Skip to content

Commit 7c43de0

Browse files
authored
Merge pull request #314390 from MartinPankraz/main
Main
2 parents d206018 + 5c0d34c commit 7c43de0

4 files changed

Lines changed: 132 additions & 0 deletions

File tree

articles/sentinel/TOC.yml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -188,6 +188,8 @@
188188
href: sap/sap-btp-security-content.md
189189
- name: Deploy SAP BTP
190190
href: sap/deploy-sap-btp-solution.md
191+
- name: SAP LogServ
192+
href: sap/sap-logserv-overview.md
191193
- name: Partner solutions
192194
href: sap/solution-partner-overview.md
193195
- name: Integrate Microsoft business applications
127 KB
Loading
1.02 MB
Loading
Lines changed: 130 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,130 @@
1+
---
2+
title: SAP LogServ integration with Microsoft Sentinel Solution for SAP overview
3+
description: This article introduces the Microsoft Sentinel Solution for SAP integration with SAP LogServ, an SAP-provided add-on that extends monitoring beyond the SAP application layer to infrastructure, database, and OS logs for SAP RISE customers.
4+
author: MartinPankraz
5+
ms.author: mapankra
6+
ms.topic: concept-article
7+
ms.date: 04/07/2026
8+
appliesto:
9+
- Microsoft Sentinel in the Microsoft Defender portal
10+
- Microsoft Sentinel in the Azure portal
11+
ms.collection: usx-security
12+
13+
#Customer intent: As a security analyst, I want to extend my Microsoft Sentinel SAP monitoring beyond the application layer so that I can gain full-stack visibility into SAP RISE managed infrastructure, database, and OS logs.
14+
15+
---
16+
17+
# SAP LogServ integration with Microsoft Sentinel Solution for SAP overview
18+
19+
The [Microsoft Sentinel Solution for SAP applications](solution-overview.md) provides powerful application-layer monitoring for SAP systems, tracking user activity, business transactions, and critical events. However, in SAP RISE/ECS environments, infrastructure and operating system logs are owned and managed by SAP, and aren't accessible through the standard SAP application connector.
20+
21+
SAP LogServ bridges that gap. It's an SAP Enterprise Cloud Services (ECS) service that centralizes logs from all systems, applications, and ECS services managed by SAP. The **SAP LogServ (RISE), S/4HANA Cloud private edition** solution in the Microsoft Sentinel Content Hub enables ingestion of these infrastructure-level logs into Microsoft Sentinel, complementing the existing application-layer coverage.
22+
23+
> [!IMPORTANT]
24+
> SAP LogServ is an optional service within your SAP Cloud ERP private (RISE) package. A purchase order for SAP LogServ must be completed before you can use this integration. Contact your SAP account team for details.
25+
26+
## What logs does SAP LogServ provide?
27+
28+
LogServ extends your monitoring scope beyond the SAP application layer to include logs that SAP ECS owns as the system provider. The available log types include:
29+
30+
| Log category | Examples |
31+
|---|---|
32+
| **Database** | SAP HANA database logs |
33+
| **Application server** | AS JAVA, ICM, SAP Gateway |
34+
| **Web and connectivity** | SAP Web Dispatcher, SAP Cloud Connector |
35+
| **Operating system** | OS-level logs |
36+
| **Network and security** | Network, DNS, Proxy, Firewall logs |
37+
| **Third-party databases** | Non-HANA database logs where applicable |
38+
39+
Check with SAP for the latest available log types and any updates to supported log sources.
40+
41+
> [!NOTE]
42+
> The SAP Security Audit Log (AS ABAP) for the application layer is handled by the [Microsoft Sentinel Solution for SAP applications](solution-overview.md) data connector, not by SAP LogServ. Deploy both solutions together for full-stack coverage.
43+
44+
## How the two solutions work together
45+
46+
Deploy the SAP LogServ solution alongside the Microsoft Sentinel Solution for SAP applications for comprehensive visibility across the entire SAP RISE stack:
47+
48+
- **Microsoft Sentinel Solution for SAP applications**: Monitors the SAP application layer, including business logic, user activity, sensitive transactions, privilege escalation, and data exfiltration via the [agentless data connector](deployment-overview.md?tabs=agentless).
49+
- **SAP LogServ solution**: Provides infrastructure, database, and OS-layer logs from SAP-managed environments via a dedicated data connector installed from the Content Hub.
50+
51+
Together, these solutions give your security team visibility from business logic down to the infrastructure layer, enabling cross-layer correlation and threat detection using the [60+ built-in analytics rules](sap-solution-security-content.md#built-in-analytics-rules) and the Microsoft Security Suite.
52+
53+
## Key capabilities
54+
55+
- **Near real-time log collection** with agentless integration into Microsoft Sentinel via the SAP LogServ data connector.
56+
- **Built-in security content** including analytics rules and workbooks provided by SAP for LogServ-specific log types.
57+
- **Long-term retention** configurable per data source with up to 12 years retention using [Microsoft Sentinel Data Lake](../datalake/sentinel-lake-overview.md).
58+
- **SOAR integration** with Microsoft Sentinel's security orchestration, automation, and response capabilities, including and [SAP user blocking via Microsoft Teams](https://blogs.sap.com/2023/05/22/from-zero-to-hero-security-coverage-with-microsoft-sentinel-for-your-critical-sap-security-signals-blog-series/).
59+
- **Cross-signal correlation** across endpoints, Microsoft Entra ID data, and other data sources in your Microsoft Sentinel workspace.
60+
61+
## Prerequisites
62+
63+
- A completed purchase order for **SAP LogServ** as part of your SAP RISE/ECS contract.
64+
- A [Microsoft Sentinel](../overview.md) workspace.
65+
- The Microsoft Sentinel Solution for SAP applications installed from the [Microsoft Sentinel Content Hub](https://marketplace.microsoft.com/en-us/product/sentinel4sap.sentinel4sap?tab=Overview) for application-layer monitoring.
66+
- The SAP LogServ (RISE), S/4HANA Cloud private edition solution installed from the [Microsoft Sentinel Content Hub](https://marketplace.microsoft.com/en-us/product/sap_jasondau.azure-sentinel-solution-saplogserv?tab=Overview).
67+
68+
> [!NOTE]
69+
> Only **Azure-hosted SAP RISE** customers have the option for fully integrated deployment. For SAP RISE on other platforms, [SAP's self-hosted log forwarder](https://pypi.org/project/sap-ecs-log-forwarder/) needs to be installed on a customer-hosted component with network connectivity to the SAP LogServ service and the Microsoft Sentinel Data Collection Endpoint. The forwarder has dedicated configuration options for Microsoft Sentinel for SAP.
70+
71+
## Deploy the solution
72+
73+
1. Install the **SAP LogServ (RISE), S/4HANA Cloud Private Edition** solution from the [Microsoft Sentinel Content Hub](https://azuremarketplace.microsoft.com/marketplace/apps/sap_jasondau.azure-sentinel-solution-saplogserv?tab=Overview). The connector deployment creates a Data Collection Endpoint and Data Collection Rule in the same resource group as your Log Analytics workspace.
74+
75+
If the deploying user lacks permissions to create a Microsoft Entra app registration automatically, create the app registration separately, supply a secret, and assign the app ID to the Data Collection Rule with the [Monitoring Metrics Publisher](/azure/role-based-access-control/built-in-roles/monitor#monitoring-metrics-publisher) role.
76+
77+
1. Contact your **SAP ECS CDM or ECS TSM** to initiate onboarding. Copy `[email protected]` on the email with the subject line **SAP LogServ and Microsoft Sentinel - Activation**, including your SAP RISE customer details.
78+
79+
1. Share the following configuration details with SAP through a secure channel:
80+
- Microsoft Entra tenant ID
81+
- Microsoft Entra app ID
82+
- Microsoft Entra app secret
83+
- Data Collection Endpoint URL
84+
- Data Collection Rule Immutable ID
85+
86+
SAP validates eligibility and configures automatic log forwarding to your Microsoft Sentinel for SAP workspace.
87+
88+
> [!TIP]
89+
> Before sharing your configuration with SAP, consider performing a smoke test to validate end-to-end connectivity. For guidance, see the [SAP LogServ blog series](https://community.sap.com/t5/enterprise-resource-planning-blog-posts-by-members/ultimate-blog-series-sap-logserv-integration-with-microsoft-sentinel/ba-p/14126401).
90+
91+
## Discovering SAP LogServ data in Microsoft Sentinel for SAP
92+
93+
Once the solution is deployed and logs are flowing, use the following resources to explore and analyze your SAP LogServ data in Microsoft Sentinel.
94+
95+
### SAP LogServ Insights workbook
96+
97+
The SAP LogServ Insights Dashboard workbook provides real-time monitoring of SAP RISE infrastructure log ingestion and system activity.
98+
99+
:::image type="content" source="./media/partner/logserv-workbook.png" alt-text="Screenshot of the SAP LogServ Insights Dashboard workbook." lightbox="./media/partner/logserv-workbook.png":::
100+
101+
The workbook shows:
102+
103+
- An overview of **Total Events**, **Active Systems**, **Data Volume**, **Data Status**, and **Most Recent Data**, helping analysts quickly assess log ingestion health and freshness.
104+
- A **Data Freshness Status** indicator using color-coded labels to highlight whether ingestion is current, delayed, or stale.
105+
- Filters for **Log Analytics Workspace**, **Time Range**, **Log Type**, **Log Sub-Type**, and **Activity Status** to narrow down specific log sources and systems.
106+
- An **Alert Configuration** section that lets you create alert rules directly from the workbook, with configurable alert type, name, threshold, and severity.
107+
- A **Log Volume Timeline** that visualizes log ingestion trends over time, helping analysts identify spikes, drops, or anomalies that might be associated with infrastructure changes or security incidents.
108+
109+
For more information on how to customize and use the workbook, see [Tutorial: Visualize and monitor your data](../monitor-your-data.md).
110+
111+
### Built-in analytics rules
112+
113+
The SAP LogServ solution and the Microsoft Sentinel Solution for SAP applications each provide analytics rules that target different layers of the SAP RISE stack:
114+
115+
- **SAP LogServ analytics rules**: Focus on **infrastructure-layer detections**, such as SAP HANA database audit trail deactivation, OS-level anomalies, network and firewall events, and other logs from SAP-managed infrastructure. These rules are installed with the SAP LogServ solution from the Content Hub.
116+
- **Microsoft Sentinel Solution for SAP applications analytics rules**: Cover the **application layer**, including [60+ built-in rules](sap-solution-security-content.md#built-in-analytics-rules) for detecting privilege escalation, sensitive transactions, data exfiltration, and unauthorized user activity within the SAP business logic.
117+
118+
Deploy both solutions together for cross-layer detection coverage spanning from SAP HANA database and OS infrastructure up through the SAP application layer.
119+
120+
The following example shows a SAP LogServ infrastructure-layer detection for a HANA database audit trail deactivation in Microsoft Sentinel, surfaced as an incident in Microsoft Defender portal:
121+
122+
:::image type="content" source="./media/partner/logserv-hana-db-detection.png" alt-text="Screenshot of a SAP LogServ HANA DB - Deactivation of Audit Trail incident in Microsoft Defender." lightbox="./media/partner/logserv-hana-db-detection.png":::
123+
124+
## Related content
125+
126+
- [Microsoft Sentinel Solution for SAP applications overview](solution-overview.md)
127+
- [Deploy the Microsoft Sentinel solution for SAP applications](deployment-overview.md)
128+
- [Microsoft Sentinel Solution for SAP BTP overview](sap-btp-solution-overview.md)
129+
- [Microsoft Sentinel solution for SAP - Partner add-ons](solution-partner-overview.md)
130+
- [Azure identity and security services with SAP RISE](../../sap/workloads/rise-integration-security.md)

0 commit comments

Comments
 (0)