Updated on 2026-07-30 GMT+08:00

Live Session

Scenarios

When an O&M engineer accesses a managed resource through a bastion host, the system automatically generates a live session record. Auditors can use the live session monitoring function to comprehensively audit ongoing O&M operations and identify risks in a timely manner. When detecting a violation or high-risk operation, the auditor can immediately terminate the session to effectively block potential risks and prevent data leakage or service interruption caused by unauthorized operations.

Notes and Constraints

Live sessions cannot be monitored or terminated for O&M through RDP clients.

Prerequisites

  • The role you belong to has the management permission for the Live Session module. For details about how to check the permissions of each role, see Role.
  • There is at least one ongoing HTML5 or SSH client O&M session.

Monitoring Live Sessions

You can monitor live sessions to audit real-time operations of O&M engineers.

  1. Log in to your bastion host system.
  2. In the navigation pane on the left, choose Audit > Live Session to go to the live session list page.

    Figure 1 Live Session

  3. Click Monitor in the Operation column of the live session you want to monitor. The O&M session window is visible to you.
  4. In the displayed session window, view real-time operations, historical O&M operations, file transmission records, and session participant records.

    Figure 2 Monitoring live sessions

Interrupting a Live Session

During live session monitoring, if a violation or high-risk operation is detected, the auditor can immediately terminate the session and forcibly disconnect it.

  1. Log in to your bastion host system.
  2. In the navigation pane on the left, choose Audit > Live Session to go to the live session list page.

    Figure 3 Live Session

  3. Click Interrupt in the Operation column of the target live session.
  4. In the displayed confirmation dialog box, click OK to forcibly disconnect the session.
  5. Upon session interruption, the session window disconnects immediately, and O&M personnel are notified that the session has been interrupted.

    Figure 4 O&M session disconnected

Searching for and Viewing Live Session Records

  1. Log in to your bastion host system.
  2. In the navigation pane on the left, choose Audit > Live Session to go to the live session list page.

    Figure 5 Live Session

  3. Configure search criteria to filter live sessions.

    Figure 6 Configuring search criteria for live sessions
    • Basic search

      Select a search attribute from the drop-down list on the left, such as the resource name, resource account, user, or source IP address. Enter a keyword in the search box and click or press Enter.

    • Advanced search

      Click Advanced to expand all advanced search attributes. Enter keywords in the search boxes of the corresponding attributes and click Search.

  4. View live session details.

    Click Detail in the Operation column of the live session you want to view.

    • On the details page, you can view resource session information, system session information, operation records, file transmission records, and collaborative session records.
    • In the upper right corner of the session details page, you can click Monitor or Interrupt to monitor or interrupt the current live session.
    Figure 7 Live session details