Skip to Content
author's profile photo Former Member
Former Member

Audit logs not displaying in sm20

Hi all,

After kernel 721_EXT_500 upgrade, i am not able to see Security audit logs in sm20. However logs are generating at OS level.

i have observed after kernel upgrade at OS level audit file format was changed in to ++++++++######.AUD before it was audit_+++++++. Then accordingly i have set the below parameters

FN_AUDIT ++++++++######.AUD DIR_AUDIT /usr/sap/SID/DVEBMGS00/log RSAU/ENABLE 1

after change the FIN_AUDIT parameter , i can see the logs only after kernel upgrade. but i want to see the full logs before and after kernel upgrade.

appreciate your quick response

Regards,

Raghav.

.

Add a comment
10|10000 characters needed characters exceeded

Assigned Tags

Related questions

4 Answers

  • author's profile photo Former Member
    Former Member
    Posted on May 13, 2015 at 10:13 AM

    Hi

    Try to change old files names to new format.

    Best regards

    Przemek

    Add a comment
    10|10000 characters needed characters exceeded

  • Posted on May 14, 2015 at 06:46 AM

    Hi Raghu,

    Have you tried keeping FN_AUDIT parameter value same as old one???

    Hope you have only few audit files with new file names!!

    Regards,

    Gangadhar

    Add a comment
    10|10000 characters needed characters exceeded

    • Hi Raghu,

      Seems we have only one option left :-( Converting the file names to new format -

      Kindly check the note 539404 (question 30) and use the report RSCP_CONVERT_FILE to covert the file name to new format

      This report should allow you to do mass file name change

      OR

      You can check with basis team to get OS level command/Script to mass rename of old files.

      It is better to take a back up of files before doing this conversion.

      Regards,

      Gangadhar

  • author's profile photo Former Member
    Former Member
    Posted on May 19, 2015 at 07:59 AM

    hi,

    issue resolved , Note 909738 is helpful .


    Regards,

    raghu.

    Add a comment
    10|10000 characters needed characters exceeded

  • Posted on May 13, 2015 at 08:13 AM

    Hi,

    As far as I know, it is not possible to evaluate both format audit logs at the same time.

    However, you could use report RSAU_SELECT_EVENTS to evaluate past logs.

    I hope this information is useful.

    Best regards,

    Ning

    Add a comment
    10|10000 characters needed characters exceeded

Before answering

You should only submit an answer when you are proposing a solution to the poster's problem. If you want the poster to clarify the question or provide more information, please leave a comment instead, requesting additional details. When answering, please include specifics, such as step-by-step instructions, context for the solution, and links to useful resources. Also, please make sure that you answer complies with our Rules of Engagement.
You must be Logged in to submit an answer.

Up to 10 attachments (including images) can be used with a maximum of 1.0 MB each and 10.5 MB total.