SAP LogServ integration with Microsoft Sentinel Solution for SAP overview

The Microsoft Sentinel Solution for SAP applications provides powerful application-layer monitoring for SAP systems, tracking user activity, business transactions, and critical events. However, in SAP RISE/ECS environments, infrastructure and operating system logs are owned and managed by SAP, and aren't accessible through the standard SAP application connector.

SAP LogServ bridges that gap. It's an SAP Enterprise Cloud Services (ECS) service that centralizes logs from all systems, applications, and ECS services managed by SAP. The SAP LogServ (RISE), S/4HANA Cloud private edition solution in the Microsoft Sentinel Content Hub enables ingestion of these infrastructure-level logs into Microsoft Sentinel, complementing the existing application-layer coverage.

Important

SAP LogServ is an optional service within your SAP Cloud ERP private (RISE) package. A purchase order for SAP LogServ must be completed before you can use this integration. Contact your SAP account team for details.

Tip

For latest updates and guidance, see the SAP LogServ blog series.

What logs does SAP LogServ provide?

LogServ extends your monitoring scope beyond the SAP application layer to include logs that SAP ECS owns as the system provider. The available log types include sources such as:

Log category Examples
Database SAP HANA database logs
Application server AS JAVA, ICM, SAP Gateway
Web and connectivity SAP Web Dispatcher, SAP Cloud Connector
Operating system OS-level logs
Network and security Network, DNS, Proxy, Firewall logs
Third-party databases Non-HANA database logs where applicable

Always check with SAP for the latest available log types and any updates to supported log sources using their Service Description Document.

Note

The SAP Security Audit Log (AS ABAP) for the application layer is handled by the Microsoft Sentinel Solution for SAP applications data connector, not by SAP LogServ. Deploy both solutions together for full-stack coverage.

How the two solutions work together

Deploy the SAP LogServ solution alongside the Microsoft Sentinel Solution for SAP applications for comprehensive visibility across the entire SAP RISE stack:

  • Microsoft Sentinel Solution for SAP applications: Monitors the SAP application layer, including business logic, user activity, sensitive transactions, privilege escalation, and data exfiltration via the agentless data connector.
  • SAP LogServ solution: Provides infrastructure, database, and OS-layer logs from SAP-managed environments via a dedicated data connector installed from the Content Hub.

Together, these solutions give your security team visibility from business logic down to the infrastructure layer, enabling cross-layer correlation and threat detection using the 60+ built-in analytics rules and the Microsoft Security Suite.

Key capabilities

  • Near real-time log collection with agentless integration into Microsoft Sentinel via the SAP LogServ data connector.
  • Built-in security content including analytics rules and workbooks provided by SAP for LogServ-specific log types.
  • Activation and reuse of Microsoft Advanced Security Information Model (ASIM) security content
  • Long-term retention configurable per data source with up to 12 years retention using Microsoft Sentinel Data Lake.
  • SOAR integration with Microsoft Sentinel's security orchestration, automation, and response capabilities, including and SAP user blocking via Microsoft Teams.
  • Cross-signal correlation across endpoints, Microsoft Entra ID data, and other data sources in your Microsoft Sentinel workspace.

Prerequisites

Note

Only Azure-hosted SAP RISE customers have the option for fully integrated deployment. For SAP RISE on other platforms, SAP's self-hosted log forwarder needs to be installed on a customer-hosted component with network connectivity to the SAP LogServ service and the Microsoft Sentinel Data Collection Endpoint. The forwarder has dedicated configuration options for Microsoft Sentinel for SAP. See SAP's announcement blog for more details.

Deploy the solution

  1. Install the SAP LogServ (RISE), S/4HANA Cloud Private Edition solution from the Microsoft Sentinel Content Hub. The connector deployment creates a Data Collection Endpoint and Data Collection Rule in the same resource group as your Log Analytics workspace.

    If the deploying user lacks permissions to create a Microsoft Entra app registration automatically, create the app registration separately, supply a secret, and assign the app ID to the Data Collection Rule with the Monitoring Metrics Publisher role.

  2. Contact your SAP ECS CDM or ECS TSM to initiate onboarding. Copy sap-logserv-sentinel-integration@service.microsoft.com on the email with the subject line SAP LogServ and Microsoft Sentinel - Activation, including your SAP RISE customer details.

  3. Share the following configuration details with SAP through a secure channel:

    • Microsoft Entra tenant ID
    • Microsoft Entra app ID
    • Microsoft Entra app secret
    • Data Collection Endpoint URL
    • Data Collection Rule Immutable ID

SAP validates eligibility and configures automatic log forwarding to your Microsoft Sentinel for SAP workspace.

Tip

Before sharing your configuration with SAP, consider performing a smoke test to validate end-to-end connectivity. For guidance, see the SAP LogServ blog series.

Discovering SAP LogServ data in Microsoft Sentinel for SAP

Once the solution is deployed and logs are flowing, use the following resources to explore and analyze your SAP LogServ data in Microsoft Sentinel.

SAP LogServ Insights workbook

The SAP LogServ Insights Dashboard workbook provides real-time monitoring of SAP RISE infrastructure log ingestion and system activity.

Screenshot of the SAP LogServ Insights Dashboard workbook.

The workbook shows:

  • An overview of Total Events, Active Systems, Data Volume, Data Status, and Most Recent Data, helping analysts quickly assess log ingestion health and freshness.
  • A Data Freshness Status indicator using color-coded labels to highlight whether ingestion is current, delayed, or stale.
  • Filters for Log Analytics Workspace, Time Range, Log Type, Log Sub-Type, and Activity Status to narrow down specific log sources and systems.
  • An Alert Configuration section that lets you create alert rules directly from the workbook, with configurable alert type, name, threshold, and severity.
  • A Log Volume Timeline that visualizes log ingestion trends over time, helping analysts identify spikes, drops, or anomalies that might be associated with infrastructure changes or security incidents.

For more information on how to customize and use the workbook, see Tutorial: Visualize and monitor your data.

Built-in analytic rules

The SAP LogServ solution and the Microsoft Sentinel Solution for SAP applications each provide analytics rules that target different layers of the SAP RISE stack:

  • SAP LogServ analytics rules: Focus on infrastructure-layer detections, including SAP HANA audit trail deactivation, operating system anomalies, network activity, and firewall events from SAP-managed infrastructure. Through ASIM normalization, customers can benefit from existing Microsoft Advanced Security Information Model (ASIM) security content and investments they already have in place, without creating SAP RISE-specific analytics rules or altering existing security operations processes.

  • Microsoft Sentinel Solution for SAP applications analytics rules: Cover the application layer, including 60+ built-in rules for detecting privilege escalation, sensitive transactions, data exfiltration, and unauthorized user activity within the SAP business logic.

Deploy both solutions together for cross-layer detection coverage spanning from SAP HANA database and OS infrastructure up through the SAP application layer.

The following example shows an isolated SAP LogServ infrastructure-layer detection for a HANA database audit trail deactivation in Microsoft Sentinel, surfaced as an incident in Microsoft Defender portal. Find a end-to-end scenario in this social engineering attack replay.

Screenshot of a SAP LogServ HANA DB - Deactivation of Audit Trail incident in Microsoft Defender.

Filter LogServ logs before ingestion

Not every log type that SAP LogServ forwards needs to land in your Analytics tier. Filtering happens in the Data Collection Rule (DCR) that the connector deploys, so excluded records are dropped before ingestion and don't incur ingestion cost.

The DCR routes records to several streams based on the clz_dir and clz_subdir attributes supplied by LogServ. For example:

Source (clz_dir / clz_subdir) Destination
windows / security SecurityEvent
windows / anything else WindowsEvent
linux (selected sublogs), hana / hanaaudit Syslog
dns ASimDnsActivityLogs
webdispatcher / accesslog, denylog ASimWebSessionLogs
everything else SAPLogServ_CL (catch-all)

For filtering, identify and remove or narrow the data flow that selects the log type you want to exclude.

For example, to exclude SAP HANA database logs, delete the data flow that selects clz_dir == "hana". For the current data flow definitions, see the SAPLogServ_DCR.json in the Microsoft Sentinel GitHub repository.

Edit the DCR with the transformation editor in the Azure portal, the ARM template export, or the Data Connectors REST API. We recommend that you export the current configuration first and use it as your working template, so you only replace the dataFlows section.

Note

Upgrading the solution from the Content Hub doesn't change DCRs that are already deployed, by design, to avoid unintended interruptions to log ingestion. Allow about 15 minutes for a DCR change to take effect before you verify the results.

Tip

If your goal is cost optimization rather than dropping data outright, use the filter and split capability to keep high-value log types in the Analytics tier and route lower-value, compliance-relevant LogServ data to the Microsoft Sentinel data lake.