Emergency Access Logs - What Is Logged And What Isn't?

Posted by Simon Persin on 30 October 2012
Simon Persin

The SAP GRC Emergency Access Management (EAM) log level has been the subject of a lot of questions and debate. In this post I have summarised the current available logs together with their purpose and a description of what is captured.

There are five key logs available in EAM:

Transaction Log - This is the equivalent of the STAD data and a log entry will appear whenever a transaction is called by the Firefighter ID. 

Change Log - This is based upon the data held in tables CDHDR and CDPOS for business change documents. All changes logged by those tables will be captured alongside the nature of the change. This includes the field and values updated. However, this does not include a number of system administration functions if not covered by the business change header tables. Therefore, it is not guaranteed to capture each and every change made in the system. 

OS Command Log - This captures operating system commands executed from within SAP systems (via transaction SM49).

System Log - This reads from the SAP Application to show debug and replace entries from transaction SM21.

Audit Log - This reads entries from the SM20 system audit log assuming that this is configured correctly in SM19.

The present solution does not read the DB Table log but there is a planned enhancement to include this.

Topics: SAP Security

We would love to hear your views. Please leave a comment.