Importing the SAP GRC Application Rule

(Applicable only for Risk Analysis Integration Mode) The IdentityIQ Rule is required for populating IdentityIQ SAP application configuration parameters with the SAP GRC connector name.

Perform the following steps to import and execute the SAP GRC application rule:

  1. Create the sapGrcApplications.csv file, which contains the following columns separated by a comma:

    • IdentityIQ Application name

    • Respective SAP GRC Server side connector name. For example:

      SAPAPPLICATION1, SAPGRCCONNECTOR

      Note
      Comments can be provided in the sapGrcApplications.csv file using the hash (#) symbol at the beginning of the line. For example, you can enter comments for the column headers.

      Note
      If the second column name is not provided then the IdentityIQ application name is treated as the SAP GRC connector name.

  2. Create the sapGrcRuleParameters.xml file, which will contain the following map of arguments that are required to pass externally to the rule:

    • path: Path of the sapGrcApplications.csv file.

    • separator: Separator used in the sapGrcApplications.csv file to separate the IdentityIQ application name and respective SAP GRC Server side connector name. For example:

      Copy
      <Map>      
        <entry key='path' value='E://SAPGRCApplications.csv'/>    
        <entry key='separator' value=','/>
      </Map>
  3. Import the sapGrcApplicationsRule.xml IdentityIQ Rule, which populates the IdentityIQ SAP application configuration parameter with the SAP GRC connector name.

    • The sapGrcApplicationsRule.xml file is present in the WEB-INF/config folder.

    • From the console, run the following commands:

      import sapGrcApplicationsRule.xml

      rule "Mapping GRC Connector Name to SAP based Application" <path of sapGrcRuleParameters.xml file>

      For example:

      rule "Mapping GRC Connector Name to SAP based application"    "E://sapGreRuleParameters.xml"

      The following figure displays the output of the above performed steps:

Logging for the Rule -

Enter the following line to set logging for the rule in the log4j.properties file:  

log4j.logger.SAPGRC.sapGrcApplicationsRule=debug