Run Configuration Checks
Use the following steps to evaluate the SAP configuration of a Systems Manager for SAP application, which is either of type SAP HANA or SAP ABAP.
See also support restrictions for Systems Manager for SAP.
Topics
To access configuration checks
-
Open the AWS Systems Manager console at https://console.aws.amazon.com/systems-manager/
-
In the navigation pane, choose Application Tools, then choose Application Manager
-
From the list of registered applications, choose the SAP application you want to evaluate
-
Choose Actions, then choose SAP Configuration Checks
To evaluate configuration checks
-
Select one or more checks you want to evaluate
-
Choose Run
-
Monitor the task status using either the operation ID provided in the notification banner or by choosing Actions > View operations
To view and analyze check results
-
Select a single check to view its details
-
Expand individual subchecks to see detailed rules
-
Sort subchecks by Rule Status, Description, or Component
-
Filter results by rule status using the status totals or the filter box
-
Clear filters by selecting the cancel indicator
-
View previous results by selecting a different evaluation date from the dropdown list
-
Access additional information through the provided Documentation links
Schedule Configuration Checks using AWS EventBridge Scheduler console
-
Sign in to the AWS Management Console, then choose the following link to open the EventBridge Scheduler section of the EventBridge console: https://console.aws.amazon.com/scheduler/home
. You can switch your AWS Region by using the AWS Management Console’s Region selector. -
On the Schedules page, choose Create schedule.
-
On the Specify schedule detail page, in the Schedule name and description section, do the following:
-
For Schedule name, enter a name for your schedule. For example,
SAPConfigurationChecksSchedule -
For Description - optional, enter a description for your schedule.
-
For Schedule group, choose a schedule group from the drop down options. If you haven’t previously made any schedule groups, you can choose the
defaultgroup for your schedule. To create a new schedule group, choose the create your own schedule link in the console description. You use schedule groups to add tags to groups of schedules.
-
-
In the Schedule pattern section, do the following:
-
For Occurrence, choose one of the following pattern options. The configuration options change depending on which pattern that you select.
-
One-time schedule – A one-time schedule invokes a target only once at the date and time that you specify. For Date and time, enter a valid date in
YYYY/MM/DDformat. Then, specify a timestamp in 24-hourhh:mmformat. Finally, choose a timezone from the drop down options. -
Recurring schedule – A recurring schedule invokes a target at a rate that you specify using a cron expression or rate expression. Choose Cron-based schedule to configure a schedule by using a cron expression. To use a rate expression, choose Rate-based schedule and enter a positive number for Value, then choose a Unit from the drop down options.
For more information on using cron and rate expressions, see Schedule types in EventBridge Scheduler.
-
-
For Flexible time window, choose Off to turn off the option, or choose one of the pre-defined time windows from the drop down list. For example, if you choose 15 minutes and you set a recurring schedule to invoke its target once every hour, the schedule runs within 15 minutes after the start of every hour.
-
-
If you chose Recurring schedule in the previous step, in the Timeframe section, specify a timezone, and optionally set a start date and time, and an end date and time for the schedule. A recurring schedule without a start date will begin as soon as it is created and available. A recurring schedules without an end date will continue to invoke it’s target indefinitely.
-
Choose Next.
-
On the Select target page, do the following:
-
Select All APIs option, and Find service "Systems Manager for SAP" from the search box.
-
Find the Target action "StartConfigurationChecks" and provide the json payload based on the StartConfigurationChecks API action (ApplicationId string input, and optionally, ConfigurationCheckIds array string)
-
-
Choose Next, then on the Settings - optional page, follow the steps described in EventBridge console Getting Started guide (Step 9 onwards), to change the default settings of the desired schedule.
-
In the Permissions section, in order for the Scheduler to execute the StartConfigurationCheck operation successfully, an IAM role needs to be created with the AWSSystemsManagerForSAPFullAccess managed policy, using the steps below:
-
In the AWS IAM Console, Create a new role, using a “Custom trust Policy“, and the following trust relationship:
{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Principal": { "Service": "scheduler.amazonaws.com" }, "Action": "sts:AssumeRole" } ] } -
On the Next page, Add Permissions by searching for and selecting the AWSSystemsManagerForSAPFullAccess managed policy
-
Next, provide the Role name and Description, (and tags if any), before creating the role for the scheduler.
-
Select this new Role in the Permissions section of the schedule on the AWS EventBridge Console, while creating the schedule
-
-
Choose Create schedule to finish creating your new schedule. You can view a list of your new and existing schedules on the Schedules page. Under the Status column, verify that your new schedule is Enabled.
-
To verify that your schedule invokes the Systems Manager for SAP service’s StartConfigurationChecks target, follow the steps listed at To view and analyze check results.