SAP Knowledge Base Article - Public

3382432 - Set a 90-day retention time for OData API and SFAPI audit logs in SAP SuccessFactors HCM Suite - 2H 2023

Symptom

We've set a 90-day retention time for OData API and SFAPI audit logs in SAP SuccessFactors HCM Suite. Audit logs older than 90 days are automatically purged from the system.

“Image/data in this KBA is from SAP internal systems, sample data, or demo systems. Any resemblance to real data is purely coincidental."

Environment

SAP SuccessFactors HCM suite

  • OData API/SFAPI audit log

Cause

Previously, old audit logs were purged when the default number limit of a company is reached. Now, both number limit and retention time are taken into account when the system determines which logs to purge.

We made the enhancement to reduce cloud storage and improve system performance.

Resolution

• The Provisioning Job 'Clean API Audit Log Company Job' is running automatically every day.
 
• If the OData audit log or SFAPI audit log exceeds one million on the first run, the job will run twice on the same day.

• Now the API audit logs will be purged if any of these conditions are met:

    • The maximum log count is exceeded. In this case the older logs get purged first.
    • A log is more than 90 days old.
By default, the maximum log count for SFAPI is 500,000.

• For OData API, the maximum log count follows the 'OData API Audit Log Setting' configuration in Provisioning.”.

 
 
Please note that the background cleanup logic is roughly 10,000 by 10,000 for cleanup, the number of cleanups fluctuates above and below 10% of the threshold.


FAQ

(1) Even after IAS/IPS activation, do SSO users need to re-enter username and password in 90 days because of Retention Time for API Audit Logs?

  • The 90 day retention period of the API audit logs does not impact the SSO user. There is no requirement to enter a username and passowrd in this case.


(2) After IAS/IPS activation, SSO users' session will time out in 12 hours by default, do SSO users need to re-enter username and PWD after 12 hours?  

  • There will be no requirement in this case to enter username and password. The system will generate a new session each time. Ensuring the users have smooth access to the system.

Keywords

KI2311, 2H 2023, 2311, KEA, release, production, preview, H2, API-28533, OData API Audit Log Setting, Clean API Audit Log Company Job , KBA , LOD-SF-INT-ODATA , OData API Framework , LOD-SF-INT-API , API & Adhoc API Framework , Product Enhancement

Product

SAP SuccessFactors HCM Core all versions