cancel
Showing results for 
Search instead for 
Did you mean: 

EAM: Unable to get session Details and other reports

former_member184114
Active Contributor

Hi All,

I am trying to view FF ID reports. However, I could not get the complete reports.

I executed: NWBC->Reports and Analytics->EAM Reports->Consolidated Log Reports->Update FireFighter Log.

It says, it is update successfully.

I also executed ABAP program "GRC_SPM_LOG_SYNC_UPDATE" in GRC system for the desired connector.

When I click on NWBC->Reports and Analytics->EAM Reports->"FireFighter Log Summary Report",

I get the screen and FF ID used are displayed. However, when I click on "Session Details", reports are empty.

I believe I have to run some of the more jobs either on GRC system or back end, but not sure which one.

Can anyone advise?

Regards,

Faisal

Accepted Solutions (1)

Accepted Solutions (1)

alessandr0
Active Contributor
0 Kudos

Dear Faisal,

there are already some topics in this regard. Please check SAP notes 1775432, 1864056 and 1696600. Also a known issue can be differences im time zone or new authorization objects which need to be added and authorized (S_ADMIN_FCD and S_TOOLS_EX) for the RFC user in the backend system.

Let me know on which SP level you are.

Regards,

Alessandro

former_member184114
Active Contributor
0 Kudos

Alessandro,

Thanks for your reply.

I have seen these notes and will get more details out of these to identify if those are implentable in our environment.

By the way, I am on:

GRCFND_A V1000 SP#9

GRCPINW V1000_700 SP#9

Regards,

Faisal

alessandr0
Active Contributor
0 Kudos

Dear Faisal,

did you check the two authorization objects in your backend system? This authorization must be given to the RFC user. I had a similar issue and could fix by updating this two objects.

Regards,

Alessandro

former_member184114
Active Contributor
0 Kudos

Alessandro,

Thanks for your reply.

Now I have added these auth. objects and maintained "*" in them.

As far time zone, I noticed that the time zone difference between GRC and back end system is approximately 3 minutes. Does it cause any issue?

Also, do I have to re-run the sync jobs after these objects?

Please advise.

Regards,

Faisal

former_member184114
Active Contributor
0 Kudos

Hi Alessandro,

The note#1775432 is implemented in back end system and I added auth. objects: S_ADMI_FCD and S_TOOLS_EX.

However, for auth. object: S_TOOLS_EX, I could not find value "S_TOOLS_EX_A" for AUTH field in the possible values. But I added it manually and system did not object it.

I also scheduled job GRAC_SPM_LOG_UPDATE_SYNC with hourly frequency.

Should I now access FF ID and check the session details or still I can view earlier FF ID session details?

Anyway, now I am going to again access FF ID session and check.

Please advise.

Regards,

FAisal

former_member184114
Active Contributor
0 Kudos

Alessandro,

I have done the needful. Still I am not able to see the session log details.

Any advice?

Regards,

Faisal

alessandr0
Active Contributor
0 Kudos

okay at least this is working fine.

How about configuration parameters 4003, 4004, 4005 and 4006? Are they set to YES?

former_member184114
Active Contributor
0 Kudos

Yes, they are set to "YES"

Answers (3)

Answers (3)

Former Member
0 Kudos

Hello,

we have a similar issue at a client, where the log is collected, but the detailed session reports are "hit and miss", i.e. some Item ID's (i.e. Document numbers) gets reported, whilst other's don't. As ST03N data seems fine on the target system, as does CDHDR table, we are wondering if the data collected and presented back in the GRC system is an issue.

We are on SP12 and using De-centralised EAM. I can confirm that the Authorisation fix via SAP note 1775432 has been implemented. Further more, we even threw in SAP_ALL to the GRC RFC user on the target system to try and eliminate authorisation issues.

The timezone's are also in sync between GRC and ECC and the EAM log sync takes place on a hourly schedule.

any thoughts much appreciated.

p.s. nearly all of the SAP notes mentioned above have been considered already.

dyaryura
Active Participant
0 Kudos

Hello Harinam,

Remember that the new alue-old value  will be shown only  for the tables where you have the change log activated.

If that's not the issue and you've applied the notes you should ask via OSS message.

Cheers,

Diego

former_member184114
Active Contributor
0 Kudos

Diego,

May I know how we can activate a change log for a table?

Regards,

Faisal

dyaryura
Active Participant
0 Kudos

Hello Faisal,

Technically isn't complicated:

https://help.sap.com/saphelp_nw70ehp2/helpdata/en/c7/69bcd2f36611d3a6510000e835363f/content.htm?fram...

1916 - Logging table changes in R/3

but you have to check with your DBA, Basis, DEV teams, etc if is suitable and determine if the volume of data is something you'll be able to manage.

Usually you coordinate what tables such be subject to logging with the Audit team. You'll find an example here: 112388 - Tables are subject to logging

By the way, have you solved the issue with the log collection? I've added some tips in the article Configure Emergency Access (EAM) in GRC 10

as mentioned earlier

Cheers,

Diego.


former_member193066
Active Contributor
0 Kudos

Follow Alessandro Banzer suggestion, and also perform Action usage sync.

Regards,

Prasant

mamoonr
Active Participant
0 Kudos

Hi Faisal,

I got the same issue and tried to run GRAC_PFCG_AUTHORIZATION_SYNC. It worked.

Thanks,

Mamoon

former_member184114
Active Contributor
0 Kudos

Mamoon,

This has run several times and I dont know still why this is not working.

Regards,

FAisal

dyaryura
Active Participant
0 Kudos

Hello Faisal,

The first you should check is is you have data in the transaction STAD in the plugin system as well as ST03N. The basic transaction data is extracted from there.

You can also perform a trace in the plugin system (ST01) to check if the RFC user is connecting and no authorization problem exist when executing SYNCH.

The log collector should be scheduled hourly as per the recommendations and not executed manually when you want to get the logs.

You also have to check SLG1 in GRC Box and ST22 in the plugin in order to know if there's some dump there produced by the RFC User.

after changing the authorizations, have you tried with new FF sessions? or you are just trying to pull the data from the old session? do you still have such data in STAD in the plugin system?

Cheers,

Diego.

former_member184114
Active Contributor
0 Kudos

Diego,

Thanks for your reply.

I am doing it now and will let you know.

Regards,

Faisal

former_member184114
Active Contributor
0 Kudos

Diego,

I have run a FireFighter session in the back end system and checked in STAD. I could find the details of the FireFighter ID (FF_ID).

But in ST03, I could not see its details (Service Manager Mode).

I noticed that the date range is 24.02.2014 to 02.03.2014. I think due to his it is not showing FF_ID user details in ST03.

But I dont see any option here to change this period so that I can get reports until today.

CAn you suggest?

Regards,

Faisal

alessandr0
Active Contributor
0 Kudos

Dear Faisal,

strange situation... best to go step for step to see where the problem comes from..

Can you check table GRACACTUSAGE if you have latest entries with correct connector and user? There was once an issue that user id was entered with "-- ? --" and then for sure EAM was not able to catch the correct information.

Regards,

Alessandro

former_member184114
Active Contributor
0 Kudos

Alessandro,

Earlier no entries were there in table GRACACTUSAGE for the back end system I was looking reports for. I then executed GRAC_ACTION_USAGE_SYNC program for my desired connector. Then I could see entries for the desired connector for FF_ID id.

But again when I clicked on "Consolidated Log Report" link and then searched for this back end system, it says "no records found".

Can you please advise.

Regards,

FAisal

dyaryura
Active Participant
0 Kudos

Hello Faisal,

The ST03N statics are updated by the standard job SAP_COLLECTOR_FOR_PERFMONITOR. You might check if the job is running properly and scheduled hourly.

By The way, have you checked for dumps in ST22 in the backend related to the RFC user?- We're currently having such issue and a lot of errors in the change log performance have been reported. We trying by implementing a new SAP note related to performance.

Have you checked SLG1 after the synch? the message is that the log collection ended succesfully or not?

Cheers,

Diego.

dyaryura
Active Participant
0 Kudos

Hello Faisal,

Also check the time you have in GRC and in the back-end. if you have form example 1-2 minutes diference you'll probably have issues with the collection.

Cheers,

Diego.