This article describes how to manage Universal Agent instances and capabilities through the Kentik portal, including editing agent settings, installing and configuring capabilities, and resolving alert policy warnings.
Note: Step 6 in Deploy a Universal Agent Through the Kentik API describes how to enable and configure agent capabilities programmatically.
Edit a Universal Agent
To edit a deployed Universal Agent instance through the portal, follow these steps:
Go to the Universal Agents UI page via Settings » Universal Agents in the Kentik portal navbar.
Click the edit button (pencil icon) in the agent's row in the list.
Update the Name, Description, Closest Network Device, and/or Site.
Click Save to save changes and exit or Cancel to exit without saving.
Install a Capability
To install a capability (see Agent Capabilities) on a Universal Agent instance through the portal, follow these steps:
Go to the Universal Agents UI page via Settings » Universal Agents in the Kentik portal navbar.
Click the agent's row in the list to open the Agent Details Drawer.
Under Capabilities » Available: Compatible and Supported, click Install for any capabilities you wish to add this Universal Agent instance.
Manage a Capability
To manage an installed capability on a Universal Agent instance through the portal, follow these steps:
Go to the Universal Agents UI page via Settings » Universal Agents in the Kentik portal navbar.
Click the agent's row in the list to open the Agent Details Drawer.
Under Capabilities » Installed: Running or Paused on this Agent, click Details.
In the Capability Drawer, you can take the following actions:
View the capability’s details like Status, Run State, Command Line Args, and metrics visualizations.
When applicable, click Edit to reveal additional capability settings like command line arguments/values.
Click Save to save changes and exit or Cancel to exit without saving.
Click Back to return to the Agent Details drawer.
Click Disable this Capability to temporarily turn off this capability for this Universal Agent instance.
Configure the DNS OTT Tap Capability
Telemetry is collected via the DNS OTT Tap capability, which supports three primary data ingestion modes:
Direct (On-Server): Agent installed directly on BIND9 or Linux-based resolvers.
Promiscuous (SPAN/Mirror): This mode is used when the agent is installed on a separate host and receives a copy of the traffic from a network tap or port mirror. The agent interface must be set to promiscuous mode to capture traffic not specifically destined for the host's MAC address.
DNSTAP Receiver (Preferred): Agent acts as a listener for real-time DNS logs from appliances like Infoblox. This mode must be explicitly configured to listen on a specific port for the incoming DNSTAP stream.
To edit the DNS OTT Tap capability through the portal, follow these steps:
Go to the Universal Agents Page via Settings » Universal Agents in the Kentik portal navbar.
Click the agent's row in the list to open the Agent Details Drawer.
Under Capabilities » Installed: Running or Paused on this Agent, click Details for DNS OTT Tap.
Click Edit to reveal the current command line argument/value settings.
Make the changes, as follows:
Update an Existing Argument: Select a different Command Line Value from the drop-down.
Add a New Argument: Click Add to add a row, then choose the argument and value (see supported combinations below).
Click Save to save changes and exit or Cancel to exit without saving.
Supported argument/value combinations for the DNS OTT Tap capability:
Command Line Argument | Accepted Values | Description |
|---|---|---|
Interface | All, lo, eth0, [other network interfaces] | Specifies the interface(s) from which to capture DNS OTT data (e.g., "All" for all available interfaces, "lo" for the loopback interface, "eth0" for the first Ethernet interface). |
Promiscuous Mode | On, Off | Determines whether the interface should operate in promiscuous mode. When "On," the interface captures all packets on the segment. "Off" means it only captures packets addressed to its MAC address.
|
Configure the Flow Proxy Capability
To configure the Flow Proxy capability of the Universal Agent, which receives, processes, and forwards your flow telemetry data to Kentik, through the portal, follow these steps:
Note: The Flow Proxy capability packages the standard Kentik Proxy (
kproxy) binary into a managed component within the Universal Agent framework.
Go to the Universal Agents UI page via Settings » Universal Agents in the Kentik portal navbar.
Click the agent's row in the list to open the Agent Details Drawer.
Under Capabilities » Installed: Running or Paused on this Agent, click Details for Flow Proxy.
Click Edit to reveal the current command line argument/value settings.
Configure the command-line arguments as necessary (see below table), and click Save.
The Universal Agent downloads the
kproxybinary, applies the configuration, and starts the process.The agent’s Status field on the Universal Agents page updates from 'Pending' to 'Up'.
Configure your routers, switches, and other network devices to export flow telemetry to the IP address of the Universal Agent host on the UDP port specified in the Port field (e.g., 9995).
Command Line Argument | Description | Example Value | Required? |
|---|---|---|---|
Host | The IP address on which the proxy will listen for incoming flow packets. Use 0.0.0.0 to listen on all available network interfaces on the host. | 0.0.0.0 | No |
Port | The UDP port used to listen for flow packets from your network devices. | 9995 | No |
Base Port | The port used by Flow Proxy to send flow to Kentik. Adjustable in case of conflict on the host machine. | 40010 | No |
Sflow Agent Address | (sFlow only) Specifies the IP address of the sFlow agent. Can be used to override the agent address in sFlow datagrams if its being reported incorrectly by the device. | 192.168.1.1 | No |
Site | Associates all flow data processed by this Flow Proxy with a specific Site configured in your Kentik portal. This is essential for data filtering and organization. | data-center-frankfurt | No |
Troubleshooting a Flow Proxy
Status is Down: If the capability status displays 'Down' with an error, such as exit status 10, it typically indicates a configuration error. Ensure that all required fields are correctly populated.
No Data in Portal: If the capability status is ‘Up’ but you see no flow data in the Kentik portal, verify the following:
Network devices are configured with the correct destination IP and port.
There are no firewalls on the agent’s host or in the network path blocking the flow export UDP port.
Check the agent logs for connection errors or other warnings.
Uninstall a Capability
To uninstall a capability from a Universal Agent instance through the portal, follow these steps:
Go to the Universal Agents UI page via Settings » Universal Agents in the Kentik portal navbar.
Click the agent's row in the list to open the Agent Details Drawer.
Under Capabilities » Installed: Running or Paused on this Agent, click Uninstall for the capability you wish to remove from this Universal Agent instance. Once the capability has been removed, you’re returned to the Agents list.
Tip: You can reinstall a capability on an agent at any time by clicking the capability’s Install button in the Agent Details Drawer.
Resolve Observation Deck Alert Policy Warnings
When you have Kentik Universal Agents deployed but no alert policies configured to monitor them, the following warning banners might appear on the Observation Deck prompting you to take action:
“Your agents do not have an associated alert policy defined and require configuration”: Appears when agents are deployed but no Agent type alert policy is enabled to monitor their health (CPU, memory, disk, status).
“Your agent capabilities do not have an associated alert policy defined and require configuration”: Appears when agent capabilities are running (e.g., Flow Proxy, SNMP Polling, Streaming Telemetry) but no Agent Capability type alert policy is enabled to monitor capability health and status.
Without these policies, you will not receive notifications if an agent goes offline, runs out of resources, or if a capability stops functioning.
To dismiss these warnings, create and enable at least one alert policy of the appropriate NMS policy type:
Agent (for the agents warning) OR
Agent Capability (for the agent capabilities warning)
Create an Agent Alert Policy from a Template (Recommended)
Kentik provides preconfigured policy templates for agent and agent capability monitoring. This is the fastest way to get started, and can be used for either warning by selecting the appropriate NMS policy type in step 3.
Go to Settings » Alert Policies from the main navigation menu.
Click the drop-down arrow on the Add Alert Policy button and select Add Alert Policy from Template.
In the template drop-down, search for “Agent” to find agent-related templates.
Select the desired template, Agent or Agent Capability, matching the warning you want to resolve and click Continue.
Review and customize the policy settings for your environment on the following tabs:
General tab: Give the policy a meaningful name (e.g., “Agent Health Monitoring”)
Dataset tab: Confirm the measurements and devices are appropriate (by default, templates monitor all devices)
Activate & Clear tab: Review threshold conditions and add notification channels (e.g., email, Slack, PagerDuty) so you are alerted when issues arise.
Click Save.
Repeat these steps for the other policy type (Agent or Agent Capability) if both warnings are displayed.
Note: Templates are starting points. Review and adjust thresholds, notification channels, and device scope to match your organization’s needs.
Create an Alert Policy from Scratch
If you prefer to build a policy manually, follow the steps below for the appropriate NMS policy type.
Create an Agent Alert Policy
Go to Settings » Alert Policies from the main navigation menu.
Click Add Alert Policy.
Under NMS policy types, select Agent.
On the General tab, enter a name and optional description (e.g., “Agent Health - All Agents”).
On the Dataset tab, under Measurements, select the metrics you want to monitor. Available agent metrics include:
/kentik/agent/cpu: Agent CPU utilization/kentik/agent/memory: Agent memory usage/kentik/agent/disk: Agent disk usage/kentik/agent/health: Overall agent health/kentik/agent/status: Agent up/down status/kentik/agent/status/alert: Agent alert status
Under Devices, choose All Devices to monitor all agents, or click Edit Devices to scope to specific sites or labels.
On the Activate & Clear tab:
Set the Severity level (e.g., Major or Critical).
Configure alert conditions (e.g., agent status equals down, or CPU utilization greater than 90%).
Under Notification Channels, select where alerts should be sent (e.g., email, Slack, PagerDuty). Click Add New Channel if you haven’t configured one yet.
On the Baseline tab, accept the default preset or adjust as needed.
Click Save.
Create an Agent Capability Alert Policy
Go to Settings » Alert Policies from the main navigation menu.
Click Add Alert Policy.
Under NMS policy types, select Agent Capability.
On the General tab, enter a name and optional description (e.g., “Agent Capability Health - All Capabilities”).
On the Dataset tab, under Measurements, select the metrics you want to monitor. Available agent capability metrics include:
/kentik/agent/capability/health: Capability health status/kentik/agent/capability/status: Capability enabled/running status
Under Devices, choose All Devices or scope to specific sites or labels.
On the Activate & Clear tab:
Set the Severity level.
Configure alert conditions for capability status changes.
Add Notification Channels for alert delivery.
On the Baseline tab, accept the default preset or adjust as needed.
Click Save.
Verify the Warnings Are Resolved
After creating and saving your alert policies:
Return to the Observation Deck (portal home page, depending on configuration).
The warning banners should no longer appear once the policies are enabled.
If the warnings persist after creating both Agent and Agent Capability policies, verify that:
The policies are Enabled (not Disabled) on the Settings » Alert Policies page.
The policies cover the devices/agents that triggered the warnings.
