Skip to main content

Monitor and Audit Database Access

This article explains how you monitor and audit access to databases that already exist in JumpCloud Privileged Access Management (PAM). You learn how to read status at a glance on the Databases list, confirm connection details, watch real-time active sessions, disconnect users, and review post-session history including Query history.

Prerequisites​

  • Access to the JumpCloud Admin Portal.
  • At least one database already exists under Privileged Resources > Databases.

Considerations​

  • If a database shows Recording disabled, that database does not produce video recordings for Session History.
  • If you want every database recorded, review rows that are missing Recording enabled. Then update that database’s DB Shield and session recording settings as needed.
  • In use means the database has active sessions open.
  • From the Active Sessions page, click View all to open Session History for that database.
  • For databases, Query history shows the commands typed during the session, including queries that were blocked.

Opening the Databases List​

  1. Log in to the JumpCloud Admin Portal.
  2. Go to Access > PAM.
  3. Open Privileged Resources.
  4. Click the Databases tab.

Reading the Status Column​

On the Databases list, use the Status column to audit each database without opening it. Hover each icon to see its tooltip.

IconTooltipWhat it means
ShieldDB Shield Enabled. / DB Shield Disabled.Whether DB Shield is on for that database.
CameraRecording enabled / Recording disabledWhether session recording is on. Recording applies when DB Shield supports isolated or recorded sessions.
SignalIn use / Not in useIn use means the database has active sessions open.
warning

If a database shows Recording disabled, that database does not produce video recordings for Session History. If you want every database recorded, review rows that are missing Recording enabled. Then update that database’s DB Shield and session recording settings as needed.

Status column on the Databases list.

Viewing Database Details​

Use View Details to confirm how JumpCloud PAM connects to an existing database.

  1. On the Databases list, find the database you want to audit.
  2. In the Actions column for that row, click the information icon. The tooltip is View Details.
  3. The Details dialog opens.
  4. Review the following fields:
    • Resource ID
    • Name
    • URI
    • Port
    • Database Name
    • Jump Server
    • Session Recording
    • Provider
    • Connection String
    • Tags
    • Notes
  5. Click Close.

Connection String shows how JumpCloud PAM connects to that database. Jump Server and Session Recording show how users reach the target and whether sessions can be recorded.

Database Details dialog.

Viewing Active Sessions​

When Status shows In use, open real-time sessions for that database.

  1. On the Databases list, find the database that shows In use.
  2. In the Actions column for that row, click the eye icon. The tooltip is View Active Sessions.
  3. The page titled {database name} Active Sessions opens. The Back control is labeled Databases.

The Active Sessions table includes these columns:

  • User
  • Username
  • Credential
  • Start Date
  • Actions

Watching a Live Session​

  1. On the Active Sessions page, in the session row Actions, click the eye icon.
  2. The Live session drawer opens.
  3. Review User, Resource, Type (shows Database), Username, Credential, and Start.
  4. Watch the live stream area.
  5. Click Cancel to close without disconnecting, or click Disconnect to end the session.

Live session drawer for a database session.

Disconnecting a User from a Resource​

  1. On the Active Sessions page, in the session row Actions, click the power / disconnect control.
  2. The Disconnect user from resource dialog opens with Are you sure?.
  3. Confirm you want to disconnect the User from the Resource.
  4. Under What action to execute after disconnection?, choose one of the following options:
    • Only disconnect
    • Lock out access to resource by, then under Duration, choose a lockout period.
  5. Click Cancel to keep the session, or click Disconnect to end it.

Disconnect user from resource dialog.

note

On the Active Sessions page, click View all to open Session History for that database.

Reviewing Session History and Query History​

Use Session History for after-the-fact audit of finished database sessions, including recordings and SQL commands.

  1. Log in to the JumpCloud Admin Portal.
  2. Go to Access > PAM.
  3. Open Session History.

You can also reach Session History from Active Sessions by clicking View all.

  1. Find the database session. Look for Resource Type Database. You can filter by Resource Type set to Databases.
  2. Open the session. Use View Recording or the session detail action for that row.
  3. On the session detail page, review these panels:
    • Session details
    • Session recording
    • Query history

Session detail page with Session details, Session recording, and Query history.

Reviewing Query History​

In Query history, review the following:

  • Original Query
  • Rewrite Query when it is shown
  • Status Executed or Blocked
  • The Command blocked message for blocked commands
  • Duration
  • Rows Affected
  • Download
  • Search
Important

For databases, Query history shows the commands that were typed during the session, including queries that were blocked.

Query history panel for a database session.

Was this information helpful?