Active sessions
The Active Sessions tab in Monitoring provides a way to oversee activities of launched secrets from FortiPAM. The page lists out all the launched secrets with information such as source IP: Port, destination IP: Port, the application that is launched and username, etc.
Additionally, a Disconnect button is available when you select a secret session. Using the Disconnect button, you can terminate the selected launched secret session. This monitor is especially powerful in situations where there is malicious activity being conducted by a user because the administrator will be able to terminate the session right away with the Disconnect button to protect the integrity of the secret.
Disconnecting native non-proxy sessions is currently not supported. |
On the top, the following widget is displayed:
-
Username: displays the total count of the users using secrets.
For every session, the following columns are displayed by default:
-
Session ID
-
Username
-
Account Name
-
Token ID
-
Source
-
Source Port
-
Source Location
-
Destination: The actual target server IP address.
-
Destination Port
-
Gateway: The gateway IP address.
-
Gateway Port
-
Gateway Name: The gateway name.
-
Application
-
Duration (sec)
The Active Sessions tab contains the following options:
Group by |
Select to group the active sessions by either username or secret. |
Refresh |
To refresh the contents, click the refresh icon. |
Search |
Enter a search term in the search field, then hit |
For an active secret session, you can terminate the session by clicking Disconnect the current secret session as you live stream the session.
|
For information on over-the-shoulder monitoring, see Over-the-shoulder monitoring (Live recording).