Dynamically created profiles, on the contrary, can be activated at any time to filter for selected events. They are automatically distributed to all active application servers (after saving and distributing them by selecting Configuration->Distribute Configuration).
Transaction SM19 - Administer Audit Profile
4. Analyzing the Audit Log
The Security Audit Log produces an audit analysis report that contains the audited activities. By using the audit analysis report you can analyze events that have occurred and have been recorded on a local server, a remote server, or all of the servers in the SAP System.
To access the Security Audit Log Analysis screen from the SAP standard menu, choose:
Tools->Administration->Monitor->Security Audit Log->Analysis (or transaction SM20). The Audit Log can be scanned for a period of time, user, transaction, report, ect.
Transaction SM20 - Analyzing the Audit Log
Example report:
Time Cat No Cl. User Transaction code Terminal MNo Text
12:00:38 DIA 0 100 I004567 SM19 PCIT0012 AU3 Transaction SM19 Started
12:00:56 DIA 1 100 I003765 SE71 PCIT0054 AU3 Transaction SE71 Started
12:01:28 DIA 1 100 I003765 SE71 PCIT0054 AUW Report RSTXDBUG Started
12:01:31 DIA 1 100 I003765 VT03N PCIT0054 AU3 Transaction VT03N Started
12:01:36 DIA 1 100 I003765 SE71 PCIT0054 AU3 Transaction SE71 Started
12:01:43 DIA 1 100 I003765 SE71 PCIT0054 AUW Report RSTXDBUG Started
12:01:45 DIA 1 100 I003765 VT03N PCIT0054 AU3 Transaction VT03N Started
12:01:58 DIA 1 100 I003765 VT12 PCIT0054 AU3 Transaction VT12 Started
12:01:58 DIA 1 100 I003765 VT10 PCIT0054 AUW Report RV56TRST Started
12:01:58 DIA 1 100 I003765 VT10 PCIT0054 AUW Report RV56TRSL Started
12:02:49 DIA 1 100 I003765 VT03N PCIT0054 AU3 Transaction VT03N Started
T r a n s a c t i o n S t a t i s t i c s
Transaction Number of entries
VA01 17 5%
VA02 13 4%
SE71 13 4%
SE16N 12 3%
ZV01 9 1%
SM19 9 1%
SE38 8 1%
SA38 7 1%
MB51 7 1%
CO03 5 1%
VT03N 5 1%
SE37 4 1%
SE91 4 1%
LX03 4 1%
VA01 3 1%
SE09 3 1%
SM18 3 1%
CO02 2 1%
BMBC 2 1%
R e p o r t S t a t i s t i c s
Report Number of entries
RSBTCRTE 653 24 %
ZFIN01 642 23 %
SAPMSSY4 298 11 %
ZCO03 297 11 %
ZFIN09 74 3 %
SAPLSMTR_NAVIGATION 40 1 %
RSRZLLG0 39 1 %
RSDSLAN1 33 1 %
CSM_LOAD_APPSRV_DATA 33 1 %
SAPMSSY8 31 1 %
RSDSBUFF 31 1 %
RSDSOSCO 31 1 %
RSDSFSYS 31 1 %
RSDSUSER 31 1 %
RSDS_DBMEMBER 31 1 %
RSDSDEFLOAD 31 1 %
RSALSUP5 30 1 %
RSRZLST0 30 1 %
RSALSUP2 30 1 %
RSUVM018 30 1 %
RSDSSPTI 30 1 %
CCUMEAS 30 1 %
RSRFCDMN 30 1 %
RSDSSPNR 25 1 %
RSDS_BP_FREEWP 16 1 %
RS_UPDATE_STATUS 14 1 %
RK_SE16N 6 %
5. Reorganizing the Audit Log
The Security Audit Log saves its audits to a corresponding audit file on a daily basis. Depending on the size of your SAP System and the filters specified, you may be faced with an enormous quantity of data within a short period of time.
Old audit log files can be deleted via Tools->Administration->Monitor ->Security Audit Log->Configuration (or transaction SM18).