Symantec Privileged Access Management

 View Only
  • 1.  About session records

    Posted Jul 12, 2024 02:48 AM
    Hi Team,
    [Product]
    Symantec Privileged Access Manager
    [Question]
    I have a question about session records.
     
    I have a question about session records.
     
    We are using PAM on AWS to record sessions.
    The session records are stored in S3.
     
    A failure occurred, and we recovered using a backup from a few days ago.
    At this time, the session records from the backup to the restoration were not registered in the backed up environment.
     
    However, is it correct to assume that they will be recovered using the "Restored Recordings" function (that is, you will be able to view the session records from the failure to recovery)?
    Thanks,


  • 2.  RE: About session records

    Broadcom Employee
    Posted Jul 12, 2024 04:22 PM

    Hello, I assume you are referring to restoring a backup of the PAM server. PAM runs hourly and daily jobs to reconcile files found on the recording share with database entries, and will add entries back into the database if needed. One hourly job is discussed on page Configure and Manage Session Recording, near the bottom under header Archive and Restore Session Recordings. Another hourly job looks for recordings from the past three days. The daily job processes all other directories on the session recording share. Look for PAM-SRR-0004 and PAM-CMN-1989 messages in the session logs under Sessions > Logs.




  • 3.  RE: About session records

    Posted Jul 16, 2024 06:14 AM
    Thank you for your answer.
     
    When did you know that this specification (Session recording Reconciliation) was implemented?
    The manual (v4.0.4) mentioned "Improved Session Recording Reconciliation."
    What were the specifications before that?
     
    Thanks,



  • 4.  RE: About session records

    Broadcom Employee
    Posted Jul 16, 2024 08:00 PM

    Prior to 4.0.4 session recording reconciliation was a single CRON job running once per hour (17 minutes past the hour). Keep in mind that we used to write all recordings into one directory, the session recording mount point. We did not have subdirectories per day, or the recoverPAM subdirectory that is mentioned in section Network Mount Point Subdirectories on the Configure and Manage Session Recording page.




  • 5.  RE: About session records

    Posted Jul 17, 2024 02:17 AM
    Thank you for your answer.
     
    When this function is enabled and there is a session record in the specified target directory that is not registered in the database, is it correct to understand that it will be re-registered in the database once an hour?
     
    > Most Recent Recordings: Reconciles recent session recordings. Runs hourly.




  • 6.  RE: About session records

    Broadcom Employee
    Posted Jul 17, 2024 03:06 PM

    Yes, if it is a recent recording, i.e. in one of the directories for the last three days, or if it was copied to the recoverPAM directory that the above documentation page discusses.




  • 7.  RE: About session records

    Posted Jul 18, 2024 06:17 AM
    I have an additional question.
     
    Regarding this session recording, even in version 4.0.4, can I assume that the history of this session recording will be backed up if I use a scheduled backup?



  • 8.  RE: About session records

    Broadcom Employee
    Posted Jul 18, 2024 11:16 AM

    There is no scheduled backup for session recordings, so I assume you are referring to scheduled database backups. Database backups will include the full list of session recording entries that were in the PAM database at the time of the backup.