For the complete documentation index, see llms.txt. This page is also available as Markdown.

Session Audit Reference

Explore session metadata and raw audit records generated by Session Audit

Session Audit captures and stores data on audited SSH and Kubernetes sessions. You can use this data for security investigations, compliance evidence, and operational auditing.

Session Audit generates two types of data.

Data type
Description
Storage location

Session metadata

Information about the session, including the user, resource, protocol, timestamps, permissions, and status.

Apono

Raw session data

Detailed activity captured during the session. The available data depends on the protocol being audited.

Customer-managed Amazon S3 bucket


Available protocol data

Session Audit captures different data depending on the protocol.

Protocol
Supported integrations
Captured data

SSH

  • SSH

  • AWS EC2 SSH

  • Commands

  • Command output

  • Session lifecycle events

  • Permission elevation events

  • Session context information

Kubernetes

  • Kubernetes

  • Kubernetes API calls

  • Request bodies for supported operations

  • Permission elevation events

  • (Coming soon) Port-forward metadata

  • (Coming soon) Kubectl session


Protocol references

Learn more about the data captured for each protocol:

Last updated

Was this helpful?