Hi Antti,
I think it will really take a long time if i go with the first choice so have to go with the second choice if there is no other alternative.
Anyways thanks for your helpful suggestion.
Hi Antti,
I think it will really take a long time if i go with the first choice so have to go with the second choice if there is no other alternative.
Anyways thanks for your helpful suggestion.
I have logged on to GRC 10 EAM and launched GRAC_EAM and was prompted to select and enter a Reason Code. Next, I clicked execute and noticed no ERP session was created for me to perform the FF action. However, I reviewed the Systm log via SM21 and saw the message:
Userxxx Deletes RFC Destination GRCCLNTXXXX_LD. I have not configured any RFC connection using a name that ends with "LD". Also, I have completed all configurations for GRC Foundation and Plug-In components, tested RFC connections, initiated and reviewed ST05/ST01 Traces and as of this post, I have no solution. Therefore, my question to this forum is Why is the User ID deleting the RFC Destination? Additionally, we installed both GRC Plug-Ins. If anyone is familiar with this issue, I would appreciate your comments and assistance.
Thanks-DP
Go to Personalization option in the GRC report output and in Personalize fields, select the fields you want to see in report output.
I hope this will resolve your issue.
Reward points if useful.
My first post in SCN by the way !
Hi all,
I was wondering if anybody has done any kind of comparison and analysis on these different rule sets?
What I would like to know is SAP_R3_LG rule set contains risks for all SAP modules including HR and BASIS. Therefore, does it mean that risks for BASIS containing in SAP_R3_LG is as same as in SAP_BAS_LG?
Also does it meant that risks containing in SAP_HR_LG for HR module is as same as in risks in SAP_R3_LG for HR?
It means that:
Risks for HR system in SAP_R3_LG = Risks for HR system in SAP_HR_LG
Risks for BASIS system in SAP_R3_LG = Risks for BASIS system in SAP_BAS_LG
Risks for other modules' system in SAP_R3_LG = Risks for other modules' system in SAP_NHR_LG
In which scenarios these different rule sets actually are used?
Please share your views and help me understand this in full.
Regards,
Faisal
Hi Kyle
My bad .I gave you the settings which came in new GRC AC 10.1 system.But it seems in earlier version there is no option SAP has provided.
Still you can cross check with SAP on this.
Regards
Pradeep
Hi Neeraj
if you look at help.sap, Google or SCN you will find the steps for maintaining Rule sets, Risks, Functions, etc.
Regards
Colleen
Hi Sachin
What does the Notification tab in the MSMP Instance Runtime DB Log look like? Also, is the notification setting on the correct step of the path (not sure how complex your MSMP configuration is - e.g. if you have initiator rule that splits your request)
Check in runtime if it actually hits the path and then also check the notification tab to see if it attempts to send the correspondence. If it's got the notification showing up then it should show the Agents
regards
Colleen
Hi Faisal
I take it to mean that the rule set SAP_R3_LG whilst the others are subsets of it.
But for me, I'll activate the entire SAP Sets (ie. exclude non-SAP components) and then export them to Excel to Review and maintain as required.
If you have multiple components in your landscape and separate HR to finance you might want to activate a only a subset of the total rules as the Finance Actions may not apply in HR component and vice versa.
You can always extract the data from the BC sets and compare (unless someone from SAP jumps in here).
Regards
Colleen
Hi Don
Do you have any short dumps in ST22 for trusted RFC? Also were you running ST01/05 in the GRC component or the plug-in system?
If you only looked at GRC, have you seen this KB Article (it is for decentrailsed FF)
1944417 - In decentralized firefighting firefighter is not able to perform firefighter logon
It mentions authorization on the FF Id for password change in the satellite.
Userxxx Deletes RFC Destination GRCCLNTXXXX_LD
As far as the _LD Connection, I've seen that in my system logs too. It must be the way SAP have the FF sessions creating - it temporary creates a connection and then deletes it. Must admit, I've been curious too but mine was working so curiosity energy levels were diverted to something that was broken and I forgot to inquire as to why
It is not deleted the RFC destination that you created as part of configuration and suspect this was quite low level details and too technical to raise in training course.
Hello Don,
The RFC destination with suffix _LD is temporarily created when the Firefighter login using FFID. Then this temporarily created RFC is then deleted. This is as per design.
Hope it answer's your query.
Thanks & Regards,
Chandani
Hi Colleen,
The answer to your questions are:
1. I did not receive any Short Dumps
2. I initiated the traces (ST01/ST05) in GRC
3. I reviewed Note # 1944417
The aforementioned note addresses Decentralized FF access.
I tried logging on in a decentralization mode using
Thanks for the update Chandani!
However, I am unable to set upa connection with the backend/ERP system and my question is how can this be accomplished?
Any ideas are welcome!
Cheers-Don
Hi Don
Can you try ST01/05 in the satellite?
Have you tested your RFC connection is working (including trusted systems in place). Apologies if you think questions are pointless since you mentioned you followed course material.
In switching between centralised and decentralised did you changer the 4010 (?) configuration parameter
In the satellite system are you able to check SM04/AL08 to see if the FF session is there? Possibly might need to be killed.
in centralised mode, when you attempt to login to FF (go into the cockpit, choose FF Id and enter reason code and press enter) - this is where screen meant to open. have you tried minimising SAP GRC and you screens to see if there is an error message on your desktop? You should still have the GRC screen but a new session is meant to open with the FF session.
What SP and Basis stack are you on?
Cheers
Colleen
Hello Don,
Can you please confirm if you are getting a login screen or no new window opens up. The logical destination is not an issue. It will be created and then used for FFID login and after that it would be deleted. So please check in ST22 if any dump is coming in plugin/ERP system. Also confirm your plugin system basis release.
Thanks & Regards,
Chandani
Hello,
@Collen: our colleage tried the release button he also tried the refresh button. But without any success. The FFID remains still locked.
@Radhu: this note is not related to our system, we run SAP GRC 10.0 on SP12.
Regards,
Jakub
Hi Ramakrishna,
The rule is created in the BRF+ workbench
TJ
Hi TJ,
Thanks for the response.
Could you please explain, how to link the rule that is created in BRF+ workbench and the business rule that is created in PC.
Regards,
Ramakrishna Chaitanya
First you need to create a placeholder condition in the business rule, in the BRF+ workbench you can modify this condition with the correct formula and test it with the ad-hoc query functionality of the business rule.
Hi Faisal and Colleen,
Thanks for your inputs. I am also going in the same way as suggested by you. Today we had a review with business and apart from few changes it went well.
Thanks for your explanation with example which gave bit more clarity for me on this SOD part.
Regards,
Madhu.
Thanks Dileep and Antti for clear explanation. Now i can understand its purpose clearly.
Regards,
Madhu.