Professional Documents
Culture Documents
812197 _ 2023 - Data Not Visible in Forensic Lab of ETD System
812197 _ 2023 - Data Not Visible in Forensic Lab of ETD System
812197 _ 2023 - Data Not Visible in Forensic Lab of ETD System
Incident: 812197 / 2023 - Data not visible in Forensic lab of ETD system
ID 002075129500008121972023
Customer 681953 - EEP - Ethiopia Electric Power
Installation 0021197165 - T_S/4HOP
System TDS - TDSDB
Component SAP Enterprise Threat Detection (BC-SEC-ETD)
Status In Processing by SAP
Priority High
Communication
15.09.2023 10:05:09 CET - Problem Description: Anurag Kumar (S0025438044)
*Note To SAP:
I give approval for SAP Support to use these Steps to Reproduce, while connected to my impacted non-production environments, even if the steps result in a
change being made and my approval remains valid until the issue is resolved, unless I inform SAP Support otherwise.
We have installed SAP ETD system and performed the configuration part on both ABAP and ETD side.
So from ABAP , we can check from SETD, data is flowing successfully to ETD system but not visible in the Forensic lab.
I am attaching the KAFKA and LOGCOLLECTIOR logs and assuming that the problem is here. Requesting you to please check the logs and help us to
resolve the issue ASAP.
Regards,
Rachit
Attachment uploaded
Attachment uploaded
Attachment uploaded
Dear Customer,
have you checked our troubleshooting guide for missing data from ABAP systems? Please check "SAP Enterprise Threat Detection does not receive log data
from an ABAP system" in
https://help.sap.com/docs/SAP_ENTERPRISE_THREAT_DETECTION/e8c03e3e8bc84d61a882844233cc1499/e49c9db881624b6eb546135347d48544.html?
locale=en-US
If not, please go through all the steps and let us know after that.
https://userapps.support.sap.com/sap(bD1lbiZjPTAwMQ==)/support/incident/print/default.htm?pointer=002075129500008121972023 1/10
9/22/23, 11:01 AM 812197 / 2023 - Data not visible in Forensic lab of ETD system
Best regards,
Pavel
Hi Pavel,
We already checked the Troubleshooting guide. We are only facing issues with KAFKA2HANA service. Log collector and Normalizer issues doesn't report
any error.
Thank you
Rachit
Attachment uploaded
Attachment uploaded
Attachment uploaded
Hi team,
This is an very urgent for us to resolve the issue ASAP as the consultant are waiting for it to complete. So , we request you to please help to resolve the
issue as early as possible.
Thank you ,
Rachit
Dear Customer,
we are working on this issue and we will return to you as soon as possible.
Best regards,
Pavel
Business Impact:
https://userapps.support.sap.com/sap(bD1lbiZjPTAwMQ==)/support/incident/print/default.htm?pointer=002075129500008121972023 2/10
9/22/23, 11:01 AM 812197 / 2023 - Data not visible in Forensic lab of ETD system
This is a showstopper issue.
Financial loss : Not sure
Deadline : Have to resolve by today 20th Sept, as the issue is stopping the team to hand it over to the customer.
Interaction summary:
Business Impact:
Contact :
Mr. Rachit
+91 8813886827
Hi team,
Adding below kafka logs here. May be this can help to understand the issue.
Regards,
Rachit
Hello team,
Sorry to ping you again but this is a very urgent issue which need to be resolved ASAP. So. could you please check once and update.
https://userapps.support.sap.com/sap(bD1lbiZjPTAwMQ==)/support/incident/print/default.htm?pointer=002075129500008121972023 4/10
9/22/23, 11:01 AM 812197 / 2023 - Data not visible in Forensic lab of ETD system
Also I am working in IST hours so it would be good if you provide an update within next two hours , so that I would be available incase of any input would be
required from our side.
Thanks,
Rachit
Interaction summary:
I informed him that the developer for this issue is located in Germany.
Contact :
Mr. Rachit
+91 8813886827
Interaction summary:
Business Impact:
Additional Comment: Team kindly check and help the customer with an update.
Contact :
Mr. Rachit
+91 8813886827
https://userapps.support.sap.com/sap(bD1lbiZjPTAwMQ==)/support/incident/print/default.htm?pointer=002075129500008121972023 5/10
9/22/23, 11:01 AM 812197 / 2023 - Data not visible in Forensic lab of ETD system
21.09.2023 11:54:54 CET - Info for Customer: SAP
Hi Rachit,
could you please attach the log collector configuration xml file and the kafka2hana configuraiton xml file please?
I would also like to check first on the ABAP system that sends logs that this is working. Could you maintain the ABAP system in remote connection login
details please?
Thank you,
Jutta
Hello Jutta,
We have configured our GRC system to send data to ETD and Remote connection is already open.
Also I am attaching all streaming XML files along with SETD transaction screenshot.
Regards,
Rachit
Attachment uploaded
Attachment uploaded
Attachment uploaded
Attachment uploaded
Attachment uploaded
Attachment uploaded
Attachment uploaded
Hi Anurag,
https://userapps.support.sap.com/sap(bD1lbiZjPTAwMQ==)/support/incident/print/default.htm?pointer=002075129500008121972023 6/10
9/22/23, 11:01 AM 812197 / 2023 - Data not visible in Forensic lab of ETD system
The version of the new ABAP extractor does not fit to your log collector version, the message that is sent is different from what is expected.
Best regards,
Jutta
Sorry, I pressed on the wrong button. I did not want to sent the ticket back to you, but just inform you.
Hi Anurag,
how have you implemented the new ABAP Extractor for ETD? Have you implemented the latest version of this note
https://me.sap.com/notes/3313550
Best regards
Jutta
Hello Jutta,
Thank you so much for helping us. Given SAP note has been implemented.
After that In Open Protocol logs, below Auth error was coming.
"User ETD_CLNT_COM is not authorized to execute the Reader for type USERCON (Authorization Object S_ETD_MD)
ETD Error Code: CX_SETD_NO_AUTH_LOG_READER; Refer to SAP Note 2957945 for further details "
I have created a new role and assigned all the missing authorization in that and assigned to user ETD_CLNT_COM.
I tried to open the given SAP note but this is not available for us.
In the logs i can see that GRC system started to send data to ETD through given RFC.
Could you please check once and suggest what else we are missing.
https://userapps.support.sap.com/sap(bD1lbiZjPTAwMQ==)/support/incident/print/default.htm?pointer=002075129500008121972023 7/10
9/22/23, 11:01 AM 812197 / 2023 - Data not visible in Forensic lab of ETD system
Regards,
Rachit
Contacts
Anurag Kumar
Reporter Centra +91 9346882902 anurag@orane.in
(S0025438044)
Attachments
APPLICATION/VND.OPE
GRC_LOG_CONFIGURA S0025438044 - NXMLFORMATS- Anurag Kumar
261.0 KB 21.09.2023 13:28:42 CET
TION.docx 9/21/2023, 4:58:42 PM OFFICEDOCUMENT.WO (S0025438044)
RDPROCESSINGML.D
Action Log
Anurag Kumar
10:05:09 CET Component BC-SEC-ETD-CLD
(S0025438044)
Anurag Kumar
10:07:37 CET Memo/Text changed Problem Description Problem Description
(S0025438044)
Anurag Kumar
10:57:39 CET Memo/Text changed Problem Description Problem Description
(S0025438044)
Anurag Kumar
10:57:39 CET Status Not Sent to SAP Sent to SAP
(S0025438044)
https://userapps.support.sap.com/sap(bD1lbiZjPTAwMQ==)/support/incident/print/default.htm?pointer=002075129500008121972023 8/10
9/22/23, 11:01 AM 812197 / 2023 - Data not visible in Forensic lab of ETD system
Anurag Kumar
11:15:28 CET Memo/Text changed Info for SAP
(S0025438044)
Anurag Kumar
11:18:56 CET Memo/Text changed Info for SAP
(S0025438044)
Anurag Kumar
11:18:57 CET Memo/Text changed Info for SAP
(S0025438044)
Monday 18.09.2023 10:43:23 CET SAP Status In Processing by SAP Customer Action
Anurag Kumar
15:36:24 CET Status Customer Action Sent to SAP
(S0025438044)
Anurag Kumar
15:37:20 CET Memo/Text changed Info for SAP
(S0025438044)
Anurag Kumar
16:02:04 CET Memo/Text changed Info for SAP
(S0025438044)
Anurag Kumar
16:26:32 CET Memo/Text changed Info for SAP
(S0025438044)
Anurag Kumar
Tuesday 19.09.2023 21:08:17 CET Memo/Text changed Info for SAP
(S0025438044)
Wednesday 20.09.2023 09:11:44 CET SAP Memo/Text changed Info for Customer
Anurag Kumar
13:14:20 CET Memo/Text changed Info for SAP
(S0025438044)
Anurag Kumar
18:20:37 CET Memo/Text changed Info for SAP
(S0025438044)
Thursday 21.09.2023 07:11:53 CET SAP Memo/Text changed Info for Customer
Anurag Kumar
13:19:49 CET Status Customer Action Sent to SAP
(S0025438044)
Anurag Kumar
13:22:23 CET Memo/Text changed Info for SAP
(S0025438044)
Anurag Kumar
13:23:16 CET Memo/Text changed Info for SAP
(S0025438044)
Anurag Kumar
13:24:00 CET Memo/Text changed Info for SAP
(S0025438044)
Anurag Kumar
13:24:24 CET Memo/Text changed Info for SAP
(S0025438044)
Anurag Kumar
13:25:54 CET Memo/Text changed Info for SAP
(S0025438044)
Anurag Kumar
13:27:31 CET Memo/Text changed Info for SAP
(S0025438044)
https://userapps.support.sap.com/sap(bD1lbiZjPTAwMQ==)/support/incident/print/default.htm?pointer=002075129500008121972023 9/10
9/22/23, 11:01 AM 812197 / 2023 - Data not visible in Forensic lab of ETD system
Anurag Kumar
13:28:43 CET Memo/Text changed Info for SAP
(S0025438044)
Anurag Kumar
21:44:46 CET Status Customer Action Sent to SAP
(S0025438044)
https://userapps.support.sap.com/sap(bD1lbiZjPTAwMQ==)/support/incident/print/default.htm?pointer=002075129500008121972023 10/10