Issue / Problem Statement
If your organization has implemented SAP GRC (governance, risk, and compliance) and the IT Support team is using Fire Fighter users to troubleshoot production issues, then many times in the change log you see a user ID associated with Fire Fighter User and you want to know that who is the actual sap system logon user (functional/developer/basis/security) who actioned the item.
Solution
You can use transaction code GRAC_FFSESSION to identify the sap system logon users with Fire Figher ID for the given period.
There are different filtering criteria for this transaction, you can input as per need and click on LIST, to generate the list.
Or you can use the table GRACFFUSER / GRACFFLOG to get the information. The FFOBJECT column is used to enter the Fire Fighter ID and FF_USER is the SAP System Logon User.