---
title: "Managing User Audit Logs for SSH Connection Attempts to Devices"
canonical: "https://docs.infoblox.com/space/NetMRI753/41945157/Managing%20User%20Audit%20Logs%20for%20SSH%20Connection%20Attempts%20to%20Devices"
format: markdown
---
To track what NetMRI or its users are doing on the network, you can also view the audit logs for all events in which NetMRI or its users attempt to use SSH or Telnet sessions to network devices. The amount of data collected for such events can substantially impact the size of the collected event database, so you can switch this feature on and off when needed and change the duration of these events being held in the database. Connection events that are covered by this log category include SSH/Telnet connections for Config Collection, Credential Collection, terminal emulation, and Job Engine Run connections. Unknown connections may also be recorded, which will be events such as API calls.

To view and change these settings, go to the **Settings** icon > **General** **Settings** > **Advanced** **Settings** > **Notification** category > **Log** **All** **CLI** **Sessions**. The default value is **On**. You can also choose the **No** **Commands** **Logged** option, which retains the session events but prevents any sensitive CLI data from being recorded.

An associated Advanced Setting, **Prune** **CLI** **Session** **Duration**, enables you to regularly prune the amount of CLI session data by setting the retention time for keeping that data in the Device Audit Log. The default setting is 7 days.