15.2 Leveraging the Administrator Console for Debugging

Key Takeaways

  • The Administrator Console has Tasks, Provisioning, and Environment areas, and access to it is controlled by IdentityIQ rights separate from the Setup > Tasks page.

  • From the Active tab you can terminate a running task or request a stack trace; from the Scheduled tab you can postpone a task or delete a schedule.

  • The Provisioning Transactions table logs only failures by default; set the Maximum Log Level to Retry or Success for more, and set a deletion age so the table does not grow forever.

  • Pending (retryable) transactions can be retried immediately; permanent failures cannot be retried but can be overridden with a manual work item.

  • Environment shows host heartbeats and statistics, lets you switch services per host, and runs application health checks from chosen hosts.

Last updated: September 2026

Leveraging the Administrator Console for Debugging

Objective 6.6 asks you to leverage the Administrator Console for debugging. Open gear icon > Administrator Console. It has three areas: Tasks, Provisioning, and Environment. Access is controlled by IdentityIQ rights, so someone may have the Administrator Console without the Setup > Tasks pages, or the reverse.

Tasks: What Is Running, Scheduled, and Done

TabColumnsActions
ActiveName, type, start date, owner, host, current runtime, average runtimeTerminate (X), and request a stack trace (</> turns green when ready; you can request a new one)
ScheduledName, type, host, next and last execution, last result, ownerPostpone to a chosen date and time, or delete the schedule
CompletedResult, start and complete dates, host, runtime, Diff from AverageReview outcomes

Key behaviors:

  • Terminate sends a request that out-of-the-box tasks honor at their next logical breakpoint. Custom tasks should also be written to handle a terminate request. You can also terminate from Setup > Tasks > Task Results.
  • Stack traces show what a long-running task is doing right now. They do not apply to workflows, which also produce task results, so the button is disabled for them.
  • Postpone blocks every instance of the task until the chosen time. Afterward, the task resumes its normal schedule. It does not run immediately at that time.
  • Average runtime and Diff from Average show when a task is slower than usual, an early sign of data growth, a slow target, or a database problem.

Provisioning: Every Change That Went to a Target

The Provisioning Transactions table records provisioning through connectors, manual work items, and IdentityIQ operations. Its tabs are All, Failure, Success, and Pending (retry).

Controlling What Is Logged

On Global Settings > IdentityIQ Configuration > Miscellaneous > Provisioning Transaction Log Settings:

  • Enable Provisioning Transaction Log turns logging on or off.
  • Maximum Log Level: Failure (the default, only failures set up for retry), Retry (failures and retry results), or Success (everything).
  • Days before provisioning transaction event deletion: 0 means never delete. With Success logging this can fill the database quickly, so always set a retention period. The Perform Maintenance task's Prune provisioning transactions option uses it.

Acting on Transactions

  • The information icon opens Transaction Details, with attribute-level request data and error messages. This is usually the fastest route to the cause of a failed provisioning.
  • Pending transactions (retryable errors) retry automatically after a configured interval. An administrator can click Retry to force an immediate retry, for example once a network problem is fixed.
  • Failure transactions are permanent. They are never retried automatically and cannot be forced to retry. Instead, Override creates a manual work item assigned to the application owner, yourself, or another user, to complete the change outside IdentityIQ. The original failure stays for history, and a new Success entry records the override.
  • The report button launches the Provisioning Transaction Object report. The Provisioning Transaction Object and Detailed Provisioning Transaction Object reports are also on Intelligence > Reports.

Environment: Hosts, Applications, Modules

Hosts tab. Every IdentityIQ instance, with Status, Last Heartbeat, CPU, memory, request threads, task threads, database response time, and timestamp. A host whose heartbeat stops advancing is marked crashed by the others. Actions per host:

  • Services tab turns host services on or off: Task, Request (never fully off), Monitoring, Reanimator (recovers or terminates hung tasks), and others (section 2.1).
  • Configuration tab overrides polling interval, statistics retention, and which statistics are kept, and selects applications to monitor from this host.
  • Delete a host's Server object. It reappears at the next heartbeat if the server is still running.
  • Global defaults (polling interval, retention, statistics) are set with the gear on the title bar.

Applications tab. Monitored applications show how many hosts see them up or down, with the last ping. With full rights, you can trigger an immediate health check with the refresh icon. An application must be monitored by at least one host before it reports.

SailPoint Modules and Extensions tab. Installed modules and extensions, their statuses, last ping, and a Problem Detected icon with details.

Administrator Console vs. Other Tools

  • Task Results (Setup > Tasks) shows task outcomes with full result details and can also terminate tasks. Postponing schedules and requesting stack traces are done in the Administrator Console, which has its own access rights.
  • Syslog (section 14.2) holds the exceptions behind many failures. The console shows that something failed, and Syslog and logs show why.
  • Debug pages > Threads give a server-wide thread dump, while the console's stack trace targets one running task.

Debugging Playbook

SymptomAdministrator Console step
The nightly refresh is still running at 9 a.m.Active tab: compare with the average runtime, request a stack trace, and terminate if necessary
Users report access was "approved but never granted"Provisioning: filter Failure or Pending and open Transaction Details
A target system was down for an hourProvisioning: after recovery, Retry the Pending items
Partitioned tasks slow downEnvironment: check hosts' request threads, heartbeats, and whether a host has dropped out
An application fails intermittentlyEnvironment: monitor it from several hosts and compare up and down results
Test Your Knowledge

A task scheduled every night must not run until next Monday because of a planned outage. What does the Administrator Console provide?

A

Postpone the task on the Scheduled tab to the chosen date and time; afterward it resumes its normal schedule.

B

Terminate the task on the Active tab, which cancels all future runs.

C

Delete the host running the task from the Environment tab.

D

Set the task's average runtime to zero.

Test Your Knowledge

A provisioning transaction shows as a Failure. The administrator fixed the cause and wants the change completed. What can be done from the Provisioning Transactions table?

A

Click Retry to rerun the failed transaction.

B

Change the Maximum Log Level to Success to rerun it.

C

Use Override to create a manual work item for someone to complete the change, because failures cannot be retried.

D

Delete the transaction so the connector processes it again.

Test Your Knowledge

The Provisioning Transactions table shows only failures, but the team wants to see successful transactions too. Which setting should change, and what else should be set?

A

Enable Syslog at WARN level, with no other change.

B

Turn on the Reanimator service on every host.

C

Set Maximum Log Level to Success in Provisioning Transaction Log Settings, and set Days before provisioning transaction event deletion so records are purged.

D

Run the Provisioning Transaction Object report with Allow Concurrency.

Test Your Knowledge

Why is the stack-trace button disabled for some entries on the Active tab?

A

Those tasks are running on a UI host.

B

The user lacks the Debug Pages Read Only Access capability.

C

The tasks are partitioned.

D

Those entries are workflow task results, and the stack-trace option does not apply to workflows.

Sections you finish are checked off in the contents.