0% found this document useful (0 votes)
35 views39 pages

SAP TPO Report for PepsiCo System

Uploaded by

Ricardo Segura
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
35 views39 pages

SAP TPO Report for PepsiCo System

Uploaded by

Ricardo Segura
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Service Report

SAP® Technical performance optimization

Confidential

Customer PepsiCo, Inc

System / Product PX3 / SAP NetWeaver 7.5 Process Orchestration

Database Oracle

Service Center SAP Support


Telephone See SAP Note 560499
Fax See SAP Note 560499

Service Team Madhu MN


Date of Service 12.05.2025 – 19.05.2025

This report contains confidential customer data and may be viewed only by SAP DBS employees, authorized SAP
partners, and customer employees. Do not distribute it to other parties.
SAP TPO for PO system PepsiCo, Inc 22.05.2025

1 Table of Contents
1 TABLE OF CONTENTS ........................................................................................................................................ 2
2 SUMMARY ............................................................................................................................................................ 4
2.1 CONTENT OF THIS DOCUMENT ............................................................................................................4
2.2 SERVICE PLAN ..................................................................................................................................5
3 PERFORMED CHECKS ........................................................................................................................................ 6
4 SAP PO SYSTEM LANDSCAPE .......................................................................................................................... 7
5 ISSUES AND RECOMMENDATIONS ................................................................................................................... 8
5.1 ISSUE 1: PI MESSAGE MONITOR PERFORMANCE ISSUES .......................................................................8
5.2 ISSUE 2: DISABLE LM CONFIGURATION WIZARD ............................................................................... 10
5.3 ISSUE 3: MISSING SECURITY NOTE IN PX3 ....................................................................................... 11
5.4 ISSUE 4: SCHEDULE IDOC MONITOR RELATED HOUSEKEEPING JOB ..................................................... 11
5.5 ISSUE 5: HIGH DB SIZE FOR TABLE BC_MSG_DUP_CHECK .......................................................... 12
5.6 ISSUE 6: MESSAGE COMPRESSION NOT ENABLED ............................................................................. 13
6 SOFTWARE CONFIGURATION.......................................................................................................................... 14
7 SYSTEM OVERVIEW .......................................................................................................................................... 16
7.1 PERSISTENCE LAYER OVERVIEW ..................................................................................................... 16
DB and Tables size/entries ............................................................................................................................ 16
7.2 CONFIGURATION OVERVIEW............................................................................................................ 16
Channel types ............................................................................................................................................... 16
Mappings....................................................................................................................................................... 18
Adapter Modules ........................................................................................................................................... 18
Adapter Engine Scheduler ............................................................................................................................ 18
CPA Cache history ........................................................................................................................................ 20
8 SAP PO RECOMMENDED SETTINGS ............................................................................................................... 21
8.1 CONFIGURATION SETTINGS ............................................................................................................. 21
Java Memory ................................................................................................................................................. 21
SAP JVM Parameters ................................................................................................................................... 21
Java Engine .................................................................................................................................................. 22
8.2 PERFORMANCE SETTINGS .............................................................................................................. 24
Java Log Configuration ................................................................................................................................. 24
AAE: Advanced Adapter Engine specific settings .......................................................................................... 25
Adapter Queues ....................................................................................................................................... 25
Receiver Parallelism ................................................................................................................................. 26
Prioritization and Dispatcher Queue ......................................................................................................... 26
Adapter Framework Scheduler ................................................................................................................. 27
Java IDoc Adapter (IDoc_AAE) ................................................................................................................ 28
Polling Channel Watchdog ....................................................................................................................... 30
Mapping Runtime ..................................................................................................................................... 30
Simple XPath Processor ........................................................................................................................... 31
Retry Configuration................................................................................................................................... 31
Large Messages ....................................................................................................................................... 32
EOIO processing ...................................................................................................................................... 33
8.3 HOUSEKEEPING ............................................................................................................................. 33
AAE housekeeping ........................................................................................................................................ 33
Retention Periods ..................................................................................................................................... 33
Housekeeping jobs ................................................................................................................................... 34
Message Compression on SAP PO application level ............................................................................... 35
Table of Contents 2/39

Confidential
SAP TPO for PO system PepsiCo, Inc 22.05.2025

UDMS data clean up ................................................................................................................................ 36


NW Scheduler for Java ............................................................................................................................. 36
SLD cleanup job ....................................................................................................................................... 36
Load Balancing and Rolling Restart .............................................................................................................. 37
8.4 OTHER CHECKS.............................................................................................................................. 37
Security .................................................................................................................................................... 37
Security Notes Check ............................................................................................................................... 39

Table of Contents 3/39

Confidential
SAP TPO for PO system PepsiCo, Inc 22.05.2025

2 Summary

This document contains recommended values for your SAP PO system,


PX3. The recommendations are related to Architecture, Configuration and
Performance of the system runtime during the TPO service performed
from May 12th to 19th 2025.

Review this detailed report and implement the recommendations

The goal of the SAP PO Technical performance optimization service was to identify issues on the configuration
and performance of your system and interfaces. The system in the service scope is the integration hub PX3 which
is based on SAP NetWeaver 7.50 SP 28 on Oracle DB

This report has been rated YELLOW.


The main problems were identified in the following areas:
• Gaps in system configuration and parameterization
• Missing Housekeeping Jobs

2.1 Content of this document


This document is composed of the following basic sections:

• Performed Checks
• SAP PO System Landscape
• Issues and Recommendations
• Software Configuration
• System Overview
• SAP PO Recommended Settings

The section “Performed Checks” gives a check list of most important aspects which were reviewed in scope of
SAP TPO service. “SAP PO System Landscape” gives a high-level overview of the landscape architecture and
structure of SAP PO solution. In “Software Configuration” we checked current version of software in PX3 system
and compared with the latest available at Service Marketplace.

“System Overview” provides monitoring statistics about system performance and configuration which was
retrieved and analyzed during service session. The paragraph “Issues and Recommendations” is based on the
results of the checks performed in your SAP PO system and can be considered as a main output of our activity.

The section “SAP PO Recommended Settings” provides you a comparison of current configuration of your system
with initial optimal parameters recommended for SAP PO.

Note: All the recommendations provided in this report are based on our general experience only. We advise you to
test our recommendations before using them in your production system. We use term “issue” in the report not only
for existing issues but also for potential issues / risks.

Summary 4/39

Confidential
SAP TPO for PO system PepsiCo, Inc 22.05.2025

2.2 Service Plan


The SAP Service Plan table reflects the recommended services for your SAP PO system and interfaces to ensure
proper implementation of provided recommendation and further analysis to minimize risks of issues by applying
proactive measures.

SAP Service Recommended Service Scope / Goal


Date
Expert On Demand (EoD) On Demand Dedicated contact person to support in case of specific
questions, implementing recommendations or resolution of
dedicated issues.

Summary 5/39

Confidential
SAP TPO for PO system PepsiCo, Inc 22.05.2025

3 Performed Checks
Based on our expertise and SAP documentation find below the check list of all items evaluated in your SAP PO
system. The outcome of the checks are described in details in the format of risks / issues in the subsequent
chapter “Issues and Recommendations” of this report.

Check Status
Performed?

Product Version: SAP PO release, SP, JVM and kernel level 


Version of installed Java software components, SLD content etc. 
Database Vendor and version 
System landscape: Number of Servers and Server Nodes Distribution 
SAP JVM configuration 
Advanced Adapter Engine: configuration (Application Threads, Worker Threads, FCA Threads,
AF Scheduler, ...), housekeeping jobs (including restart job), Caches, etc. 
Java Scheduler 
Logs and Traces: configuration, application logs and default traces 
Integration Scenarios configuration: ICO, logging / staging settings, configuration of
communication channels, adapter modules and mappings used, prioritization, UDMS, etc. 
SAP JVM Consumption: Memory, CPU and Threads 
IDoc_AAE, Resource Adapters configuration 
RCA Tools: XPI Inspector, Performance Monitor 
Message Monitoring: Communication Channels, Backlogs, Runtime errors 

Performed Checks 6/39

Confidential
SAP TPO for PO system PepsiCo, Inc 22.05.2025

4 SAP PO System Landscape


This section provides a high-level overview of the structure of your SAP PO solution. PX3 is SAP PO installation
type of SAP Netweaver release 7.50 and SP-stack level 28 with 6 Java Application Servers having 4 server nodes
with 6 GB of configured heap.

PRODUCT
SID SAP Product Product Version
PX3 SAP NetWeaver PO 7.5 SP28
DATABASES
Database SID Database System Database Version Database Host
PX3 Oracle Oracle Database 19c Enterprise pepldr03154
Edition Release [Link].0 -
Production Version [Link].0)
SAP APPLICATION SERVERS
SID Host Instance Name Operating System JAVA

PX3 sappx3ap01 ID4317033 Linux (amd64) 5.15.0-[Link].el8uek.x86_64 


PX3 sappx3ap03 ID4317031 Linux (amd64) 5.15.0-[Link].el8uek.x86_64 
PX3 sappx3ap04 ID4317030 Linux (amd64) 5.15.0-[Link].el8uek.x86_64 
PX3 sappx3ap05 ID4317029 Linux (amd64) 5.15.0-[Link].el8uek.x86_64 
PX3 sappx3ap06 ID4317028 Linux (amd64) 5.15.0-[Link].el8uek.x86_64 
PX3 sappx3ap07 ID4317027 Linux (amd64) 5.15.0-[Link].el8uek.x86_64 

SAP PO System Landscape 7/39

Confidential
SAP TPO for PO system PepsiCo, Inc 22.05.2025

5 Issues and Recommendations

ISSUES RELEVANT FOR SERVICE


No. Priority Description
1 High PI message monitor performance issues
2 High Disable LM Configuration Wizard
3 High Missing Security Note in PX3
4 High Schedule idoc monitor related housekeeping jobs
5 Medium High DB size for table BC_MSG_DUP_CHECK
6 Medium Message compression not enabled

The priorities assigned are defined according to the below criteria:

CRITERIA FOR SETTING PRIORITIES


Priority Description
Very high Has or will have critical impact on business operations (possible financial loss)
High Has or will have serious impact on business operations
Medium Has or will have some impact on business operations
Low Has or will have minor impact on business operations

All the recommendations provided in this report are based on our general experience only. We advise you to test
our recommendations before using them in your production system. We use “issue” in the following not only for
existing issues but also for potential issues / risks.

5.1 Issue 1: PI message monitor performance issues


Priority: High

Description: The loading of messages from the message monitor takes long time. During the service we noticed
that the global message retention duration on PX3 is set to 4 days. Currently we see around 48 million entries in
the BC_MSG table. It was observed the archive job is currently not working as expected due to the below error
(see screenshot below). Because of the error, the messages in DLVD state are not archived and deleted from the
BC_MSG and other related tables thus leading to the performance issue.

Issues and Recommendations 8/39

Confidential
SAP TPO for PO system PepsiCo, Inc 22.05.2025

Impact on Business: Large storage required for database and database operations will slow down and will lead
to performance issues in the PO system.

Recommended Task 1: For the failing archive job, Modify parameter ARCHCONN_READTIMEOUT and increase
its value, for example to 600000 (10mins) or larger.

Refer SAP note : [Link]

Recommended Task 2: Considering the current message load in the system, For specific integration scenarios,
where business or legal teams require a higher retention, periods can be defined on interface level following the
SAP Note 1960448 - Configure message retention period per interface. Set the global message retention to 1 day
and configure interface specific retention.

Recommended Task 3: Disable the checkbox "Log JSON message" from the REST based channels. If the
checkbox "Log JSON message" is activated, the converted JSON content is logged in the message monitor and it
will add records to BC_MSG_LOG table.

Refer to the SAP note: [Link]


An example has been provided below:

Issues and Recommendations 9/39

Confidential
SAP TPO for PO system PepsiCo, Inc 22.05.2025

Recommended Task 4:

Refer to SAP Note 2518441- The tablespace PSAPSR3DB of PI system grows quickly. Resolution steps 1-4
should help

Additionally, refer SAP Note 872388 – “Troubleshooting Archiving and Deletion in PI”
For archive and deletion job on BC_MSG*

5.2 Issue 2: Disable LM Configuration Wizard


Priority: High

Description:
During the service we observed that application LM Configuration Wizard is not disabled yet on PX3 system.
WSDL URL of this service is still accessible.
[Link]

Impact on Business:
LM Configuration Wizard of SAP NetWeaver AS JAVA, does not perform an authentication check which allows an
attacker without prior authentication, to execute configuration tasks to perform critical actions against the SAP
Java system, including the ability to create an administrative user, and therefore compromising Confidentiality,
Integrity and Availability of the system.

Refer SAP Note 2934135 - [CVE-2020-6287] Multiple Vulnerabilities in SAP NetWeaver AS JAVA (LM
Configuration Wizard) for more information.

Recommended Task:
The disabling of this application is a defence in depth to reduce the risk of potential undetected flaws in the LM
Configuration Wizard. Implement the steps detailed in SAP Note 2939665 - Disable/Enable LM Configuration
Wizard | Critical API's in LM Configuration Wizard.

We recommend disabling the application aliases unless required. This application is used by a few SAP Lifecycle
procedures only, such as the initial technical setup, and it is not needed in day-to-day operations. You can enable
this application temporarily for executing these SAP lifecycle procedures.

Issues and Recommendations 10/39

Confidential
SAP TPO for PO system PepsiCo, Inc 22.05.2025

5.3 Issue 3: Missing Security Note in PX3


Priority: High

Description:
During the service we observed that PX3 system is missing an important Security Note with a CVSS score of > 5
based on the current SP level and patch levels of installed Java Software Components.

Impact on Business:
Missing Security Notes might allow an unauthorized attacker to access configuration objects, including such that
grant administrative privileges. This could result in complete compromise of PX3 system confidentiality, integrity,
and availability.

Recommended Task:
It is recommended to implement the below missing Security Notes in PX3.
3434192 - [CVE-2024-28163] Information Disclosure vulnerability in SAP NetWeaver Process Integration (Support
Web Pages)

5.4 Issue 4: Schedule idoc monitor related housekeeping job


Priority: High

Description: We observed in PO database that the table XI_IDOC_IN_MSG has 81,858,104 entries and
XI_IDOC_OUT_MSG has 2,797,600 entries. Currently the IDOC related housekeeping job is not scheduled in
PX3.

Impact on Business: PO Database performance issue.

Recommended Task: Schedule the housekeeping job IdocDBTableCleanupPeriodicAdvanced for regular


deletion of the Java IDoc database [Link] to SAP Note 2624188 - IdocDBTableCleanupPeriodicAdvanced: a
new improved job for IDoc_AAE data deletion with optimized option for SAP ASE DB.

Issues and Recommendations 11/39

Confidential
SAP TPO for PO system PepsiCo, Inc 22.05.2025

The job has a parameter Retention_period that can be configured so that idoc messages older than the retention
period are cleaned up

5.5 Issue 5: High DB size for table BC_MSG_DUP_CHECK


Priority: Medium

Description: We observed in PO database that table BC_MSG_DUP_CHECK has 56,273,129 entries. For each
asynchronous message (EO or EOIO) that enters the PI/PO system, an entry is stored in table
BC_MSG_DUP_CHECK and kept for 30 days by default to prevent reprocessing of the same message.

Impact on Business: PO Database performance issue.

Recommended Task: The property '[Link]' specifies the duplicate check persist
time. The default value is 30 days. If you would like to delete the entries in table BC_MSG_DUP_CHECK earlier,
you can consider to decrease the value of property '[Link]'. You can modify this
property online under NWA > Configuration > Infrastructure > Java System Properties > Service "XPI Service:
Messaging System". SAP Note: 2778426 - How to decrease the size of table BC_MSG_DUP_CHECK

Issues and Recommendations 12/39

Confidential
SAP TPO for PO system PepsiCo, Inc 22.05.2025

5.6 Issue 6: Message compression not enabled


Priority: Medium

Description: We observed that message compression in system is not enabled. You can configure the Messaging
System to compress the asynchronous message content before storing it in MSG_BYTES field. It will help to
decrease the size of BC_MSG and BC_MSG_VERSION tables and reduce the LOB space occupied by
MSG_BYTES field of these tables.

Impact on Business: PO Database performance issue.

Recommended Task: Message compression can be configured using the properties


[Link] and [Link] of Messaging System service and by
default is disabled. For more information refer to SAP Note 2538365 - How to enable message compression on
PI/PO system.
Based on the performance monitor data collected from PX3 between May 18th to May 23rd, on a daily basis there
are 2300 to 2800 messages with average payload size of more than 10 MB. It is recommended to configure
parameter [Link] to value 10000000 (bytes).
Note: With compression the CPU overhead will increase, so you should choose the threshold carefully to ensure
that the CPU overhead is not getting too high.

Issues and Recommendations 13/39

Confidential
SAP TPO for PO system PepsiCo, Inc 22.05.2025

6 Software Configuration
We reviewed software configuration and compared current software versions in system PX3 with the latest
available on Service Marketplace. SAP releases Support Packages stacks (including SAP kernel patches) on
regular basis. For more information, see SAP Support Package Stack information at [Link]
stacks.

PX3 is SAP Process Orchestration (PO) installation of SAP NetWeaver release 7.5 and SP-stack level 28. The
latest available SP for this release is 31: [Link]
information/[Link].

For more information about product strategy refer to the roadmaps at


[Link] and product availability matrix (PAM) at
[Link] Also refer to SP Stack Release Notes for
available features in the newest releases:
[Link]

SAP AS Version
Installation Name Usage Scenario Release Current SP Level Latest SP Level

PX3 SAP PO 7.50 28 31

SAP JVM
VM Runtime Version Current Patch Level

SAP JVM 8.1 096


SAP Note 1367498 - SAP JVM installation prerequisites
SAP Note 1442124 - How to download a SAP JVM patch from the SMP
Note: new behavior with HTTP redirect responses has been introduced with SAP JVM version 6.1.114 / SAP JVM
version 8.1.054. If you observe issues with internal HTTP communication, refer to SAP Note 2836850 - PI/PO
Internal HTTP connections start to fail with HTTP 401 Unauthorized after JVM update.

In the following table you can review the current patch levels of Java Software components in PX3 against the
latest available on Service Marketplace

Software Configuration 14/39

Confidential
SAP TPO for PO system PepsiCo, Inc 22.05.2025

Java Software Components versions


Generally, it is especially important to have up to date patches for the most critical components of AAE engine the
system: MESSAGING, SAPXIAF, SAPXIESR, SAPXITOOL, SOAMON, etc. For additional information regarding
deployment and dependencies refer to SAP Note 1335523 – FAQ: Deployment PI Patches in Release 7.1 and
higher and SAP Note 1974464 - Information on SCA Dependency Analysis for Java download objects. The
dependencies between the different Software Components deployed on the system and the new versions
available on SAP Service Marketplace can be analyzed using SCA Dependency Analysis Tool as described in
SAP Note 1974464 - SMP: Information on SCA Dependency Analysis for Java download objects. SAP Note
2041071 - How to download latest Java patches using System Recommendation explains how to download the
latest Java patches. Although applying patch levels will not change the SAP PO functionality, they are bug fixes,
stability and performance improvements, it is recommended to create a full system backup before implementing
new patches.

System Landscape Directory (SLD)


URL CIM Version Content Version

[Link] 1.6.60 SAP_CR 19.1


Refer to SAP Note 669669 - Update of SAP System Component Repository for update of SAP CR Content in the
SLD.

Wily Introscope
URL Agent Version Enterprise Manager
Version

[Link] - -

SAP Note 797147 - Introscope Installation for SAP Customers contains release information and installation
procedure of CA Introscope (Enterprise Manager, Agent, Workstation and Webview). Known restrictions of this
version are listed in SAP Note 1565954 - Introscope 9 Release Notes / SAP Note 2071100 - Introscope 9.5
Release Notes / SAP Note 2138309 - Introscope 9.7 Release Notes for changes and open issues / SAP Note
2285189 - Introscope 10.1 Release Notes for changes and open issues.
For further information refer to the link [Link]

The latest available version of XPI Inspector can be downloaded from SAP Note 1514898 - XPI Inspector for
troubleshooting XI.

Software Configuration 15/39

Confidential
SAP TPO for PO system PepsiCo, Inc 22.05.2025

7 System Overview
The following areas of your system are discussed in this section:

• Configuration Overview
• AAE Statistics.

7.1 Persistence Layer Overview


In scope of the TPO service, we reviewed set up of archiving and deletion and performed a review of entries in the
most important tables. This section contains information about general set up of housekeeping in SAP PO system.
Detailed recommendation on housekeeping gaps are provided in “Issues and Recommendations” section of this
report.

DB and Tables size/entries


Main table in to AAE engine is BC_MSG that is a master table of messages. This size is usually influenced by
configured retention periods.

Area: Messaging System Overview in DB

Global retention period settings is currently set to 4 days PX3. For specific integration scenarios, retention periods
can be adjusted on interface level according to SAP Note 1960448 - Configure message retention period per
interface.

Area: AAE DB tables size/entries

Table Name Number of Entries

BC_MSG 45,359,208
BC_MSG_VERSION 7,150,323
BC_MSG_AUDIT 5,869,438
BC_MSG_LOG 137,060,781
XI_IDOC_IN_MSG 81,148,615
XI_IDOC_OUT_MSG 2,636,386
BC_JOB_LOG 279,385
XI_AF_PROF_PERF_CA 2,190,567

7.2 Configuration Overview


In scope of the service, integration scenario’s configuration and objects in PX3 system were reviewed. This
section contains information about key configuration objects in SAP PO system.

Channel types
The following chart gives the number of sender and receiver channels which are classified by adapter types.
Analysis is based on CPA Cache information. Totally there are 1780 communication channels (709 sender and
1071 receiver channels). Major part of channels is of type SOAP.

Not that this graph provides an overview of configuration only and does not reflect actual processing volumes for
adapter types / transport protocols.

System Overview 16/39

Confidential
SAP TPO for PO system PepsiCo, Inc 22.05.2025

System Overview 17/39

Confidential
SAP TPO for PO system PepsiCo, Inc 22.05.2025

Mappings
Mapping overview shows all the mappings in non-SAP namespace distributed according to mapping types.

Adapter Modules
Below chart reflects all the adapter modules that are used in PX3

Adapter Engine Scheduler


Default value of property “[Link]” of Java service “XPI Service: AF Core” is ‘-10’ which means that
new Adapter Framework Scheduler is enabled. This version is a recommended because the “old” scheduler has
performance and reliability issues in a cluster environment, especially when there are a large number of jobs.

System Overview 18/39

Confidential
SAP TPO for PO system PepsiCo, Inc 22.05.2025

The following chart shows the distribution of polling tasks with server nodes.

System Overview 19/39

Confidential
SAP TPO for PO system PepsiCo, Inc 22.05.2025

Next graph reflects the number of polling tasks per hour and per server node (i.e. number of execution of polling
tasks instances):

CPA Cache history


Note that delta CPA cache refreshes are executed on each server node startup to read the configuration data from
the Integration Directory. The Integration Directory is an application, whereas the CPA Cache is an J2EE service
and starts earlier. Therefore, the automatic delta cache refresh fails on the central AE in case of a server restart
with HTTP 503 Service Unavailable. On system restart, the number of failed delta cache refreshes is equal with
the number of server nodes. Refer to SAP Note 881276 - CPADirectoryCacheException during J2EE Engine
startup.

Latest executions of CPA Cache updates:

System Overview 20/39

Confidential
SAP TPO for PO system PepsiCo, Inc 22.05.2025

8 SAP PO Recommended Settings


This section provides list of parameters to be configured in your SAP PO system. The recommendations are
based on the our expertise and SAP Documentation.

8.1 Configuration Settings

Java Memory
Memory utilization is extremely important for systems based on Java stack. PX3 is configured with 6 Java
Application servers having 4 server nodes each .
Note that the Memory parameters are customer specific and heavily depend on application usage (BPM, AEX,
BRM).

Area: Memory VM Parameters


Parameter Current Value Recommended Value

maxHeapSize Customer specific (4096m - 6144m)


6144
(default: 4096m)
intialHeapSize intialHeapSize = #maxHeapSize
6144
(default: 4096m)
maxNewSize maxNewSize = #[Link]}/3
2048
(default: 1365m)
newSize newSize = #maxNewSize
2048
(default: 1365m)
* Note that starting with SAP JVM 6.1.073 the PermGen was removed, refer to SAP Note 2121243 - SAP JVM:
PermGen removal and parameters permSize and maxPermSize are obsolete and will be ignored by the SAP JVM
using the new metaspace implementation. In general, it is not required to remove these parameters, however, it
can be done in order to simplify configuration. Also there are new properties like -XX:MetaspaceSize and -
XX:CompressedClassSpaceSize (described in mentioned SAP Note) and default values for them are enough in
general.
In case of issues with code cache size refer to SAP KBA 2442336 - How to enable SAP JVM code cache
sweeping to enable aggressive SAP JVM code cache sweeping (typically, it is relevant for large systems only).

SAP JVM Parameters


General information on JVM parameters:
Boolean options are turned on with -XX:+<option> and turned off with -XX:-<option>.
Numeric options are set with -XX:<option>=<number>. Numbers can include 'm' or 'M' for megabytes, 'k' or 'K' for
kilobytes, and 'g' or 'G' for gigabytes (for example, 32k is the same as 32768).
String options are set with -XX:<option>=<string>, are usually used to specify a file, a path, or a list of commands.
All default flags of a JVM can be printed with: /path_to_jvm/java -XX:+PrintFlagsFinal.

The following parameters can be checked via SAP NetWeaver Administrator → Configuration Management →
Infrastructure → Java System Properties (or direct link [Link]

SAP PO Recommended Settings 21/39

Confidential
SAP TPO for PO system PepsiCo, Inc 22.05.2025

Area: Additional VM Parameters


Parameter Current Value Recommended Value

-[Link] true true


-[Link] 10 10
-[Link] 1 1
-XX:TargetSurvivorRatio 90 90
-XX:+UseConcMarkSweepGC Set Set
-verbose:gc Set Set
-XX:+DumpDetailedClassStatisticOnOutOfMemory Set Set
-XX:+PrintGCDetails Set Set
-XX:+PrintGCTimeStamps Set Set
-XX:+DisableExplicitGC Set Set
-XX:MaxErrorQueueLength 200 200
-XX:SoftRefLRUPolicyMSPerMB 1 1
-Xss2m Set Set
-XX:HeapDumpPath [Link] [Link]
-XX:+HeapDumpOnOutOfMemoryError ““  turned on with :+<option>
-XX:SurvivorRatio 6 6
-[Link] DEFAULT 2000
Refer to Note 2206410
-[Link] DEFAULT 300000
Refer to Note 2206410
-[Link] DEFAULT 3000
Refer to Note 2206410

Note that heap dump files ([Link]) can consume significant amount of disk space. The free space should be
at least the total of server nodes multiplied by the configured heap size. You may also set the heap dump path to a
directory of your convenience, however, note that in case the target file system is slow this will increase the restart
/ recovery time of server node.

Java Engine
The following configuration must be set via SAP NetWeaver Administrator → Configuration Management →
Infrastructure → Java System Properties (or direct link [Link]

Area: Kernel
Name Properties Current Recommended Recommended Source
Value Value (AAE) Value (CE)
ApplicationThreadManager MaxThreadCount 350 350 150-200 Note
937159
ThreadManager MaxThreadCount 140 140 150-200 Note
937159
ClusterManager* [Link] 300000 450000** 450000**

* In order to display properties of Cluster Manager you need to click on the button “Show Advanced Properties” in
Java System Properties.
** Cluster Manager property “[Link]” specifies max reconnect timeout (in milliseconds) to
another node. If reconnection does not finish in this timeout the node itself will be shut down. The default value is
300 000 ms. There is another property of the Message Server “ms/keepalive” (default value is 300 s) – the
Message Server makes a ping in order to see if the nodes of its participants list are alive. If some node does not
return response in the specified timeout it is being removed from the participants list. These two properties have
the same values and can overlap which can cause the following issue: a node is shut down and it can take up to
300 sec for the Message Server to understand that. Meanwhile another node tries to connect to the shutdown
node because it does not yet have the info that the node is gone from the MS. And as the node will not be able to
connect for 300 sec it will restart itself (exitcode = 888 (engine exit codes:

SAP PO Recommended Settings 22/39

Confidential
SAP TPO for PO system PepsiCo, Inc 22.05.2025

\usr\sap\SID\instance\j2ee\cluster\bootstrap\exitcode. properties)). So in order to avoid that restart


“[Link]” property should be set at least to value ‘450 000’ so that there will be enough time to
get the correct participants list from the MS.

Cluster communication issues may happen due to network problems and lead to automatic restart of the whole
SAP PO cluster. In order to avoid it SAP Note 2265959 - Missed broadcast due to network problems provides
recommendations to increase default values of several Cluster Manager parameters (for the values refer to SAP
Note):
• [Link]: Specifies the timeout after which a reconnection to the message server is no
longer possible. If the switchover software is not able to detect the need for a switch and start the central
services instance on a different host within this time, the server process(s) will restart (exit code: -335).
• [Link]: Amount of time that a joining cluster element waits for the confirmation replies
from the cluster elements. If one or more cluster elements do not send a confirmation message, the
server process will restart (exit code: -334).
• [Link]: Amount of time for receiving the acknowledgment from the message server that
the message has been delivered. If the message server fails to deliver the acknowledgment, the server
process will restart.
• [Link]: If there has been no communication between a server process and the message server for
the specified amount of time, the server process triggers a liveness check (ping / pong protocol). This
ping / pong mechanism is important for the server process to detect that the connection to the message
server is broken. Without sending messages to the message server, the connection failure cannot be
detected.

Area: Service, AAE Engine


Name Properties Current Recommended Source
Value Value (AAE)
JDBC 50 20* -
[Link]
Connector
JDBC 500 100* Note 1375656
[Link]
Connector
JDBC 120 120*
[Link]**
Connector
XPI Service:
Messaging [Link] 120000 120000 Note 791655
System
XPI Service:
Messaging [Link] 5 5 Note 791655
System
XPI Service: 120000 120000
clusterCommunicationTimeoutMsec
AF Core
XPI Service: true true Note 1636215
[Link]
AF Core
XPI Adapter: 180000 180000 Note 791379
[Link]
XI
XPI Adapter:
syncMessageDeliveryTimeoutMsec 300000 300000 Note 730870
RFC
XPI Adapter:
lazyConnection true true Note 1012393
JDBC
Note 1375656,
JCo RFC WaitForAppsStart
false true* 1444430 and
Provider (click on the button “Show Advanced Properties”)
1506101
HTTP
FCAServerThreadCount 50 50* Note 1375656
Provider
80% of the total
XPI Service:
cacheObjectsCriticalLimit 9000 number of CPA Note 2205344
CPA Cache
Objects***
80% of the total
XPI Service:
cacheObjectsUpperLimit 9000 number of CPA Note 2205344
CPA Cache
Objects***
80% of the total
XPI Service:
thresholdStartEviction 9000 number of CPA Note 2205344
CPA Cache
Objects***
SAP PO Recommended Settings 23/39

Confidential
SAP TPO for PO system PepsiCo, Inc 22.05.2025

Name Properties Current Recommended Source


Value Value (AAE)
User
[Link].default_caching_time
Management 3600 18000 Improve the
(click on the button “Show Advanced Properties”)
Engine UME CACHE
User users/roles ratio
[Link].initial_cache_size (visible in MMC)
Management 6000 24000
(click on the button “Show Advanced Properties”)
Engine

* Recommended values for these parameters can impact the system if the use-case is different / customized.
Changing them must be done with extensive testing.

** In order to check maxTimeToWaitConnection go to SAP NetWeaver Administrator → Configuration


Management → Infrastructure → Application Resources; then, select the JDBC System DataSource from the
Resources List and choose the “Connection Pooling” tab in the Resource Details. There you find the field
“Maximum Time to Wait for Connection”.

*** Refer to SAP Note 2205344 - Performance tuning of CML cache within XPI Service: CPA Cache.

8.2 Performance Settings


This section provides best practices in performance configuration of SAP PO system and your interfaces. PI
Performance guide can help in your analysis and troubleshooting of performance related issues, refer to SAP
Note 894509 - PI Performance Check.

Java Log Configuration


The Logging Configuration can impact your SAP system runtime performance in specific circumstances and it is
mainly used in troubleshooting cases. Logs are important to identify system issues and exceptions and they can
be found in different locations of the system. Main configuration of both “Tracing Locations” and “Logging
Categories” in the Java stack is done under the following path: SAP NetWeaver Administrator → Configuration →
Infrastructure → Log Configuration.

Current set up in PX3 system is the following:

Area: Log Configuration, Java


Type Root Category / Location Root Category / Location
Current Severity Level Recommended Severity Level
Logging Categories Info Info
Tracing Locations Error Error

Overall recommendation is setting Tracing Location to severity “Error” and Logging Categories to “Info” with some
exceptional categories for which “Info” writes in some cases too many details:

Area: Log Configuration → Logging Categories


Category Current Severity Recommended
Level Severity Level
/System/Security/Authentication n/a Warning
/System/Security/WS/ n/a Warning
/System/Security/WS/Authentication n/a Warning
/System/Security/WS/Authorization n/a Warning
/Applications/ExchangeInfrastructure/AdapterFramework/SOAPI_* Info Warning
(i.e. all categories like SOAPI_File_Adapter, SOAPI_Modules, etc.)

Note: some of aforementioned categories might be missing in the system as they depend on usage of a
respective adapter.

Having “Logging Categories” with severity “Error” may lead to insufficient information in case of RCA activities in
the system. The goal is to have troubleshooting information and additionally to avoid an overhead in productive

SAP PO Recommended Settings 24/39

Confidential
SAP TPO for PO system PepsiCo, Inc 22.05.2025

systems. More information about authentications logging is in SAP Note 2209271 - Failed Authentications Logged
in the Security Audit Log with Severity Info.

If the “Logging Categories” generates a lot of logs, it can also be set to “Warning” / “Error” in this case and specific
categories that are required for audit purposes can be kept on “Info” (all the unnecessary ones set to “Warning” /
“Error”).
Some Tracing Locations like deploy service or SMD related are by default set to low logging level in order to keep
the information from these (seldom) actions which do not impact the runtime.

AAE: Advanced Adapter Engine specific settings


Tuning configuration is important as it helps to ensure sufficient throughput and performance of your interfaces.
Bottlenecks or even recurrent backlogs due to lack of parallelism can be identified in the PI Dashboards in Wily
Introscope. The parameters mentioned below consume Application threads only during the runtime and the
recommended value of 350 (total of Application Thread per server node) is usually enough for most of SAP PO
systems.

There are most useful monitoring tools which simplifies the monitoring of an SAP PO system and analysis of
performance issues:
• Performance monitor is enabled in PX3 system
• Wily Introscope is configured for PX3 system

Adapter Queues
For the meaning of each Thread queue, refer to SAP Note 1129604 - New Queueing Scheme in XI 3.0 SP19 / 7.0
SP11. For the documentation of the Messaging System Service properties, refer to SAP Note 791655 -
Documentation of the XI Messaging System Service Properties.

For Asynchronous Communication:


1. <Adapter-Type> [Link] (Sender Side)
2. <Adapter-Type> [Link] (Receiver Side)

For Synchronous Communication:


3. <Adapter-Type> [Link] (Sender Side)
4. <Adapter-Type> [Link] (Receiver Side)

NOTE: For Java Only installations only Consumer Threads related to the Sender Side are used.

Currently the following value of the property [Link] of XPI Service: AF Core is used in
PX3:

Channels Default Value


(name=global, messageListener=localejbs/AFWListener, exceptionListener=localejbs/AFWListener,
pollInterval=60000, pollAttempts=60, [Link]=5, [Link]=5,
global [Link]=5, [Link]=5)

(name=global, messageListener=localejbs/AFWListener, exceptionListener=localejbs/AFWListener,


pollInterval=60000, pollAttempts=100, [Link]=10, [Link]=10,
[Link]=10, [Link]=10) (name=JDBC_[Link]
[Link]=20, [Link]=10, [Link]=10,
[Link]=10) (name=File_[Link] [Link]=10,
Custom [Link]=10, [Link]=10, [Link]=10)
(name=REST_[Link] [Link]=20, [Link]=10,
[Link]=10, [Link]=10) (name=SOAP_[Link]
pollInterval=60000, pollAttempts=100,[Link]=30, [Link]=20,
[Link]=30,[Link]=10)

NOTE: There is another property “[Link]” of service “XPI Service: Messaging System”
that is used for tuning of special adapters like CIDX, RNIF, Java Proxy or AFW queues. Standard adapters like
SOAP have to be configured using service “XPI Service: AF Core” and property “[Link]”.

SAP PO Recommended Settings 25/39

Confidential
SAP TPO for PO system PepsiCo, Inc 22.05.2025

Receiver Parallelism
One more important setting is restriction of number of worker threads which can be blocked by one interface
(based on receiver Party / Service and Interface / Namespace information) in specific adapter: property
“[Link]” of “XPI Service: Messaging System”. By using this property
you can ensure that even during backlog situations resources are kept free for other interfaces.

The global setting limiting the throughput of all the interfaces can be set via the global parameters or starting with
7.31 SP11 / 7.40 SP06 it can be set as well per interface (refer to SAP Note 1916598 - Configure receiver
parallelism per Interface in Messaging System).

Area: Service, XPI Service: Messaging System


Name Properties Current Recommended Source
Value Value
XPI Service: [Link] 6 3 Note
Messaging 1136790
System
XPI Service: [Link] Send,Recv IcoAsync* Note
Messaging 1493502
System
XPI Service: [Link] true true Note
Messaging 1916598
System

* “[Link]” defines the set of queues for which the restriction shall be
enforced. For releases 7.30 and higher the default behavior (empty value) is to enforce the max receiver
restriction on both the receive queue for classical scenarios and the send queue for Integrated Configurations (this
corresponds to the value “Recv, IcoAsync”).

The value “Recv” is only relevant for dual stack SAP PI installations and ignored in Java only systems like SAP
PO or PI-AEX. Therefore, the following values are possible:
• “IcoAsync” will enforce the max receiver restriction on all asynchronous messages of Integrated
Configurations (which corresponds to the send queue);
• “IcoSync” will enforce the max receiver restriction on all synchronous messages of Integrated
Configurations (which corresponds to the call queue);
• “IcoAll” will enforce the max receiver restriction on all messages of Integrated Configurations (send and
call queue).

NOTE: It is important to keep in mind that, for synchronous scenarios, this setting is not recommended (in default
case) due to the restriction of parallelism and risk of timeout. Therefore, initial recommended setting is
[Link]=IcoAsync.

In addition, it is recommended to enable property “[Link]” in order to


achieve possibility of dynamic configuration of receiver parallelization under PIMON → Configuration and
Administration → Adapter Engine → PI Receiver Parallelism. It means that parallelization can be adjusted online
(without restart), for example, in case of backlog for specific receiver. In comparison, global property
“[Link]” is not changeable online and requires restart.

Note: In order to avoid performance issue due to hanging messages in To Be Delivered status in Dispatcher
queue that may occur in case of restarting or cancelling messages in TBDL state if property [Link].
[Link] is set to “true”, apply correction from SAP Note 2575215 - Parallel message
processing restricted due to [Link] property.

Prioritization and Dispatcher Queue


Use Prioritization functionality in AAE to ensure that critical interfaces are not blocked in case of bottlenecks /
backlog in the system. Configuration is described in the SAP Help Portal:
[Link]
US/[Link]

Note that it does not make sense to assign “high” priority for many interfaces. Normally the majority of your
interfaces should have “normal” priority. And only several scenarios can be treated with “high” or “low” importance.

SAP PO Recommended Settings 26/39

Confidential
SAP TPO for PO system PepsiCo, Inc 22.05.2025

Configured rules can be checked / adjusted under PIMON → Configuration and Administration → Adapter Engine
→ Message Prioritization.
Message prioritization is currently being used.

Based on the priority, the Dispatcher Queue of the Messaging System will forward the messages to the standard
adapter-specific queues. The dispatcher queue must not be adjusted. If this queue is mentioned in the parameter
“[Link]” or number of threads is adjusted in “[Link].
dispatcherThreadCount”, there is a risk of issue with duplicate messages. There must be one only thread for the
dispatcher to ensure its consistent behavior.

Starting with 7.31 SP13 / 7.40 SP08, the Dispatcher queue can also be disabled as per SAP Note 2009152 –
Message Prioritization in Adapter Queues (without Dispatcher Queue) in case high backlogs are observed for the
DispatcherDisp queue (if the high backlog slows down the message dispatching of other time critical scenarios).

Adapter Framework Scheduler


The old AF Scheduler has known issues concerning polling of File and JDBC Adapter and therefore was replaced
by a new and reviewed version of the Scheduler. As per the SAP Note 1355715 - AF Scheduler to avoid using
cluster communication the old Adapter Framework's scheduler has several performance and reliability issues in a
cluster environment, especially when there are a large number of jobs. In order to implement the new AF
Scheduler, the value of the parameter “[Link]” under the Java service “XPI Service: AF Core”
should be set to negative value.

Area: Service, XPI Service: AF Core


Name Properties Current Value Recommended Value

XPI Service: AF Core [Link] -10 -10

For File and JDBC based sender communication channels polling configuration can be adjusted on channel level
using advanced property “clusterSyncMode”:
• “Scheduler”: this is the default option that guarantees that at any time only one server node will have any
channel instance active. The adapter runs locally on a server node which is assigned by the scheduler.
The polling of the adapter continues on the same server node, until the node crashes or “relocMode”
value is reached;
• “lock”: this option will ensure that there is only one instance of the channel running across server node.
When this option is set, adapter acquires an enqueue service lock on the server node. Lock is taken on
channel object and it is exclusive and non-cumulative such that no second instance (even it is from the
same channel) can fetch the data until first instance has completed (success / fail) the processing.
Another key aspect of this setting is that the polling is submitted to all the server nodes. Therefore, the
processing happens at all server nodes depending on the lock acquired by the instance.

For File adapter the “clusterSyncMode” can be also enabled at Service level: property
“[Link]” of service “XPI Adapter: File”. Moreover, a new mode is provided to force the File
sender channel to execute its polling job at specific cluster node with SAP Note 2029410 - Assign a File Sender
Channel to poll at specific cluster node.

NOTE: Globally scheduled polling tasks are causing high overhead on enqueue server and SAP system. In
addition, it is quite often that such channels have issues with load balancing across server nodes (the same server
node gets the messages). Therefore, it is recommended to use default “Scheduler” behavior.

SAP PO Recommended Settings 27/39

Confidential
SAP TPO for PO system PepsiCo, Inc 22.05.2025

Java IDoc Adapter (IDoc_AAE)


Main information resource for tuning and configuration of Java IDoc Adapter is SAP Note 1641541 - IDoc_AAE
Adapter performance tuning.

Note that most of the IDoc_AAE based channels should be configured in Default mode and use only one
inboundRA resource adapter:
• JRA inboundRA is used by Java IDoc sender adapter;
• JRA outboundRA is used by Java IDoc receiver adapter;
• JRA is shared between all IDoc communication channels configured in default mode – meaning that
there is no channel-specific isolation and the parallelism is for all channels in default mode together;
• The number of reader threads or parallel server connections registered at the gateway is configurable
(see below).

Cloned resource adapters and executor threads in the application thread pool:
If you need to isolate specific IDoc_AAE based integration scenarios by some criteria (interface, prioritization,
sender system), you may have few cloned Resource Adapters for them. In general, it is not recommended to use
many cloned Resource Adapters since it could lead to the issues during CPA cache updates (refer to SAP Note
2246340).

Number of threads in executor pool is controlled by property ExecutorPoolMaxSize of ApplicationThreadManager


and should be adjusted in case of need. Go to SAP NetWeaver Administrator → Configuration → Infrastructure →
Java System Properties ([Link] → Kernel tab → ApplicationThreadManager.

Name Properties Current Value Recommended Value


ApplicationThreadManager ExecutorPoolMaxSize 150 Σ (MaxReaderThreadCount)
+ amount of inboundRAs +
10 additional threads for
other tasks

It is necessary to make sure there is a sufficient number of executor threads in the application thread pool when
adding new RAs or change capacity of already existing cloned RAs.

For Outbound communication (e.g. from Sender to SAP PO):


Threading: The number of reader threads (MaxReaderThreadCount) or parallel server connections registered to
the gateway can be configured in the Resource adapter. In case of the “Default” configuration mode of Java IDoc
Adapter, the existing inboundRA resource adapter is used for receiving IDocs by the Java IDoc Adapter.

Number of threads can be configured under the following path: SAP NetWeaver Administrator → Configuration →
Infrastructure → Application Resources (or direct link [Link] → Show:
“Resource Adapters” → filter for the Resource Adapter by name (e.g. inboundRA).

Area: Application Resources, Resource Adapter configuration


Name Properties Current Value Recommended
Value
inboundRA MaxReaderThreadCount 10 5-10
inboundRA GatewayServer [Link] SCS Gateway
inboundRA GatewayService sapgw44 SCS Gateway
inboundRA Local false false

MaxReaderThreadCount specifies the number of connections (registered programs) on the Gateway for each
server node of the SAP PO system. It should be a positive number and should be specified taking into account the
number of sender systems, the load of the sent IDoc documents / lists and the available resources (especially
memory and application executor thread usage) on the SAP PO system to process as much parallel calls as
defined. If inboundRA is started and registered properly on the Gateway there should be exactly: (number of sever
nodes) multiplied by the (MaxReaderThreadCount value) registered programs with the value of the ProgramID
property.

Note that multiRepository must never be changed. The data will be filled automatically when a message for a
channel is processed. If it is not filled automatically there is typically another issue (e.g. the required
XI_IDOC_DEFAULT_DESTINATION_<SID> is not there. In case of requirement to change the naming of the
destinations (e.g. because there are multiple clients), the CustomDestMap value of the Java IDoc Resource

SAP PO Recommended Settings 28/39

Confidential
SAP TPO for PO system PepsiCo, Inc 22.05.2025

Adapter can be used (override default metadata destination). After specifying the relation there, the corresponding
entry will be automatically populated in the multiRepository.

XI_IDOC_DEFAULT_DESTINATION can be configured with a dummy destination targeted to a non-reachable


host. In this case the inboundRA does not rely on this connection and get the metadata from the matching multi
repository entries and there is no fallback done in case the dedicated multi repository is unavailable. WARNING:
changing of this configuration (switching to dummy XI_IDOC_DEFAULT_DESTINATION) must be done carefully
and tested in non-production environment as it requires adding dummy values for many destination attributes
(client, user details, etc.) and if any of them is missing – inboundRA will not start, so it can affect all IDoc based
interfaces.

For Inbound communication (e.g. from SAP PO / PI-AEX to Receiver):


In case of “Default” mode you need only to specify an already created RFC destination in SAP NetWeaver
Administrator pointing to the receiver system. The IDoc_AAE receiver adapter uses JCA connection factories to
connect and send IDoc documents to the receiving systems.

The connection pool is automatically managed by default. If you require a higher pool size for particular channel
you can change this via SAP NetWeaver Administrator → Configuration → Infrastructure → Application Resources
(or direct link [Link] → Show: “JCA Connection Factories” → filter for the
Connection Factory by name. Then, open the Connection pooling tab and check the property “Maximum
Connections”. The default value is ‘-1’ (automatically managed). Refer to the SAP Help Portal:
[Link]
US/[Link]

Global configuration of IDoc_AAE adapter


All global configuration of the Java IDoc adapter is made in the application resource JavaIDocAdapter resource
adapter. Go to SAP NetWeaver Administrator → Configuration → Infrastructure → Application Resources (or
direct link [Link] → Show: “Resource Adapters” → filter for the
“JavaIDocAdapter”.

Area: Application Resources, JavaIDocAdapter configuration


Name Properties Current Recommended Source
Value Value
JavaIDocAdapter Persistance true As per Note
explanation 1641541
bellow *
JavaIDocAdapter AutoNumberFromDB false false Note
1641541
JavaIDocAdapter HandleMSEvent true As per Note
explanation 1918557
bellow **
JavaIDocAdapter CFPoolMaxConnections -1 customer- 2831372
specific, start (global
value can be 20 connection
JavaIDocAdapter CFPoolMaxWaitTime -1 30 - 60 sec factory
pooling),
JavaIDocAdapter CFPoolCleanupInterval -1 300 sec
2189576
JavaIDocAdapter CFPoolConnLifetime -1 300 sec (pooling in
channel
level)

* The property “Persistance” is used to enable / disable the additional persistency of IDoc documents in the SAP
PO / PI-AEX system. It should be set to “true” if you want to monitor the IDoc documents in the “IDoc Adapter
Monitor” of PIMON or if you need to process IDoc acknowledgements (ALEAUD IDocs) via IDoc_AAE adapter. If
the IDoc_AAE additional monitoring and ALEAUD processing are not used, then, it is recommended to turn off the
additional persistence. This functionality impacts on the size of tables like XI_IDOC_OUT_MSG,
XI_IDOC_IN_MSG, etc.

** The property “HandleMSEvent” specifies whether the IDoc_AAE adapter registers and processes the event
triggered by the Messaging System background Delete and Archive events. In order to reduce the number and
complexity of the database queries during database tables cleanup by the AAE Deletion / Archiving jobs, a
separate Java job was introduced to delete old entries from the Java IDoc database tables. For this purpose the
job IdocDBTableCleanupPeriodic can be scheduled to run regularly and property “HandleMSEvent” of the
JavaIdocAdapter resource adapter is disabled. Refer to the SAP Note 1918557 - IDoc_AAE: Additional
persistency tables cleanup for more details. In addition, there is a newer job
SAP PO Recommended Settings 29/39

Confidential
SAP TPO for PO system PepsiCo, Inc 22.05.2025

IdocDBTableCleanupPeriodicAdvanced for regular deletion of the Java IDoc database tables. It offers more
options than IdocDBTableCleanupPeriodic. Refer to SAP Note 2624188 - IdocDBTableCleanupPeriodicAdvanced:
a new improved job for IDoc_AAE data deletion with optimized option for SAP ASE DB.

Polling Channel Watchdog


The Polling Channel Watchdog helps to recognize the situation when a sender channel is not polling anymore or
hanging. In this case the channel status is set to “error” and alerts can be triggered. Required configuration is
described in SAP Note 1808222 - Trigger alerts if channel stops polling.

Area: Service, XPI Service: AF Core


Name Properties Current Recommended Source
Value Value
[Link] true true Note 1808222
XPI Service: 10 10 Note 1808222
[Link][min]
AF Core
[Link][sec] 30 30 Note 1808222

For this functionality there is an important correction from the SAP Note 2584443 - Polling Channel Watchdog
consumes many threads that should be applied in the system before activation of the watchdog as it may occupy
many application threads in the system. This problem can lead to an exhaustion of all application threads and to
severe problems with the system.

Mapping Runtime
Support Java8 features in Message Mappings of SAP Netweaver 7.5
New features of Java8 in User-Defined Functions and Function Library in Message Mappings of SAP Netweaver
7.5 can be activated by selecting the JDKCompliance from the dropdown present in functions tab of Message
Mapping editor, Function Library editor, Imported Archive editor. Per default in SAP Netweaver 7.5 the mappings
are generated using Java 5 compatible code.

Default value in the JDK Compliance can be enabled with the property [Link].
supportCompileWithVMJavaVersion of AII Config Service. For more information refer to SAP Note 2482929 -
NewFeature: Support for features of Java8 and above in UserDefinedFunctions and FunctionLibrary in Message
Mappings of SAP NetWeaver Process Integration 7.5 and above

Area: Service, XPI Service: AII Config Service


Name Properties Current Recommended Source
Value Value
XPI Service: Property
Note
AII Config [Link] not true
2482929
Service defined

Execute Message Mapping in a single thread


Graphical mappings are processed in two threads – parser and mapper threads. The parser thread is parsing the
source message and feeding the data to the mapper thread, which is generating the target message. In case
there is no sufficient data parsed the mapper thread wait for the parser thread to provide more input. Under high
load the thread switching between the parser and the mapper thread consumes significant CPU resources.
Switching to one thread model where the payload is first parsed and then the mapping is performed can lead to
performance improvement in case of small message payloads.

The single thread execution for graphical mapping can be switched on:
• Globally for all mappings it can be enabled with property [Link] of
AII Config Service. For more information refer to SAP Note 1991275 - Execute graphical mapping in a
single thread.
• For specific Message Mapping: add the following statement in the init() method of the message
mapping in the “Functions” tab of the mapping editor: mt$setHeaderObj("SingleThread",
"true");

SAP PO Recommended Settings 30/39

Confidential
SAP TPO for PO system PepsiCo, Inc 22.05.2025

Area: Service, XPI Service: AII Config Service


Name Properties Current Recommended Source
Value Value
XPI Service: Property As per
Note
AII Config [Link] not explanation
1991275
Service defined bellow *

* Not recommended to enable globally, but it makes sense to configure it for specific Message Mappings where
small payloads and frequent mapping invocations are expected.

SAP XML Toolkit


The SAP XML Toolkit used for the XSLT mapping is deprecated in newer releases and is not maintained any
longer for higher SAP PO / PI-AEX releases. In order to replace fully the SAP XML Toolkit, the JDK transformer
was enhanced to cover existing gaps. Usage of this deprecated tool is known for high consumption of heap
memory.

Ensure that all your XSLT transformations use JDK. The respective switch is done by disabling the checkbox “Use
SAP XML Toolkit” in the operation mapping that references to the corresponding custom XSLT transformation
program. Note that such a switch should be properly tested in quality environment. For additional information refer
to SAP Notes:
SAP Note 1731772 - Migrate XSLT mappings to JDK JAXP implementation
SAP Note 1634755 - PI Mapping: XSL compatibility SAP XML Toolkit to XSLTC
SAP Help: Recommendation Related to Usage of SAP XML Toolkit and JDK
[Link]
US/[Link]

Support XSLT 2.0 in XLST Mappings


Custom XSLT Transformer can be used to enable XSLT 2.0 in SAP PO / PI-AEX. To enable the use of external
transformers the following steps to be done:
1) Import the transformer as an external archive.
2) Enable property [Link] of AII Config Service.

Area: Service, XPI Service: AII Config Service


Name Properties Current Recommended Source
Value Value
XPI Service: Depends on
Note
AII Config [Link] false requirement to
1893110
Service use XSLT 2.0

SAP Note 1893110 - Integrate external XSLT transformer in PI Mapping RuntimeVersion

Simple XPath Processor


In case of usage integration scenarios with XPath expressions in the Receiver / Interface Determination steps of
the Integrated Configuration or XPath based extractors for User Defined Message Search (UDS), the memory
consumption during message processing can be very high and there is a risk of OutOfMemory. The XPath
evaluation with the default parser builds a DOM document out of the message payload. DOM object trees
consume much heap memory because of their data structures. Usually, they require multiple times the size of the
message payload in the Java heap memory. Besides the memory consumption, the building of the DOM tree
requires a lot of processing time and can slow down the message processing.

New XPath parser is provided within SAP Note 2239367 - Simple XPath Processor that does not use a DOM tree,
requires less memory and is faster than the default parser. More information about configuration is in this SAP
Note.

NOTE: new parser has limitations on the complexity of the XPath expressions (no attributes in the middle of the
XPath expression and expressions with double slash are not allowed).

Retry Configuration
According to global retry settings each erroneous message is reprocessed maximum 3 times with interval 5
minutes per default. There are predefined pipeline steps where reprocessing takes place: Inbound XML Validation
(VI), Receiver Determination (MS), Mapping (AM) or Outbound XML Validation (VO). It is also possible to prevent
automatic retries in case of an error during execution of specific pipeline steps.
SAP PO Recommended Settings 31/39

Confidential
SAP TPO for PO system PepsiCo, Inc 22.05.2025

The default settings are taken from the outbound properties for the Java service XPI Adapter: XI and receiver
communication channel specific configuration can be done in the Communication Channel Monitor (link
[Link] Configuration Settings tab ➔ Number of Retries and Retry Interval
(only relevant for receiver channels).

Area: Service, XPI Adapter: XI


Name Properties Current Recommended Source
Value Value
XPI Adapter: XI [Link] 3 3 Note 791379
XPI Adapter: XI [Link] 300000 300000 Note 791379
XPI Adapter: XI [Link] 3 3 Note 791379
XPI Adapter: XI [Link] 300000 300000 Note 791379
XPI Adapter: XI [Link] ““ As per Note 2289377
explanation
bellow *

* the property “[Link]” can be used to prevent automatic retries in case of an error during
execution of specific pipeline steps – e.g. very often reprocessing of mapping and receiver determination errors
does not help as errors are typically permanent. This property with value “MS,AM” can help to avoid such not
beneficial reprocessing attempts at these specific steps and in the most of the cases configuration of this value is
recommended. This property will affect all asynchronous messages that are persisted at some previous pipeline
step according to their staging configuration.
Note that it is still customer specific as e.g. in case of many mappings with lookups reprocessing of mapping step
might be useful.

Large Messages
Normally SAP PO system can handle large messages without impact on the system runtime. However, problems
may occur in case of concurrent execution of several large messages or incoming one but extremely huge
message which might negatively affect system performance. There is a functionality which can help to protect your
SAP PO system in such circumstances.

Area: Service, XPI Service: Messaging System


Name Properties Current Value Recommended
Value
XPI Service: Messaging [Link] true true
System
XPI Service: Messaging [Link] 10 10
System
XPI Service: Messaging [Link] 10240 10240
System
XPI Service: Messaging [Link] true exceptionally to be
System set to “true”

Large Message Handling restricts the number of large messages that can be processed at the same time across a
configured set of Messaging System queues on one AS Java server node. This restriction helps to improve the
performance of message processing and protect your server node from out of memory problems.

A message is considered large when its size is larger than the threshold that is defined using the
“[Link]”. Messages that are larger than this threshold have to obtain respective
number of permits to continue message processing. When the parameter “[Link].
blacklistXLMessage” is activated, it will push the large message directly to be blacklisted (the support efforts will
be higher due to the blacklisted messages monitoring and manual processing). Correction from SAP Note
2604234 - Corrections related to blacklisting of large messages should be applied.

For the further information refer to links:


SAP Note 1727870 - Handling of large messages in the Messaging System
[Link]
US/[Link]

SAP PO Recommended Settings 32/39

Confidential
SAP TPO for PO system PepsiCo, Inc 22.05.2025

EOIO processing
Quality of Service Exactly Once In Order (EOIO) guarantees that a message is only processed once its
predecessor reached a final status (either successful delivered, or manually cancelled). Therefore, all messages
with a non-final predecessor are put to “HOLD” status until the predecessor is finally processed.

There are some known issues that may lead to backlogs of EOIO messages that are put on “HOLD”. Ensure that
these fixes are applied in your system:

1) In systems with high memory consumption (caused by any running scenario) the message may remain in
holding state after delivery of predecessor message and no errors in default trace files generated at this time. SAP
Note 2381352 - EOIO message remains in Holding state after successful delivery of predecessor message should
be applied to fix the issue.

2) Similar symptoms may occur for the interfaces with Staging configuration before determination of
receiver (e.g. configuration on ICO level: staging BI=3;MS=3). Detailed description of the issue and fix is available
in SAP Note 1678427 - EOIO messages put on HOLD in AAE with message versioning and 2177278 - EOIO
messages remain in Holding state without blocking predecessor message. This issue is fixed in all new releases,
however, in specific circumstances (mappings between “old” and “new” serialization contexts are kept in memory
and in case of server node failover / restart it will be lost), manual restart of EOIO messages might be necessary
as queue may stuck. Therefore, it is better to avoid staging configuration for EOIO interfaces before Receiver
Determination.

It is possible to configure alerting functionality for notifying about stuck messages, e.g. in on “HOLD” state. This
functionality is available in the standard for release 7.50 SPS06, refer to SAP Note 2279043 - New Feature:
Alerting: changes and improvements in Component Based Message Alerting (#1). For older releases refer to SAP
blog [Link] the background job AlertStuckMessagesJob
can be deployed to your SAP PO / PI-AEX system and scheduled periodically to check for messages that are in a
non-final status and without an update / change for a certain time and send Alerts in case of such situation (non-
final message status on the AAE are System Error, Waiting, To Be Delivered, Delivering and Holding).

There is also a functionality of Extended EOIO Exception Handling that helps to configure rules how a serialized
message is handled after all retries of the first message in the queue have failed. It is possible to enable automatic
continue of EOIO sequence, even though a predecessor message cannot be delivered successfully. This
requirement can be considered as a controlled violation of the EOIO delivery guarantee. In general, this
functionality might be useful for some special interfaces. Refer to SAP Help portal:
[Link]
US/[Link]

8.3 Housekeeping

AAE housekeeping
Housekeeping needs to be defined in your SAP PO . It is important to reduce / avoid unnecessary data in the
system. Basically there are two options: either delete processed messages or archive them. By default only
Deletion is enabled in AAE engine. Explanation of message persistence in AAE is provided in SAP KBA 1872758 -
How XI/PI messages are persisted in Adapter Engine.

Retention Periods
The following configuration must be set via SAP NetWeaver Administrator → Configuration Management →
Infrastructure → Java System Properties (or direct link [Link]

Area: Services, XPI Adapter: XI


Name Properties Current Recommended Source
Value [ms] Value [ms]
XPI Adapter: XI [Link] 86400000 86400000 * Note 791379
XPI Adapter: XI [Link] 86400000 86400000 * Note 791379

Note: The value of 86,400,000 ms corresponds to 1 day retention period. Consequences of a large retention
period are visible in the increase of the other related tables: BC_MSG, BC_MSG_AUDIT,
BC_MSG_LOG_VERSION.
SAP PO Recommended Settings 33/39

Confidential
SAP TPO for PO system PepsiCo, Inc 22.05.2025

Starting with 7.31 SP12 / 7.40 SP07 the Java retention period can also be set at interface level: SAP 1960448 -
Configure message retention period per interface. For example, this setting allows to increase retention period
only for a specific interface for which data needs to be persisted for longer period days (e.g. due to legal / audit
reasons). If you need to configure retention period per interface for logged synchronous messages, ensure that
correction from SAP Note 2218407 - Message Retention Per Interface for logged synchronous messages is
applied.

NOTE: It is not recommended to configure local retention rules with all wildcards as it is better to adjust global
retention periods to influence on all interfaces. Global properties “[Link]” and
“[Link]” are changeable, i.e. online modifiable and restart is not required.
Scenario-specific rules are aimed to adjust the retention periods of messages of specific interfaces and provide
maximum flexibility to ensure that only critical messages are kept for a longer time in the system.

Currently, Interface level retention has been set to 4 days for all the interfaces.

Housekeeping jobs
As a general information on the SAP PO / PI-AEX Background Job Types, refer to the SAP Help Portal at link:
[Link]
US/[Link]

Restarting Messages in the AAE:


There is a job responsible for restarting automatically the not delivered messages (NDLV) in the Advanced
Adapter Engine. It is important to ensure that a job with type “Restart” is scheduled in the PIMON under the path
Monitoring / Configuration and Administration → Adapter Engine → Background Job Processing Monitor
([Link]

This job should be scheduled with the following parameters (refer to the screenshot below):
• The frequency must be defined;
• The input field “Max Number of Restarts” must be set and activated (value “3” is recommended);
• Parameter for blacklist messages with the checkbox unselected (value “false”) should be added.

It is recommended to create this job at earlier stage to avoid future overhead when there are already old
messages in error in the system (NDLV status) and setting up the Restart job for the first time can create a high
load on SAP PO application and the database.

Deletion / Archiving Jobs for Messages in AEE:


The successful (DLVD) or cancelled (FAIL) messages should be deleted or archived after a while (depending on
the daily volumes) from the SAP PO database in order to avoid huge database size and performance problems.

Usually archiving in SAP PO is not required (unless strict legal requirements demand it), as data is already
available on sender and receiver business systems (SAP PO is not a business system). Note that Default Version
Archive Job might be necessary to take care of messages that were edited and need to be archived. Usually, it
needs to be activated and runs with default daily frequency. Rules cannot be assigned to this job.

SAP PO Recommended Settings 34/39

Confidential
SAP TPO for PO system PepsiCo, Inc 22.05.2025

Area: AEX Background Jobs

* WARNING: Scheduling the Restart job for the first time or after a long period of inactivity can restart very old
messages and/or a high volume of messages (risk of system overload, in extreme cases can lead to downtime),
so a cleanup of the old messages in NDLV is highly recommended before scheduling this job.

With SAP Note 2611192 it is possible to create a rule for a background job of type Archive, Restart, Cancel or
Delete Archive, to make the job skip certain messages, e.g. to configure an Archive job to archive all messages
except those belonging to specific scenario, with certain interface, sent from specific sender, etc.

For SAP PO housekeeping troubleshooting refer to SAP Note 872388 - Troubleshooting Archiving and Deletion in
PI that provides an approach how to analyze non-final messages and links to the Notes for known problems.

Archive Deletion Job


Since 7.31 SP18 / 7.40 SP13 / 7.50 SP02 a new periodic job is provided to delete archived messages and the
entries belonging to them from the XML DAS archive (SAP Note 2174022 - Message Archive Deletion Job). This
job can be scheduled in Background Job Processing Monitor ([Link] similar to
other Messaging System jobs. This job has a parameter specifying the time, how long the message should be
kept in the archive since the creation of the message in the Messaging System (retention period).

If you schedule this job in productive system, ensure that important fixes from SAP Note 2420535 - Delete Archive
background job may cause OutOfMemoryError and SAP Note 2447828 - Delete Archive job may never finish if
messages have been manually deleted from the archive store are applied as well.

XML DAS expects the information about the archived resources to be consistent in both file system and database.
In case of manual deletion of archived messages on file system, the DELETE method of XML DAS will fail as
there is still information in XML DAS database. To overcome this issue Delete Archive background job has a
configuration parameter “delete_mode” with possible values “default” or “ignore_io_error”. It is recommended to
use “ignore_io_error” only in case when it is verified that the failing resource is missing. In all other cases it is
better to use the “default” value to keep the consistency of the archived resources. Refer to SAP Note 2811802 -
New delete_mode parameter in XML DAS DELETE command and Delete Archive Job.

Message Compression on SAP PO application level


You can configure the Messaging System to compress the asynchronous message content before storing it in
MSG_BYTES field. It will help to decrease the size of BC_MSG and BC_MSG_VERSION tables and reduce the
LOB space occupied by MSG_BYTES field of these tables. The BYTES_COMPRESSED field will have a value 'Y'
and the actual (uncompressed) size of the message content will be kept in UNCOMPRESSED_SIZE field. The
actual size of the message kept in MSG_BYTES field is stored in BYTES_LENGTH field.

Message compression can be configured using the properties [Link] and


[Link] of Messaging System service and by default is disabled. For more information
refer to SAP Note 2538365 - How to enable message compression on PI/PO system. With compression the CPU
overhead will increase, so you should choose the threshold carefully to ensure that the CPU overhead is not
getting too high.

SAP PO Recommended Settings 35/39

Confidential
SAP TPO for PO system PepsiCo, Inc 22.05.2025

Area: Service, XPI Service: Messaging System


Name Properties Current Recommended Source
Value Value
True Note
XPI Service: [Link] false
2538365
Messaging
<customer-
System [Link] 0
specific>

Note: important prerequisite for enabling payload compression is applying the fix from SAP Note 2434204 -
IndexOutOfBoundsException with payload compression enabled.

UDMS data clean up


If you use User-Defined Message Search to search for messages in the database by certain payload attributes or
dynamic headers, housekeeping configuration is important to prevent growing of tables XI_AF_LMS_DATA and
XI_AF_LMS_ARC_KEYS. By default after messages are removed from database by Delete job, all related User-
Defined attributes are also removed; if XML messages are moved to archive store by Archive job, related User-
Defined attributes are moved to archive store as well.

It means that if you archive an interface with active User-Defined Message Search configuration, you need to
configure UDS data archiving (xi_af_uds_msg set) according to SAP Help Portal:
[Link]
US/[Link]

With SAP Note 2424103 - Deletion of User-Defined Search attributes upon message archiving it is also possible
to deletes UDMS attributes from the database without archiving, even if original XML message has been archived
(if no requirement to search in the archive using UDS criteria). The property “[Link]” of
service “XPI Service: Lean Message Search” can be set to “archive” or “delete”.

NW Scheduler for Java


SAP NetWeaver Scheduler for Java is a core service that enables the automated execution of tasks that
applications can perform in the background. Java Scheduler persists all information about future, current, and past
jobs and in case of increased size of respective tables, startup of Scheduler Service can take long time (e.g. in
case of service failover).

There are several tables that should be checked:


• BC_JOB_JOBS persists Jobs data and all completed Jobs are moved to BC_JOB_JOBS_CO;
• BC_JOB_TASKS contains Tasks data (finished tasks have status ‘2’);
• BC_JOB_LOG contains log entries.

The CleanJob is a housekeeping job for the NetWeaver Scheduler which ensures that outdated and obsolete
information is removed from the system. By default this job has retention period for Tasks 30 days (parameter
RemoveTasksEndedBefore). In case of many Single Timers in the system, i.e. one Task produces one Job, default
retention period for Tasks should be reduced to avoid growing BC_JOB_TASKS.

SLD cleanup job


As per SAP Note 1799613 - SLD Change Log clean up tool a housekeeping job has been introduced in order to
clean the SLD change log table. It is available in SAP NetWeaver since release 7.11 and can be found under the
following path: SLD home page ([Link] and navigate to "Administration" → "Changes" →
"Cleanup Task Configuration".

In order to reduce the growth of the change log, you should regularly remove obsolete entries. It is recommended
to set up automatic cleanup task to reduce the growth of the obsolete change log entries on a regular basis. Go to
“Cleanup Task Configuration” and schedule new task using Java Scheduler (you can check this job definition and
start condition also in SAP NetWeaver Administrator).

For additional information refer to the links:


[Link]
US/[Link]
SAP Note 1799613 - SLD Change Log clean up tool
SAP Note 1792134 - Table BC_SLD_CHANGELOG Overflow
SAP Note 1840184 - Features which relies on the SLD change log

SAP PO Recommended Settings 36/39

Confidential
SAP TPO for PO system PepsiCo, Inc 22.05.2025

Load Balancing and Rolling Restart


HTTP internal Load Balancing within an AS (only relevant when there is more than one server node)
As per SAP Note 1596109 - Uneven distribution of HTTP requests on Java server nodes, it may happen that a
high difference in the number of incoming HTTP requests across multiple server nodes is noticed. This is usually
the case for stateless application on the SAP J2EE engine based on Netweaver 7.1 and higher, such as SAP PO.
In Wily Introscope Dashboards it is visible that one Java server node processes much more messages or are
facing a higher backlog causing a decrease in message throughput. In such case, implement the SAP Note
mentioned.

Rolling Restart
Considering that SAP PO is based on the Java Stack and most of the parameters on the Java stack are not
dynamic, the required restart of this stack used to impact then the implementation of optimized parameterization
as well the update of some components.

With the configuration and procedure of the controlled restart, the SAP PO application servers can be restarted
with a minimized impact to business.

For further information refer to the SAP Blog “Controlled restart of a J2EE engine in a PI system with multiple
application servers” under the link:
[Link]
servers/

8.4 Other checks


Security
Available security features in SAP PO system are explained in Security Guide:
[Link]
US/[Link]

In order to achieve more secure communication, you can utilize security mechanisms on transport level and
message level. It should be noted that transport level and message level security mechanisms should not be
considered as substitutes – even though they both are targeted at securing communication between service
consumer and service provider, approach and toolset used for securing this communication is fundamentally
different.

Additional important area from security perspective is Data Storage Security (especially for AAE) which helps to
prevent unauthorized access to stored data, because data can contain sensitive information. During runtime
several message versions can be persisted in SAP PO and each message version can contain sensitive data.
There are several measures in order to increase data security:
• Encrypting Data – encrypt message content (payload) on database level;
• Reducing Storage Duration of Data and Deleting Data – change the storage duration according to your
needs;
• Access Protection – prevent unauthorized users from accessing different monitoring tools;
• Change Protection – prevent unauthorized users from modifying message content:
[Link]
US/[Link]
• Logging Data Access – access to encrypted message content is logged:
[Link]
US/[Link]

There are different tools to display messages in SAP PO. Depending on the tool, there are different measures to
increase access protection:
• In Open SQL Data Browser of SAP Netweaver Administrator you can restrict access to the content of
Java database tables. Refer to SAP Note 1611852 - Support-roles to access Java NW PI-DB Tables;
• In Message Monitor of PIMON you can restrict access to message payloads of certain types of
messages (e.g. excluding special interfaces or including only messages from a certain sender). Refer to
SAP Note 1370334 - Securing Payloads in Message-Monitoring.

SAP PO Recommended Settings 37/39

Confidential
SAP TPO for PO system PepsiCo, Inc 22.05.2025

It is recommended to check regularly for SAP notes (especially security related ones) via the System
Recommendations functionality available in your SAP Solution Manager under the path: Change Management →
System Recommendations.

Code Injection Protection


SAP AS Java Web Container provides a default implementation of the HTTP 1.0 PUT method (PutServlet). Its
usage is configured in the [Link] global descriptor. By default, the servlet is enabled according to the
Web Services standard, which means that uploading any files is possible once a user is authenticated. As a
drawback, this enables malicious users to inject files into the application server to prepare further attacks.
PutServlet can be disabled per SAP KBA 1975430 - How to disable PUT method for Java Engine Web Container.

Enhanced Cross-Site Scripting (XSS) Protection


SAP Web AS provides an enhanced Cross-Site Scripting protection library, which provides up-to-date standard
defense mechanisms against XSS. A global redirect to this secure encoder can be achieved by configuration. This
is done as follows:

1) Open NetWeaver Administrator and navigate to Configuration → Infrastructure → Java System


Properties → “System VM Parameters” tab.
2) Create System property “[Link]” and set its value to "1"
3) Restart AS Java

Clickjacking Protection
To protect your system from clickjacking attacks, it is recommended to enable the clickjacking framework, as
described in SAP Notes [1] – [4].
• SAP Note 2290783 - Whitelist based Clickjacking Framing Protection for Java Server Pages
• SAP Note 2170590 - Whitelist service for Clickjacking Framing Protection in AS JAVA
• SAP Note 2286679 - Whitelist Service API required for the Clickjacking Framing Protection in JAVA at the
framework or application level
• SAP Note 2319727 - Clickjacking protection framework in SAP Netweaver AS ABAP and AS Java

DOS and Information Disclosure Protection


Opening your company network to remote networks always constitutes a security risk. It enables attackers from
these remote networks to spy on your systems, to collect data, and to even execute specific Denial of Service
(DOS) attacks. Therefore, all applications, which are accessible via network, shall minimize the number of ports,
since they are open by default. This can be achieved by secure network configuration, i.e. usage of firewall,
reverse proxy, DMZ etc. Furthermore, usage of Internet Communication Manager (ICM) Filter rules is
recommended, refer to SAP Note 1451753 - Filtering of administration requests for AS Java.

AS Java System Overview and Services Registry Protection


An attacker can trick the AS Java System Overview in SAP NetWeaver Administrator to send a crafted request
from a vulnerable web application. The issue has been fixed with a hot news 2813811 - [CVE-2019-0344 ]Server-
Side Request Forgery in SAP NetWeaver Application Server for Java (Administrator System Overview). After
applying the fix on some systems System Overview may display incorrect information about started/failed java
server nodes, for example these monitors may show N/A values. The side effect is resolved by applying the
settings from SAP KBA 2577844 - AS Java Monitoring and Logging parametrization best practice.

A Remote Code Execution vulnerability was found in the Services Registry. In order to fix it SAP Note 2800779 -
[CVE-2019-0351] Remote Code Execution(RCE) in SAP NetWeaver UDDI Server (Services Registry) needs to be
applied.

You can setup a weekly job to send data to SAP Service Marketplace and receive the SAP recommended notes
grouped by:
• Security Notes
[Link]
[Link]
• HotNews
• Performance Notes
• Legal Changes Notes
• Patch Notes

This procedure is also described in SAP Note 2041071 - SysRec: How to download latest Java patches using
System Recommendation.

SAP PO Recommended Settings 38/39

Confidential
SAP TPO for PO system PepsiCo, Inc 22.05.2025

Security Notes Check


SAP security notes has been checked in PX3 system according to the latest published fixes on SAP Support
portal [Link]

Below is the missing security patches in PX3 which have CVSS score 5 or higher.

Missing security note CVSS Score

3434192 - [CVE-2024-28163] Information Disclosure vulnerability in SAP NetWeaver Process Integration 5.3
(Support Web Pages)

LM Configuration Wizard
Check that application LM Configuration Wizard is disabled as there were critical vulnerabilities detected in the
API of this application. Refer to SAP Note 2939665 - Disable/Enable LM Configuration Wizard | Critical API's in
LM Configuration Wizard for more information. Check that the URL for WSDL of this service is not accessible (404
error)
[Link]

It is observed that LM Configuration Wizard is not disabled yet and is accessible in PX3.

SAP PO Recommended Settings 39/39

Confidential

Common questions

Powered by AI

Regularly scheduling housekeeping jobs such as 'IdocDBTableCleanupPeriodicAdvanced' is vital to maintain optimal database performance and prevent table bloating. These jobs efficiently manage data by clearing old or redundant entries, thereby enhancing database speed, improving data retrieval times, and ensuring efficient database management operations in ELT (Extract, Load, Transform) processing environments .

Without the 'Restart' job, undelivered messages (NDLV) in the PX3 system are left unresolved, potentially causing a backlog. Scheduling this job ensures that such messages are automatically retried and processed, reducing manual intervention and improving system reliability and throughput .

Implementing security notes with a CVSS score of over 5 is essential to prevent unauthorized access to configuration objects in the PX3 system. Failure to do so risks allowing attackers to gain administrative privileges, leading to potential breaches of system confidentiality, integrity, and availability. Addressing these vulnerabilities is crucial for maintaining system security and safeguarding against potential exploits .

Increasing the ARCHCONN_READTIMEOUT parameter value is recommended because it may resolve the failing archive job that causes messages in the DLVD state to remain unarchived. This adjustment allows the system more time to read and process large amounts of data, reducing performance issues by effectively deleting and archiving messages, thus lowering storage requirements .

Currently, PX3 retains messages for four days generically, contributing to a large number of entries in database tables like BC_MSG. Reducing the global retention period to one day and configuring interface-specific retention based on business or legal needs could significantly enhance system efficiency. This approach balances storage demands against operational requirements, ensuring essential data retention without unnecessary database overhead .

Enabling message compression is necessary to reduce the size of the BC_MSG and BC_MSG_VERSION tables by compressing asynchronous message content before storage. This action decreases the space occupied by the MSG_BYTES field, potentially improving database performance by minimizing the load and volume of data to be processed. However, enabling compression could increase CPU overhead, so it requires careful threshold configuration to balance performance benefits with resource usage .

Not disabling the LM Configuration Wizard on PX3 has significant security implications, as this application does not require authentication checks. This vulnerability allows attackers to perform unauthorized configuration tasks, including creating administrative users, which could compromise the SAP Java system's confidentiality, integrity, and availability .

The high number of entries in the XI_IDOC_IN_MSG and XI_IDOC_OUT_MSG tables can lead to performance issues in the PO database. Without regular housekeeping jobs, such as IdocDBTableCleanupPeriodicAdvanced, these entries accumulate, negatively affecting database speed and efficiency. This results in slower processing times and could impair other system functionalities due to increased database load .

Modifying the 'messaging.duplicateCheck.persistTime' property can improve the PX3 system's performance by decreasing the number of entries in the BC_MSG_DUP_CHECK table earlier than the default 30 days. This reduces database size and load, potentially enhancing database operations and system performance .

Not enabling large message handling can lead to increased memory usage and potential out-of-memory errors, especially when processing concurrent or unusually large messages. By setting thresholds and permits for large message processing, the system can manage resources better, improving reliability and performance during high-load periods .

You might also like