on 03-03-2014 1:27 PM
Hi All,
I am trying to view FF ID reports. However, I could not get the complete reports.
I executed: NWBC->Reports and Analytics->EAM Reports->Consolidated Log Reports->Update FireFighter Log.
It says, it is update successfully.
I also executed ABAP program "GRC_SPM_LOG_SYNC_UPDATE" in GRC system for the desired connector.
When I click on NWBC->Reports and Analytics->EAM Reports->"FireFighter Log Summary Report",
I get the screen and FF ID used are displayed. However, when I click on "Session Details", reports are empty.
I believe I have to run some of the more jobs either on GRC system or back end, but not sure which one.
Can anyone advise?
Regards,
Faisal
Dear Faisal,
there are already some topics in this regard. Please check SAP notes 1775432, 1864056 and 1696600. Also a known issue can be differences im time zone or new authorization objects which need to be added and authorized (S_ADMIN_FCD and S_TOOLS_EX) for the RFC user in the backend system.
Let me know on which SP level you are.
Regards,
Alessandro
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Alessandro,
Thanks for your reply.
Now I have added these auth. objects and maintained "*" in them.
As far time zone, I noticed that the time zone difference between GRC and back end system is approximately 3 minutes. Does it cause any issue?
Also, do I have to re-run the sync jobs after these objects?
Please advise.
Regards,
Faisal
Hi Alessandro,
The note#1775432 is implemented in back end system and I added auth. objects: S_ADMI_FCD and S_TOOLS_EX.
However, for auth. object: S_TOOLS_EX, I could not find value "S_TOOLS_EX_A" for AUTH field in the possible values. But I added it manually and system did not object it.
I also scheduled job GRAC_SPM_LOG_UPDATE_SYNC with hourly frequency.
Should I now access FF ID and check the session details or still I can view earlier FF ID session details?
Anyway, now I am going to again access FF ID session and check.
Please advise.
Regards,
FAisal
Hello,
we have a similar issue at a client, where the log is collected, but the detailed session reports are "hit and miss", i.e. some Item ID's (i.e. Document numbers) gets reported, whilst other's don't. As ST03N data seems fine on the target system, as does CDHDR table, we are wondering if the data collected and presented back in the GRC system is an issue.
We are on SP12 and using De-centralised EAM. I can confirm that the Authorisation fix via SAP note 1775432 has been implemented. Further more, we even threw in SAP_ALL to the GRC RFC user on the target system to try and eliminate authorisation issues.
The timezone's are also in sync between GRC and ECC and the EAM log sync takes place on a hourly schedule.
any thoughts much appreciated.
p.s. nearly all of the SAP notes mentioned above have been considered already.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Hello Faisal,
Technically isn't complicated:
1916 - Logging table changes in R/3
but you have to check with your DBA, Basis, DEV teams, etc if is suitable and determine if the volume of data is something you'll be able to manage.
Usually you coordinate what tables such be subject to logging with the Audit team. You'll find an example here: 112388 - Tables are subject to logging
By the way, have you solved the issue with the log collection? I've added some tips in the article Configure Emergency Access (EAM) in GRC 10
as mentioned earlier
Cheers,
Diego.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Hi Faisal,
I got the same issue and tried to run GRAC_PFCG_AUTHORIZATION_SYNC. It worked.
Thanks,
Mamoon
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Hello Faisal,
The first you should check is is you have data in the transaction STAD in the plugin system as well as ST03N. The basic transaction data is extracted from there.
You can also perform a trace in the plugin system (ST01) to check if the RFC user is connecting and no authorization problem exist when executing SYNCH.
The log collector should be scheduled hourly as per the recommendations and not executed manually when you want to get the logs.
You also have to check SLG1 in GRC Box and ST22 in the plugin in order to know if there's some dump there produced by the RFC User.
after changing the authorizations, have you tried with new FF sessions? or you are just trying to pull the data from the old session? do you still have such data in STAD in the plugin system?
Cheers,
Diego.
Diego,
I have run a FireFighter session in the back end system and checked in STAD. I could find the details of the FireFighter ID (FF_ID).
But in ST03, I could not see its details (Service Manager Mode).
I noticed that the date range is 24.02.2014 to 02.03.2014. I think due to his it is not showing FF_ID user details in ST03.
But I dont see any option here to change this period so that I can get reports until today.
CAn you suggest?
Regards,
Faisal
Dear Faisal,
strange situation... best to go step for step to see where the problem comes from..
Can you check table GRACACTUSAGE if you have latest entries with correct connector and user? There was once an issue that user id was entered with "-- ? --" and then for sure EAM was not able to catch the correct information.
Regards,
Alessandro
Alessandro,
Earlier no entries were there in table GRACACTUSAGE for the back end system I was looking reports for. I then executed GRAC_ACTION_USAGE_SYNC program for my desired connector. Then I could see entries for the desired connector for FF_ID id.
But again when I clicked on "Consolidated Log Report" link and then searched for this back end system, it says "no records found".
Can you please advise.
Regards,
FAisal
Hello Faisal,
The ST03N statics are updated by the standard job SAP_COLLECTOR_FOR_PERFMONITOR. You might check if the job is running properly and scheduled hourly.
By The way, have you checked for dumps in ST22 in the backend related to the RFC user?- We're currently having such issue and a lot of errors in the change log performance have been reported. We trying by implementing a new SAP note related to performance.
Have you checked SLG1 after the synch? the message is that the log collection ended succesfully or not?
Cheers,
Diego.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.