Symantec Privileged Access Management

 View Only
  • 1.  PAM session recording back up and restore

    Posted Mar 26, 2023 07:44 PM

    Hi all,

    I have reviewed these KBs and I have a few questions about session recording back up and restore steps.
    https://knowledge.broadcom.com/external/article/113299/how-to-backuprestore-the-session-recordi.html
    https://knowledge.broadcom.com/external/article/121216/backing-up-and-removing-pam-session-reco.html

    1. Is it necessary to unmount the network share before moving the session recording files?

    2. Is it safe to move the session recording files while the network storage is mounted?

    3. While restoring, I only copied .gsr.inf file back to the network share. While trying to view the session recording, I get the the unable to locate recording data error. Will I be able to view the session recording immediately after restoring .gsr? Or do I need to wait for reconcile-session-recordings.pl to run?

    Thanks.

    Regards,
    Ain



  • 2.  RE: PAM session recording back up and restore

    Broadcom Employee
    Posted Mar 27, 2023 10:13 AM

    Hello, You do not need to unmount the network share. PAM doesn't care about those files unless you want to view them. Just removing files implies that you are using option 2 discussed in KB 121216. In that case the records for the session recording will stay in the PAM database, and what you need to restore is the actual recording data, which is in the .gsr file, not the .inf file. Restoring just the .inf file is of no use. The KB asks you to restore both files together for consistency.

    The reconciliation does not come into play in option 2, because the PAM database records never got removed and don't need to be restored.




  • 3.  RE: PAM session recording back up and restore

    Posted Mar 30, 2023 11:01 PM
    Hi Ralf,
    Thanks for responding. That answered my questions.
    I do have a few more questions about session recording files.
     
    What are these files for?
    xxxxx_RDP
    xxxxx_RDP_CS
    xxxxx.txt
    xxxxx.txt.inf
    xxxxx_Event
     
    in case there are files older than number of days configured in the purge policy, do I need to delete all files associated the same session recording reference. 
    For example: 
    PAM1a-000001234.RDP
    PAM1a-000001234.RDP_CS
    PAM1a-000001234_Event
    PAM1a-000001234.gsr
    PAM1a-000001234.gsr.inf
     
    Thanks again.
     
    Regards,
    Ain



  • 4.  RE: PAM session recording back up and restore

    Broadcom Employee
    Posted Mar 31, 2023 07:34 PM

    Hello Ain, _RDP and RDP_CS are discussed in KB 241395. .txt and .txt.inf files are for text-based recordings. The .txt file would be the actual recording file and the .inf file holds metadata. An _Event file could hold data for events that occurred during the recordings. I can't think of any scenario where it would make sense to delete one file associated with a specific session recording that you are ready to delete, but not another associated with the same session recording. So yes, you should always delete them together.