Skip to main content
Session logs are a paid feature.If you’re using Infisical Cloud, they’re available under the Enterprise Tier. If you’re self-hosting Infisical, contact [email protected] to purchase an enterprise license to use them.
A session log is the per-request record of what an agent actually did: the method, host, path, status, and whether a credential went out with it. Every request that reaches a proxy is recorded, including requests to hosts that no access bundle covers. Records are encrypted before they leave the proxy and stored in an Amazon S3 bucket you own.

Setting up session logs

Go to Settings under Agent Vault and select Set Up Session Logs on the Session Logs card:
  1. Turn on Enable.
  2. Pick the AWS Connection whose credentials write the records. It can be one from your organization or one created in Agent Vault, or select Create New Connection to add one.
  3. Enter the Bucket and Region of an S3 bucket you’ve already created.
  4. Optionally set a Key Prefix, so session logs sit under one path in a bucket you use for other things.
  5. Select Save.
The Session Logs dialog with Enable turned on and an AWS connection, region, bucket, and key prefix filled in
When you save, Infisical checks that the bucket exists and that it can write to it. The connection needs an IAM policy and the bucket needs a CORS rule. Select View AWS Setup in the Session Logs dialog to see both.
Attach this identity policy (not a bucket policy) to the user or role the connection authenticates as:

Viewing session logs

Go to Sessions and select View Session Logs on the session’s row. You can filter and search the requests, and while the session is active, new logs keep appearing.
The Session Logs sheet for an active session, listing each request's time, method, host, path, upstream status, and outcome
The API returns a session’s logs as chunks. A chunk is one encrypted batch of records that a proxy uploaded to your bucket. You can read a session’s logs if you created the session or you’re an Agent Vault admin.
1
Call the endpoint that lists session logs. It returns the newest chunks first. To get older chunks, call it again with the response’s nextCursor as cursor.
2
Download each chunk from its presignedGetUrl within 5 minutes, before the URL expires. If presignedGetUrl is null, either the chunk is in a bucket other than the current one, or sessionLogs.storageUnavailable says why the chunk can’t be downloaded right now.
3
Check that the SHA-256 digest of the downloaded bytes, as base64 without padding, matches ciphertextSha256. If the digests differ, the chunk was changed after the proxy uploaded it.
4
Decrypt the chunk with AES-256-GCM. The key is sessionLogs.sessionKey and the IV is the chunk’s iv, both base64 decoded. The associated data is the SHA-256 digest of <sessionId>|<chunkId>|v1. The last 16 bytes of the chunk are the authentication tag.
5
Parse the decrypted bytes as JSON. Each chunk holds an array of records, and decision holds the outcome in lowercase:
This Node.js script reads the newest page of a session’s logs:
The script runs outside a browser, so the bucket’s CORS rule doesn’t apply to it.To receive new logs as they arrive, pass the response’s liveCursor as cursor to the endpoint that tails session logs, then keep calling it with each response’s nextCursor. If hasMore is true, call again right away. Otherwise, wait a few seconds before the next call. The same chunk can appear in more than one response, so skip any chunkId you’ve already read.

What gets recorded

Each request produces one record with: The outcome is one of four: Request and response bodies, headers, and query strings aren’t recorded.

Managing session logs

Connections

Session logs use one AWS connection at a time, which you pick in the Session Logs dialog. It can be one created in Agent Vault or one your organization already has under Integrations. See AWS connection for how to create one. To update its AWS credentials, open the menu next to Configure on the Session Logs card and select Edit AWS Credentials. For an organization connection, update the credentials under Integrations instead. To add or delete Agent Vault’s AWS connections, select Manage Connections from the same menu:
The Manage Connections sheet listing Agent Vault's AWS connections, with the one session logs use marked In Use
You can’t delete the connection session logs are using. Pick a different one in the Session Logs dialog first.

Changing the bucket or prefix

Changing the bucket copies nothing, so everything recorded before the change can’t be read in Infisical until you switch back to that bucket. Changing only the key prefix keeps earlier records readable, as long as the AWS connection can still read the old prefix. The IAM policy on this page covers only the current prefix.

Retention

Infisical never deletes sessions or their session logs. To delete older logs automatically, add a lifecycle rule to the bucket in AWS.

Troubleshooting

If a session shows no session logs when you expect some, check the logs of each proxy the agent used.