Skip to Content
Author's profile photo Former Member

SAP Enterprise Threat Detection 1.0 SP02 is Now Available

There are a lot of things to like about the latest version of SAP Enterprise Threat Detection. In this blog I am going to introduce one of the more subtle improvements – semantic events.

Semantic Events

Take a look at the screenshot and compare the two filter paths. Can you guess what each does?

/wp-content/uploads/2015/07/blog_semantic_events_754309.gif

If you are intimate with the Security Audit Log in AS ABAP, you will of course know that the Event ID AU2 indicates that a user has attempted a dialog logon and failed. If that log type is not so familiar to you, I suspect you would rather deal with the semantic event “User, logon, failure, dialog”.

Usability is not the only difference though. In the screenshot, both paths found the same event because the failed logon took place in an ABAP system. By using the semantic event, Path2 is not restricted to events from ABAP systems. Therefore, many of the attack detection patterns delivered in SP02 are now based on semantic events to broaden their applicability.

Relevant SAP Notes

2139392 – Release Note SAP Enterprise Threat Detection 1.0 SP02

Assigned Tags

      1 Comment
      You must be Logged on to comment or reply to a post.
      Author's profile photo Mercedes Barrachina Fernandez
      Mercedes Barrachina Fernandez

      I would like to know the complete list of the event IDs....where can I find this information?

       

      Thanks,

       

      Regards,