Live Session
Scenarios
When an O&M engineer accesses a managed resource through a bastion host, the system automatically generates a live session record. Auditors can use the live session monitoring function to comprehensively audit ongoing O&M operations and identify risks in a timely manner. When detecting a violation or high-risk operation, the auditor can immediately terminate the session to effectively block potential risks and prevent data leakage or service interruption caused by unauthorized operations.
Notes and Constraints
Live sessions cannot be monitored or terminated for O&M through RDP clients.
Prerequisites
- The role you belong to has the management permission for the Live Session module. For details about how to check the permissions of each role, see Role.
- There is at least one ongoing HTML5 or SSH client O&M session.
Monitoring Live Sessions
You can monitor live sessions to audit real-time operations of O&M engineers.
- Log in to your bastion host system.
- In the navigation pane on the left, choose to go to the live session list page. Figure 1 Live Session
- Click Monitor in the Operation column of the live session you want to monitor. The O&M session window is visible to you.
- In the displayed session window, view real-time operations, historical O&M operations, file transmission records, and session participant records. Figure 2 Monitoring live sessions
Interrupting a Live Session
During live session monitoring, if a violation or high-risk operation is detected, the auditor can immediately terminate the session and forcibly disconnect it.
- Log in to your bastion host system.
- In the navigation pane on the left, choose to go to the live session list page. Figure 3 Live Session
- Click Interrupt in the Operation column of the target live session.
- In the displayed confirmation dialog box, click OK to forcibly disconnect the session.
- Upon session interruption, the session window disconnects immediately, and O&M personnel are notified that the session has been interrupted. Figure 4 O&M session disconnected
Searching for and Viewing Live Session Records
- Log in to your bastion host system.
- In the navigation pane on the left, choose to go to the live session list page. Figure 5 Live Session
- Configure search criteria to filter live sessions. Figure 6 Configuring search criteria for live sessions
- Basic search
Select a search attribute from the drop-down list on the left, such as the resource name, resource account, user, or source IP address. Enter a keyword in the search box and click
or press Enter. - Advanced search
Click Advanced to expand all advanced search attributes. Enter keywords in the search boxes of the corresponding attributes and click Search.
- Basic search
- View live session details.
Click Detail in the Operation column of the live session you want to view.
- On the details page, you can view resource session information, system session information, operation records, file transmission records, and collaborative session records.
- In the upper right corner of the session details page, you can click Monitor or Interrupt to monitor or interrupt the current live session.
Figure 7 Live session details
Feedback
Was this page helpful?
Provide feedbackThank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot