Documentation
Every view and setting, in the order you meet them. The same text ships inside the dashboard under Help.
One dashboard for the infrastructure you already run — Citrix NetScaler / ADC, XenServer pools, Hyper-V hosts and Windows servers, plus uptime targets, syslog and the analytics the gateways and VDAs can give you — collected on a schedule, shown live, and run entirely on your own server.
NetScalers and XenServer pools are read without agents: Vantage connects out from one Windows server over SSH, NITRO REST and XenAPI, stores what it reads locally, and renders it. Windows servers report through a small PowerShell agent that Vantage deploys from the dashboard and that runs as a least-privilege service account.
Reading is the default. Where you license a management module — NetScaler Configuration, the XenServer Console, the Hyper-V Console, Windows Update — the same pages carry the controls, every change is confirmed in words, and every change is logged with who made it and what the system answered. See Licensing for the module list.
The product tabs
Across the top are the products: XenServer Pools, NetScalers, Uptime, Data analytics and Windows Infrastructure. A tab you have not licensed shows a 🔒 badge. Click one to switch the whole workspace to that product; the left sidebar then shows that product's views.
The sidebar
XenServer, NetScaler and Windows share one shape: a narrow icon rail (Overview, Certificates, Notifications, Analyze, Console, Agents, Windows Update, Identity threat — whichever the product has) beside a tree of your pools, appliances or servers grouped by category, with a search box. The button above the divider folds the tree away and leaves the rail. Data analytics and Uptime are plain lists of views.
Header tools
The header shows how fresh the data on screen is, a Tasks pill for anything running in the background (reports, deploys, XenServer operations) with Cancel, Refresh, Help (this documentation), Settings (admins), and your name, role and Sign out.
These are two different operations, because what they cost is not the same.
Refresh redraws the screen from data Vantage has already collected. It is instant, and it never opens a connection to an appliance — so it cannot make what you are looking at any newer than the last poll. Next to it is the thing that answers "am I looking at current data": the age of the data on screen. On the NetScaler side that is a range, because a fleet is polled on a rolling schedule.
Polling is the scheduled collection. Operators can force one (Poll now, Rescan, Collect now, depending on the product), and the XenServer console additionally follows the pool's own event stream, so a VM that changes state shows within seconds.
HA pairs count as one. Vantage reads the full picture from the primary of a pair and probes the standby, so the pair is as fresh as its freshest half. An appliance that did not answer its last poll is named, with the reason, rather than shown with stale numbers.
Three roles, from least to most privileged:
| Role | Can do |
|---|---|
| Viewer | Read every enabled view: overviews, pages, trends, analytics, notifications, reports. Cannot change anything or trigger a collection. |
| Operator | Everything a viewer can, plus on-demand collection, the pool / appliance / target / server lists, NetScaler reports, the restart analysis, XenServer VM operations that do not destroy data, and the read-only side of the NetScaler object editor. |
| Admin | Everything, plus Settings, licensing, TLS, agent deployment, NetScaler configuration writes, gateway blocking enforcement, Windows Update installs, Hyper-V changes, and the data-destroying XenServer actions (delete, revert, host power). |
Roles map to Active Directory groups — see Mapping AD groups to roles. Admin-only controls are hidden from other roles on the page and refused on the server.
The landing view for XenServer. A summary strip totals pools by health, hosts up vs. down, and findings by severity. Below, one card per pool, grouped by category, in Tiles or Detail form.
Reading a pool card
- The card's colour is the pool's verdict: green healthy, amber needs attention, red action required. Every verdict comes with its reasons, and the same rule draws the card, the sidebar and the pool page.
- A pool that has never reported, or whose report is older than twice the collection interval, says so.
- Click a card to open the pool's page. Click a reason and you land on the host, finding or repository it names, highlighted.
Trends draws per-host CPU, memory, disk and load over time from the readings kept at every collection.
The page is the pool: its verdict and reasons at the top, the console's tiles (hosts, VMs, storage, networks, templates — each opening the fold that holds its figure), then one card of folds: pool details, updates, networks, licensing and alerts, followed by the health report's hosts, storage, findings, notifications and the full rendered report.
Folds arrive collapsed and remember their state per pool. The full report is drawn the dashboard's way: metadata strip, verdict, a row per finding with its recommendation, tinted by severity.
Updates shows the pool's update readiness and, with the console licensed, applies updates host by host (see XenServer Console).
Under Manage pools you enroll and remove pools and set their category.
Enrolling a pool
- Add the pool's coordinator address and a label.
- The dashboard offers to install its public key into the coordinator's
authorized_keys. You enter the root password once; it is used only to install the key and is then discarded — never written anywhere. From then on the health check runs over that key. - For the console, add a XenAPI credential. It is stored encrypted with a key that never leaves the server, and the coordinator's certificate is pinned by its SHA-256 the first time it is used. A changed certificate is refused until an administrator accepts it by hand; a credential never reaches a certificate Vantage has not seen.
Collecting on demand
Operators and admins see Collect now and Rescan pools. Normal collection runs on the configured interval; the console's inventory is also rescanned whenever the pool's event stream reports a change, and every few minutes as a safety net.
Licensed as XenServer Console. XenCenter's pages and menus, in the browser. The sidebar tree lists every pool's hosts, VMs, templates, storage repositories and networks, kept live; right-click anything for its actions, or open its page.
Virtual machines
Start, shut down, reboot, suspend, resume, migrate, snapshot, revert, copy, convert to template, delete — each a confirmation in words and then a task whose outcome is the pool's own answer. VM properties is one dialog for name, description, folder, tags, vCPUs, memory, home server, HA priority, boot order, and the disk and NIC tables with their actions. Changes are judged against the live record and only the fields that differ are written; shape changes (vCPUs, memory) are refused on a running VM before anything is written.
The console screen
The Console tab is the VM's screen over VNC, relayed by the Vantage server through the pool's pinned session. The toolbar has Connect, Ctrl+Alt+Del, Full screen, an Options menu (fit, resize the guest, mouse capture, USB tablet), Send text (types text into the guest as keystrokes), Fixes (named command recipes typed line by line — the built-in Windows network reset, DNS flush, WinRM enable and others, plus your own from Settings), Detach to a window of its own, and, for admins, Take over when someone else is on the same screen. The status line says which pointer mode the guest reports and whether the mouse is captured.
Wizards and pool operations
New VM from a template (disks, network, ISO or install URL, start after create), New storage (NFS, iSCSI, SMB, ISO libraries; attach an existing repository), Add VLAN network, network and virtual-interface properties, host restart toolstack, SSH enable / disable, licence assignment, and Install updates: the pool syncs, readiness is checked, then each host is evacuated, updated, rebooted or its toolstack restarted as the update asks, and re-enabled, coordinator first, every step on the task log, Cancel between steps.
Above the appliance list is a row of cards for the whole fleet: appliances reporting, and the up / down / partial split for VIPs, service groups, services, content switches, gateways and GSLB. Every non-zero figure opens the objects it counted, across every appliance, with the box each one lives on; Copy list puts it on the clipboard for a change ticket. The counts and the lists are built by the same code on the server, deliberately, so a card never says "6 down" over a list of five.
The Detail table sorts by any column — address, name, state, version, last poll, the object counts — inside each category group. Each row carries its unread critical events. Build report opens the reports dialog for the fleet.
Opening an appliance gives you the pair's health and HA state, a live topology diagram, and category tiles for virtual servers, content switches, gateways, authentication (AAA) servers, service groups, services, GSLB, certificates, network (interfaces, VLANs, routes), high availability and resources — each with up / down / partial counts you can expand. Tiles can be arranged and the arrangement is remembered.
Two clocks per node
The High Availability tile prints, for both nodes, when the software started and how long the operating system has been up. A software start well after the boot is a restart of the software alone (a warm restart, an upgrade in place, a crash the watchdog recovered) and is marked as such. Resource history — CPU, memory, disks, interfaces — is kept per node at every poll and probe, so both halves of a pair have history.
Right-click a row
Every object row has a menu: Properties opens the object as the appliance reports it (read-only for operators; editable with NetScaler Configuration).
NITRO access
Each appliance can be read over NITRO REST as well as SSH. Test & enable on the appliance's page (or Enable NITRO on selected in the Appliances table) probes the API, records the certificate's SHA-256, and from then on refuses a changed certificate. Monitoring uses a read-only account; configuration uses a separate one.
The Analyze tile on an appliance's page, and the Analyze view on the rail for several pairs at once, answer questions as a verdict with a confidence, the evidence, what happened afterwards, and what would settle it. Every verdict says plainly that it is an estimate from the records held here, not a fact the appliance stated.
| Analysis | What it reads |
|---|---|
| Restart analysis | Both nodes' clocks; the syslog held on Vantage (every command line naming reboot, shutdown, install, upgrade, restart, kill, failover); the appliance's own audit log, crash dumps, rotated logs and the previous run's event log, read live; the firmware before and after. Pick a time range, or an event from the Around list of software starts, failovers and firmware changes Vantage has already identified. Verdicts include "an upgrade", "an operator restarted it: <user> ran <command>", "a deliberate restart of the pair", "a crash the watchdog recovered". |
| Failover analysis | Every role change over the last 90 days, each with its cause where one is in the records: a command, a software restart of the old primary, a firmware change, a link going down, the appliance's own HA lines. |
| HA analysis | Roles (split brain, no primary), sync state, a standby not probed, the two nodes' software ages, flapping over the last 7 days, each node's health. |
| Health and capacity | Today's figures, the last poll's failure, the certificate tally, and what is climbing over 7, 30 or 90 days: a disk that reaches its threshold within 30 days, memory rising like a leak, CPU busy for the window rather than a spike. |
Licensed as NetScaler Configuration. Writes go over NITRO, the appliance's own object model — the calls its GUI makes — so a firmware update moves the object model, not text parsers.
The configuration account
A separate read-write account, set under Manage NetScalers, must differ from the monitoring account, is never returned by any read, and is used only for explicit admin actions, never for collection. Nothing can be written without NITRO enabled and the appliance's certificate pinned.
What you can do
- From a tile row's menu: Enable, Disable, Bind / unbind a service or service group, Save config, and Properties — an editor drawn from the object as NITRO returns it, in the GUI's sections (Basic settings, Method, Persistence, Protection, Profiles, Push, Authentication, Traffic settings, SSL), with every binding list the GUI's page has: certificates and SSL, services, policies of every family, authentication, gateway settings (STA, intranet applications, bookmarks, portal theme, EULA), monitors, members. Bind, unbind, edit a binding's priority, open a bound policy and its action.
- Policies, actions and profiles are editors of their own.
- Apply sends only the fields that differ from a fresh read. A field the reference does not allow is refused in words.
- Certificate upload, gateway sign-in blocking (Identity threat), AppFlow export setup (HDX Insight) and Migrate config live on the same licence.
Every change is a row in the configuration log (who, what, the appliance's words) and an audit line. The Configuration bar on the appliance's page says whether the config is saved.
The Certificates view lists every certificate bound on every appliance with its expiry, expired first, then within 30, 60 and 90 days. The rail badge counts what has expired or expires within 30 days. The same appears per appliance on its Certificates tile, where a new certificate can be uploaded with the Configuration licence.
Operations reports
Build a report across one or more appliances for a date window: executive summary, incidents, uptime, resources and trends, certificates, HA and GSLB, interfaces, syslog activity, inventory. A report runs as a background job — the dialog counts the seconds and the Tasks pill offers the download even if you closed the dialog — so a month across a busy fleet finishes instead of timing out. Export as HTML or PDF; footers carry your branding.
Documentation export
Generate a standalone document for an appliance — topology diagram plus full text and tables — as HTML or PDF, from a live collection or an imported ns.conf. An optional AI pass adds prose summaries and findings.
Config compare and migration
Compare the running configuration between two appliances to spot drift, side by side. Migrate config copies an old appliance's configuration onto a new one, every command verbatim from the source's running config in its own order, with the identity commands (NSIP, hostname, HA node table, RPC passwords, licensing) blocked and named, and the whole plan shown before anything runs.
Each Windows server runs a small PowerShell agent as a Windows service. It runs as a shared, least-privilege service account — deliberately not an administrator, so that a password stored for monitoring is not a password worth stealing — and reports to Vantage over HTTPS on the collection interval, each report signed with a per-server secret.
The secret is shown once, at enrolment or redeploy, and never returned by any read. Rotating it keeps a grace window on the previous one so a server mid-update keeps reporting. A server whose report is late is marked not reporting; nothing on its page pretends to be current.
What the agent collects: OS health and reboot state, services, disks, event log alerts by rule, certificates, IIS sites and bindings, RDS, Citrix roles (StoreFront, Cloud Connector, Delivery Controller, VDA, licence server — detected, or set per server), Hyper-V guests, running applications with CPU and IO, failed sign-ins, and for VDAs the per-session performance. Some collectors need a right the account does not have by default (the Security log, Hyper-V); the deploy grants exactly those, and the page says when a collector is blind and why.
Add server asks for the server's name and your own credentials. Vantage connects over WinRM as you, enables remoting on the target if it is off, creates the service account's rights, installs the agent, starts it, and waits for the first report. Your password is typed per action, held in memory for the deploy, handed to the child process over stdin, and never stored; the audit line records your user name and "credential not stored".
Each deploy is a job with a live log on the Agents view or the server's page; a refusal (WinRM not listening, a rejected credential, a target that cannot be reached) is said in Windows' own words with the fix.
Update agents redeploys the shipped agent build to every server whose agent is older. The Agents view shows each server's build against the one shipped, which are older, and which are blind to a log.
Agentless: Inventory reads a server over WinRM without the agent (hardware, OS, roles, software, IIS configuration), on demand as you by delegation or on a schedule as the server's own identity.
| View | What it shows |
|---|---|
| Overview | The fleet by category with a verdict per server and its reasons; tiles that narrow the list to a state. |
| A server's page | The verdict and reasons, then folds: services, disks, alerts, certificates, IIS, RDS, Citrix, applications, sessions, identity threat, inventory, jobs. Admin-only actions (reboot, sign a user off, end a process, Remote Desktop, session shadowing) sit in the bar and in the folds, by delegation as you. |
| Hyper-V | The hosts running Hyper-V and their guests, matched to the servers that report; with the Hyper-V Console, the host and guest pages. |
| Certificates | Every certificate the inventory read, joined to the IIS bindings that use it, bucketed by expiry with a twelve-month calendar, exportable as CSV. |
| Notifications | Open alerts with filters (state, severity, server, search), plus the fleet's reboot-pending, not-reporting, critical, blind and sign-in-attack lists. |
| Agents | Every agent's build against the shipped one, older and blind marked, Update agents, Add server. |
| Windows Update | See Windows Update. |
| Identity threat | The servers' half of Identity threat. |
Licensed as Hyper-V Console. A guest's page and a host's page are live reads from the host, as you by delegation: state, generation, processors, memory and its dynamic range, checkpoints, adapters, disks, DVD drives, firmware, integration services; the host's folders, switches, adapters, live migration and NUMA settings.
Actions (power, checkpoints, rename, settings, adapters, disks, switches, new VM, remove VM, host settings) are admin, confirmed in words, and write only what differs from the live object. Right-click a host or guest in the sidebar tree for the same menu.
The guest's screen
Hyper-V exposes a guest's screen only as RDP to the host (VMConnect). Connect offers two ways: open the screen in the browser through a Myrtille gateway (an open-source HTML5 Remote Desktop gateway the installer can set up beside Vantage; you type your password into the connection form, which is posted straight to Myrtille and never stored by Vantage), or download the VMConnect .rdp file for your own client.
Licensed as Windows Update; reading the pending list needs only Windows Infrastructure. A scheduled task the deploy registers scans each server on your cadence (Settings → Windows Update) and the agent reports the result: pending updates with KB, severity, category and size, the source (WSUS, Windows Update for Business, Microsoft Update), reboot state, and the install history.
Select servers and Scan, Install now or Schedule (a start time, a stagger between servers, an optional reboot after each). Installs run as you by delegation, one server at a time, and the outcome is written per server. The Pending cell says apart nothing pending, not scanned yet, agent too old, stale, not reporting and scan failed.
Licensed as Syslog. Vantage runs a syslog receiver on the standard port (the installer opens the firewall rule). The Messages view lists what arrives with severity and source, searchable, with the full message on demand; retention is set under Settings → Data retention. From a NetScaler's page an admin can push the syslog configuration to the appliance in one step.
The same store feeds the identity threat rules, the restart analysis and the syslog section of reports.
Two halves, licensed apart: NetScaler Identity Threat (the gateways) and Windows Identity Threat (the servers). The page under Data analytics shows both; each product's rail shows its own half.
Gateways
Every minute Vantage scores the failed gateway sign-ins in the appliances' syslog per source address: failures, accounts tried, the appliance's reason, the browser, and the gateway they were aimed at. Ten failures or three accounts in an hour is an attack; private ranges, your allow list and the appliances' own addresses are never blocked. In report only mode the page shows what would be blocked. With enforcement switched on (per appliance, needs NetScaler Configuration) each appliance holds exactly the block list through a pattern set and a responder policy Vantage creates and maintains on every gateway; the CLI it writes is shown as written. A quiet address is unblocked after 24 hours; a block by hand never ages. Where the sources are comes from a local geolocation database (Settings → Geolocation).
Servers
The agent reads failed sign-ins from the Security log and, where RD Web Access is installed, the IIS logs, scores them the same way and blocks attacker addresses on the host's firewall. The Windows servers table shows each server's failures, blocks and where they came from; a row opens the server's Identity threat fold.
Licensed as NetScaler Data Analytics. NetScaler Gateway exports AppFlow (IPFIX) records about sign-ins, launches and ICA sessions; Vantage listens for them (UDP 4739 by default, on by default) and decodes what arrives.
Configure a NetScaler (admin, needs NetScaler Configuration) sets an appliance up to export to Vantage: the collector, action and policy, bound on each gateway you tick at both Request and ICA Request, every step's outcome in the appliance's words.
The Decoded records card shows gateway sign-ins, ICA launches, sessions and ICA sessions — the last with round trip (last, average, worst), bandwidth each way, reconnects and the connection's state, and a chart per session minute by minute. Type a user's name to narrow every table to them; click a column header to sort. The exporters table says which appliance sent what, and the raw capture can be downloaded or decoded again.
Licensed as NetScaler Data Analytics with Windows Infrastructure. Once a server's Citrix role is set to VDA, its agent reads every signed-in session's CPU, memory and disk, the ICA round trip and bandwidth from the VDA's own counters, and the logon duration. The view shows tiles, the sessions across every VDA, and per-user charts over 1 hour to 7 days: sessions, round trip against the 150 ms line, CPU, memory, bandwidth in and out. The gateway's side of each session (sign-in, launch, HDX metrics) sits beside it from HDX Insight.
A counter that could not be read, a session list that was refused, or a session nobody could name is said in one plain line, with the diagnostics behind a Details link for administrators.
Reachability checks for any target — a URL, host, port or mail server — independent of the other modules. Add a target with its address and check type; the monitor polls on the configured schedule, records up / down transitions and latency, and reports uptime over any window.
Checks: ICMP, TCP, HTTP(S), UDP and SMTP. A UDP check sends a real question where the port has one (a DNS query on 53, an NTP request on 123) and reads the answer; silence is down. An SMTP check holds the mail server's own conversation: the greeting must be 220, EHLO must be answered, and with STARTTLS (the default on 587) or TLS from the start (465) the handshake must complete; what went wrong is said in words (no greeting, STARTTLS not offered, a handshake failure, something that is not SMTP on the port). Uptime data feeds the NetScaler reports when both modules are licensed.
Internal and External
The Uptime sidebar has two views of the one list. Internal is your team's; External is what your company sees from outside. Tick targets and press Move to external (or Move to internal) in the selection bar to move them across; an operator may.
The company's status page
On the External view an administrator switches on Publish to the company portal and sets the cadence (30 s to an hour). The external targets, with their state, latency and 24-hour figure, are then sent to uptime.dtrvantage.com, and the portal serves them at a status link made for this installation: Get the status link asks for it, Copy and Open share it. Nobody signs up; the licence is the credential, and only a licence carrying the Uptime module can publish (the portal refuses otherwise, in words). The link is replaced on a schedule you set on the same card (Rotate the link every 24 h by default; 0 = never); a link replaced on schedule keeps working for an hour and says so, while Rotate link by hand kills the old one at once. Publishing is off by default and is the one timed contact the dashboard makes with the portal.
Each product has a Notifications view collecting the noteworthy events from its sources — for XenServer the pool's messages and task outcomes; for NetScaler state changes, HA role changes and failed polls; for Windows the agents' alerts and the fleet's reboot-pending, not-reporting and attack lists. Marking an event read persists, so a re-collection does not resurface what you have already triaged. Per-appliance muting is under Settings.
The installer is a single PowerShell file. Run it from an elevated prompt on a Windows Server. It installs Python silently if absent, places the app under C:\Program Files\DTR Vantage, registers the DTR-Vantage Windows service, opens the firewall rules (the dashboard port, the syslog and AppFlow receivers), and can set up IIS in front of the dashboard with HTTPS. Offline installs read Python, NSSM and the IIS pieces from a deps folder beside the script.
Full-auto install
.\DTRVantage-Setup.ps1 -InstallIIS -EnableHTTPS -NonInteractive
Useful switches: -PfxPath for your own certificate, -RedirectHTTPToHTTPS, -WindowsAuth for IIS single sign-on instead of the LDAP form, -MaxMindAccountId / -MaxMindLicenseKey or -GeoIPFile for the geolocation database, -InstallMyrtille for the Hyper-V browser console. An interactive run asks each of these.
After it finishes, browse to the dashboard, sign in with the setup account, connect Active Directory, install your licence, and enroll your first pool, appliance or server.
Updating
Under Settings → License and updates, Check for updates presents the dashboard's own key to the update service and says whether a newer build is published for it. Download fetches the package into the install folder's updates directory with its SHA-256 checked against the portal's answer. Install now hands it to a system task that runs the updater apart from the service — stop, back up, swap the files, restart, roll back on failure — and the outcome is written on the same page once the dashboard is up again (about a minute offline). A report that never came back can be cleared from the page.
By hand, as before: copy the package to the server and run Update-DTRVantage.cmd; it swaps the files, restarts the service, and keeps your configuration, enrolled systems, database, licence and branding. Then hard-refresh the browser. Agent-side changes additionally need Update agents on the Windows servers.
- A Windows Server VM (2019 or later) that can reach the systems you will monitor: XenServer coordinators over SSH and HTTPS (XenAPI), NetScalers over SSH and HTTPS (NITRO), Windows servers over WinRM for deployment and HTTPS inbound from their agents.
- Inbound to the dashboard: the web port, UDP 514 for syslog and UDP 4739 for AppFlow where you use them.
- For AD sign-in: reachability to a domain controller over LDAPS (port 636).
- Sizing: a small estate is comfortable on 2 vCPU and 8 GB; a busy syslog and AppFlow feed wants disk and retention set accordingly.
Place the VM alongside the infrastructure it watches, not inside a pool it monitors, so a pool problem never takes the dashboard with it.
| Section | What it holds |
|---|---|
| Collection | Poll intervals per product, SSH timeout, the XenServer health thresholds, the scheduled inventory's identity. |
| Data retention | How long snapshots, events, syslog and the decoded HDX records are kept; retention prunes run hourly in small batches so nothing waits on them. |
| Console | The XenServer rescan cadence, the Consoles grid, the Myrtille gateway address for Hyper-V consoles (with a Check that says whether Myrtille answers there), and the Fixes library. |
| Geolocation | A MaxMind GeoLite2 or DB-IP database, uploaded or downloaded straight from MaxMind on a schedule (the licence key is stored encrypted and never shown again), and an optional online provider, off by default. |
| Windows Update | The scan cadence the agents' scheduled task follows. |
| Authentication, License, TLS, Branding | See their own sections. |
Save names exactly what changed, old value to new, or says that nothing did.
The product name, subtitle, footer text, support email, classification label, and colour palette are all configurable. Report exports pick up your product name automatically, so customer-facing documents carry your identity, not ours.
Under Settings → Authentication, operators sign in with their domain accounts — no separate user store.
Settings you provide
- Domain (e.g.
company.local) - LDAPS URL (e.g.
ldaps://dc01.company.local:636or an IP) - Search base (e.g.
DC=company,DC=local) - The AD groups that map to each role
Use the Test login button before saving. Only disable the local setup account after a domain login has succeeded.
user@company.local) over TLS. With IIS in front, -WindowsAuth at install time gives single sign-on instead of the form.Map one AD group to each role — viewer, operator, admin. A user gets the highest role whose group they belong to.
Group membership is resolved even in hardened domains: the dashboard reads the user's memberOf where available, and falls back to a transitive group query when a domain's ACLs hide that attribute.
A session is an idle timeout, not a stopwatch. Every request pushes the clock back out, and an open dashboard window checks in on its own, so a window you are using — or one left up on a wall display — does not sign itself out. A window that comes back from being hidden renews before it does anything else; if the session cannot be revived, a bar across the top says so instead of every panel quietly rendering empty.
Once signed in, the browser can come back the next morning without retyping the password: a random token, stored on the server only as a hash, separate from the session, revocable from the sign-in settings.
| Symptom | Likely cause & fix |
|---|---|
| Login fails for everyone right after setup | Bind method or UPN suffix. Confirm the domain is in UPN form and the LDAPS URL is reachable. Use Test login. |
| User authenticates but lands with no access | Their AD group is not mapped to a role, or group lookup returned empty — the transitive fallback handles hardened domains, but confirm the group names match exactly. |
| LDAPS by IP fails on certificate name | The certificate is validated against a name, not the IP. The dashboard reverse-resolves the IP and synthesizes a matching name; if it still fails, reach the DC by its hostname. |
Your licence is a signed file naming the modules it enables and any limits (appliances, pools, hosts, servers). The dashboard verifies it offline with an embedded public key — there is no phone-home. A locked tab or button says which module it needs.
A key is bound to the installation it was issued for: Settings → License shows the Installation ID (DTRV-XXXX-XXXX-XXXX-XXXX-XXXX, a hash of the machine identifier and host name) with Copy, and a key naming another installation is refused in words. Activate online asks the licensing portal for a short code; you sign in on the portal, approve this installation there, and the key lands here bound to it — no portal password passes through the dashboard. Without internet, quote the Installation ID and a key file is issued for it. The portal's three names (licensing, updates, uptime) are built in.
| Module | Covers | Presumes |
|---|---|---|
| NetScaler | Monitoring, certificates, Analyze, reports | — |
| NetScaler Configuration | Writes to the appliances: the object editor, bindings, policies, certificate upload, gateway blocking enforcement, AppFlow setup, migration | NetScaler |
| NetScaler Identity Threat | Gateway sign-in attacks, report only or enforced | NetScaler |
| NetScaler Data Analytics | HDX Insight data; Session performance | NetScaler; Windows Infrastructure for the VDA side |
| Config Compare, Config Import, NetScaler Documentation, AI Enhancement | Drift comparison, ns.conf import, documentation export, the AI narrative | NetScaler |
| XenServer | Pool health, trends, alerts, reports | — |
| XenServer Console | The tree, VM and host operations, wizards, updates, the VM screen | XenServer |
| Windows Infrastructure | The agent, the fleet views, certificates, notifications, inventory, actions by delegation, the Windows Update reading side | — |
| Hyper-V Console | Hyper-V Manager's pages and actions, the browser console | Windows Infrastructure |
| Windows Update | Scheduling and installing updates across the servers | Windows Infrastructure |
| Windows Identity Threat | Sign-in attacks on the servers, blocking on the host firewall | Windows Infrastructure |
| Uptime | Reachability monitors (ICMP, TCP, UDP, SMTP, HTTP), uptime reports, the company's status page | — |
| Syslog | The receiver and the Syslog messages view | — |
Under Settings → License, paste or upload the licence file you were issued and apply it. The status panel shows which modules are enabled by name, the limits and any expiry. New tabs and controls appear immediately, no restart.
Under Settings → TLS Certificate, upload a certificate and key for the HTTPS endpoint. After validation the dashboard applies it and IIS rebinds the HTTPS port — your browser may briefly drop and reconnect.
- Your password is never stored. Anything Vantage does as you — an agent deploy, a Hyper-V change, a Windows Update install, Remote Desktop — takes your password for that action, holds it in memory, hands it to the child process over stdin, and forgets it. The audit line says "credential not stored".
- Certificates are pinned before a credential is sent. XenServer coordinators and NetScaler NITRO endpoints are recorded by SHA-256 on first use; a changed certificate is refused until an administrator accepts it. Nothing here has a "skip TLS verification" switch.
- The Windows agent is not an administrator. It runs as a shared least-privilege account and is granted exactly the rights its collectors need.
- Two NetScaler accounts. Monitoring is read-only; configuration is a separate read-write account that exists only where NetScaler Configuration is licensed and is used only for explicit actions.
- Secrets never come back out. The agent secret is shown once; stored keys (appliance passwords, the XenAPI credential, the MaxMind licence key) are encrypted with a machine-local key and never returned by any read.
- Every change is an audit line naming who, what, and the system's own answer.
- Reads by default. Monitoring never changes anything. Management is licensed apart, confirmed in words, and written only where it differs.
- No agents where none are needed. XenServer and NetScaler are read from one server reaching out; Windows has one small agent, deployed and updated from the dashboard.
- Honest about freshness and about failure. Data carries its age; "nothing to show" and "could not read" are always said apart, with the reason.
- Verdicts with reasons. Every health colour comes with why, and the analyses say how confident they are and what would settle it.
- Written against real output. Parsers and decoders are built from captures taken on production appliances, not from documentation samples.
- Offline. After install it needs no internet.
Why is a number stale?
Collection runs on an interval. Check the age in the header; an operator can force a fresh poll. The XenServer console also follows the pool's own events.
A tab or button is missing or shows a lock.
That module is not licensed. The lock names it; an admin adds it under Settings → License.
A panel says "could not read".
It says why beside it: a refused credential, a certificate that changed, a collector without the right it needs, an agent that is not reporting. Fix that and the next collection fills it.
Can Vantage change my NetScaler or my VMs?
Only with the management module licensed and only when an administrator or operator asks for a specific change, which is confirmed first and logged afterwards. Without those modules it reads.
I can sign in but can't see anything.
Your AD account is not mapped to a role, or the group names do not match. An admin maps groups under Settings → Authentication.