SAP Security Audit
Background
When I was working at CyberSec company, one of the client requested for auditing SAP user activity. Because of that, I've been assigned by Team Lead to do integration with SIEM, it takes 4 months to do just that with another task of course. So I'll share what I've found, because SAP do not have clear documentation and no blog post have good guide at that time.
SAP Configuration
-
Open SAP Easy Access

-
Go to sm19

-
Go to Dynamic Configuration

-
Select top individual server and edit configuration

-
Go to filter 1 and set selection criteria:
Client : * User : *
-
Make sure the filter is active (˅), also dialog logon and RFC/CPIC logon enabled (˅)

-
Save the configuration

-
Raw log example (tsv)

Ship Log with Archsight Connector
-
Key configuration for parsing

-
Successfully shipped

-
Parsed SAP log to syslog server
