Document toolboxDocument toolbox

SUIM

Data Description

The SUIM event is used to view the changes associated with SAP users, profiles, roles and authorizations. Data from multiple clients could be extracted (from SP 6.07).

Potential Use Cases

This event could be used in the following scenarios:

  • Identify and alert on changes, which could create compliance concerns

Splunk Event

SUIM with EVENT_SUBTYPE=”AUTH”

Changes of Authorizations. The event will look like this in Splunk:

SUIM with EVENT_SUBTYPE=”PROF”

Changes of Profiles. The event will look like this in Splunk:

SUIM with EVENT_SUBTYPE=”ADMR”

Changes for Roles Assignments. The event will look like this in Splunk:

SUIM with EVENT_SUBTYPE=”USER”

User related changes. The event will look like this in Splunk:

SUIM with EVENT_SUBTYPE=”ROLE”

Changes of Roles. The event will look like this in Splunk:

 

SAP Navigation

Log into the managed system and execute the SUIM transaction. Expand the Change Documents section to review one of options below: