Auditing and Logging Admin Sessions
Record every command an operator runs for accountability.
Accountability for Admins
Granting administrative access is only half the job; you must also record what administrators do. Session Manager provides rich logging so every command and session is accountable. The SCS-C02 exam stresses this auditability as a core advantage over SSH, where command-level logging is hard to centralize.
Two Layers of Logging
Session Manager logging has two layers: API-level logging of who started and stopped sessions, captured by CloudTrail, and session-content logging of the actual keystrokes and output, sent to CloudWatch Logs or S3. Together they answer both "who connected" and "what did they do."
All lessons in this course
- Why Bastion Hosts Add Risk
- Session Manager Without Open Ports
- Auditing and Logging Admin Sessions
- Hardening Endpoints and Patch Manager