This message was deleted.
# citrix-vad
s
This message was deleted.
😂 1
w
Yes, but it is a useful piece of kit. One time I implemented it because the bosses kept getting complaints from EU users that printing PDFs from Excel was painfully slow. SR allowed us to see the PDF was created and printed in less than two seconds. The complaining users were using the slowness as an excuse to take a smoke break. When they were shown video evidence of the Excel/PDF/print speed, the slowness complaints disappeared.
😀 1
j
I want it to start when PowerShell starts and stop when PowerShell exits. I am rapidly reaching the "hair tearing" state. It's very poorly documented and is not user-friendly at all
w
It is not admin-friendly. I thought they added a way to start/stop recording for certain apps/actions?
Application starts and ends Session Recording supports detection of both application starts and ends. When you add a process to the App monitoring list, apps driven by the added process and its child processes are monitored. Child processes of a parent process that starts before Session Recording runs can also be captured. Session Recording adds the process names,
cmd.exe
,
powershell.exe
, and
wsl.exe
, to the App monitoring list by default.
j
They did, but getting it to work is a black art. It seems to start when it feels like it and doesn't end at specific times
w
Ahhh. I haven't used SR in a few years, but I enjoyed it, warts and all, when I did as it is a useful piece of kit.
r
I feel your pain, been down that road. I ended up giving up, and just recorded the who dang session. Wasn't ideal at the time, plus extra storage. But I was on a time crunch and it gave them what they wanted. However, I had to find it within the session because it was hours of users working.
j
Yeah my CSO just want to see what PS the devs are running. PS logging is not enough, apparently 🤷‍♂️
r
I can understand that. If you do figure it out, please share. I remember It was a pain and I was able to get approval for the half baked solution I shown the business.
j
WHY DO I ALWAYS END UP TINKERING WITH THE INFURIATING STUFF
🙂
l
There was someone I know that's done this, I just cannot remember for the life of me who it was. When/if it comes to me I'll let you know.
j
Wasn't @Dave Brett was it, I know he's into some Session Recording stuff
r
I think @Hal Lange is another one who is into SR as well.
l
Might be Dave actually. I distinctly remember whoever it was saying it was on the stop and start of a process though.
j
it's so annoying. I've got it set up to capture uninstall events as a test, and it works most of the time, but it only starts recording about ten seconds after the uninstall event
l
Is this a recording server lag thing? Maybe there's a bit of time before the storage is available or something?
r
Good point. I was at a place that had a unc path to dump the recordings in side the setup where it ask for place to put the recordings. It was off from when it was suppose to record some.
j
I tried setting the "pre-delay" thing but that seems to make no difference
l
You live. Challenge mate. Try Windows 11 with enterprise 😂
j
That's on my radar now, let's not joke about it 🙂 I need to slow down and all the youngsters need to deal with this garbage
l
Ha ha, so much wrong. As well as all the apps (msedge, teams, OneDrive) that allow enterprise rollout. All managed slightly differently with different settings. Does my head in.
The only way I've found to manage the start menu effectively is to apply MDM settings in the registry. Was a post on twitter and that approach does work. It's just faking MEM doing it.
l
my biggest complaint is that it doesnt export videos in a friendly format. I end up having to play the video in real time, and screen capture it. You can't put a link to a server in a forensic file
h
What we have done is create a posh script to export the files for forensics. It will search by username or client name and dump it the videos to a local folder on the desktop. I will post the script when back at my desk. Unfortunately it is still in their proprietary format so you need the player installed to play it. I have a dev request in for exporting in easy format. ( They do say coming soon) Also, don't use a NAS for storage. It does not seem to keep up with the msmq for recording and data gets lost. As far as event recording. We have not played with that as much as we should, but during initial testing it was working fine on 2112 as long as using the local loopback storage
Here is the script to export videos from SR
Copy code
$DBServer = "<Enter SQL Server>"
$DBName = "<Enter DB Name>"

function GetInfo($QSQL,$DB,$DBS){
		$Connect = "Provider=SQLNCLI11.1;Integrated Security=SSPI;Persist Security Info=False;Initial Catalog=$DB;Data Source=$DBS"
		Try{
			$sqlConnection = New-Object System.Data.OleDb.OleDBConnection $Connect
			$command = New-Object System.Data.OleDb.OleDbCommand $QSQL,$Connect
			$sqlConnection.Open()
			$dataAdapter = New-Object System.Data.OleDb.OleDbDataAdapter $Command
			$dataset = New-Object System.Data.DataSet
			$dataAdapter.Fill($dataSet)
			$sqlConnection.Close()
			Foreach ($Table in $Dataset.Tables){
				if ($Table -ne $Null){
                    write-host Copying Files
                    foreach ($Row in $Table){
					    $FileName = $Row.FilePath
                        write-host $FileName
						Copy-Item -path $FileName -Destination "$desktoppath\Videos\"
					}
				}
			}
		}
		catch{
            [string]$ErrorText = $Error[0].CategoryInfo.Reason
            Write-Warning $ErrorText		
		}
}

cls
$DesktopPath = [System.Environment]::GetFolderPath([System.Environment+SpecialFolder]::Desktop)
if (test-path "$DesktopPath\Videos"){remove-item "$DesktopPath\Videos" -recurse -force}
write-host ""
write-host "Default is (U)ser Search"
$ClientorUser = Read-Host -prompt "Search for (C)lient or (U)ser? "
if ($ClientorUser -match "c"){
	$NameSearch = Read-Host -Prompt "ClientName to search for"
	$strTable = "Client"
	} else {
	$NameSearch = Read-Host -Prompt "UserID to search for"
	$strTable = "UserAccount"
}
write-host ""
$days = Read-Host -Prompt "How many days to search"
$days = -1 * $days
$Query = "Select 
	[$strTable].Name,
	[ICLFile].FilePath,
	[ICLFile].LoginTime
	From [ICLFile] Inner Join [$strTable] on [ICLFile].$($strTable)ID = [$strTable].ID
	where [$strTable].Name like '$NameSearch' and LoginTime >= dateadd(day,$days,GetUTCDate())"
md "$DesktopPath\Videos"

Write-host "Checking $DBName on $DBServer"
GetInfo $Query $DBName $DBServer

pause
👍 1
👍🏻 1