Sap Solution Function Reference
In brief
The page date was updated, AI-usage metadata was added, and documentation for seven SAP functions—including BAPI_XMI_LOGON and TH_SERVER_LIST—was removed.
What Defender admins need to know
Administrators using this reference will no longer find descriptions or connector links for these functions.
Summaries are generated from the documentation change itself.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
These functions are intended to serve as the principal user interface to the data. They form the basis for all the built-in analytics rules and workbooks available to you out of the box. Using functions allows for changes to be made to the data infrastructure beneath the functions, without breaking user-created content.
BAPI_XMI_LOGON (Preview)
The BAPI_XMI_LOGON function is relevant when your SAP system is an older system using XAL, and authenticates to collect SAP XAL audit logs.
The BAPI_XMI_LOGON function is supported only for the SAP agentless data connector. For more information, see Install a Microsoft Sentinel solution for SAP applications.
BAPI_SYSTEM_MTE_GETTIDBYNAME (Preview)
The BAPI_SYSTEM_MTE_GETTIDBYNAME function is relevant when your SAP system is an older system using XAL, and retrieves the ID of a system monitoring element by name.
The BAPI_SYSTEM_MTE_GETTIDBYNAME function is supported only for the SAP agentless data connector. For more information, see Install a Microsoft Sentinel solution for SAP applications.
BAPI_SYSTEM_MTE_GETTREE (Preview)
The BAPI_SYSTEM_MTE_GETTREE function is relevant when your SAP system is an older system using XAL, and retrieves the structure of system monitoring elements.
The BAPI_SYSTEM_MTE_GETTREE function is supported only for the SAP agentless data connector. For more information, see Install a Microsoft Sentinel solution for SAP applications.
BAPI_SYSTEM_MTE_GETMLHIS (Preview)
The BAPI_SYSTEM_MTE_GETMLHIS function is relevant when your SAP system is an older system using XAL, and fetches historical performance and status data.
The BAPI_SYSTEM_MTE_GETMLHIS function is supported only for the SAP agentless data connector. For more information, see Install a Microsoft Sentinel solution for SAP applications.
BAPI_XMI_SET_AUDITLEVEL (Preview)
The BAPI_XMI_SET_AUDITLEVEL function is relevant when your SAP system is an older system using XAL, and configures the XAL audit logging level.
The BAPI_XMI_SET_AUDITLEVEL function is supported only for the SAP agentless data connector. For more information, see Install a Microsoft Sentinel solution for SAP applications.
BAPI_XMI_GET_LOGHISTORY (Preview)
The BAPI_XMI_GET_LOGHISTORY function is relevant when your SAP system is an older system using XAL, and retrieves past XAL audit log entries.
The BAPI_XMI_GET_LOGHISTORY function is supported only for the SAP agentless data connector. For more information, see Install a Microsoft Sentinel solution for SAP applications.
SAPUsersAssignments
The SAPUsersAssignments function gathers data from multiple SAP data sources and creates a user-centric view of the current user master data, including the roles and profiles currently assigned. | | SystemRole | The SAP system's role | Production, UAT | | | SystemUsage | The main usage of the SAP system | ERP, CRM |
TH_SERVER_LIST (Preview)
The TH_SERVER_LIST function is relevant when your SAP system is an older system using XAL, and lists active SAP application servers.
The TH_SERVER_LIST function is supported only with the SAP agentless data connector (Preview). For more information, see Install a Microsoft Sentinel solution for SAP applications.
Related content
For more information, see:
@@ -4,7 +4,8 @@ description: Learn about the functions available from the Microsoft Sentinel sol ms.author: monaberdugo author: mberdugo ms.topic: reference-ms.date: 09/30/2025+ms.date: 08/04/2026+ai-usage: ai-assisted appliesto: - Microsoft Sentinel in the Microsoft Defender portal - Microsoft Sentinel in the Azure portal@@ -29,42 +30,6 @@ We *strongly recommend* that you use the functions listed in this article as the These functions are intended to serve as the principal user interface to the data. They form the basis for all the built-in analytics rules and workbooks available to you out of the box. Using functions allows for changes to be made to the data infrastructure beneath the functions, without breaking user-created content. -## BAPI_XMI_LOGON (Preview)--The **BAPI_XMI_LOGON** function is relevant when your SAP system is an older system using XAL, and authenticates to collect SAP XAL audit logs.--The **BAPI_XMI_LOGON** function is supported only for the SAP agentless data connector. For more information, see [Install a Microsoft Sentinel solution for SAP applications](deploy-sap-security-content.md?pivots=connection-agentless).--## BAPI_SYSTEM_MTE_GETTIDBYNAME (Preview)--The **BAPI_SYSTEM_MTE_GETTIDBYNAME** function is relevant when your SAP system is an older system using XAL, and retrieves the ID of a system monitoring element by name.--The **BAPI_SYSTEM_MTE_GETTIDBYNAME** function is supported only for the SAP agentless data connector. For more information, see [Install a Microsoft Sentinel solution for SAP applications](deploy-sap-security-content.md?pivots=connection-agentless).--## BAPI_SYSTEM_MTE_GETTREE (Preview)--The **BAPI_SYSTEM_MTE_GETTREE** function is relevant when your SAP system is an older system using XAL, and retrieves the structure of system monitoring elements.--The **BAPI_SYSTEM_MTE_GETTREE** function is supported only for the SAP agentless data connector. For more information, see [Install a Microsoft Sentinel solution for SAP applications](deploy-sap-security-content.md?pivots=connection-agentless).--## BAPI_SYSTEM_MTE_GETMLHIS (Preview)--The **BAPI_SYSTEM_MTE_GETMLHIS** function is relevant when your SAP system is an older system using XAL, and fetches historical performance and status data.--The **BAPI_SYSTEM_MTE_GETMLHIS** function is supported only for the SAP agentless data connector. For more information, see [Install a Microsoft Sentinel solution for SAP applications](deploy-sap-security-content.md?pivots=connection-agentless).--## BAPI_XMI_SET_AUDITLEVEL (Preview)--The **BAPI_XMI_SET_AUDITLEVEL** function is relevant when your SAP system is an older system using XAL, and configures the XAL audit logging level.--The **BAPI_XMI_SET_AUDITLEVEL** function is supported only for the SAP agentless data connector. For more information, see [Install a Microsoft Sentinel solution for SAP applications](deploy-sap-security-content.md?pivots=connection-agentless).--## BAPI_XMI_GET_LOGHISTORY (Preview)--The **BAPI_XMI_GET_LOGHISTORY** function is relevant when your SAP system is an older system using XAL, and retrieves past XAL audit log entries.--The **BAPI_XMI_GET_LOGHISTORY** function is supported only for the SAP agentless data connector. For more information, see [Install a Microsoft Sentinel solution for SAP applications](deploy-sap-security-content.md?pivots=connection-agentless).- ## SAPUsersAssignments The **SAPUsersAssignments** function gathers data from multiple SAP data sources and creates a user-centric view of the current user master data, including the roles and profiles currently assigned.@@ -428,12 +393,6 @@ The **SAPUsersHeader** function returns the following output: | | SystemRole | The SAP system's role | Production, UAT | | | SystemUsage | The main usage of the SAP system | ERP, CRM | -## TH_SERVER_LIST (Preview)--The **TH_SERVER_LIST** function is relevant when your SAP system is an older system using XAL, and lists active SAP application servers.--The **TH_SERVER_LIST** function is supported only with the SAP agentless data connector (Preview). For more information, see [Install a Microsoft Sentinel solution for SAP applications](deploy-sap-security-content.md?pivots=connection-agentless).- ## Related content For more information, see: 