---
title: Additional configuration
source: https://docs.newrelic.com/docs/sap-solutions/install-and-configure/additional-configuration
---

Complete these configuration tasks for each monitored system.

## Upload authorization role [#upload-authorization-role]

1.  Use **SAP transaction** `PFCG`.

2.  Go to **Role** > **Upload** and upload the file **\_NEWR_DATA_PROVIDER.SAP** from the installation package.

3.  Confirm that the role `/NEWR/DATA_PROVIDER` loads.

    ![A screenshot displaying the authorization role upload](https://docs.newrelic.com/images/authorisation-role.webp "Authorization Role")

4.  Select the ![change icon in SAP](https://docs.newrelic.com/images/change-icon.webp "Change icon indicator in SAP") icon after the role loads.

5.  On the **Authorizations** tab, select ![change icon in SAP](https://docs.newrelic.com/images/change-icon.webp "Change icon indicator in SAP") **Change Authorization Data**, and then activate it using the ![activate icon in SAP](https://docs.newrelic.com/images/activate-option.webp "Activate Icon in SAP") icon.

    ![A screenshot displaying the authorization tab and Change Authorization Data in SAP upload](https://docs.newrelic.com/images/sap-authorization-1.webp "Authorizations Tab")

6.  If a profile name is suggested, select the green check icon.

7.  Verify that **Profile(s) were updated** appears on the status bar.

> #### ⚠️ IMPORTANT
>
> If you need **SLT module monitoring** on the system, also upload the `/NEWR/SLT_COLLECTOR` role from the `_NEWR_SLT_COLLECTOR.SAP` file in the installation package.

## Create New Relic RFC user ID [#create-rfc-user-id]

After you activate the **authorization profile**, use transaction `SU01` to create a new **RFC user ID** (for example, `NR4SAPDP`). Set the **user type** to **Communication** on the monitored (data provider) systems and **System** on the central monitoring system (CMS). Then add the role `/NEWR/DATA_PROVIDER`.

![A screenshot displaying the creation of a new RFC user in SAP](https://docs.newrelic.com/images/rfc-userid.webp "Create New RFC User")

## Standard RFC destination [#standard-rfc-destination]

Use transaction `SM59` to create an **RFC destination** for each monitored system.

1.  Select **ABAP Connections** and then select the **Create** icon to set up a new **RFC destination**.

2.  Enter a descriptive **RFC Destination** name. We recommend: `NR_<SYSID>CLNT<CLNT#>`

3.  Set **Connection Type** to `3 - ABAP Connection`.

4.  On the **Technical Settings** tab, enter:

    -   **Target Host** (fully qualified domain or IP) and **Instance No.**
    -   **Gateway Host** and **Service** if necessary.

    ![A screenshot displaying the how to create RFC destinations for monitored systems](https://docs.newrelic.com/images/rfc-destination.webp "Create RFC destinations for monitored systems")

    > #### 💡 TIP
    >
    > Use **load balancing** whenever possible. It allows data collection to continue even when a single connection goes down. For detailed steps, see [Setting Up an RFC Destination with Load Balancing](https://help.sap.com/doc/saphelp_nw75/7.5.5/en-US/cd/d9a38c1709414b8bc6a4380c398063/content.htm?no_cache=true) in the SAP documentation.

5.  On the **Logon & Security** tab, enter the **RFC user** (`NR4SAPDP`) and password.

6.  Select **Save**.

7.  Go to **Utility > Test > Connection Test** and **Authorization Test**.
    -   **Expected result**: Both tests show successful status.

## Set HTTP destination to New Relic cloud [#set-http-destination-to-new-relic-cloud]

Use transaction `SM59` to set up **HTTPS connections** to the **New Relic API endpoints**.

> #### ⚠️ IMPORTANT
>
> Create individual **RFC destinations** for **Events**, **Logs**, **Metrics**, and **Traces** separately.

1.  Enter a **Destination Name** (for example, `NR_API_EVENT`).

2.  Set **Connection Type** to `G` (HTTP Connections to External Server).

3.  Enter **Target Host**, **Service No.** as **443** (see [standard port](https://docs.newrelic.com/docs/sap-solutions/reference/network-accessibility) for **HTTPS**), and **Path Prefix** (see [installation readiness checklist](https://docs.newrelic.com/docs/sap-solutions/reference/pre-installation-checklist/#installation-readiness-checklist) for details).

4.  If you need a proxy, configure it on the **Technical Settings** tab.

5.  On the **Security Options** tab, select the **Active** option for **SSL**.

    ![A screenshot displaying the connection setup for HTTP destination to New Relic](https://docs.newrelic.com/images/http-destination-to-new-relic.webp "HTTP destination to New Relic")

6.  If the SSL certificate isn't configured yet, download the **root and intermediate certificates** from the New Relic endpoint in your browser and import them into **SAP** using transaction `STRUST`.

7.  Select **Connection Test** to verify the connection.
    -   **Expected result**: A successful connection prompts you to enter logon data.
    -   **If test times out**: A firewall is likely blocking the connection. Consult your network team to ensure access is granted to the **New Relic domains**.

8.  At the logon prompt, select **Cancel** to proceed. An **HTTP 4xx** response code screen confirms the connection is working.

9.  Repeat this procedure for all **New Relic API endpoints**.

## Cloud (BTP) RFC destination [#cloud-btp-rfc-destination]

Select the tab for your service:

### **BTP process integration runtime**

1.  Open the downloaded **Service Key** to identify and record the `clientId`, `clientsecret`, and `tokenurl`.

2.  Navigate to the URL specified in your service key using a web browser.

3.  From that page, obtain the **SAP on demand**, **Digicert global**, and **Digicert root** certificates.

    ![A screenshot displaying the connection setup for BTP process integration runtime](https://docs.newrelic.com/images/btp-process-integration.webp "BTP process integration runtime")

4.  Navigate to transaction code `STRUST` and select **SSL Client (Standard)** while in edit mode.

5.  Individually upload the three certificates, select **Add to Certificate List** for each, and then save your changes.

6.  Navigate to Tcode `SMICM`, then select **Administration > ICM > Exit Soft > Global**. Executing this action triggers a restart of all **ICM processes** within the system.

    ![A screenshot displaying the Administration ICM](https://docs.newrelic.com/images/administration-icm.webp "Administration ICM")

7.  Access the SAP system and navigate to transaction code `SM59`, then establish a new **RFC connection** within the **HTTP Connections to External Server** category.

8.  Configure the destination by dividing the token URL into its respective host and path prefix components.

9.  Set the service number to `443` and modify the path prefix by appending `?grant_type=client_credentials`.

    ![A screenshot displaying the Service No.](https://docs.newrelic.com/images/service-no.webp "Service No.")

10. On the **Login & Security** tab, select **Basic Authentication** and enter `clientId` and `clientsecret` as the username and password.

11. Set **Secure Protocol** status to **Active** and save the configuration.

12. Select **Connection Test**.

### **CloudALM API**

1.  Note the `clientId`, `clientsecret`, and `url` from the downloaded **Service Key**.

2.  Go to the **url** in a web browser and download the **Digicert root**, **global**, and **SAP on demand** certificates.

    ![A screenshot displaying the connection setup for CloudALM API](https://docs.newrelic.com/images/cloudalm-api.webp "CloudALM API")

3.  Navigate to transaction code `STRUST` and select **SSL Client (Standard)** while in edit mode.

4.  Individually upload each of the three certificates, then select **Add to Certificate List** and save your changes.

5.  Navigate to Tcode `SMICM`, then select **Administration > ICM > Exit Soft > Global**. Executing this action triggers a restart of all system **ICM processes**.

    ![A screenshot displaying the Administration ICM](https://docs.newrelic.com/images/administration-icm.webp "Administration ICM")

6.  Access transaction code `SM59` after logging into the SAP system, then establish a new **RFC connection** under the **HTTP Connections to External Server** category.

7.  Configure the **Target Host** with the appropriate URL and set the **Service No.** to `443`. Set the **Path Prefix** to `/oauth/token?grant_type=client_credentials`.

    ![A screenshot displaying the SM59 configuration](https://docs.newrelic.com/images/sm59-configuration.webp "SM59 Configuration")

8.  Navigate to the **Login & Security** tab and choose **Basic Authentication** in the **Login with user** section. Provide the `clientId` as the username and the `clientsecret` as the password.

9.  Locate the **Secure Protocol** status below and set it to **Active**.

10. Apply the configuration changes by saving, then select **Connection Test**.

## Create database connection [#create-database-connection]

Use transaction `DBACOCKPIT` to define the remote **HANA Database connections**. In the left pane, double-click **Database Connections**, then select **Add** to create a new connection.

![A screenshot displaying the Database Connection](https://docs.newrelic.com/images/database-connection.webp "Database Connection")

Under **Database Details**, perform the following steps:

1.  Enter the **Connection Name** (we recommend using the **SAP system ID**).

2.  Select **HANA Database** as the designated **Database System**.

3.  Provide a database user ID (`NRAGENT` is the recommended ID), then enter and confirm your password.

4.  Enter the **Database Host** and the **SQL Port**.

    ![A screenshot displaying the SAP Connection Name](https://docs.newrelic.com/images/connection-name.webp "SAP Connection Name")

5.  After saving your entries, select **Test** to verify the connection to the database.
    -   **Expected result**: Connection test shows successful status.
