Monday, April 7, 2008

SAP Security Audit: SM19

使用SA38_RSPARAM 或 T-code: RZ11檢查Security Audit Log是否啟用:
  • rsau/enable=1 啟用
  • rsau/enable=0 未啟用
但即使未啟用 (rsau/enable=0),客戶使用SM19啟動Audit Log功能仍有效,此係動態方式設定;若要採用靜態方式才須設定rsau/enable為1。

1. Static filters
If you use static filters, all of the application servers use identical filters for determining which events should be recorded in the audit log. You have to define filters only once for all application servers. You can also define several different profiles that you can alternatively activate.

Result
The filters you define are saved in the audit profile. If you activate the profile and restart the application server, actions that match any of the active filter events are then recorded in the security audit log. Before you can set Static Filters, you must first set the following profile parameters:
rsau/enable
rsau/local/file
rsau/max_diskspace/local
rsau/selection_slots

2. Dynamic filters
Dynamic filters enable you to respond to real-time events in your system environment, setting traps that can assist you in addressing a security problem. With this option, you can dynamically change the filters used for selecting events to audit. The system distributes these changes to all active application servers.

Result
The audit filters are dynamically created on all active application servers. If you activate the profile(s), any actions that match any of these filters are recorded in the security audit log. Changes to the filter definitions are effective immediately and exist until the application server is shut down. Before you can set dynamic filters, you must first set the following profile parameters:
rsau/local/file
rsau/max_diskspace/local
rsau/selection_slots


資料來源 (Provided by Rita)
https://www.sdn.sap.com/irj/sdn/thread?threadID=328127
SM19 Dynamic Configuration.


Monday, March 31, 2008

Oracle DB connection

Oracle's password file

If the DBA wants to start up an Oracle instance there must be a way for Oracle to authenticate this DBA. That is if (s)he is allowed to do so. Obviously, his password can not be stored in the database, because Oracle can not access the database before the instance is started up. Therefore, the authentication of the DBA must happen outside of the database. There are two distinct mechanisms to authenticate the DBA: using the password file or through the operating system. The init parameter remote_login_passwordfile specifies if a password file is used to authenticate the DBA or not. If it set either to shared or exclusive a password file will be used.

The initialization parameters can be set in the init.ora file.

Default location and file name
The default location for the password file is:
$ORACLE_HOME/dbs/orapw$ORACLE_SID on Unix and
%ORACLE_HOME%\database\PWD%ORACLE_SID%.ora on Windows.


Monday, March 24, 2008

SAP CO 月結與差異分攤

SAP Controlling month end and variance allocation

1. Cost Center month end

1.1 Collect indirect expense
Collect indirect expense

1.2 Collect manufacturing expense
Collect manufacturing expense

1.3 Actual Price calculation
Actual LAB FOH VOH rate calculation

1.4 Overhead per production order calculation (Indirect expense allocation)
Indirect expense allocation (Std)

1.5 Revaluation at Actual Price : Production Order (Manufacturing expense allocation)
Manufacturing expense allocation

2. Production Order Settlement

2.1 Calculate Work in Process (WIP)
Calculate WIP
Movement type relevant to Production Order

2.2 Variance Calculation (Quantity variance)
Quantity variance
Month end production orders settlement

2.3 Actual settlement (Allocate variance and Create accounting document)
Accountant use CO88 to perform actual settlement. Variance was allocated and accounting documents were created by SAP.

3. Material Ledger Update

3.1 Price variance calculation and allocation
Price Variance

3.2 Manual allocate remained expenses to COGS
Accountant check all 4* and 5* accounts and post a journal entry manually to allocate all remained expenses to COGS.

4. Actual cost walkthrough test
ROH actual cost walkthrough
WIP actual cost walkthrough

5. Material records price control check
Material records price control