14.3 Leveraging the IdentityIQ Console for Debugging

Key Takeaways

  • Start the console from WEB-INF/bin with iiq console (-j adds command history on UNIX); it requires the System Administrator capability and tries spadmin/admin first.

  • Enter any command with no arguments to see its syntax; command names are case sensitive, and output can be redirected with > file or piped to OS tools.

  • connectorDebug tests a connector (test, iterate, get, auth) directly, outside aggregation.

  • rule and workflow commands run a rule or workflow with inputs from an XML Map file; validate checks a workflow or rule, and parse validates XML against the DTD.

  • run with sync makes a task finish in the console and print errors there; listLocks and breakLocks work on Identity locks.

Last updated: September 2026

Leveraging the IdentityIQ Console for Debugging

Objective 6.3 is leverage IdentityIQ console for debugging. The console runs on the server against the same database as the web application, so you can inspect objects, run rules and tasks, test connectors, and reload logging, often faster and more precisely than in the UI.

Launching

cd identityiq_home/WEB-INF/bin
./iiq console -j                 # UNIX; -j enables JLine command history
iiq console -u amy.cox -p secret  # explicit credentials
  • The console requires the System Administrator capability.
  • It first tries spadmin / admin and prompts for credentials if that fails.
  • Authentication is disabled when there are no identities, which is the state before init.xml is imported during installation.
  • Command-line options include -c "<command>" (run one command and exit), -f <file> (run commands from a file and exit), and -e <services> / -heartbeat (start background services such as Heartbeat or Task in the console process).

Syntax Basics

  • Enter a command with no arguments to see its usage. For example, workflow prints usage: workflow name [varfile].
  • Command names are case sensitive. Parameters are not.
  • Redirect output with > file, for example get identity Adam.Kennedy > adam.xml.
  • Pipe to operating-system tools, for example list workitem | grep manual or list policy | wc -l on UNIX.
  • source file runs a script of commands, and echo helps annotate scripted runs.

Commands for Debugging

Objects

CommandUse
list <class> [filter]List objects, with name filters such as ent*, *xxx, *xxx*
count <class> / summary / classesCounts and available classes
get <class> <name>Print an object's XML
checkout <class> <name> <file> [-clean] / checkin <file>Pull one object to a file and save it back. Checking in a role with approve launches role approval.
import [-noids] <file> / export [-clean] <file> [classes]Move objects (section 3.1)
delete <class> <name>Deletes the object and its owned objects. It cannot be undone and is not recommended in production unless Support directs it.
oconfigLists extended attributes by class (section 2.3)

Tasks and Workflows

  • run <task> [trace] [profile] [sync] runs a task. sync keeps control in the console until it finishes and prints errors there. trace and profile add execution detail.
  • runTaskWithArguments "<task>" arg1=val1,... runs a task with simple arguments, always synchronously.
  • tasks lists schedules, restart restarts a failed task, and terminateOrphans marks orphaned pending TaskResults as Terminated.
  • workflow <name> [varfile] launches a workflow with variables from an XML Map file and prints the WorkflowCase.
  • validate validates a workflow or a rule.
  • event <identity> <workflow> [seconds] schedules a workflow for an identity.
  • list workflowcase / get workflowcase "<name>" inspect in-flight workflows.

Tests

  • rule <name> [varfile] runs a rule with inputs from an XML Map. Support also uses this to run BeanShell against the database for cleanup.
  • parse <file> validates XML against the IdentityIQ DTD. It prints nothing if the file is valid.
  • warp <file> parses XML into an object and prints it.
  • sql "<statement>" / sql -f <file> runs one SQL statement. Updates and deletes cannot be undone. hql runs a Hibernate query.
  • connectorDebug <app> <method> tests connectors directly:
    • test – can a connection be made?
    • iterate [account|group] [-q] – read records natively. -q returns only the count and time.
    • get account|group <nativeIdentity> – fetch one object's ResourceObject XML.
    • auth – test pass-through authentication, if the application's features include AUTHENTICATION.

Locks, Services, and Logging

  • listLocks identity / breakLocks identity show or force-release identity locks. Use them with caution. lock / unlock act on a single object.
  • service list|start|stop|run manages console background services: Cache, SMListener, ResourceEvent, Heartbeat, Task (Quartz scheduler), and Request (request processor). status reports the task and request schedulers.
  • logConfig reloads log4j2.properties (section 14.1). about, properties, and threads give environment and thread information. clearCache clears the object cache. meter times each command.

Console Safety Rules

The console acts directly on the production database with administrator rights, so treat it as a sharp tool:

  • Prefer read-only commands such as get, list, count, connectorDebug ... test, and parse when investigating.
  • Checkout before you change. Keep a copy of any object before a checkin or import so you can roll back. The Debug pages and the console have no undo.
  • Avoid delete, sql updates, and breakLocks in production unless SailPoint Support or a tested runbook calls for them. Deletes also remove owned objects, and SQL changes bypass IdentityIQ's own logic and auditing.
  • Record what you ran. Script repeatable actions in a file and run them with source or -f, so the steps are reviewable.

Debugging Scenarios

ProblemConsole approach
Aggregation returns nothingconnectorDebug HR test, then connectorDebug HR iterate -q to count source records
One account looks wrongconnectorDebug AD get account "<DN>" to compare raw data with the Link (get link ...)
A rule misbehavesrule "ACME Correlation" vars.xml with a crafted input Map
A workflow fails at step 5validate the workflow, then run it with workflow "<name>" vars.xml and trace on
An edited XML file will not importparse file.xml to find the DTD error
An identity is stuck "locked"listLocks identity, then unlock identity <name> if safe
Test Your Knowledge

An aggregation from the HR application returns zero accounts. Which console command best confirms whether the connector can read records from the source?

A

run "HR Aggregation" profile

B

connectorDebug HR iterate -q

C

oconfig

D

listLocks identity

Test Your Knowledge

A developer wants to run a custom rule from the console with specific input values. How are the inputs supplied?

A

As command-line flags such as -identity=bob

B

By typing them interactively after the rule starts

C

In an XML Map variable file passed as the second argument to the rule command

D

Through the -c option only

Test Your Knowledge

What does adding sync to the console run command change?

A

It runs the task on every host in the cluster.

B

It schedules the task for the next maintenance window.

C

It disables the task's error handling.

D

The task runs in synchronous mode, so control returns only after completion and error messages print to the console.

Test Your Knowledge

An engineer edited a workflow XML file by hand, and the import fails with a vague error. Which console command validates the file against the IdentityIQ DTD without importing it?

A

parse

B

warp

C

checkin

D

summary

Sections you finish are checked off in the contents.