> For the complete documentation index, see [llms.txt](https://docs.itconductor.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.itconductor.com/user-guide/automation/sap-kernel-update-windows.md).

# SAP Kernel Update on Windows using ChAI

Keeping the SAP kernel up to date on Windows is essential for maintaining system stability, security, and performance. Each kernel patch release includes bug fixes, security vulnerabilities remediation, and compatibility improvements that ensure the SAP system operates reliably with the underlying operating system and database. Running an outdated kernel can expose the system to known vulnerabilities and increase the risk of unexpected downtime or data integrity issues.

IT-Conductor ChAI streamlines this process as part of its Autonomous Operations platform and focuses on Security Remediation, by integrating orchestration and monitoring capabilities to automate and optimize SAP kernel updates on Windows environments. It relieves SAP administrators from performing time-consuming tasks, such as establishing connections to the SAP server for patch deployment and manually stopping and restarting SAP services and instances.

By reducing manual effort, IT-Conductor enables IT teams to schedule, deploy, and verify kernel updates with minimal manual intervention — automating key tasks such as backing up the existing kernel directory, extracting new kernel archives, and validating system status before and after the update.

### How to Update SAP Kernel using IT-Conductor ChAI <a href="#how-to-update-sap-kernel-using-it-conductor-chai" id="how-to-update-sap-kernel-using-it-conductor-chai"></a>

Now that the central kernel directory has been backed up, proceed to follow the steps below in IT-Conductor. The automation will handle stopping the SAP system, replacing the kernel files, and restarting the system as part of the process.

To start the automation, proceed to follow these steps in IT-Conductor:

1. Visit [service.itconductor.com](https://service.itconductor.com/) and enter your login credentials.
2. On the IT-Conductor main menu, navigate to **Support → Service Catalog**

<figure><img src="/files/qabRimZQz6VBKQgPtWfR" alt=""><figcaption><p>Figure 1: Main Menu - Service Catalog</p></figcaption></figure>

3. On the service catalog, click on **Application support → BASIS Support → Patch SAP Kernel on Windows**

<figure><img src="/files/xqs8EkoQFSucfWKTDfaB" alt=""><figcaption><p>Figure 2: Service Catalog - Patch SAP Kernel on Windows</p></figcaption></figure>

4. Click on the **Checkout Service Request** <img src="/files/M7GQI7r4U4jNr3U3SJbW" alt="" data-size="line"> icon

<figure><img src="/files/W20JTf4eF6OH3zAnuQvD" alt=""><figcaption><p>Figure 3a: Patch SAP Kernel on Windows Wizard</p></figcaption></figure>

5. Fill in the following fields
   1. **SAP Host Agent** - SAP program installed on the host server
   2. **Execution System** - The target SAP system on which the kernel update will be performed.
   3. **Instances** - A group of all SAP app server processes running in the host
   4. **Message Server** - The message server running on the host
   5. **SAPCAR Path** - The directory where the SAPCAR is located, used to extract kernel archive files (.SAR).
   6. **Backup Path** - The directory where the backup archive of the current kernel is saved
   7. **Run Directory** - The active kernel directory on the target server, defined by the SAP profile parameter `DIR_CT_RUN`.
   8. **SAP EXE Path** - The path to the SAPEXE archive (.SAR)
   9. **SAP DB Exe Path** - The path to the SAPEXEDB archive (.SAR)
   10. **STRDBS Path** - The path to the STRDBS archive (.SAR)

<figure><img src="/files/VeDQip9X2c0Nxe8KZwCx" alt=""><figcaption><p>Figure 3b: Patch SAP Kernel on Windows Wizard - Input Parameters</p></figcaption></figure>

6. Click on <img src="/files/oqn8RL2g7n684ORCwtgx" alt="" data-size="line"> to save and continue.
7. On the following screen, you’ll see the processes starting up. To view the status of the process definition and workflow in real time, click the process definition name, then click **Process Viewer.**

<figure><img src="/files/CWa5eFNIEtMwcO5yBSdN" alt=""><figcaption><p>Figure 3c: Patch SAP Kernel on Windows Wizard - Process Log</p></figcaption></figure>

8. This automation workflow is composed of the following steps, executed sequentially as part of the process definition:
   1. Stop SAP on Windows
   2. Back Up the Central Kernel Directory (It is strongly recommended to back up the central kernel directory before making any changes, so the system can be restored to its previous state if the update fails. The new kernel files must be extracted into the correct directory on the target Windows server.)
   3. Remove Kernel Directory Structure
   4. Extract SAP EXE
   5. Extract SAP DB EXE
   6. Copy STRDBS
   7. Start SAP on Windows
9. Upon starting, the workflow will look like the picture below, with the process definitions in their initial state (light blue). Click the refresh button <img src="/files/EZ934Omu6ucyjFwolF1V" alt="" data-size="line"> to see its progress.

<figure><img src="/files/sTg7T39EaIHyIgFmVyJN" alt=""><figcaption><p>Figure 4: Patch SAP Kernel on Windows - Starting Process Definitions</p></figcaption></figure>

10. If any of the process definitions turn red, check the icon next to it and review the log <img src="/files/3SXlNMwWxiHcqzkNv3p7" alt="" data-size="line"> to troubleshoot.

<figure><img src="/files/n7W7AnnDOMldgueFUGxF" alt=""><figcaption><p>Figure 5: Troubleshooting Log</p></figcaption></figure>

11. Wait until all the process definitions have turned green. This process should take between 5 and 10 minutes.

<figure><img src="/files/CNyJywlEZXJ0QvSuodak" alt=""><figcaption><p>Figure 6: Patch SAP Kernel on Windows - Process Definition in Progress</p></figcaption></figure>

12. Once the process definitions turn green, click the icon next to any box to view the log ![](/files/3SXlNMwWxiHcqzkNv3p7) or execution log ![](/files/8P0PVQddBEO9LwWgMCwG) for each activity.

<figure><img src="/files/H8YgD82zHBdjBwgRi1RQ" alt=""><figcaption><p>Figure 7: Patch SAP Kernel on Windows - Finished Process Definition</p></figcaption></figure>

<figure><img src="/files/qntrgsA1evzbBKly2kO6" alt=""><figcaption><p>Figure 8: Finished Process Definition - Execution Log</p></figcaption></figure>

13. Check that the kernel version has been updated. Navigate to the service grid of the SAP system where you’re going to update the kernel and click on the **View Service Info** <img src="/files/SuIncSHgvy7tcw7wCCtj" alt="" data-size="line"> icon to see the current kernel number.

<figure><img src="/files/Gof8SFuYu2TyQLjK9ZXL" alt=""><figcaption><p>Figure 9: Windows SAP System Information in IT-Conductor</p></figcaption></figure>

Alternatively, you can also check this on your SAP system.

<figure><img src="/files/Iquw7lokXjOfalNY5qGE" alt=""><figcaption><p>Figure 10: SAP System - Kernel Information</p></figcaption></figure>

### Important Recommendations <a href="#important-recommendations" id="important-recommendations"></a>

* **Stop the System**: Before restoring kernel files, ensure that the SAP services and the SAP instance are stopped; otherwise, the files will be locked by active processes.
* **Verify Permissions**: Make sure the user running the command has full write permissions for the `D:\usr\sap\...` directory.
* **View Content**: If you want to see what is inside the archive without extracting it, use the `-tf` flag:`SAPCAR -tf C:\Install\UPG\Backup_Kernel_CR_.SAR`

### Related information <a href="#related-information" id="related-information"></a>

* [SAP Kernel Update on Linux using ChAI](https://docs.itconductor.com/user-guide/automation/sap-kernel-update#how-to-update-sap-kernel-using-it-conductor-chai)


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.itconductor.com/user-guide/automation/sap-kernel-update-windows.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
