SAP-grade Linux assessment,
before it becomes an incident.
OctoPus audits every SAP-certified Linux distribution at the OS level — surfacing configuration drift, security exposure, performance risk, and compliance gaps across your entire SAP landscape before they touch production.
- 5
- SAP-certified Linux distros covered
- 100k+
- Servers assessable per platform
- <500ms
- p95 API response time
$ sp-agent scan --target hana-prod-01OS: SLES for SAP Applications 15 SP5Checking kernel parameters ................. 42/42 passChecking HANA filesystem layout .............. 2 warningsChecking Pacemaker cluster config ............. 1 findingChecking CVE exposure (OSV.dev feed) ......... 3 findingsRisk score: 68 / 100 — Medium$ report ready → dashboard.octopus.io/hana-prod-01
Assesses every SAP-certified Linux distribution
- RHEL for SAP Solutions
- SUSE Linux Enterprise Server for SAP Applications
- Oracle Linux
- SUSE Linux Enterprise Server for SAP HANA
- Amazon Linux (SAP-certified)
Everything an OS-level assessment for SAP needs to cover
Purpose-built checks for SAP-supported Linux — not a generic server scanner retrofitted with SAP keywords.
Multi-distro OS assessment
One consistent assessment engine across RHEL for SAP, SLES for SAP Applications, SLES for SAP HANA, and Oracle Linux — no per-distro tooling to maintain.
HANA & application readiness
Filesystem layout, kernel parameters, memory/swap configuration, and storage checks validated against SAP HANA and NetWeaver requirements.
Security & CVE tracking
Continuous vulnerability tracking against the OSV.dev feed with CIS benchmark scoring, mapped to the exact packages running on each host.
HA cluster validation
Pacemaker, Keepalived, and HANA System Replication configurations checked for split-brain risk, fencing gaps, and failover readiness.
Performance & kernel tuning
Flags kernel and I/O scheduler settings, huge pages, and NUMA configuration that commonly cause SAP workload performance degradation.
Audit-ready compliance reporting
Immutable audit trail, scheduled assessments, and exportable PDF/CSV reports built for SOC 2 and internal change-control processes.
From SSH connection to risk-scored report
No agents baked into golden images, no manual checklists spread across spreadsheets.
- 01
Deploy the agent
A lightweight Go agent connects over SSH — no inbound ports, no persistent access, nothing installed on the SAP system itself.
- 02
Automated OS-level scan
The agent collects kernel, filesystem, cluster, package, and configuration data and streams it to your OctoPus tenant for analysis.
- 03
Risk-scored report
Findings are scored, prioritized, and mapped to SAP-specific requirements — with AI-generated executive summaries for stakeholders.
- 04
Continuous monitoring
Scheduled re-assessments and alert rules catch configuration drift the moment it happens, not during the next audit cycle.
One risk score per host, rolled up across the landscape
Every assessment produces a 0–100 risk score with full traceability back to the underlying finding — no black-box grading, no ambiguous severity labels.
- Drill from landscape view down to a single kernel parameter or CVE.
- Export PDF/CSV reports for change-control and audit evidence.
- Alert on score regressions via email, Slack, Teams, or PagerDuty.
hana-prod-01
SLES for SAP HANA 15 SP5
app-prod-02
RHEL for SAP Solutions 9.3
ascs-prod-01
SLES for SAP Applications 15 SP5
ers-prod-01
Oracle Linux 8.9
See your SAP landscape's risk profile
Run an assessment against a sandbox environment or bring your own hosts — deployable as SaaS or fully self-hosted inside your network.