cancel
Showing results for 
Search instead for 
Did you mean: 

Logging all actions performed by users

Former Member
0 Kudos

Hi all

There are some audit requirements whereby all the actions performed by a group of users need to logged. i.e. transactions visited, reports run, data changed and viewed etc.

I am aware of the Security Audit log (that captures transaction starts) and table logs (that captures changes made in data). Besides these, is there any other provision in SAP that allows us to capture the data viewed by people?

There is a tool called Firefighter that does something similar; is there anything in standard SAP that gives this functionality?

Thanks and Regards

Joy Kaushish

Accepted Solutions (0)

Answers (2)

Answers (2)

former_member185954
Active Contributor
0 Kudos

Hello Joy,

The best approach is to tighten your authorizations so that people have limited access and are unable to view data which they shouldn't.

This I say, since you need something that is over and above Audit and Table logs and your customer doesn't wish to invest money into a Security product.

You can use the SUIM transaction report and setup a list of Critical transactions to be monitored.

Regards,

Siddhesh

chemicala_srimallikarjuna
Active Contributor
0 Kudos

Hi,

Virsa Fire Figther:

The privileged-user access management functionality of SAP GRC

Access Control is enabled by the Virsa FireFighter application for SAP.

Virsa FireFighter for SAP can grant privileged access to select users, which could not be accomplished from outside the target applications. It is typically deployed on the production system to ensure proper super-user handling. Only the reporting component runs outside of the SAP application.

Regarding the Security auditing log, this might helps,

http://help.sap.com/saphelp_nw04/helpdata/en/c7/69bcb7f36611d3a6510000e835363f/frameset.htm

Some Tcodes: like ST03/ST03N/STAD, Reports RSSTAT10/RSSTAT83.- can chk the TCODE Logs for last 3 months

Hope this helps,

Regards

CSM Reddy

Former Member
0 Kudos

Thanks for the reply. Do you know of any tools other than FireFighter that can achieve something similar? The client doesnt want to invest in it as the GRC package is quite expensive.

How does ST03 help in logging all the table reads made by selected users?

Regards

Joy