14.3 Leveraging the IdentityIQ Console for Debugging
Key Takeaways
Start the console from WEB-INF/bin with iiq console (-j adds command history on UNIX); it requires the System Administrator capability and tries spadmin/admin first.
Enter any command with no arguments to see its syntax; command names are case sensitive, and output can be redirected with > file or piped to OS tools.
connectorDebug tests a connector (test, iterate, get, auth) directly, outside aggregation.
rule and workflow commands run a rule or workflow with inputs from an XML Map file; validate checks a workflow or rule, and parse validates XML against the DTD.
run with sync makes a task finish in the console and print errors there; listLocks and breakLocks work on Identity locks.
Leveraging the IdentityIQ Console for Debugging
Objective 6.3 is leverage IdentityIQ console for debugging. The console runs on the server against the same database as the web application, so you can inspect objects, run rules and tasks, test connectors, and reload logging, often faster and more precisely than in the UI.
Launching
cd identityiq_home/WEB-INF/bin
./iiq console -j # UNIX; -j enables JLine command history
iiq console -u amy.cox -p secret # explicit credentials
- The console requires the System Administrator capability.
- It first tries
spadmin/adminand prompts for credentials if that fails. - Authentication is disabled when there are no identities, which is the state before
init.xmlis imported during installation. - Command-line options include
-c "<command>"(run one command and exit),-f <file>(run commands from a file and exit), and-e <services>/-heartbeat(start background services such as Heartbeat or Task in the console process).
Syntax Basics
- Enter a command with no arguments to see its usage. For example,
workflowprintsusage: workflow name [varfile]. - Command names are case sensitive. Parameters are not.
- Redirect output with
> file, for exampleget identity Adam.Kennedy > adam.xml. - Pipe to operating-system tools, for example
list workitem | grep manualorlist policy | wc -lon UNIX. source fileruns a script of commands, andechohelps annotate scripted runs.
Commands for Debugging
Objects
| Command | Use |
|---|---|
list <class> [filter] | List objects, with name filters such as ent*, *xxx, *xxx* |
count <class> / summary / classes | Counts and available classes |
get <class> <name> | Print an object's XML |
checkout <class> <name> <file> [-clean] / checkin <file> | Pull one object to a file and save it back. Checking in a role with approve launches role approval. |
import [-noids] <file> / export [-clean] <file> [classes] | Move objects (section 3.1) |
delete <class> <name> | Deletes the object and its owned objects. It cannot be undone and is not recommended in production unless Support directs it. |
oconfig | Lists extended attributes by class (section 2.3) |
Tasks and Workflows
run <task> [trace] [profile] [sync]runs a task. sync keeps control in the console until it finishes and prints errors there. trace and profile add execution detail.runTaskWithArguments "<task>" arg1=val1,...runs a task with simple arguments, always synchronously.taskslists schedules,restartrestarts a failed task, andterminateOrphansmarks orphaned pending TaskResults as Terminated.workflow <name> [varfile]launches a workflow with variables from an XML Map file and prints the WorkflowCase.validatevalidates a workflow or a rule.event <identity> <workflow> [seconds]schedules a workflow for an identity.list workflowcase/get workflowcase "<name>"inspect in-flight workflows.
Tests
rule <name> [varfile]runs a rule with inputs from an XML Map. Support also uses this to run BeanShell against the database for cleanup.parse <file>validates XML against the IdentityIQ DTD. It prints nothing if the file is valid.warp <file>parses XML into an object and prints it.sql "<statement>"/sql -f <file>runs one SQL statement. Updates and deletes cannot be undone.hqlruns a Hibernate query.connectorDebug <app> <method>tests connectors directly:test– can a connection be made?iterate [account|group] [-q]– read records natively.-qreturns only the count and time.get account|group <nativeIdentity>– fetch one object's ResourceObject XML.auth– test pass-through authentication, if the application's features include AUTHENTICATION.
Locks, Services, and Logging
listLocks identity/breakLocks identityshow or force-release identity locks. Use them with caution.lock/unlockact on a single object.service list|start|stop|runmanages console background services: Cache, SMListener, ResourceEvent, Heartbeat, Task (Quartz scheduler), and Request (request processor).statusreports the task and request schedulers.logConfigreloadslog4j2.properties(section 14.1).about,properties, andthreadsgive environment and thread information.clearCacheclears the object cache.metertimes each command.
Console Safety Rules
The console acts directly on the production database with administrator rights, so treat it as a sharp tool:
- Prefer read-only commands such as
get,list,count,connectorDebug ... test, andparsewhen investigating. - Checkout before you change. Keep a copy of any object before a
checkinorimportso you can roll back. The Debug pages and the console have no undo. - Avoid
delete,sqlupdates, andbreakLocksin production unless SailPoint Support or a tested runbook calls for them. Deletes also remove owned objects, and SQL changes bypass IdentityIQ's own logic and auditing. - Record what you ran. Script repeatable actions in a file and run them with
sourceor-f, so the steps are reviewable.
Debugging Scenarios
| Problem | Console approach |
|---|---|
| Aggregation returns nothing | connectorDebug HR test, then connectorDebug HR iterate -q to count source records |
| One account looks wrong | connectorDebug AD get account "<DN>" to compare raw data with the Link (get link ...) |
| A rule misbehaves | rule "ACME Correlation" vars.xml with a crafted input Map |
| A workflow fails at step 5 | validate the workflow, then run it with workflow "<name>" vars.xml and trace on |
| An edited XML file will not import | parse file.xml to find the DTD error |
| An identity is stuck "locked" | listLocks identity, then unlock identity <name> if safe |
An aggregation from the HR application returns zero accounts. Which console command best confirms whether the connector can read records from the source?
run "HR Aggregation" profile
connectorDebug HR iterate -q
oconfig
listLocks identity
A developer wants to run a custom rule from the console with specific input values. How are the inputs supplied?
As command-line flags such as -identity=bob
By typing them interactively after the rule starts
In an XML Map variable file passed as the second argument to the rule command
Through the -c option only
What does adding sync to the console run command change?
It runs the task on every host in the cluster.
It schedules the task for the next maintenance window.
It disables the task's error handling.
The task runs in synchronous mode, so control returns only after completion and error messages print to the console.
An engineer edited a workflow XML file by hand, and the import fails with a vague error. Which console command validates the file against the IdentityIQ DTD without importing it?
parse
warp
checkin
summary
Sections you finish are checked off in the contents.