Events overview
The Sessions page tells you “who was approved to do what.” Events tells you “what actually happened.” Each page in this group lists one kind of action, with filters tuned for that event.
Everything here is per-event. For the parent session view, use Sessions.
How to get here
Open the sidebar and expand Audit → Events (or Audit → My events if you’re a regular user).
Pages in this group
- Websh — terminal sessions opened against your servers. Who connected, from where, and what they ran.
- Sudo — sudo authorizations. Who was allowed to run which privileged command on which server, and how the authorization was granted.
- Commands — commands sent to your servers, with the issuer, the result, and the verification outcome.
- File transfers — WebFTP uploads and downloads.
What you see depends on your role
The sidebar label flips with your role: Events for administrators, My events for regular users.
- Administrators see every event across the workspace.
- Regular users see only their own activity. Sessions, terminals, sudo grants, commands, and file transfers all narrow to the rows tied to the signed-in user.
The narrowing is enforced server-side, not just by the menu — direct URLs follow the same rule.