CommandLog_FileTransfer
This log type applies only to RDP Proxy and contains logs of files that are transferred (upload or download) by the user during remote desktop connections in Kron PAM. The packets are sent to the server in the following format:
sessionId | Specific ID of the log in the PAM Database |
|---|---|
userName | The username that transferred the file during the remote connection |
Host | KRON PAM Host IP |
tenantId | Tenant, the command log was captured. |
sessionStartTime | When the session started |
sessionEndTime | When the session finished |
globalUserName | GlobalUserName is used for authentication |
clientIp | Source IP of the device that executed the command |
commandTime | Exact time when the file transfer started |
command | Transferred file |
allowed | If the executed command is allowed by the administrator or not allowed=true is the default value for RDP sessions |
instanceName | Which instance executed the command |
deviceGroups | Group names of the device on which the command is executed |
Example:
The test user downloads a Testfile during a remote desktop connection on Kron PAM: