Kentik has joined Infoblox! Read the blog post

UA Portal Management

Prev Next

This article describes how to manage Universal Agent instances and capabilities through the Kentik portal, including editing agent settings, installing and configuring capabilities, and resolving alert policy warnings.

Note: Step 6 in Deploy a Universal Agent Through the Kentik API describes how to enable and configure agent capabilities programmatically.

Edit a Universal Agent

To edit a deployed Universal Agent instance through the portal, follow these steps:

  1. Go to the Universal Agents UI page via Settings » Universal Agents in the Kentik portal navbar.

  2. Click the edit button (pencil icon) in the agent's row in the list.

  3. Update the Name, Description, Closest Network Device, and/or Site.

  4. Click Save to save changes and exit or Cancel to exit without saving.

Install a Capability

To install a capability (see Agent Capabilities) on a Universal Agent instance through the portal, follow these steps:

  1. Go to the Universal Agents UI page via Settings » Universal Agents in the Kentik portal navbar.

  2. Click the agent's row in the list to open the Agent Details Drawer.

  3. Under Capabilities » Available: Compatible and Supported, click Install for any capabilities you wish to add this Universal Agent instance.

Manage a Capability

To manage an installed capability on a Universal Agent instance through the portal, follow these steps:

  1. Go to the Universal Agents UI page via Settings » Universal Agents in the Kentik portal navbar.

  2. Click the agent's row in the list to open the Agent Details Drawer.

  3. Under Capabilities » Installed: Running or Paused on this Agent, click Details.

  4. In the Capability Drawer, you can take the following actions:

    1. View the capability’s details like Status, Run State, Command Line Args, and metrics visualizations.

    2. When applicable, click Edit to reveal additional capability settings like command line arguments/values.

      1. Click Save to save changes and exit or Cancel to exit without saving.

    3. Click Back to return to the Agent Details drawer.

    4. Click Disable this Capability to temporarily turn off this capability for this Universal Agent instance.

Configure the DNS OTT Tap Capability

Telemetry is collected via the DNS OTT Tap capability, which supports three primary data ingestion modes:

  • Direct (On-Server): Agent installed directly on BIND9 or Linux-based resolvers.

  • Promiscuous (SPAN/Mirror): This mode is used when the agent is installed on a separate host and receives a copy of the traffic from a network tap or port mirror. The agent interface must be set to promiscuous mode to capture traffic not specifically destined for the host's MAC address.

  • DNSTAP Receiver (Preferred): Agent acts as a listener for real-time DNS logs from appliances like Infoblox. This mode must be explicitly configured to listen on a specific port for the incoming DNSTAP stream.

To edit the DNS OTT Tap capability through the portal, follow these steps:

  1. Go to the Universal Agents Page via Settings » Universal Agents in the Kentik portal navbar.

  2. Click the agent's row in the list to open the Agent Details Drawer.

  3. Under Capabilities » Installed: Running or Paused on this Agent, click Details for DNS OTT Tap.

  4. Click Edit to reveal the current command line argument/value settings.

  5. Make the changes, as follows:

    1. Update an Existing Argument: Select a different Command Line Value from the drop-down.

    2. Add a New Argument: Click Add to add a row, then choose the argument and value (see supported combinations below).

  6. Click Save to save changes and exit or Cancel to exit without saving.

Supported argument/value combinations for the DNS OTT Tap capability:

Command Line Argument

Accepted Values

Description

Interface

All, lo, eth0, [other network interfaces]

Specifies the interface(s) from which to capture DNS OTT data (e.g., "All" for all available interfaces, "lo" for the loopback interface, "eth0" for the first Ethernet interface).

Promiscuous Mode

On, Off

Determines whether the interface should operate in promiscuous mode. When "On," the interface captures all packets on the segment. "Off" means it only captures packets addressed to its MAC address.

Note: If DNS traffic is being collected through SPAN/mirror ports, the interface may need to run in promiscuous mode so it can capture mirrored packets. However, most deployments (like Direct or DNSTAP) do not use promiscuous mode.

Configure the Flow Proxy Capability

To configure the Flow Proxy capability of the Universal Agent, which receives, processes, and forwards your flow telemetry data to Kentik, through the portal, follow these steps:

Note: The Flow Proxy capability packages the standard Kentik Proxy (kproxy) binary into a managed component within the Universal Agent framework.

  1. Go to the Universal Agents UI page via Settings » Universal Agents in the Kentik portal navbar.

  2. Click the agent's row in the list to open the Agent Details Drawer.

  3. Under Capabilities » Installed: Running or Paused on this Agent, click Details for Flow Proxy.

  4. Click Edit to reveal the current command line argument/value settings.

  5. Configure the command-line arguments as necessary (see below table), and click Save.

    1. The Universal Agent downloads the kproxy binary, applies the configuration, and starts the process.

    2. The agent’s Status field on the Universal Agents page updates from 'Pending' to 'Up'.

  6. Configure your routers, switches, and other network devices to export flow telemetry to the IP address of the Universal Agent host on the UDP port specified in the Port field (e.g., 9995).

Command Line Argument

Description

Example Value

Required?

Host

The IP address on which the proxy will listen for incoming flow packets. Use 0.0.0.0 to listen on all available network interfaces on the host.

0.0.0.0

No

Port

The UDP port used to listen for flow packets from your network devices.

9995

No

Base Port

The port used by Flow Proxy to send flow to Kentik. Adjustable in case of conflict on the host machine.

40010

No

Sflow Agent Address

(sFlow only) Specifies the IP address of the sFlow agent. Can be used to override the agent address in sFlow datagrams if its being reported incorrectly by the device.

192.168.1.1

No

Site

Associates all flow data processed by this Flow Proxy with a specific Site configured in your Kentik portal. This is essential for data filtering and organization.

data-center-frankfurt

No

Troubleshooting a Flow Proxy

  • Status is Down: If the capability status displays 'Down' with an error, such as exit status 10, it typically indicates a configuration error. Ensure that all required fields are correctly populated.

  • No Data in Portal: If the capability status is ‘Up’ but you see no flow data in the Kentik portal, verify the following:

    • Network devices are configured with the correct destination IP and port.

    • There are no firewalls on the agent’s host or in the network path blocking the flow export UDP port.

    • Check the agent logs for connection errors or other warnings.

Uninstall a Capability

To uninstall a capability from a Universal Agent instance through the portal, follow these steps:

  1. Go to the Universal Agents UI page via Settings » Universal Agents in the Kentik portal navbar.

  2. Click the agent's row in the list to open the Agent Details Drawer.

  3. Under Capabilities » Installed: Running or Paused on this Agent, click Uninstall for the capability you wish to remove from this Universal Agent instance. Once the capability has been removed, you’re returned to the Agents list.

Tip: You can reinstall a capability on an agent at any time by clicking the capability’s Install button in the Agent Details Drawer.

Resolve Observation Deck Alert Policy Warnings

When you have Kentik Universal Agents deployed but no alert policies configured to monitor them, the following warning banners might appear on the Observation Deck prompting you to take action:

  • Warning message indicating agents lack an alert policy configuration in the observation deck.“Your agents do not have an associated alert policy defined and require configuration”: Appears when agents are deployed but no Agent type alert policy is enabled to monitor their health (CPU, memory, disk, status).

  • Warning message indicating agent capabilities require configuration in the observation deck.“Your agent capabilities do not have an associated alert policy defined and require configuration”: Appears when agent capabilities are running (e.g., Flow Proxy, SNMP Polling, Streaming Telemetry) but no Agent Capability type alert policy is enabled to monitor capability health and status.

Without these policies, you will not receive notifications if an agent goes offline, runs out of resources, or if a capability stops functioning.

To dismiss these warnings, create and enable at least one alert policy of the appropriate NMS policy type:

  • Agent (for the agents warning) OR

  • Agent Capability (for the agent capabilities warning)

Kentik provides preconfigured policy templates for agent and agent capability monitoring. This is the fastest way to get started, and can be used for either warning by selecting the appropriate NMS policy type in step 3.

  1. Go to Settings » Alert Policies from the main navigation menu.

  2. Click the drop-down arrow on the Add Alert Policy button and select Add Alert Policy from Template.

  3. In the template drop-down, search for “Agent” to find agent-related templates.

  4. Select the desired template, Agent or Agent Capability, matching the warning you want to resolve and click Continue.

  5. Review and customize the policy settings for your environment on the following tabs:

    1. General tab: Give the policy a meaningful name (e.g., “Agent Health Monitoring”)

    2. Dataset tab: Confirm the measurements and devices are appropriate (by default, templates monitor all devices)

    3. Activate & Clear tab: Review threshold conditions and add notification channels (e.g., email, Slack, PagerDuty) so you are alerted when issues arise.

  6. Click Save.

  7. Repeat these steps for the other policy type (Agent or Agent Capability) if both warnings are displayed.

Note: Templates are starting points. Review and adjust thresholds, notification channels, and device scope to match your organization’s needs.

Create an Alert Policy from Scratch

If you prefer to build a policy manually, follow the steps below for the appropriate NMS policy type.

Create an Agent Alert Policy

  1. Go to Settings » Alert Policies from the main navigation menu.

  2. Click Add Alert Policy.

  3. Under NMS policy types, select Agent.

  4. On the General tab, enter a name and optional description (e.g., “Agent Health - All Agents”).

  5. On the Dataset tab, under Measurements, select the metrics you want to monitor. Available agent metrics include:

    1. /kentik/agent/cpu: Agent CPU utilization

    2. /kentik/agent/memory: Agent memory usage

    3. /kentik/agent/disk: Agent disk usage

    4. /kentik/agent/health: Overall agent health

    5. /kentik/agent/status: Agent up/down status

    6. /kentik/agent/status/alert: Agent alert status

  6. Under Devices, choose All Devices to monitor all agents, or click Edit Devices to scope to specific sites or labels.

  7. On the Activate & Clear tab:

    1. Set the Severity level (e.g., Major or Critical).

    2. Configure alert conditions (e.g., agent status equals down, or CPU utilization greater than 90%).

    3. Under Notification Channels, select where alerts should be sent (e.g., email, Slack, PagerDuty). Click Add New Channel if you haven’t configured one yet.

  8. On the Baseline tab, accept the default preset or adjust as needed.

  9. Click Save.

Create an Agent Capability Alert Policy

  1. Go to Settings » Alert Policies from the main navigation menu.

  2. Click Add Alert Policy.

  3. Under NMS policy types, select Agent Capability.

  4. On the General tab, enter a name and optional description (e.g., “Agent Capability Health - All Capabilities”).

  5. On the Dataset tab, under Measurements, select the metrics you want to monitor. Available agent capability metrics include:

    1. /kentik/agent/capability/health: Capability health status

    2. /kentik/agent/capability/status: Capability enabled/running status

  6. Under Devices, choose All Devices or scope to specific sites or labels.

  7. On the Activate & Clear tab:

    1. Set the Severity level.

    2. Configure alert conditions for capability status changes.

    3. Add Notification Channels for alert delivery.

  8. On the Baseline tab, accept the default preset or adjust as needed.

  9. Click Save.

Verify the Warnings Are Resolved

After creating and saving your alert policies:

  1. Return to the Observation Deck (portal home page, depending on configuration).

  2. The warning banners should no longer appear once the policies are enabled.

If the warnings persist after creating both Agent and Agent Capability policies, verify that:

  • The policies are Enabled (not Disabled) on the Settings » Alert Policies page.

  • The policies cover the devices/agents that triggered the warnings.