> ## Documentation Index
> Fetch the complete documentation index at: https://syteca.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Events and Monitoring

> The full audit trail of every Privilege Elevation decision. Auto-elevate, Require approval, and Deny plus how session recording behaves depending on your Syteca license.

Every Privilege Elevation decision automatic, approved, denied, or blocked is recorded on the **Events** tab, giving you a complete, permanent audit trail independent of whether the rule that triggered it still exists.

<Note>
  Access to the Events tab requires the **Privilege Elevation** administrative permission. Without it, the tab isn't shown, and its data isn't reachable by direct URL either.
</Note>

## Open the Events tab

<Steps>
  <Step title="Open Privilege Elevation">
    In the left navigation, under **Security**, click **Privilege Elevation**.
  </Step>

  <Step title="Select the Events tab">
    Shows every recorded transaction, most recent first.
  </Step>
</Steps>

<Frame caption="The Privilege Elevation Events tab.">
  <img src="https://mintcdn.com/syteca/V2nKrBDlsXgnyFWU/images/pam/privilege-elevation/events-tab-overview.png?fit=max&auto=format&n=V2nKrBDlsXgnyFWU&q=85&s=e28322c164bda3ca54f881ef2f9d2570" alt="Privilege Elevation Events tab showing recorded transactions" width="899" height="895" data-path="images/pam/privilege-elevation/events-tab-overview.png" />
</Frame>

## The Events grid

| Column | Shows |
| - | - |
| **Time** | When the event occurred, formatted per your [Date & Time Format settings](/docs/administration/configuration/date-time-format). |
| **User** | The user who triggered the elevation attempt. |
| **Endpoint** | The hostname of the endpoint where it happened. |
| **Action** | **Auto-elevate**, **Require approval**, or **Deny** — the final decision applied. |
| **Processed By** | The username of whoever approved or denied the request. Shows **None** if the request expired, or if the rule never required a decision (Auto-elevate/Deny). |
| **Rule** | The name of the rule that was applied. |
| **Object** | The elevation target — the application's file name (for example `powershell.exe`). |
| **Details** | A fixed set of lines — see below. |

<Note>
  Events remain in the grid even after the rule that generated them is deleted — the audit trail doesn't depend on the rule still existing.
</Note>

### What the Details column shows

Every event shows three consistent lines:

```text theme={"system"}
Elevated as: <secret_name> / None
Access Request: Approved / Denied / Expired / None
Privilege Elevation recording: enabled / disabled
```

* For **Deny** events, all three are fixed: `Elevated as: None`, `Access Request: None`, `Privilege Elevation recording: disabled`.
* For a scheduled **Auto-elevate** rule blocked by its own schedule (outside allowed hours), the event logs as **Deny** with `Elevated as: None`, plus a note on why (for example, outside working hours).

### Filters, search, and export

**Default filters:** **When** (date range, defaults to all time), **Who** (defaults to all users), **Action** (Auto-elevate / Require approval / Deny, defaults to all).

**More Criteria:** **Rule**, **Endpoint**, **Object**, **Processed By**.

**Search** matches User, Endpoint, Secret, Approver, and Object fields.

**Export** produces a CSV containing every column, respecting whatever filters are currently applied.

<Frame caption="Filtering the Events tab.">
  <img src="https://mintcdn.com/syteca/S902s0P3SJkGolLq/images/pam/privilege-elevation/events-tab-filters.png?fit=max&auto=format&n=S902s0P3SJkGolLq&q=85&s=56232636cf6fccab1de8df2e823a4f57" alt="Events tab filters including When, Who, and Action" width="1888" height="840" data-path="images/pam/privilege-elevation/events-tab-filters.png" />
</Frame>

## Session recording during elevation

If **Session recording during elevation** was enabled on the rule (available for Auto-elevate and Require approval, not Deny), Syteca can additionally record the elevated session itself — capturing screen, keyboard, and command input for the duration.

What actually gets recorded depends on your license:

| License | Recording behavior |
| - | - |
| **Privilege Elevation + User Activity Monitoring (UAM)** | Full session activity is recorded using standard UAM logic — the same screen, input, and contextual capture as any other monitored session, for the duration of the elevated session. |
| **Privilege Elevation only (no UAM)** | Recording is scoped narrowly: only the specific elevated application or file, starting when it launches and stopping as soon as it's closed. No background or session-wide activity is captured — conceptually the same as [recording tied to a Secret's use](/docs/pam/access/linux-pacm#7--recording-secret-usage) rather than a full monitored session. |

<Note>
  **Deny** mode never triggers or allows recording — there's no elevated session to capture.
</Note>

## Related

<CardGroup cols={2}>
  <Card title="Overview" icon="shield-check" href="/docs/pam/privilege-elevation/overview">
    What Privilege Elevation does and how it's licensed.
  </Card>

  <Card title="Creating and managing rules" icon="list-checks" href="/docs/pam/privilege-elevation/rules">
    Where Session recording during elevation is enabled per rule.
  </Card>

  <Card title="End-user experience" icon="monitor" href="/docs/pam/privilege-elevation/end-user-experience">
    What triggers each of the Action values shown here.
  </Card>

  <Card title="Audit log" icon="file-text" href="/docs/administration/audit-log">
    The administrative audit trail for Management Tool configuration changes.
  </Card>
</CardGroup>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.