Audit Events
Every session produces a detailed audit trail. Activities that were invisible under RDP or VDI — file handling, printing, clipboard use — become recorded, reportable events for security and compliance teams.
Events tracked
| Event | Captured detail |
|---|---|
| Login / logout | User, time, and outcome. |
| Application launch | Which application was started in a session. |
| File open / save | File operations performed by the application. |
| File transfer panel usage | Uploads and downloads through the transfer panel. |
| Clipboard transfers | Direction and size of each transfer. |
| Print events | Print jobs and the document output produced. |
| Policy enforcement actions | When a policy allowed or blocked an action. |
| Session recording metadata | Recording start/stop and references. |
Where to view audit data
- Dashboard — recent activity at a glance.
- Reports — System Audit Log, Session Events Log, and Activity Log. See Reports.
- Activity API — programmatic access for SIEM integration. See API Reference.
For compliance, pair the audit trail with the User Access and Entitlements report: one shows what users did, the other shows what they could do.
Retention requirements
Session activity and related logs are stored in the customer deployment (your databases and storage). Product defaults for some activity stores are short (for example, Metrics Engine activity retention often defaults to about 10 days unless you configure otherwise). Session recording retention is separately configurable (commonly around 30 days when recording is enabled).
When the deployment processes regulated or security-sensitive Customer Content, configure audit and activity retention to at least one year (365 days), or continuously export events to your SIEM / log archive that meets that retention. Do not rely on short product defaults for compliance evidence.
IAM activity_log (Access Management) is retained in your IAM database; operators must not purge security-relevant rows earlier than one year when Marketplace or regulated use applies.
See Session Recording for recording retention, and the AWS Marketplace Quick Start for Marketplace deployment expectations.