Select a pool to open its page: health, hosts, VMs, storage and the console.
Pick a pool, host, VM, storage repository or network in the tree on the left.
▾ Recent tasks
No operations yet.
Findings over time
Overall verdict over time
Host resources over time
Per-host CPU load, memory and disk use, one sample per health report, for the last 7 days.
Select a pool to load host history.
Pick a pool.
Notifications & Events
Important alerts from each pool and appliance.
Events from the health report
NetScaler overview
Select an appliance to explore its topology, virtual servers, and network configuration.
Manage certificate
Automated renewal
Renews a certificate through ACME — the protocol Let's Encrypt, DigiCert and
InCommon's CertiNext all speak. The private key is generated on the appliance and
never leaves it; only the signing request travels. The certificate is replaced with
update ssl certKey, which keeps every existing binding, so
the virtual server is never without one.
Certificate authority
Loading…
Register with the CA (External Account Binding)
Commercial CAs — InCommon included — tie an ACME account to your subscription with a
key identifier and an HMAC key from their portal. These are used once and never
stored. ACME consumes them when the account is created and never asks again; if the
account key is ever lost you paste them again.
Renew a certificate
The challenge is answered by a temporary responder policy on that virtual server, bound at
priority 1 and removed afterwards — whatever the outcome. It must be the server the CA
reaches on port 80 for these names; Vantage will not guess which one that is.
Migrate configuration
Copies an appliance's configuration onto a new one, line for line, from its own
show ns runningConfig. The new appliance's NSIP, hostname,
HA setup and licensing are never touched — it keeps its own identity. Nothing is
applied until you review the plan and confirm.
→
Build NetScaler report
Generate a history & stats report over a date range. Pick the appliances, time window, and sections to include, then export as HTML or PDF.
Today by default. A longer period reads every collection in it (a month is about 8,600 per appliance at the default poll) and takes a few minutes; what is being read is shown below while it runs.
Sections marked NITRO read live
from the appliance over its REST API and need NITRO enabled on it
(appliance view › NITRO ACCESS). An appliance without it is filled from
its last SSH poll instead, and the report says so.
NITRO access —
NITRO is the appliance's REST
API. It is used for certificate expiry, HA config-sync state and interface
error counters — the things
nscli does not report in a
form that can be parsed reliably. Routine collection still runs over SSH.Signs in
with the appliance's password credential, or the shared NetScaler service
account where the appliance uses an SSH key. Nothing extra is stored, and
the account only needs read access: collection only reads. Configuration
changes (a licensed feature) use a separate configuration account from
Settings, never this one.
Analyze
Pick an analysis and the appliances to run it on; every HA pair answers with its own verdict, from the records held here (Restart analysis reads both nodes of each pair).
Appliances
·
Certificates
Every SSL certificate installed across the fleet, with what is about to expire first.
NetScalers
Citrix ADC load-balancer health via SSH + nscli. Authenticate per appliance with the dashboard's SSH key (nsroot), the shared service account, or an appliance-specific password (stored encrypted). HA pairs are detected automatically and shown as one entry; organize the fleet with categories. Virtual servers, service groups and their members, and standalone services. Polled every 5 min. State changes also appear in the header bell.
Uptime monitor
Monitor any host or IP by ICMP ping, TCP port, UDP, SMTP or HTTP(S). Live status streams in real time; up/down and latency are tracked with a 24-hour uptime figure.
●
Loading…
Add target
Uptime report
Syslog messages
Receiver status…
Loading…
Session performance
Reading…
Identity threat
Reading…
NetScaler Gateway
HDX Insight data
Reading…
Capture
Decoded records
What this is
NetScaler exports its AppFlow (IPFIX) records to this host. The decoder reads gateway sign-ins, ICA launches and sessions as they arrive, written against one capture from a real gateway (2026-09-14) and nothing else: every field it names was named from that capture's values, and a record kind it has not seen is counted, not guessed at. The per-session HDX metrics (round trip and bandwidth, one record a minute) arrive once the AppFlow policy is bound at the gateway's ICA_REQUEST point as well, which Configure a NetScaler does (confirmed on 2026-09-15). The raw capture is kept untouched, and Decode the kept capture reads it into the tables again.
Configure a NetScaler to send HDX data here
Pushes an AppFlow collector aimed at this host's capture port, an action and a policy, binds the policy to the gateway virtual servers ticked below at both bind points (Request and ICA Request; the second is what carries the per-session HDX metrics) and turns their AppFlow logging on, sets the template refresh, then runs save ns config. Over SSH, one command at a time; each step's outcome is the appliance's own words. The capture here must be listening for anything to arrive.
Compare configurations
Compares two imported ns.conf configs line by line. Volatile and secret fields — passwords, keys, certificate material, sequence numbers, per-node IDs — are excluded so only meaningful differences show. System time is shown for reference.
Configure a NetScaler to send logs here
This pushes an audit syslog action, policy, and global bind onto the appliance over SSH, then runs save ns config. The appliance will start sending its logs to this dashboard.
Binds to audit syslogGlobal (the correct audit bind point), falling back automatically on old firmware. Tick “Force classic bind” only to force bind system global.
Configured Pools
Add, edit, or remove pools that this dashboard monitors.
Settings
Runtime values that take effect immediately — no service restart needed.
Collection
minutes
(1 to 1440)
minutes
(1 to 1440)
hours
(1 to 168)
hours
(default 6; each agent asks Windows Update what is pending on this cadence, and at once when Scan now is pressed)
seconds
(5 to 300)
Data retention
days
(0 to 3650; 0 means forever)
days
(default 14; 0 means forever; the decoded HDX Insight records follow it)
MB
(default 64; 0 keeps the file growing to its 256 MB stop; the HDX records are decoded as they arrive, the file is for Download and Decode the kept capture)
Console
Off by default. Who is on a console, an administrator's Take over and Send text stay available on every VM's Console tab either way.
A Hyper-V guest's screen is Remote Desktop on the host (VMConnect), which a browser cannot draw on its own. Myrtille is an open-source
HTML5 Remote Desktop gateway (Apache 2.0, FreeRDP underneath) installed on this IIS beside Vantage; with its address here, a guest's
Connect offers the screen in the browser. The sign-in is your own Windows account, typed in Myrtille's page and never held here;
the account needs Hyper-V Administrators on the host, or access to the VM by Grant-VMConnectAccess. Empty turns it off.
The console draws what the last scan stored. A pool is rescanned the moment one of its tasks finishes, and on this cadence besides, so the tree is current without anyone asking. A scan is a read of the pool's records, a second or two.
Reading…
A recipe is typed where the guest's cursor is; it cannot open a prompt or run elevated on its own, so say what it needs.
Geolocation
Where an address is -- country, region, city, network -- on the Identity threat and HDX Insight data pages, beside every source address. The Windows servers' feeds carry it from their agent.
Reading…
An .mmdb, or MaxMind's tar.gz as downloaded. It is sent in 8 MB pieces, so a proxy's request limit does not apply (IIS refuses a single request over 30 MB). A file copied into the install folder as geoip.mmdb is picked up on its own.
Download from MaxMind -- the database straight from your MaxMind account over their download API, and again on a schedule so it stays current. GeoLite2 needs a free MaxMind account and a licence key from it; the key is stored encrypted on this host and never shown again.
Reading…
Only the address leaves this host, at most 25 per pass, cached 30 days. The default is the provider the Windows agent uses; a provider swap is a URL change, the fields are read by their usual names.
Auto-deploy
When enabled, the dashboard uploads its embedded copy of the health-check script to each coordinator on enrollment, and re-uploads when the SHA-256 differs (e.g. after a dashboard upgrade ships an updated script). Disable only if you manage
XenServerHealthCheck.sh via configuration management.
The most recent report is kept on the coordinator so you can inspect it directly via SSH. Older reports are pruned after each successful import (the raw markdown is already stored in the dashboard's database). Disable only if some other tool reads the full history of those files.
Embedded script SHA-256:
...
Health-check thresholds
These values are passed to
XenServerHealthCheck.sh as environment variables on every run, so changes take effect on the next collection (no script re-upload needed). All values are integer percentages or multipliers.
%
%
%
%
%
%
x vCPU
x vCPU
%
minutes
Note: warning thresholds must give you headroom before critical. For free-space and free-memory, warn % must be higher than critical %. For disk usage and load multiplier, warn must be lower than critical.
Backup & restore
Export this box's full configuration — pools, NetScalers, monitors, settings, branding, AD mapping, collected history, and the SSH key — as a single file. Import restores a backup onto this box (or clones another box's setup here).
Sensitive: the backup file contains the SSH private key that grants root access to your pools. Store and transfer it securely — treat it like a password.
Authentication & Authorization
Configure Active Directory connectivity and which AD groups map to dashboard roles.
Changes apply immediately to new logins.
Active Directory
For a directory behind a VIP / load balancer whose certificate can't match the dialed address. The connection stays encrypted, but the server certificate is not verified.
Staying signed in
A session is an idle timeout: as long as a dashboard window is open and visible it keeps itself alive, so nobody gets signed out mid-shift. These two settings decide what happens after that.
Counted from the last request this browser made, not from when you signed in.
The stay-signed-in credential is a random token, stored here only as a hash and replaced every time it is used, so a copied cookie stops working as soon as the real browser comes back. Signing out revokes it. Setting this to 0 revokes every one that is currently issued. It is never given out on Windows-authenticated installs, which re-authenticate on every request anyway.
Tests the values above (even unsaved) by binding once.
Service accounts
One credential per product, used for its ongoing work and stored
encrypted on this host. Neither is ever shown again and no endpoint
returns either password. These are not the credentials anyone
signs in with, and not the admin credentials used to install an agent —
those are typed at the moment of use and never stored.
NetScaler appliances
One credential for every appliance set to Service account (shared).
Read-only on the appliances: collection only reads. Update the password here
once and all of them use the new one on their next connection — no
per-appliance edits. Stored encrypted; never shown again.
Configuration account
NetScaler configuration from Vantage is a licensed feature. It uses a
separate read-write account, only when an administrator changes an
appliance's configuration — never by collection, which stays on the read-only
account above. Stored encrypted, never shown again. Leave the username empty
and save to remove it.
Windows Infrastructure agent
One credential for the agent service on every monitored Windows server.
It needs “log on as a service” and read access to the agent folder —
nothing more. Changing it here applies to servers deployed from now on;
those already deployed keep the account they were installed with until
they are redeployed. Stored encrypted; never shown again.
Role mappings
Add AD group names (sAMAccountName, e.g.
XenServer-Admins) that should grant each role.
Highest role wins if a user is in multiple. Group names are matched case-insensitively.
Admin
admin Everything Operator can do, plus: configure authentication, install licenses, manage NetScaler certificates, and configure/remove NetScaler syslogOperator
operator Everything Viewer can see, plus: enroll/edit/delete XenServer pools, trigger collections, and mark NetScaler config changes as readViewer
viewer Read-only across all modules: XenServer pools, NetScaler topology & stats, uptime monitors, syslog, and reportsSetup account
A local fallback account used to bootstrap the dashboard. Disable it once your AD groups are configured and working.
Validate groups against AD
Confirms each AD group name above actually exists in the directory. Your password is used once to bind, then discarded — not stored. Validation is informational; you can still save groups that don't exist yet.
Test AD connection
Binds to the domain using the values entered above (Domain, LDAP server(s), Search base) — even if you haven't saved them yet. Enter an AD account to bind with; its password is used once, then discarded — not stored.
Loading…
Loading…
Loading…
Loading…
Monitored servers
Tick a row to act on it. Click one to open it.
Deploy agent to
Runs from the Vantage host over WinRM. These credentials are used for
this deployment only — they are not stored, and Vantage keeps no
copy once the run has started. The agent service afterwards runs as the
shared service account, not as this admin.
Deploying rotates this server’s secret. The agent already on it
stops being accepted the moment this starts, and stays that way until
the deployment finishes.
Build a Windows infrastructure report
Choose what goes in it. Sections you leave out are not collected, not
summarised and not mentioned.
Title
Servers
Sections
Administrator credentials
Run diagnostics on
Runs one collection cycle on the server, now, in the foreground, and
shows exactly what it said. Nothing is copied, no secret is rotated and
the service is not touched — so there is nothing to undo if it
fails. The credentials are used for this run only and are not stored.
This goes to the machine directly.
The agent calls Vantage, never the other way round, so the only thing
Vantage can normally do is answer the agent’s next check-in
— which is what Health now does. That needs the agent to be
reporting. When it is not, this is the way in, and Windows wants an
identity with rights on the box. Where delegation is in place that is
you, with no password; where it is not, an administrator account
is needed for this run only. The service account is deliberately not one:
it is a plain user, so a password stored for monitoring is
not a password worth stealing.
Inventory across the estate
Read over WinRM, on a schedule,
with no agent involved. Vantage tries its own computer account first, then
the shared service account; a run you start here uses your own account
where the target allows it.
Update agents
Each server is updated in turn, and each one’s secret is rotated as
it starts. A server whose update fails stops reporting until it is
deployed again — the run says which ones those were.
Shadow
Joins the user’s session from your own workstation, with your own Windows sign-in: run one of these there. Vantage reads whether the server allows it and can set that; it cannot open the session itself, since a browser cannot start mstsc.
Reboot
Runs as you, by delegation. Sessions with unsaved work lose it whichever you choose.
Deploy the agent to virtual machines
Remove
Its metrics and alert history are deleted and cannot be recovered.
Vantage removes the server from its own records only after the agent is
actually gone from the machine. If the uninstall fails, the server stays
here and says why.
Job
Edit
Applied on this server’s next report — the agent adopts its
configuration from Vantage, so none of this needs a redeploy. The server
name cannot be changed: it is the identity the agent was deployed with.