LogServ with Sentinel - Enhancing Support for RISE on AWS & GCP
| Hemanth Kusampudi | Bastian Ulke | Martin Pankraz |
Episode #298
Introduction
In episode 298 of our SAP on Azure video podcast we talk about LogServ with Sentinel and enhancing Support for RISE on AWS & GCP.
In previous episodes we already talked about LogServ and how this can help collecting, storing and forwarding log information. The SAP LogServ integration with Microsoft Sentinel is already used by lots of SAP RISE customers. When your SAP on RISE system is running on Azure that is an obvious choice. But what if you selected AWS or GCP as the underlying infrastructure? I am glad to have Martin, Bastian and Hemanth from SAP with us today.
Find all the links mentioned here: https://www.saponazurepodcast.de/episode298
Reach out to us for any feedback / questions:
- Goran Condric: https://www.linkedin.com/in/gorancondric/
- Holger Bruchelt: https://www.linkedin.com/in/holger-bruchelt/
#Microsoft #SAP #Azure #SAPonAzure #RISE #Sentinel #LogServ
Summary created by AI
- Overview of SAP LogServe and Microsoft Sentinel Integration:
- Holger, Martin, Hemanth, and Bastian discussed the background, * motivation, and strategic importance of integrating SAP LogServe with Microsoft Sentinel, highlighting its adoption among SAP RISE customers and the extension to AWS and GCP platforms.
- Background and Adoption: Holger explained that SAP LogServe integration with Microsoft Sentinel is already widely used by SAP RISE customers running on Azure, providing a robust solution for collecting, storing, and forwarding log information from SAP systems.
- Strategic Partnership: Martin emphasized the strategic partnership between SAP and Microsoft, noting that the collaboration enhances SAP security and provides customers with a best-in-class managed cloud environment, leveraging both companies’ strengths.
- Extension to AWS and GCP: Holger introduced the extension of LogServe and Sentinel integration to customers using AWS or GCP as their infrastructure, with Martin, Bastian, and Hemanth providing insights into the new support and its implications for non-Azure customers.
- Security Landscape and AI-Driven Threat Detection:
- Martin and Holger discussed recent advancements in AI-driven security, the emergence of new vulnerabilities, and the need for continuous monitoring and threat detection, referencing Microsoft’s Project Perception and the competitive landscape in AI security research.
- AI and Vulnerability Detection: Martin described how AI models, such as Claude Mutos and Microsoft’s MAI-Cyber-1-Flash, are outperforming humans in finding vulnerabilities in large codebases, with benchmarks like CyberGym being used to evaluate their effectiveness.
- Project Perception Overview: Martin introduced Project Perception, a system of specialized agents (red, blue, and green teams) designed to simulate attacks, detect and triage findings, and automatically remediate issues, forming a closed-loop security system.
- Shift from Pre-Breach to Post-Breach: The discussion highlighted the industry shift from focusing solely on breach prevention to emphasizing monitoring, threat protection, and rapid recovery, acknowledging that breaches are increasingly inevitable due to advanced AI capabilities.
- Technical Implementation of LogServe and Sentinel Integration:
- Martin and Bastian provided a step-by-step walkthrough of deploying the LogServe-Sentinel integration across Azure, AWS, and GCP, detailing the installation process, configuration, and the role of the SAP ECS LogForwarder.
- Azure Integration Process: Martin explained that for Azure, customers can deploy the LogServe solution directly from the content hub in the Azure portal or Microsoft Defender, with SAP handling the integration once endpoint details are shared securely.
- AWS and GCP Integration Differences: For AWS and GCP, Martin clarified that customers are responsible for providing the compute resources to run the log forwarder, following a similar process but with additional steps to deploy and configure the forwarder on their infrastructure.
- SAP ECS LogForwarder Details: Bastian described the SAP ECS LogForwarder as a Python-based, cloud-agnostic tool that supports Azure, AWS, and GCP, enabling customers to forward log data to various destinations, including Microsoft Sentinel, via straightforward configuration.
- Configuration and Credential Management: The team outlined the process for obtaining necessary credentials from the SAP self-service portal, configuring the forwarder with tenant and application IDs, and ensuring secure data transmission to Sentinel.
- Security Operations and Use Cases with Sentinel Integration:
- Martin and Holger demonstrated how the integration enhances security operations by enabling advanced detections, correlation, and incident response within Microsoft Defender and Sentinel, using real-world examples and out-of-the-box detections.
- Out-of-the-Box Detections: Martin showcased built-in detections such as HANA database audit trail deactivation, which are available immediately upon integration and provide actionable security insights.
- Correlation Engine and Incident Graphs: The value of the correlation engine was highlighted, as it aggregates signals from various sources to build comprehensive incident graphs, enabling security analysts to identify complex attack patterns and respond effectively.
- Dynamic Threat Detection: Martin explained the role of dynamic threat detection agents, which use advanced reasoning to identify threats that may not be detected by traditional mathematical models, further enriching the security posture.
- ECS Security Portal and Self-Service Capabilities:
- Hemanth presented the ECS Security Portal, emphasizing its self-service features for log management, dashboard customization, compliance monitoring, and integration with customers’ SIEM tools, supporting both centralized and distributed environments.
- Portal Overview and Features: Hemanth described the portal as a central hub for managing log collection, retention, and recovery, offering customers the ability to create and share custom dashboards and use cases within their organization or the broader SAP community.
- Self-Service Integration: The portal provides self-service options for integrating logs into customers’ SIEM tools, with simplified workflows for Azure and more flexible, customer-managed options for AWS and GCP.
- Compliance and Security Posture: Customers can monitor cloud and application compliance, view vulnerabilities, and assess the security posture of their SAP environments, with data structured by region and source for granular analysis.
- Observability, Vulnerability Management, and Network Monitoring:
- Hemanth and Martin discussed the observability suite within the ECS Security Portal, covering system vulnerabilities, network activity, and the ability to customize and share dashboards for enhanced visibility and actionability.
- Vulnerability and Compliance Dashboards: The portal provides consolidated views of vulnerabilities, missing patches, and compliance status across all SAP RISE systems, enabling customers to quickly identify and address security gaps.
- Network and Flow Log Monitoring: Detailed network dashboards display flow logs, DNS activity, proxy usage, and WAF/ALB statistics, allowing customers to monitor inbound and outbound traffic and identify unusual or risky behavior.
- Customizable and Shareable Templates: Customers can create, customize, and share dashboard templates, facilitating collaboration and knowledge sharing within the SAP security community.
- Roadmap and Future Enhancements:
- Hemanth outlined upcoming features, including enhanced application-layer detections, deeper integration of threat intelligence between Sentinel and the ECS Security Portal, and expanded use of AI for automated response and shared responsibility.
- Upcoming Application Detections: Hemanth announced that new detections for ABAP, Java, cloud connectors, web dispatchers, and SAP routers will be released by the end of August or early September, expanding coverage beyond HANA.
- Threat Intelligence Sharing: Plans are in place to enable two-way sharing of threat intelligence between Sentinel and the ECS Security Portal, leveraging APIs and AI-powered assistants for more efficient and collaborative security operations.
- 0:00 Introduction and Guest Intros
- 4:02 MAI-Cyber-1-Flash & CyberGym Evaluation
- 6:48 Security Landscape and AI Threats
- 8:05 Project Perception and Security Agent Teams
- 8:59 Content Hub – Install Sentinel
- 10:01 Architecture Overview & Multi-Cloud Support (Azure, AWS, GCP)
- 12:27 SAP ECS LogForwarder (Technical Walkthrough)
- 16:53 Defender Portal – Threat Detection & Correlation Engine
- 19:54 SAP RISE as an Extension of the Local Datacenter
- 23:11 ECS Security Portal & Observability
- 24:07 Raven Dashboards
- 29:00 Compliance and Application Security Posture
- 31:23 Network Observability and API Integration
- 35:07 Future Directions and AI Integration
- 36:06 Closing Remarks and Collaboration
