Most teams cover a dozen SIDs with four people and a SAPGUI window per system. Farrenio puts SM50, SM37, ST22, ST04 and the rest in one browser tab, and flags the disk filling before users feel it.
One production system or forty across a dozen customers. The operating model is the same and only the tenancy changes.
Run SM50, SM37, ST22 and RFC checks from one console, with no Windows GUI.
See SAP operationsRead-only alert monitoring with escalation tracking and audit-grade history.
Inspect alertsMulti-tenant by design. Per-customer RBAC and isolated audit trails.
Multi-tenant modelMFA-gated reveal, 96-permission RBAC, tiered audit retention, SOC2-aligned.
Review the security modelTwelve Basis transactions, mapped to where they live in the stack, from the ABAP dispatcher down to the HANA indexserver and the OS. One web console, cross-system search, every action on the audit trail.
The ABAP dispatcher, its work processes, sessions and the enqueue lock table.
DIA/BTC/UPD/ENQ/SPO state per instance, catching PRIV mode and runaways before the queue backs up
One work-process table across the whole cluster, not one instance at a time
Active users and orphaned sessions per application server
Lock-table entries and orphaned locks, drillable by user or object
Batch, runtime errors, the system log and where response time actually goes.
Released / active / cancelled jobs cross-system, with job logs and long-runner trends
Runtime errors with short text, frequency and trend analytics
Dialog response-time breakdown by task type, top transactions and top users
Filtered syslog tail across every SID at once
The HANA / anyDB layer, the operating system, and the RFC links between systems.
HANA & anyDB health, cache ratios and expensive statements
Tablespace and HANA volume pressure with fill forecasting
Connection and authorization probes on your RFC / gateway links
CPU, memory, disk, inode and sapcontrol, read via the agent
The question every Basis lead asks first, answered plainly: one Python daemon runs on the host, reads what it is allowed to read, and pushes outbound over HTTPS. There is no inbound listener and nothing to open on your perimeter.
One Python daemon per SID, under its own unprivileged service account rather than <sid>adm. Each collector is isolated, so one failing source never takes the others down with it.
The agent polls for its config and pushes metrics on 443. No firewall change, no NAT rule, no exposed port on a production SAP box.
RFC and HANA credentials are encrypted under a key issued per agent, never returned in plaintext on a read, and unlocked only behind a PIN or a fresh TOTP code, with every reveal on the audit trail.
Scroll the four steps a landscape goes through with Farrenio. The panel keeps pace.


A three-step wizard hands you an install script and a scoped token. The agent dials out and starts streaming while you watch. No firewall change, no inbound port.

SM50, SM37, ST22, DB02 and SM21 indexed across every SID. "Which system has the long-running job?" is one search with the answer attached, rather than twelve SAPGUI logons.

Per-metric, per-customer thresholds. Escalation ladders by severity and fans out to Slack, Teams, PagerDuty and email. Any alert can be promoted to an incident workflow.

Ninety-two permissions across eight roles, PIN- or MFA-gated token reveal, auto-block on credential-stuffing, and an audit trail carrying operator, IP and outcome behind every action.
Monitoring, automation, the HANA database and the move to S/4HANA on AWS. Each has a page of its own.
Roll out collectors, watch the landscape, control who can touch what, and route what breaks to whoever is on call.

Onboarding a system is usually a ticket, a firewall request and a week of waiting. Here it is a wizard that hands you an install script and a scoped token, then the agent dials out and starts streaming while you watch.
Based on benchmark workflows from teams running 6–25 SAP systems. Your mileage will vary, so we ship live dashboards you can measure it with yourself.
Cross-system SM50 / SM37 / ST22 queries take seconds instead of opening one GUI window per SID.
A single Python daemon, no firewall changes, no inbound ports. Heartbeat shows up immediately.
Tiered audit retention: 365 days for auth and role events, 180 for the rest. Every login, every config change, every sapcontrol command.
Permissions, audit, and brute-force protection aren't bolted on. They are the spine of every endpoint and every UI surface.
Farrenio acts as an AWS Reseller and Cloud Services provider, supporting customers throughout their cloud adoption, optimization and operational journey. We help organizations leverage Amazon Web Services for:
Kernel patching, HANA signals, S/4HANA on AWS. Deep-dives written from the Basis work itself rather than by the marketing team.
AI & AutomationWhy the SAP operating model has to change now that landscapes are hybrid and ECC and S/4HANA run side by side, and what a SaaS control layer does about it: one console across the estate, alerts that route, guided runbooks, and an AI layer grounded on the platform’s own checks.
SAP BasisA walk through the platform: what it watches across ABAP, HANA, the instance and the host layer, how the collector connects outbound-only over HTTPS, the path from alert to SLA evidence, the automation it runs, the 96-permission access model, and what it does not do.
SAP on AWSDesigning SAP HA across two AWS Availability Zones: HANA System Replication modes and operation modes, a Pacemaker cluster with the SAPHana agents and AWS fencing, overlay IPs and Route 53, and ENSA2 for the ASCS, plus why an untested cluster is not HA.

Thirty minutes to scope it, about an hour to get your first production SID streaming. No commitment past that.