Skip to content

Conversation

@randomstr1ng
Copy link
Contributor

What reference architecture does this PR apply to?

This PR relates to the Log Driven Security Operations reference architecture. It adds a concrete example showing how SAP Enterprise Threat Detection can be combined with SIEM and SOAR solutions, using FortiSIEM and FortiSOAR, to support centralized monitoring, correlation, and automated incident response in SAP environments.

Who should review your contribution? (Use @mention)

@jmsrpp

Checklist before submitting

  • My commits are only for the reference architecture mentioned above.
  • I have followed the folder structure in the main README

@randomstr1ng randomstr1ng requested a review from a team as a code owner December 28, 2025 09:07
@randomstr1ng randomstr1ng changed the title Reference Architecture for Log Driven Security Operations (SAP ETD, FortiSIEM & FortiSOAR( Reference Architecture for Log Driven Security Operations (SAP ETD, FortiSIEM & FortiSOAR) Dec 28, 2025
@cla-assistant
Copy link

cla-assistant bot commented Dec 28, 2025

CLA assistant check
All committers have signed the CLA.

@github-actions
Copy link

Preview website is available here.

@jmsrpp jmsrpp self-assigned this Jan 12, 2026
@sap-email-compliance
Copy link

SAP employees are expected to use their SAP-email address for commits related to their work. Our compliance check has detected usage of an email other than a SAP one by a SAP employee. Please update your pull request accordingly.

If you think this is wrong or need any assistance, please contact [email protected].

@github-actions
Copy link

Preview website is available here.

@guilherme-segantini
Copy link
Contributor

@randomstr1ng Hi - thanks for your collaboration.

Overall, this is a solid RA. It’s a positive step for the architect community.

The value prop is clear: SAP ETD is excellent at deep, SAP-specific detection, but it’s not designed to look at the rest of the world—firewalls, endpoints, network traffic, AD, etc. If you want to correlate SAP events with infrastructure-wide data, you need a SIEM to aggregate it and a SOAR to handle the ops. That’s exactly where the integration fits in.

That said, I have a few specific requests to improve the positioning:

Vendor Neutrality: Please rewrite the content to be vendor-neutral throughout. The text should describe the synergy of integrating ETD with a generic SIEM/SOAR, using FortiSIEM and FortiSOAR strictly as the vendor-specific examples for this iteration. We want to avoid locking the concepts down to one vendor.

"Umbrella" Approach: Ideally, we want this to be an umbrella RA for "SIEM/SOAR with ETD." Fortinet is the first mover here, but we’ll eventually add others (like Microsoft Sentinel). Writing it this way keeps the guidance relevant for all our architects, regardless of their stack.

Line 39: Let's change the phrasing "must be combined" to "can be integrated." Saying "must" is too prescriptive and accidentally downplays SAP ETD’s value as a standalone solution.

Architecture Diagram: It's clear and transmit the key integration points perfectly. No changes needed there.

Once these changes are applied, we'll be glad to review again.
Thanks again.

Copy link
Contributor

@guilherme-segantini guilherme-segantini left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for your collaboration.

Overall, this is a solid RA. It’s a positive step for the architect community.

The value prop is clear: SAP ETD is excellent at deep, SAP-specific detection, but it’s not designed to look at the rest of the world—firewalls, endpoints, network traffic, AD, etc. If you want to correlate SAP events with infrastructure-wide data, you need a SIEM to aggregate it and a SOAR to handle the ops. That’s exactly where the integration fits in.

That said, I have a few specific requests to improve the positioning:

Vendor Neutrality: Please rewrite the content to be vendor-neutral throughout. The text should describe the synergy of integrating ETD with a generic SIEM/SOAR, using FortiSIEM and FortiSOAR strictly as the vendor-specific examples for this iteration. We want to avoid locking the concepts down to one vendor.

"Umbrella" Approach: Ideally, we want this to be an umbrella RA for "SIEM/SOAR with ETD." Fortinet is the first mover here, but we’ll eventually add others (like Microsoft Sentinel). Writing it this way keeps the guidance relevant for all our architects, regardless of their stack.

Line 39: Let's change the phrasing "must be combined" to "can be integrated." Saying "must" is too prescriptive and accidentally downplays SAP ETD’s value as a standalone solution.

Architecture Diagram: It's clear and transmit the key integration points perfectly. No changes needed there.

Once these changes are applied, we'll be glad to review again.
Thanks again.

@randomstr1ng
Copy link
Contributor Author

Hi @guilherme-segantini,

Thank you for your detailed feedback - much appreciated!

I have reworked the content to be more vendor-neutral and highlighted that it is built based on Vendor Products as an example.
In addtion I have also updated the metadata, like tags and keywords.

Let me know what you think. Would love to hear your thoughts.
Thank you.

@github-actions
Copy link

Preview website is available here.

@cernus76 cernus76 marked this pull request as draft January 27, 2026 14:46
@cernus76
Copy link
Contributor

Hey @guilherme-segantini , please let me know once the content review is done. I've marked it as Draft but you can switch back to Ready for review (please add the corresponding label when ready). Thanks!

@cernus76 cernus76 added reference-architecture Content contributions for new or updated reference architectures content labels Jan 27, 2026
@github-actions
Copy link

Preview website is available here.

@github-actions
Copy link

Preview website is available here.

@github-actions
Copy link

Preview website is available here.

Copy link
Contributor

@jmsrpp jmsrpp left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks @randomstr1ng and @guilherme-segantini for making the relevant updates. This is approved!

@jmsrpp jmsrpp marked this pull request as ready for review January 27, 2026 18:22
@jmsrpp jmsrpp added the ready for review This need to be reviewed label Jan 27, 2026
@jmsrpp
Copy link
Contributor

jmsrpp commented Jan 27, 2026

@cernus76 I have reviewed and approved. This is good to go from our POV.

@cernus76 cernus76 dismissed guilherme-segantini’s stale review January 28, 2026 11:31

The review has been approved

@cernus76 cernus76 merged commit f6b3ac9 into SAP:dev Jan 28, 2026
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

content ready for review This need to be reviewed reference-architecture Content contributions for new or updated reference architectures

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants