Audit Events

Every session produces a detailed audit trail. Activities that were invisible under RDP or VDI — file handling, printing, clipboard use — become recorded, reportable events for security and compliance teams.

Events tracked

EventCaptured detail
Login / logoutUser, time, and outcome.
Application launchWhich application was started in a session.
File open / saveFile operations performed by the application.
File transfer panel usageUploads and downloads through the transfer panel.
Clipboard transfersDirection and size of each transfer.
Print eventsPrint jobs and the document output produced.
Policy enforcement actionsWhen a policy allowed or blocked an action.
Session recording metadataRecording start/stop and references.

Where to view audit data

Tip

For compliance, pair the audit trail with the User Access and Entitlements report: one shows what users did, the other shows what they could do.

Retention requirements

Session activity and related logs are stored in the customer deployment (your databases and storage). Product defaults for some activity stores are short (for example, Metrics Engine activity retention often defaults to about 10 days unless you configure otherwise). Session recording retention is separately configurable (commonly around 30 days when recording is enabled).

When the deployment processes regulated or security-sensitive Customer Content, configure audit and activity retention to at least one year (365 days), or continuously export events to your SIEM / log archive that meets that retention. Do not rely on short product defaults for compliance evidence.

IAM activity_log (Access Management) is retained in your IAM database; operators must not purge security-relevant rows earlier than one year when Marketplace or regulated use applies.

See Session Recording for recording retention, and the AWS Marketplace Quick Start for Marketplace deployment expectations.