DTR Vantage

XenServer Pools

Select a pool to open its page: health, hosts, VMs, storage and the console.
Pick a pool, host, VM, storage repository or network in the tree on the left.
Recent tasks
No operations yet.

Hosts

Pool

Pool

Pick a pool.

Notifications & Events

Important alerts from each pool and appliance.

Events from the health report

NetScaler overview

Select an appliance to explore its topology, virtual servers, and network configuration.

Analyze

Pick an analysis and the appliances to run it on; every HA pair answers with its own verdict, from the records held here (Restart analysis reads both nodes of each pair).
Appliances ·

Certificates

Every SSL certificate installed across the fleet, with what is about to expire first.

NetScalers

Citrix ADC load-balancer health via SSH + nscli. Authenticate per appliance with the dashboard's SSH key (nsroot), the shared service account, or an appliance-specific password (stored encrypted). HA pairs are detected automatically and shown as one entry; organize the fleet with categories. Virtual servers, service groups and their members, and standalone services. Polled every 5 min. State changes also appear in the header bell.

Uptime monitor

Monitor any host or IP by ICMP ping, TCP port, UDP, SMTP or HTTP(S). Live status streams in real time; up/down and latency are tracked with a 24-hour uptime figure.
Loading…

Syslog messages

Receiver status…
Loading…

Session performance

Reading…

Identity threat

Reading…

NetScaler Gateway

HDX Insight data

Reading…

Capture

Decoded records

What this is

NetScaler exports its AppFlow (IPFIX) records to this host. The decoder reads gateway sign-ins, ICA launches and sessions as they arrive, written against one capture from a real gateway (2026-09-14) and nothing else: every field it names was named from that capture's values, and a record kind it has not seen is counted, not guessed at. The per-session HDX metrics (round trip and bandwidth, one record a minute) arrive once the AppFlow policy is bound at the gateway's ICA_REQUEST point as well, which Configure a NetScaler does (confirmed on 2026-09-15). The raw capture is kept untouched, and Decode the kept capture reads it into the tables again.

Configured Pools

Add, edit, or remove pools that this dashboard monitors.

Settings

Runtime values that take effect immediately — no service restart needed.

Collection

minutes (1 to 1440)
minutes (1 to 1440)
hours (1 to 168)
hours (default 6; each agent asks Windows Update what is pending on this cadence, and at once when Scan now is pressed)
seconds (5 to 300)

Data retention

days (0 to 3650; 0 means forever)
days (default 14; 0 means forever; the decoded HDX Insight records follow it)
MB (default 64; 0 keeps the file growing to its 256 MB stop; the HDX records are decoded as they arrive, the file is for Download and Decode the kept capture)

Console

Off by default. Who is on a console, an administrator's Take over and Send text stay available on every VM's Console tab either way.
A Hyper-V guest's screen is Remote Desktop on the host (VMConnect), which a browser cannot draw on its own. Myrtille is an open-source HTML5 Remote Desktop gateway (Apache 2.0, FreeRDP underneath) installed on this IIS beside Vantage; with its address here, a guest's Connect offers the screen in the browser. The sign-in is your own Windows account, typed in Myrtille's page and never held here; the account needs Hyper-V Administrators on the host, or access to the VM by Grant-VMConnectAccess. Empty turns it off.
The console draws what the last scan stored. A pool is rescanned the moment one of its tasks finishes, and on this cadence besides, so the tree is current without anyone asking. A scan is a read of the pool's records, a second or two.
Reading…
A recipe is typed where the guest's cursor is; it cannot open a prompt or run elevated on its own, so say what it needs.

Geolocation

Where an address is -- country, region, city, network -- on the Identity threat and HDX Insight data pages, beside every source address. The Windows servers' feeds carry it from their agent.
Reading…
An .mmdb, or MaxMind's tar.gz as downloaded. It is sent in 8 MB pieces, so a proxy's request limit does not apply (IIS refuses a single request over 30 MB). A file copied into the install folder as geoip.mmdb is picked up on its own.
Download from MaxMind -- the database straight from your MaxMind account over their download API, and again on a schedule so it stays current. GeoLite2 needs a free MaxMind account and a licence key from it; the key is stored encrypted on this host and never shown again.
Reading…
Only the address leaves this host, at most 25 per pass, cached 30 days. The default is the provider the Windows agent uses; a provider swap is a URL change, the fields are read by their usual names.

Auto-deploy

When enabled, the dashboard uploads its embedded copy of the health-check script to each coordinator on enrollment, and re-uploads when the SHA-256 differs (e.g. after a dashboard upgrade ships an updated script). Disable only if you manage XenServerHealthCheck.sh via configuration management.
The most recent report is kept on the coordinator so you can inspect it directly via SSH. Older reports are pruned after each successful import (the raw markdown is already stored in the dashboard's database). Disable only if some other tool reads the full history of those files.
Embedded script SHA-256: ...

Health-check thresholds

These values are passed to XenServerHealthCheck.sh as environment variables on every run, so changes take effect on the next collection (no script re-upload needed). All values are integer percentages or multipliers.
%
%
%
%
%
%
x vCPU
x vCPU
%
minutes
Note: warning thresholds must give you headroom before critical. For free-space and free-memory, warn % must be higher than critical %. For disk usage and load multiplier, warn must be lower than critical.
Backup & restore
Export this box's full configuration — pools, NetScalers, monitors, settings, branding, AD mapping, collected history, and the SSH key — as a single file. Import restores a backup onto this box (or clones another box's setup here).
Sensitive: the backup file contains the SSH private key that grants root access to your pools. Store and transfer it securely — treat it like a password.

Authentication & Authorization

Configure Active Directory connectivity and which AD groups map to dashboard roles. Changes apply immediately to new logins.

Active Directory

For a directory behind a VIP / load balancer whose certificate can't match the dialed address. The connection stays encrypted, but the server certificate is not verified.
Staying signed in A session is an idle timeout: as long as a dashboard window is open and visible it keeps itself alive, so nobody gets signed out mid-shift. These two settings decide what happens after that.
Counted from the last request this browser made, not from when you signed in.
The stay-signed-in credential is a random token, stored here only as a hash and replaced every time it is used, so a copied cookie stops working as soon as the real browser comes back. Signing out revokes it. Setting this to 0 revokes every one that is currently issued. It is never given out on Windows-authenticated installs, which re-authenticate on every request anyway.
Tests the values above (even unsaved) by binding once.

Service accounts

One credential per product, used for its ongoing work and stored encrypted on this host. Neither is ever shown again and no endpoint returns either password. These are not the credentials anyone signs in with, and not the admin credentials used to install an agent — those are typed at the moment of use and never stored.
NetScaler appliances One credential for every appliance set to Service account (shared). Read-only on the appliances: collection only reads. Update the password here once and all of them use the new one on their next connection — no per-appliance edits. Stored encrypted; never shown again.
Configuration account NetScaler configuration from Vantage is a licensed feature. It uses a separate read-write account, only when an administrator changes an appliance's configuration — never by collection, which stays on the read-only account above. Stored encrypted, never shown again. Leave the username empty and save to remove it.
Windows Infrastructure agent One credential for the agent service on every monitored Windows server. It needs “log on as a service” and read access to the agent folder — nothing more. Changing it here applies to servers deployed from now on; those already deployed keep the account they were installed with until they are redeployed. Stored encrypted; never shown again.

Role mappings

Add AD group names (sAMAccountName, e.g. XenServer-Admins) that should grant each role. Highest role wins if a user is in multiple. Group names are matched case-insensitively.

Admin

admin Everything Operator can do, plus: configure authentication, install licenses, manage NetScaler certificates, and configure/remove NetScaler syslog

Operator

operator Everything Viewer can see, plus: enroll/edit/delete XenServer pools, trigger collections, and mark NetScaler config changes as read

Viewer

viewer Read-only across all modules: XenServer pools, NetScaler topology & stats, uptime monitors, syslog, and reports

Setup account

A local fallback account used to bootstrap the dashboard. Disable it once your AD groups are configured and working.

Windows notifications

Open event-log alerts, reboots pending, agents not reporting, collectors running blind and sign-in attacks, across every Windows server.
Loading…

Windows certificates

Every certificate the inventory read from the servers' machine stores (My, WebHosting, Remote Desktop), with what expires first and which IIS sites use it.

Hyper-V

The Hyper-V hosts among the servers and the guests each lists, with which guests report to Vantage. A guest or a host opens its page: Hyper-V Manager's actions and settings, run on the host as you.
Loading…

Windows Update

What every server is waiting to install, where it gets updates from, and when it last did -- from the agents' scans. Install now or at a time, across the servers you pick, staggered, with a reboot after each if you want one; each run is as you, by delegation, no password stored.
Loading…

Agents

Every server's agent: its build against the one this Vantage ships, when it last reported, and what it cannot see. Deploying to a Hyper-V host's guests is on that host's page.
Loading…

Windows Infrastructure

Windows servers reporting through the DTR Vantage agent: OS health, event-log alerts, and credential-attack detection. Inventory — software, certificates, services, IIS — is read separately over WinRM and needs no agent.

Monitored servers

Tick a row to act on it. Click one to open it.