Skip to content

Direct recording Configurations

The Direct recording Configurations module links user groups, sites, machines and alerts, and — for direct-access sessions — filters the allowed network connections. A direct recording configuration defines, for users in the targeted groups, the set of machines reachable through direct access from the selected sites, with a consistent recording and alert policy.


Configuration list

The main grid displays the existing configurations in a paginated view (15, 25 or 50 rows per page):

Column Description
Name Configuration name, preceded by a padlock icon.
Groups Number of user groups linked.
Sites Number of sites linked.
Machines Number of machines linked.
Alerts Number of alerts linked.
Network connections Number of authorized networks (column hidden by default).

Expanding a row shows the configuration details, one line per family: groups (grouped by domain, the domain in bold), sites, machines, alerts — that last line only appears when the configuration carries some — and authorized networks when filtering is enabled. Hovering the details shows the same information as a tooltip.

A search field in the toolbar filters the list on the fly (triggered 700 ms after the last keystroke or immediately with Enter).


Add a configuration

Clicking the + button opens the Add Direct Recording Configuration window: two common fields, then five tabs.

Field Description
Name Mandatory. A string made of whitespace only is rejected.
Description Free text.

The Previous and Next buttons at the bottom move between tabs. The Validate button is only enabled once at least one group, one site and one machine have been selected.

The Groups, Sites, Machines and Alerts tabs all work the same way: the left-hand list holds the available items, the right-hand list the selected ones, and items are moved by drag and drop. Each list carries a Select All button.

Item Description
Domain Combo of the Microsoft domains. The first domain in the list is selected automatically when the form opens. The list of available groups reloads on every domain change.
Available group list Groups returned for the selected domain. Search field, Select All button and Manual entry button (see below).
Selected group list Groups assigned to the configuration, shown as name - domain. Search field, Remove and Remove all buttons.

The Manual entry button opens the Addition of a custom group window, which registers a group by its Name and Microsoft Domain without it being present in the returned list. A duplicate (same name and same domain) is rejected with the message This group is already in the list.

Two lists, available on the left and selected on the right, each with a Select All button.

As a reminder, a site is a set of Edge Gateways defining a single secure entry point to a local network.

Default site hidden

The platform's default site is automatically removed from the list of available sites: it cannot be assigned to a direct recording configuration.

Two lists, available on the left and selected on the right, each with a Select All button. Only machines in agent mode are proposed.

Two lists, available on the left and selected on the right, each with a Select All button. On creation, the alerts flagged Enabled by default are moved to the right-hand list automatically.

Checking Filter network connections expands two blocks.

New authorized network — collapsible block where a rule is entered before being added with the Add button:

Field Description
Target IP Allowed destination IP address. Mandatory, checked as an IP address.
Network mask (optional) When left empty, the rule applies to the address alone.
Port (0 to allow all ports) Positive integer. The default value 0 allows every port.
Protocol TCP, UDP or TCP and UDP.

Authorized networks — grid of the registered rules, with the Target IP (suffixed with the mask where applicable), Port and Protocol columns. Each row can be removed individually, after confirmation.

Filtering with no rule

If Filter network connections is checked while no network has been added, no connection is allowed — the configuration details then read No authorized connections.


Edit a configuration

Select the configuration in the list then click the Properties icon (or double-click the row). The Modify Direct Recording Configuration window is identical to the add window, pre-filled. Make the changes then click Validate. The button is enabled only when exactly one row is selected.


Delete a configuration

Select one or more configurations then click the × button. A confirmation is requested (wording adapted to the singular or plural case).