Skip to content

Device access report

This reporting page looks at device access and user sessions. The topics covered in this section are:

Introduction

The Device access report provides an audit of users that have logged into the PAM Server at any point and the device connections that have been made.

Device access report

The Device access report also allows you to view filtered screenshots from UI user sessions and monitor or terminate any active connections.

Note

To view filtered screenshots and monitor connections, session recordings must be enabled for, and agreed to by, the user.

For more information, see Privileged Session Management.

To view the Device access report:

  • In the Admin Interface, click Device access. The Device access report will appear.
  • In the top area of the Device access report, use the checkboxes to select one or more of the following categories to be displayed on the report:

    • PAM sessions
    • Device connections
    • Screenshots

Note

By default, only Device connections is selected.

Terminate active sessions

To terminate active sessions:

  1. In the top area of the Device access report, select PAM sessions or Device connections.

  2. Within the table, select one or more active sessions.

    Note

    Active sessions are indicated ACTIVE in the End time column and marked Checked box icon in the Active? column.

  3. Click the TERMINATE button. The Question window will appear.

  4. If you want to prevent the selected user(s) from logging back onto the UI after termination, select Also disable the user [name].

  5. Click YES.

  6. The selected user(s) will be logged out.

Device connections report

The Device connections report provides visibility of all device connections made through Osirium PAM.

On the Device access report page, click the Device connections checkbox to view this report.

The following information is presented in the Device connections report:

Heading Description
ID Shows the unique channel ID relating to the connection made by the user.
Session ID Shows the unique UI connection ID made by the user.
Start time The date and time a device tool session was first accessed by the named user.
End time The date and time a device tool session was closed by the named user, or indicates if the session is still ACTIVE.
Play icon A play icon in this column indicates that the session has been recorded.
Archive icon An archive screenshot icon in this column indicates that the session has been archived and, therefore, cannot be played. Retrieve the file from the Manage Files page to view.
Shadow icon A shadow icon in this column indicates that the session is still active and can be viewed in real time.
Duration Total time the device session was active.
Active duration Total time the session that is currently live has been active.
Device The name of the device that was accessed by a user.
User IP address The IP address of the connected user’s computer.
User Display name of user who initiated the connection.
Username Hidden by default
Username of user who initiated the connection.
Account source Refers to the authentication service that the account is linked to i.e. this could be the PAM Server for local accounts, Active Directory for external accounts and Static Vault for stored credentials.
Access level Device access level (role, account, mapping, always ask or pass-through) used to single sign-on users onto the device. See Configuring a Profile.
Tool Connection method used to access the device.
Active? Indicates the current status of the session.

Checked box icon is active and means the device tool is still being accessed by a user.

Unchecked box icon is inactive and means the device tool has been closed and the user no longer has a single sign-on connection to the device using that protocol.

Recorded? Relates to Privileged Session Management and if ticked, indicates that device session was recorded.

Whether or not a device session for a user is recorded is determined through a Profile and Record session on this profile task.

See Privileged Session Management.

Change tickets Lists the change tickets the device connection was performed under.
Approver Name of the person who approved the access requested by the user to connect to the device.
MAP Server If the device was accessed through a MAP Server, a MAP Server name will be listed.
MAP Account Shows the local account of the MAP Server used to make the connection.

PAM sessions

Selecting the PAM sessions lists all the user connections made to Osirium PAM and the number of devices accessed during the session.

Client sessions report

The following information is presented in the report:

Heading Description
Session ID The unique UI connection ID.
Start time The date and time the user logged onto the UI.
End time The date and time the user logged off the UI. ACTIVE indicates that the user is still logged on.
Duration The total time the user was logged into the UI.
User Display name of the user who initiated the connection.
Username Hidden by default
Username of user who initiated the connection.
# Device connections The number of device connections the user has made through the UI.
User IP address The IP address of the connected user’s computer.
Active? A selected check box indicates that the user is still logged onto the UI.
Archived? A selected check box indicates that the recorded screenshots have been archived to a ZIP file which can then be downloaded through the Manage files page.

NOTE For more information, see Managing Files.

Archive screenshots

Sessions can be archived on an individual basis. This allows you more flexibility in how you can manage your archiving and group files as required before archiving.

To archive session screenshots:

  1. In the Device access report page, select PAM sessions.

  2. On the PAM sessions table, click one or more sessions.

    Note

    Only inactive sessions can be archived.

  3. Click ARCHIVE SCREENSHOTS. The Question window appears.

  4. On the Question window, click YES to confirm that you want to store the screenshots from the user sessions in your files list. The Action queue window appears.

  5. On the Action queue window, click DONE. The archived screenshots will be located in the Manage files page.

Export videos

Device connections that have an associated recording can be exported to video file. Video files are created as mp4 files and are available to download via the Manage files page once successfully created.

To export a recording to a video file:

  1. Select a single or multiple entries from the Device connections list that have a Play icon or filter using the Recorded? column.

    Recordings selection

  2. Click the Archive EXPORT VIDEO.

  3. Within the Question window, click YES to continue with the export.

  4. Within the Action queue window you will see the progress of the exporting tasks that have been executed. Click DONE when completed.

  5. To download the exported video files, navigate the Manage files page, you will see the exported video files listed. Each device connection video selected is exported individually.

  6. Click Download at the end of the row to download the mp4 file.

    If the PAM Server Browser (HTTP) tool is being session recorded, then you will need to use the Shared Drive mechanism for downloading files. For further details see Downloading a file using Shared Drive.

Fuzzy filter

The fuzzy filter enables you to search keywords inside recorded connections to find specific changes/updates that have been made on a device.

The search term is matched against:

  • The keystrokes of a connection.
  • The titles of a recorded connection window, i.e. SSH window or web browser, etc.

Note

The window refers to the local tool opened to access the device.

Screenshots

The Screenshots section shows the session recorded screenshots, starting with the most recent. If screenshots have been archived, they will no longer be shown here. Archived screenshots can be downloaded from the Manage files page.

From the Device access report, select Screenshots.

Screenshots can be grouped by:

  • Session: shows all the screenshots relating to connection made to the UI only and the devices accessed during the logon.
  • Device connection: shows all the screenshots relating to protocol connection types that have been made from Osirium PAM.
  • None: shows all screenshots recorded.

Live monitor

The Live monitor button allows you to shadow an active connection.

Note

Only device connections that are within profiles with Session Recording enabled can be shadowed.
For more information, see Privileged Session Management.

Playing a session recording

Saved session recordings can be viewed using the session player.

To play a session:

  1. Click the Play icon Show recoding icon on a device connection with an available recording.

  2. A Session player window will open.

    Session Player|

    The below functions are available within the Session player window:

    Section Button heading Description
    Transport Start icon First Takes you back to the start of the recording.
    Previous icon Previous Takes you back to the previous frame played.
    Play icon Play Plays the session recording from the start.
    Next icon Next Takes you to the next frame
    Last icon Last Takes you to the end of the recording.
    Playback speed Playback speed from the moment the frame is loaded but will depend on the overall system speed.
    - Normal: 1 second
    - Fast: 0.5 second
    - Fastest: 450 milliseconds
    Zoom Actual Shows the actual size of the window when recorded.
    Fit Resizes the recording window to fit the Session Viewer screen so you can see the whole recorded window.
    Timeline bar Indicates the time as the recording is played and allows you to scroll quickly to a specific time.

Within the Live monitor window, you can also:

  • Shadow: to start or stop shadowing an active session.

  • Hold inactive: allows you to keep disconnected sessions visible for 60 seconds after they become inactive.

  • Group by: allows you to filter the active sessions by UI sessions or Device connections.

  • Zoom bar: allows you increase or decrease the size of the active session windows listed.