Session Audit Reference
Explore session metadata and raw audit records generated by Session Audit
Last updated
Was this helpful?
Explore session metadata and raw audit records generated by Session Audit
Session Audit captures and stores data on audited SSH and Kubernetes sessions. You can use this data for security investigations, compliance evidence, and operational auditing.
Session Audit generates two types of data.
Session metadata
Information about the session, including the user, resource, protocol, timestamps, permissions, and status.
Apono
Raw session data
Detailed activity captured during the session. The available data depends on the protocol being audited.
Customer-managed Amazon S3 bucket
Session Audit captures different data depending on the protocol.
SSH
SSH
AWS EC2 SSH
Commands
Command output
Session lifecycle events
Permission elevation events
Session context information
Kubernetes
Kubernetes
Kubernetes API calls
Request bodies for supported operations
Permission elevation events
(Coming soon) Port-forward metadata
(Coming soon) Kubectl session
Learn more about the data captured for each protocol:
Last updated
Was this helpful?
Was this helpful?
