<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic What do I need to get SAP logs? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/What-do-I-need-to-get-SAP-logs/m-p/631593#M108249</link>
    <description>&lt;P&gt;Hi, I have been tasked to investigate what is needed to receive SAP logs in Splunk.&lt;/P&gt;&lt;P&gt;The first thing I find when I make my first queries on google is that there is a connector called "SAP PowerConnect for Splunk" but when I enter &lt;A href="https://splunkbase.splunk.com/app/3153" target="_blank" rel="noopener"&gt;https://splunkbase.splunk.com/app/3153&lt;/A&gt; and try to download it I get a message saying that the download is restricted.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="splunkcol_0-1676906784500.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/23957i1851E18C8E1DFC9E/image-size/medium?v=v2&amp;amp;px=400" role="button" title="splunkcol_0-1676906784500.png" alt="splunkcol_0-1676906784500.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I also found this step by step and I would like to know what you think if the information is current because as we know about Splunk we find information on the internet but in many cases it is very old and perhaps obsolete information.&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.wallsec.de/blog/siem-your-sap-security-audit-log-with-splunk#h.p_2Y3sy8TDSHCy" target="_blank" rel="noopener"&gt;https://www.wallsec.de/blog/siem-your-sap-security-audit-log-with-splunk#h.p_2Y3sy8TDSHCy&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and in this last link I see a process and the truth is that the matter is complex.&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.splunk.com/t5/Getting-Data-In/How-to-Splunk-the-SAP-Security-Audit-Log/m-p/380913" target="_blank" rel="noopener"&gt;Solved: How to Splunk the SAP Security Audit Log - Splunk Community&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 20 Feb 2023 15:30:46 GMT</pubDate>
    <dc:creator>splunkcol</dc:creator>
    <dc:date>2023-02-20T15:30:46Z</dc:date>
    <item>
      <title>What do I need to get SAP logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-do-I-need-to-get-SAP-logs/m-p/631593#M108249</link>
      <description>&lt;P&gt;Hi, I have been tasked to investigate what is needed to receive SAP logs in Splunk.&lt;/P&gt;&lt;P&gt;The first thing I find when I make my first queries on google is that there is a connector called "SAP PowerConnect for Splunk" but when I enter &lt;A href="https://splunkbase.splunk.com/app/3153" target="_blank" rel="noopener"&gt;https://splunkbase.splunk.com/app/3153&lt;/A&gt; and try to download it I get a message saying that the download is restricted.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="splunkcol_0-1676906784500.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/23957i1851E18C8E1DFC9E/image-size/medium?v=v2&amp;amp;px=400" role="button" title="splunkcol_0-1676906784500.png" alt="splunkcol_0-1676906784500.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I also found this step by step and I would like to know what you think if the information is current because as we know about Splunk we find information on the internet but in many cases it is very old and perhaps obsolete information.&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.wallsec.de/blog/siem-your-sap-security-audit-log-with-splunk#h.p_2Y3sy8TDSHCy" target="_blank" rel="noopener"&gt;https://www.wallsec.de/blog/siem-your-sap-security-audit-log-with-splunk#h.p_2Y3sy8TDSHCy&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and in this last link I see a process and the truth is that the matter is complex.&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.splunk.com/t5/Getting-Data-In/How-to-Splunk-the-SAP-Security-Audit-Log/m-p/380913" target="_blank" rel="noopener"&gt;Solved: How to Splunk the SAP Security Audit Log - Splunk Community&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Feb 2023 15:30:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-do-I-need-to-get-SAP-logs/m-p/631593#M108249</guid>
      <dc:creator>splunkcol</dc:creator>
      <dc:date>2023-02-20T15:30:46Z</dc:date>
    </item>
    <item>
      <title>Re: What do I need to get SAP logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-do-I-need-to-get-SAP-logs/m-p/631608#M108253</link>
      <description>&lt;P&gt;"Download restricted" means the app is not free and you haven't paid for it.&amp;nbsp; Contact the developer for more information.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There are several other "SAP" apps in splunkbase that may be free.&lt;/P&gt;&lt;P&gt;The Wallsec steps are still accurate.&amp;nbsp; If you're not using Splunk Enterprise Security (SIEM) then you can ignore the last 2 sections.&lt;/P&gt;&lt;P&gt;The linked Community post looks accurate as well.&amp;nbsp; Choose the method that works for you.&lt;/P&gt;&lt;P&gt;You are attempting&lt;/P&gt;&lt;P&gt;to integrate two complex products so expect some complexity in the solution.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Apr 2024 14:39:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-do-I-need-to-get-SAP-logs/m-p/631608#M108253</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2024-04-10T14:39:37Z</dc:date>
    </item>
    <item>
      <title>Re: What do I need to get SAP logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-do-I-need-to-get-SAP-logs/m-p/631612#M108254</link>
      <description>&lt;P&gt;tnx&lt;/P&gt;</description>
      <pubDate>Mon, 20 Feb 2023 16:33:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-do-I-need-to-get-SAP-logs/m-p/631612#M108254</guid>
      <dc:creator>splunkcol</dc:creator>
      <dc:date>2023-02-20T16:33:10Z</dc:date>
    </item>
    <item>
      <title>Re: What do I need to get SAP logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-do-I-need-to-get-SAP-logs/m-p/683828#M114151</link>
      <description>&lt;P&gt;Have you looked deeper into PowerConnect? It's a pretty fantastic tool.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Apr 2024 14:31:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-do-I-need-to-get-SAP-logs/m-p/683828#M114151</guid>
      <dc:creator>Dare2SplunkSAP</dc:creator>
      <dc:date>2024-04-10T14:31:17Z</dc:date>
    </item>
  </channel>
</rss>

