DTR Vantage

Licensing portal ↗Request a demo

VDA and NetScaler session diagnostics

The same session seen from the VDA and from the gateway, what each side can tell you on its own, and what the two together settle.

Two clocks
one row
the VDA's counters and the gateway's metrics on the same session
Round trip
both ends
the VDA's ICA RTT beside the gateway's per-minute RTT
Join
3 keys
user · client ip:port · the VDA's address
Stored
your server
the database on the VM, 7 days of samples and the syslog retention
Honest
always
not read is said, with the reason
The direct answer. The VDA perspective tells you what the session is doing: its CPU, memory and disk, its logon time, and the ICA round trip and bandwidth as the VDA measures them. The NetScaler perspective tells you what the session's path is doing: which gateway and virtual server it came through, the client's address, the VDA it was sent to, a round trip and bytes each way once a minute, reconnects and the close. Vantage joins them by user and by the connection's client address and port. When both round trips are low and the user is still waiting, the session's own CPU or disk is the suspect; when the gateway's round trip climbs while the VDA's counters read normal or are not read, the path or the connection is; when the VDA's session exists but the gateway holds no connection, the user came in another way.

The VDA perspective

WhatSource on the VDAWhere it shows
Who is signed in, since when, from which clientquser, the Terminal Services API, the console session, the ICA counter instance nameSession performance, the sessions table; the server page's Sessions fold
Logon durationRDS LocalSessionManager events 21 and 22the sessions table
CPU, memory, disk per sessiontwo raw process-counter samples a second apart, grouped by sessionthe charts per user
ICA round trip and bandwidththe ICA Session counter object, per instancethe round trip chart against 150 ms; the bandwidth chart
What the box is likeservices, disks, reboot pending, event log rules, certificates, the Citrix rolethe server's verdict and reasons

The NetScaler perspective

WhatSource on the applianceWhere it shows
The sign-inAppFlow sign-in record; syslog LOGIN / LOGIN_FAILED with the appliance's reasonHDX Insight sign-ins; Session performance's Gateway connections; Identity threat
The launch and the sessionAppFlow launch and session records; syslog ICASTART / ICAEND by ICA UUIDHDX Insight launches and sessions
The connection to the VDAAppFlow ICA connection record: gateway session, client ip:port, VDA ip:portthe ICA sessions table, with the VDA named
Round trip and bytes, once a minuteAppFlow ICA metric recordthe ICA session's chart
Reconnects and the closethe ICA start record seen again with a new client port; the close record with its codethe ICA sessions table's State column
The appliance itselfthe poll over SSH and NITRO: CPU, memory, disk, HA, certificates, the gateway's bindings and STA serversthe appliance's page; Analyze

Reading both together

SymptomVDA sideGateway sideWhat it points at
Slow session, user on the LAN through the gatewayRTT 67 ms, CPU 90 % in that sessionRTT 61 ms per minute, bytes normalthe session's own load: end the process, or the VDA is oversubscribed
Slow session from a remote siteRTT 240 ms, CPU lowRTT 230 ms, bytes lowthe path: both ends agree; look at the client's link, not the VDA
Session freezes, then comes backcounters not read for the minutes betweenreconnects counted, the close record with its code, a new client portthe connection dropping: the client's network or the gateway's DTLS / TCP profile
User says they cannot get inno session rowa sign-in with the failure code, or a sign-in and no launchthe credential or the store / broker: see failed launches
A session exists with no gateway connectiona session row named from the countersnothing for that userthe user came in directly (RDP, an internal StoreFront), not through the gateway

The figures are illustrative; the rows are the cases the product was built to tell apart.

What each side needs, and its limits

VDA side. Windows Infrastructure licence, the agent on the VDA with the Citrix role VDA. Limits: the ICA counters exist only while an ICA connection is up; the agent is not an administrator, so the session list can come from the counter instance rather than quser, and the page names which; no client-device measurements.
Gateway side. NetScaler monitoring and NetScaler Data Analytics licences, AppFlow bound at Request and ICA Request, syslog to the receiver. Limits: the decoder was written from captures on NetScaler 14.1; a record it cannot read cleanly is counted as unreadable with its bytes shown; an exporter that is not an enrolled appliance is listed as such, never guessed.

Checked against build b429, 2026-09-21. Where a statement is product knowledge rather than a tested capture, it says so.

The HDX Insight page in the demo ↗Session-performance monitoringFailed launchesAgainst uberAgent, ControlUp and eG