Removing session recording entries in PAM after files were deleted
search cancel

Removing session recording entries in PAM after files were deleted

book

Article ID: 275620

calendar_today

Updated On:

Products

CA Privileged Access Manager (PAM)

Issue/Introduction

You only need to keep recordings for sessions to a subset of target devices for a long time. Other recordings can be purged sooner. This cannot be configured in PAM. Every once in a while you compile a list of old session recording files that can be removed. E.g. the syslog server/Splunk will have information on which file recorded a session to which target device from the session log messages. An NFS server admin will process the list and remove those files from the session recording share. This will leave orphaned session recording entries in the PAM database and thus on the Sessions > Session Recordings page. Is there any way to remove those entries from the PAM database so that they don't show up in the PAM UI anymore as if they were viewable?

Resolution

If your environment allows PAM Support to access your PAM servers using Remote SSH Debugging Services, open a case with PAM Support to have the team look into cleaning up the stale session recording entries.