member
0 Kudos

Thanks for the tip CJ! I believe that resolved my issue. I really appreciate your help on this matter. Thanks again.

Paul

Former Member
0 Kudos

Hi CJ,

We are trying to log idoc changes. However, it appears that SAP does not create change log documents for idoc edits. Is this a GRC10 issue or and idoc program issue? Can these changes be logged and displayed by GRC? Thanks.

Paul

cchawla
Discoverer
0 Kudos

Hi Paul,

Personally I haven't tested if the idoc changes are tracked but I think it is not tracked by GRC.

GRC EAM tracks transaction logs from STAD, change logs from CHPOS and CDHDR, system logs from SM21, Security logs from SM20, and OS command logs from SM49.

Regards,

CJ

Former Member
0 Kudos

Hi CJ,

Thank you for reply! I have done some research and it does appear that GRC cannot track idoc edits.

Paul

Answers (3)

Answers (3)

Former Member
0 Kudos

Hi,

Is this issue fixed? We are also in SP 13, and we have implemented Decentralized firefighting, we get the login notification email, but not the log notification email. Please help.

Reyas

Former Member
0 Kudos

Hi Experts,

We are trying to log idoc changes. However, it appears that SAP does not create change log documents for idoc edits. Is this a GRC10 issue or and idoc program issue? Can these changes be logged and displayed by GRC? Thanks.

Paul

madhusap
Active Contributor
0 Kudos

Hi Paul,

Can you tell me your support pack details for GRC 10.0?

Check below configuration settings in GRC.

check below configuration settings in Plug-in system

For more details you can check the below blog by Diego.

Configure Emergency Access (EAM) in GRC 10 | SCN

Regards,

Madhu.

Former Member
0 Kudos

Hi Madhu,

We are on SP13. Thanks.

Paul

madhusap
Active Contributor
0 Kudos

Hi Paul,

We are also on SP13. Check the parameter settings shared by me. If still issue persists, let me know.

Regards,

Madhu.

Former Member
0 Kudos

Hi Madhu,

Please review/implement  the SAP Note 1775432 in the Plug-in system. Also have your Basis review and apply SAP Note 1582473.

Best Regards,

Nandita

Former Member
0 Kudos

Hi Madhu,

Thank you for your help. Unfortunately, the configuration settings in our systems match and it still is not working. Do you have any other ideas? Thanks again.

Paul

Former Member
0 Kudos

Hi Nandita,

I will have my teams look into SAP note 1775432. However, SAP Note 1582473 appears to be for GRC 5.3. Would this note still apply for GRC 10? Thanks.

Paul