Install a Microsoft Sentinel solution for SAP applications

This article shows you how to install the Microsoft Sentinel solution for SAP applications from the content hub. The solution includes an SAP data connector, which collects logs from your SAP systems and sends them to your Microsoft Sentinel workspace, and out-of-the-box security content—including workbooks and analytics rules—that helps you gain insight into your organization's SAP environment and detect and respond to security threats. Installing your solution is a required step before you can configure your data connector. Before you start, make sure you meet the prerequisites for deploying the Microsoft Sentinel solution for SAP applications.

Diagram of the SAP solution deployment flow, highlighting the Install solution content step.

Content in this article is relevant for your security team.

Prerequisites

To deploy a Microsoft Sentinel solution for SAP applications from the content hub, you need:

Make sure that you also review the prerequisites for deploying Microsoft Sentinel solution for SAP applications, especially Azure prerequisites.

Install the solution

Installing the Microsoft Sentinel Solution for SAP makes the agentless data connector available to you from the Microsoft Sentinel Configuration > Data connectors page. The solution also deploys security content, such as the SAP -Audit Controls workbook and SAP-related analytics rules.

  1. In the Microsoft Sentinel Content hub, search for SAP to install the SAP applications solution.

  2. On the Microsoft Sentinel solution for SAP applications page, select Create to define deployment settings. For example:

    Screenshot that shows the Microsoft Sentinel solution for SAP applications solution pane.

  3. On the default Basics tab, scroll down to select where to install the solution.

  4. Select Review + create or Next to browse through the solution components. When you're ready, select Create

    The deployment process can take a few minutes. After the deployment is finished, you can view the deployed content in Microsoft Sentinel.

For more information, see Discover and manage Microsoft Sentinel out-of-the-box content.

View deployed content

When the SAP applications solution deployment is finished, display your new content by browsing again to the Microsoft Sentinel for SAP applications solution from the Content hub. Alternatively, to view the deployed content without returning to the Content hub:

Your data connector doesn't appear as connected until you configure your data connector and complete the connection.

Next step

For more information, see Microsoft Sentinel solution for SAP applications: security content reference.