LogoLogo
CtrlK
Help CenterGet A DemoTry It Free
  • Home
  • Administrators
  • Users
  • Concepts
  • References
  • Changelog
  • Admin Guide
  • Deployment
    • Quick Start Guide
    • Terraform
      • Quick Start StrongDM With Terraform and AWS
      • Quick Start StrongDM With Terraform and Azure
    • Deployment Scenarios
      • Ansible with SDM
      • AWS Registration and Cleanup
      • Create a Self-Registering Relay with Chef
      • Deploy Gateways Via AWS Organizations With CloudFormation StackSets
      • Deploy HA Gateways with CloudFormation
      • Grant Temporary Access with a Hubot Chatbot
      • Use Chef Knife with SDM
      • Automate Temporary Access with PagerDuty Schedules
    • Environment Variables
    • Integrations
      • AWS
      • GCP
      • Microsoft
    • Parent/Child Organizations
    • Support
  • Networking
    • Proxy Clusters
      • Bridged Proxy Cluster
      • Deploy ECS Fargate Proxy Cluster
      • Deploy Kubernetes Proxy Cluster
      • Proxy Clusters Migration
    • Gateways and Relays
      • Azure VM Nodes
      • Nodes in Docker Containers
      • EC2 Nodes
      • ECS Fargate Gateway Deployment Guide
      • Explicit Routing
      • GCP Nodes
      • Kubernetes Nodes
      • Linux Nodes
      • Nomad Nodes
      • StrongDM Gateway AMI Installation Guide
      • Uninstall Linux-Based Nodes
    • Maintenance Windows
    • Ports Guide
    • Metrics
    • Security-Enhanced Linux
  • Resources
    • Clouds
      • AWS Management Console
      • AWS (Instance Profile)
      • AWS Cloud
      • Azure Cloud
      • GCP (Workforce Identity Federation)
      • GCP CLI/SDK (Service Account)
      • Microsoft Entra ID
      • Snowsight
    • Clusters
      • Kubernetes (Pod Identity)
      • Identity Alias for Kubernetes
      • Kubernetes Discovery and Privilege Levels
      • AKS
      • EKS
      • EKS (Instance Profile)
      • GKE
      • Kubernetes
      • Kubernetes (Service Account)
      • Kubernetes (User Impersonation)
    • Datasources
      • Aerospike
      • Amazon Elasticsearch (IAM)
      • Amazon Elasticsearch
      • Amazon MQ AMQP
      • Amazon MQ (AMQP 0.9.1)
      • Amazon Neptune
      • Athena (IAM)
      • Athena
      • Aurora MySQL (IAM)
      • Aurora MySQL
      • Aurora PostgreSQL (IAM)
      • Aurora PostgreSQL
      • Azure Database for MySQL
      • Azure MySQL (Managed Identity)
      • Azure PostgreSQL (Managed Identity)
      • Azure PostgreSQL
      • BigQuery
      • Cassandra
      • Citus
      • ClickHouse
      • Clustrix
      • CockroachDB
      • Couchbase
      • Db2 LUW
      • Db2i
      • DocumentDB (single host IAM)
      • DocumentDB (Replica Set)
      • DocumentDB (Single Host)
      • Druid
      • DynamoDB (IAM)
      • DynamoDB
      • ElastiCache Redis
      • Elasticsearch
      • Greenplum
      • Maria
      • Memcached
      • MemSQL
      • Microsoft SQL Server (Azure AD)
      • Microsoft SQL Server (Kerberos)
      • Microsoft SQL Server
      • MongoDB (Replica Set)
      • MongoDB (Sharded Cluster)
      • MongoDB (Single Host)
      • MySQL
      • Oracle
      • PostgreSQL
      • Presto
      • RabbitMQ
      • RDS PostgreSQL (IAM)
      • Redis Cluster
      • Redis
      • Redshift (IAM)
      • Redshift Serverless (IAM)
      • Redshift
      • SingleStore
      • Snowflake
      • Sybase ASE
      • Sybase IQ
      • Teradata
      • Trino
      • Vertica
    • Servers
      • SSH (Certificate Auth)
      • SSH (Public key)
      • SSH (Customer Managed Key)
      • SSH (Password)
      • Identity Alias for SSH
      • RDP
      • RDP (Certificate Auth)
      • Identity Alias for RDP
      • TCP
      • Port Forwarding
      • Network Device Management
    • Websites
    • Import Resources
    • Port Overrides
    • Resource Discovery
    • Resource Lock
    • Rotate Passwords
  • Principals
    • Users
    • Authentication
    • Multi-factor Authentication
      • MFA with Cisco Duo
      • MFA with Okta Verify
      • MFA with RSA ID Plus
      • MFA with TOTP
    • SSO
      • SSO With ADFS
      • SSO With Auth0
      • SSO With Microsoft Entra ID
      • SSO With Google
      • SSO With Keycloak
      • SSO With Okta
      • SAML for Okta
      • SSO With OneLogin (OIDC)
      • SSO With OneLogin (SAML)
      • SSO With Ping Identity (OIDC)
      • SSO With Ping Identity (SAML)
      • SAML for Rippling
      • SSO With SAML
      • SSO With VMware Workspace ONE
    • Provisioning
      • Provisioning With Microsoft Entra ID
      • Provisioning With Google Cloud
      • Provisioning With JumpCloud
      • Provisioning With Okta
      • Provisioning With OneLogin
    • Identity Aliases
    • Service Accounts
    • Admin Tokens
    • Import Users
  • Access
    • Roles
    • Access Workflows
      • Integration With Slack
      • Integration with Teams
    • Approval Workflows
      • Integration with Jira
      • Integration with ServiceNow
    • Permission Level
    • Policies
      • Policy Use Cases
      • Policy Creation
      • Policy Taxonomy
      • Device Trust
    • Entitlements Visibility
    • Import Roles
  • Clients
    • Client Networking
      • Loopback IP Ranges
      • Virtual Networking Mode
    • Run the StrongDM Client on Docker
    • Managed Client Installations
    • StrongDM Release Endpoint
    • StrongDM Binary Verification
  • Secrets Management
    • Certificate Authorities
      • Active Directory Certificate Services CA Integration for RDP
      • AWS CA Integration for RDP
      • Keyfactor EJBCA CA Integration for RDP
      • Keyfactor EJBCA CA Integration for SSH
      • GCP Certificate Authority Service Integration for RDP
      • Strong CA
      • HashiCorp Vault CA Integration for RDP
      • HashiCorp Vault CA Integration for SSH
    • Secret Stores
      • AWS Secrets Manager
      • Azure Key Vault
      • CyberArk Conjur
      • CyberArk PAM
      • Delinea Secret Server
      • GCP Secret Manager
      • HashiCorp Vault
      • Strong Vault
  • Audit
    • Reports
    • Logs
      • Generate a Key Pair
      • Log Stream
      • How to Read Node Log Files
      • View Logs from the Admin UI
      • View Logs from the CLI
      • Log Event References
        • Policy Evaluation and Authorization Information in Logs
        • Log Stream - Activities
        • Log Stream Queries
        • Log Stream - Replays
        • Node Logs - Complete Event
        • Node Logs - Post Start Event
        • Node Logs - Replay Chunks
        • Node Logs - Start Event
      • Log Scenarios
        • Regularly Export Activities
        • Regularly Export Queries
        • Regularly Export SSH Replays
        • Send Local Logs to CloudWatch
        • Send Local Logs to Filebeat
        • Send Local Logs to Graylog
        • Send Local Logs to S3
        • Send Local Logs to Splunk
        • Logging with Rsyslog
Powered by GitBook
On this page

Was this helpful?

  1. Audit
  2. Logs

Log Scenarios

Regularly Export ActivitiesSend Local Logs to CloudWatchSend Local Logs to FilebeatSend Local Logs to GraylogRegularly Export QueriesLogging with RsyslogSend Local Logs to S3Send Local Logs to SplunkRegularly Export SSH Replays

Last updated 1 month ago

Was this helpful?

© 2025 StrongDM