Skip to main content
Version: v45

Session Recording

PrivX session recording captures activity in target connections for review and auditing. Depending on the connection type, recordings can include video playback, transferred files, clipboard content, channel logs, and protocol streams. Authorized users can review recorded sessions and monitor supported connections in real time.

Before enabling session recording, plan the required CPU, memory, and storage capacity and configure external storage for recordings.

Planning Resources for Session Recording​

caution

Recording browser-based RDP and Web connections in PrivX 45 can require substantially more CPU, memory, and storage than in PrivX 44. The impact depends on connection type, screen activity, recording quality, and concurrent usage. Native RDP recordings are unaffected.

Before upgrading, review CPU, memory, and storage utilization during typical workloads and peak usage. Provision additional resources where needed, and test the recording settings before upgrading your production deployment.

The default PrivX settings are Enable RDPGFX disabled and Session Recording Quality set to Full. Selecting Medium reduces recording-storage requirements but increases CPU and memory consumption. Use it only when sufficient CPU and memory capacity is available.

For measured resource increases and upgrade considerations, see PrivX 45 Release Notes.

Planning Storage Capacity​

RDP session recordings can consume substantial disk space. For storage estimates, see Session Recording and Playback.

While an RDP session is active, PrivX temporarily stores transferred files and the session recording in the PrivX servers' /tmp directory. Ensure sufficient local disk space even when external recording storage is configured.

SSH transcripts require approximately ten times the storage space of the original recording.

Planning Resources for RDPGFX Connections​

RDPGFX is the Remote Desktop Protocol graphics pipeline extension. It supports graphics codecs that can improve screen-refresh performance for RDP Proxy connections, particularly over slower networks. Enabling RDPGFX increases memory consumption and can produce larger recordings when Session Recording Quality is set to Full. With Medium or Low, enabling or disabling RDPGFX is expected to have little effect on recording size.

The Enable RDPGFX setting applies to regular RDP desktop and RDP RemoteApp connections. RDPGFX is disabled for Web connections and cannot be enabled for them.

Before enabling RDPGFX, review the available memory and session-recording storage capacity. Monitor memory consumption and trail-storage growth after enabling the setting.

To enable or disable RDPGFX, in the PrivX Web UI, go to Administration → Settings → RDP Proxy and change Enable RDPGFX. Changing this setting does not require restarting PrivX.

Configuring External Storage​

Session recordings can consume substantial disk space. Store them on an external share, such as NFS or EFS, instead of on PrivX servers.

To configure external storage share for PrivX session recordings:

  1. On the external storage server, create a share for storing PrivX session recordings. The share must be a directory that satisfies the following:

    • All PrivX servers can mount the share.
    • The privx system user on each PrivX server can read from and write to the share.
  2. On each PrivX server, install the packages required to mount the external share. For example, NFS shares typically require nfs-utils, and SMB shares typically require cifs-utils. Install these packages from your operating system repositories. For example, for RHEL 9, see Mounting NFS shares or Mounting an SMB share.

  3. On each PrivX server, mount the external share to a local directory. Use the same directory path on all PrivX servers. To enable mounting the share on system startup, we recommend adding the mount directive to /etc/fstab. To allow the PrivX Web UI to display other connection logs when the NFS server is unavailable, mount the share with options like the following:

    soft
    timeo=10
    retry=1
    note

    To enable live monitoring it is required that NFS clients do not buffer write operations. All PrivX nodes (in an HA setup) should mount the NFS mount point with noac option. This will likely increase the load on the NFS server due to heavier traffic.

  4. To configure PrivX with the new storage location, in the PrivX Web UI, go to Administration → Settings → Global, and specify the location in Data Folder. Save your changes and restart PrivX services to apply the changes.

Configuring Session Recording​

When session recording is enabled, connection-specific audit events also provide the following content, depending on the connection type:

  • Video playback, with keyword searches for SSH sessions.
  • Transferred files.
  • Clipboard content, for RDP only.
  • Channel logs, for SSH only.
  • Protocol streams for SSH command execution channels, SFTP commands, and database connections.

To enable session recording for connections to a host:

  1. In the PrivX Web UI, go to Administration → Hosts, select the host and click Edit.

  2. Under Options, enable the Session Recording option.

    • [Optional] You can exclude clipboard content, file transfers, or both from recordings. For example, exclude content that contains sensitive information, such as user credentials.
  3. Click Save to apply your changes.

Subsequent sessions to the host are recorded. To view recordings and transferred files, go to Monitoring → Connections and open the connection-specific audit events.

Session Recording Quality​

The Session Recording Quality setting controls the quality and storage requirements of recordings for browser-based RDP and Web connections. It does not affect VNC connections or native RDP recordings.

The available options are:

QualityRecording Behavior
Full (default)Stores the original protocol updates.
MediumUses JPEG snapshots on a reduced frame-rate to lower recording size.
LowUses JPEG snapshots on a reduced frame-rate and produces the smallest recordings.
tip

Selecting Medium or Low reduces recording size at the cost of increased CPU and memory usage. Before lowering the quality, check that the deployment has sufficient CPU and memory capacity during peak usage.

To change the recording quality:

  1. In the PrivX Web UI, go to Administration → Settings → RDP Proxy and then click Edit.
  2. Under Session Recording Quality, select Full, Medium, or Low.
  3. Save your changes.

The setting takes effect for newly opened connections. It does not affect ongoing recordings and does not require restarting PrivX.

For Carrier Web connections, we recommend using the VNC protocol if all needed interactive functionality on the target is covered by it. Select the protocol in the host-specific settings. Reported measurements show lower CPU and memory requirements than Web connections using RDP in PrivX 45, although memory consumption remains higher than for Web connections using RDP in PrivX 44.

Inspecting Session Recordings​

Recordings of interactive SSH shell sessions and RDP and VNC desktop sessions are available for playback. Playback shows the shell or desktop as the user sees it during the session. Transferred files are available for download.

note

PrivX generates keyframe data when an RDP session recording is opened for the first time. Processing large RDP and web-connection recordings can take several minutes. PrivX indexes session recordings when they are searched for the first time. The initial search can take longer depending on the recording duration.

Protocol streams for SSH command execution channels, SFTP commands, and database connections are available as downloadable log files in two formats:

Log FormatMetadata Included in Each MessagePayload Format
hexHeader with the timestamp, connection ID, channel type, and message direction.Hexadecimal dump following the header.
jsonlJSON properties for the timestamp, connection ID, channel type, and message direction.Base64-encoded value in the same JSON object.

Configuring Real-Time Auditing for SSH Connections​

Session recordings are generally available after the session ends. Certain channels also support live monitoring. For more information, see Monitoring Live Connections.

For real-time auditing SSH connections, configure PrivX to send SSH connection audit events to syslog. After, you can forward these events to a security information and event management (SIEM) system for automatic event handling.

tip

Before configuring real-time auditing, ensure that PrivX can access the SIEM system.

To send SSH connection audit events to syslog:

  1. Configure logging for your deployment:

    • RPM Deployments: Configure syslog to forward events containing SSH-PRIVX-SENSITIVE-AUDIT to your SIEM system.

      caution

      SSH-PRIVX-SENSITIVE-AUDIT events contain sensitive data. Never store these events in files or on disk. Ensure that they are forwarded to your SIEM system or discarded.

      For example, add the following rsyslog rule. Replace @@192.0.2.8:9010 with the address of your SIEM listener or forwarder:

      :msg, contains, "SSH-PRIVX-SENSITIVE-AUDIT" @@192.0.2.8:9010

      By default, the following rule in /etc/rsyslog.d/privx-syslog.conf discards these events:

      :msg, contains, "SSH-PRIVX-SENSITIVE-AUDIT" /dev/null
    • Kubernetes Deployments: Set the following values in the PrivX Helm chart bt replacing @@192.0.2.8:9010 with the address of your SIEM listener or forwarder:

      privx.syslog.enabled = true
      privx.syslog.audit.sensitive.to = @@192.0.2.8:9010
    important

    PrivX sends real-time SSH connection audit events only to syslog, when syslog is enabled. By default, PrivX discards these events in both deployment types. RPM deployments use a rule in /etc/rsyslog.d/privx-syslog.conf. Kubernetes deployments use a similar rule in the syslog pod.

  2. In PrivX Web UI, go to Administration → Settings → Global:

    • Click Edit and under SSH Common enable Send SSH events to audit log.
    • Select the SSH channels that are to output audit events.
    • Save your settings, then restart PrivX to apply your changes.

PrivX now sends SSH connection audit events to syslog in real time.

Monitoring Live Connections​

Live monitoring provides real-time video of ongoing connections.

To enable live monitoring:

  1. Enable session recording for the hosts to monitor.
  2. In the PrivX Web UI, go to Administration → Settings → Global. Under Live Connection Monitoring enable live monitoring for the required connection types.

To monitor an ongoing connection:

  1. Go to Monitoring -> Connections and select a connection with the Connected status and the REC indicator.
  2. Under Channels, click a channel to view its live playback.

Each supported channel can be monitored independently.

Planning Resources for Live Monitoring​

Live monitoring affects PrivX performance. It increases file system read and write operations, encryption, and decryption. This overhead applies while session recording is enabled, even when no one is monitoring the channel. RDP live monitoring is particularly resource-intensive.

Before using live monitoring at scale, review the RAM, CPU capacity, and recording storage configuration of your PrivX deployment. Ensure sufficient RAM and CPU capacity, a fast file system, and a fast network connection if recordings are stored remotely.

To improve performance, disable live monitoring if you only need to play back recordings after connections end.

Access Control​

Live monitoring uses the same access controls as session recordings. Users can access recordings if they meet any of the following conditions:

  • The user has the privx-admin role.
  • The user has the connection-playback permission. The role must be in the same Access Group as the target. This grants access to all recordings in that access group.
  • The user has a role and this role is specified as access role to a connection. This grants access to recordings for that connection only.

The following scenarios describe typical access control configurations.

Scenario 1: Allowing internal administrators to monitor specific targets​

Requirement: Allow a group of internal administrators to monitor connections to specific target hosts.

Initial setup: A sub group of internal administrators needs to monitor connections to highly classified targets. Session recording and live monitoring are enabled for these hosts.

Configuring access:

  1. Create a role in the same Access Group as the target hosts. If the hosts belong to multiple Access Groups, create a role in each access group.
  2. Enable the connection-playback permission for each role.
  3. Assign the appropriate roles to the administrators.

Depending on their responsibilities, the administrators may also need connections-view, connections-manage, connections-trail, connections-terminate, and logs-view permissions to view connection details and audit events, manage connections, and terminate connections.

Monitoring connections: In the PrivX Web UI, go to Monitoring → Connections and select an ongoing connection. Under Channels, click a channel to view its live playback.

Result: The administrators can monitor ongoing connections and access session recordings for hosts in the access groups covered by their roles.

Scenario 2: Sharing live playback with an external user​

Requirement: Give an external user view-only access to a single ongoing connection during a demonstration.

Initial setup: An internal administrator needs to share view-only access to a single connection with an external user during a demonstration. The external user has a role in a separate access group that contains no target hosts. Session recording and live monitoring are enabled for the demonstration target.

Configuring access:

  1. Start a connection to the target host with session recording enabled.
  2. In the PrivX Web UI, go to Monitoring → Connections and select the connection to open its details.
  3. Under Access Roles, add the external user's role.
  4. Open the channel and click its ☰ menu to retrieve the channel URL.
  5. Send the URL to the external user.

Result: The external user can open the channel URL to view live playback without controlling the target session. The assigned access role grants access to recordings for this connection only.

Viewing Live Playback​

When you open an ongoing channel, playback starts at the latest recorded position. A Live indicator appears next to the timer on the playback progress bar.

During live playback, playback controls such as rewind, fast-forward, and pause are unavailable. Data is served passively in one direction to the monitoring user. The monitoring user, however, can resize the browser as needed.

Processing and delivering session data introduces a delay in live playback.

The monitoring user can close the live playback at any time without affecting the original connection. If the user in the original connection closes the channel (by closing the connection, or closing the channel tab), the monitoring session switches to standard playback and the playback controls become available.

Audit Events for Live Monitoring​

Two audit events record the start and end of a live monitoring session. They contain the same information as the session-added and session-removed events, except for the monitoring-user-id field, which contains the UUID of the user who monitored the connection.

Monitoring Limitations​

There is no limit for the total number of monitoring sessions, for the number of live monitoring sessions by any users and for any single channel. This is consistent with playing back the recordings after the connection has ended. The playback is not counted towards license's concurrent connection limit in all cases.

Within an SSH connection each channel is independently monitored.

For SSH only shell and exec (with PTY) channels can be played back and therefore monitored live. Requests to playback other channels, live or not, will be rejected.

When SSH live monitoring flag is set to false PrivX will reject requests to playback the recording while the channel is ongoing. Only after the channel has ended it is possible to playback the recording.

Monitoring Notifications​

The PrivX Web UI does not notify the user in the original connection when another user starts or stops monitoring it. The monitoring user does not receive notifications when the user in the original connection opens new channels.

HA setup with NFS external storage: live monitor feature requires trail data to be pushed to NFS server as soon as possible. NFS clients typically buffer file-write operations thus making it hard for the monitoring session to follow updates in the actual connection. Mount the NFS mount point (on client side) with noac to disable write buffering on all PrivX nodes.