This article covers how to configure and use Kentik NMS with AI Advisor to assist with NetOps.

AI Advisor performing an NMS device configuration analysis, highlighting changes and their impacts.
Overview
Kentik NMS has two SSH-powered features to supercharge NetOps practitioners with better network intelligence:
Command Access (On-Demand Device Diagnostics)
Config Context (Backups and Diffs)
With these features, AI Advisor becomes more powerful: It can access, analyze, and interpret device configurations and, with user permission, pull real-time operational data from devices during live investigations using read-only show commands via SSH.
"Show me why my network performance dropped after last night's edge router change."
IMPORTANT:
Access to this feature requires an active NMS device license (see Licenses).
Kentik enforces AI Advisor’s strict read-only behavior by default using a standard command block-list. Users can supplement the block-list with custom allow or deny filters. For additional company-wide control, administrators can independently disable access to stored platform configurations and the ability to execute filtered show commands (see SSH Access & Security Policy).
Prerequisites
Before configuring AI Advisor for network device analysis, ensure your environment meets the following requirements:
Licensing: An active NMS Device License is required for each device you intend to monitor.
Kentik Universal Agent: You must have the latest version of the Universal Agent deployed within your infrastructure with network reachability to the target devices.
Connectivity: Port TCP/22 (SSH) must be open between the Universal Agent and the device management IP.
Note: The Universal Agent must have a direct route to the device's Management IP; it does not scrape configuration data via the data plane.
Supported Platforms: Ensure your device OS is supported for configuration scraping:
Platform
Support Level
Recommended Role
Juniper Junos
Full
read-onlyclassCisco NX-OS
Full
network-operatorArista EOS
Full
network-operatorCisco IOS-XE
Full
Parser View(Custom)
Credentials: A read-only SSH user account must be configured on the device (see Configuration Examples for platform-specific templates).
SSH Access & Security Policy
Kentik brings context to your observability data by securely pulling state data via SSH.
Read-Only: Kentik never requests write access to your infrastructure. Administrators can disable AI Advisor’s config backup and SSH command features entirely, while built-in vendor block-lists and customizable user filters provide extra execution safety.
Zero Configuration Changes: Kentik’s features are designed to scrape config diffs and execute ad hoc troubleshooting commands. Kentik will never execute
configure terminalorcommitchanges.Audit Trail: All activity is initiated via your local Collection Agent, ensuring every command is logged in your local AAA (TACACS+/RADIUS) systems.
