Atlas Knowledge Base
Dashboard
Dashboard

Dashboard


The SBN Services Dashboard is a browser-based console for the background SBN Services running on a server -- the services that do SBN's automated work such as alarm generation, report generation, e-mail notifications, front-end signal receiving, watchdog monitoring, and scheduled tasks. From one page you can see every service, install or remove it, start or stop it, edit its properties, watch its log live, browse and download its output and log files, and create additional service instances.

The Dashboard runs on the same server as the services and is served over HTTPS on its own port. Open it in a web browser using the address and port set up for that server (for example https://your-server:port). You sign in with the Dashboard's own administrator credentials; the first time it is opened on a new server it prompts you to set the administrator password.

Browse to the Dashboard address for the server. The sign-in screen is a dark panel asking for a username and password; the Dashboard has a single administrator account. Sign-in is required for everything except the sign-in page itself. Repeated failed attempts are rate-limited. Use Sign out at the top-right of the header to end your session and return to the sign-in screen.

The header shows the Dashboard name, a live refresh countdown, and the installed version number. To rename the Dashboard, click the pencil next to the name in the header, type a new name, and press Enter. This is a display name only.

Once you are signed in the Dashboard is organised into three tabs: Services, API Keys and Account.

Services

The services list

The Services tab lists every SBN service found on the server, grouped by category. Each row shows the service, its current state (Running, Stopped, Not installed, or other), and the actions available for it. The list refreshes on its own every few seconds so the state you see stays current.

You can narrow the list without changing anything on the server:

  1. Filter services -- type in the search box to show only matching services.
  2. State filters -- tick Running, Stopped, Not installed, or Other to show only services in those states. Your choice is remembered for next time.
  3. Category headers -- click a category to collapse or expand it. Collapsed categories are remembered. The categories whose services run as numbered instances -- Front End, Nats Front End and Alarm Gen. -- also carry an Add (+) button on the category header, which creates a new numbered instance in that category.

Only the services you are permitted to see are listed. Categories or services that have been hidden through Configure visibility do not appear.

Toolbar actions

Above the list is a toolbar of actions that apply to the whole server:

  1. Start all / Stop all -- start or stop every installed service at once.
  2. Versions -- show the installed file version of each service (see Understanding the version number).
  3. Configure visibility -- hide categories or services from the list, and Export or Import that visibility configuration.

Per-service actions

Each service row carries a set of action icons. Which icons appear depends on the service's state -- for example, Start shows for an installed, stopped service, and Install shows for a service that is not yet installed.

Install

Registers the service with the server's operating system so it can run. Clicking Install opens a short form:

  1. Service user (optional) -- the account the service should run under, in DOMAIN\user form. Leave blank to use the system default.
  2. Password (optional) -- the password for that account, if you supplied one.
  3. Startup type -- whether the service starts automatically with the server or must be started manually.

Confirm to install. The service then appears as installed and stopped, ready to start.

Start and Stop

Start launches an installed service; Stop halts it. The request is issued immediately and the row updates to the new state on the next refresh. A service must be installed before it can be started.

Stopping a service from the Dashboard is respected: the Watchdog will not start it again behind you. A service an operator stopped stays stopped until it is started again.

Uninstall

Removes the service's registration from the operating system. The service's files remain on disk; only its registration is removed, so it can be installed again later. Stop a service before uninstalling it.

Properties (Settings)

The gear icon opens the service's Properties in a tab. This is where you set everything the service needs to run -- for example its data-server connection, timer intervals, logging options, listening ports, and e-mail settings, depending on the service. Properties are organised into tabs and sub-tabs, mirroring the classic service properties -- the same tabs and the same fields, in the browser instead of on the server’s desktop.

  1. Save writes your changes. The Dashboard re-reads and re-displays the saved values afterward.
  2. Test connection (on a data-server tab) checks that the entered server, port, and login actually connect, without saving.
  3. Send test email (on an e-mail tab) sends a test message using the entered e-mail settings, without saving.
  4. Discover (on the File Paths tab of the Reports service) locates the installed Crystal Reports runtime for you.
  5. Include timing diagnostics (Reports service) adds a detailed timing trace to the service’s log, for use while investigating an issue. Leave it off in normal running.

Passwords are shown masked. Editing an array of values -- such as a list of e-mail servers -- is done by adding and removing rows, and the change is written when you next Save.

Live log

Each service can stream its log to the Dashboard so you can watch it work in real time. Use the eye toggle on a service row to select it for the live log portal at the bottom of the page. The portal fills in recent history and then follows new lines as they are written. Portal controls include:

  1. Pause / Resume -- hold the view still or let it follow again.
  2. Find -- filter the visible lines by text.
  3. Level filters -- show or hide Info, Warning, and Error lines.
  4. Autoscroll -- keep the newest line in view.
  5. Clear view -- empty the on-screen buffer (this only clears your view; it does not delete the log).

You can select more than one service and watch them together. The lines shown are exactly the lines written to each service’s own log file.

Log-file navigator and download

The log-file navigator icon opens a list of the service's historical log files, newest first. From there you can:

  1. Open a file -- click a file name to read it in a tab, paging through it with Load earlier for older content.
  2. Download a file -- the download icon on a row saves that log file to your computer.

Files

For services that produce output files, a folder icon opens a Files tab that lists the service's configured output folders. You can browse the folders and open or download individual files. The file browser is read-only -- it never renames, moves, or deletes anything on the server.

Rename

The pencil icon on a service row lets you give the service a custom display name. This changes only how the service is labelled in the Dashboard; it has no effect on how the service runs. Clear the custom name to return to the default label. Display names must be unique: if the name is already taken, the Dashboard answers That name is already in use. and keeps the old one.

Creating additional instances

Some services run as numbered instances -- for example a Front End or Alarm Gen instance per signal path. The Add (+) button on the Front End, Nats Front End and Alarm Gen. category headers creates another one:

  1. Choose the Service to create an instance of. Only services that support additional instances are listed; a service whose instance numbers are all in use is marked full.
  2. Choose an Instance number from the free numbers offered for that service.
  3. Optionally tick Install after create to register the new instance with the operating system immediately.

Confirm to create the instance. It then appears in the list, ready to have its properties set and to be started.

A dynamic instance that is not installed can be removed with the trash icon on its row, which deletes that instance's own files. An instance cannot be removed while it is installed -- uninstall it first. Removal asks you to type the instance’s displayed name exactly as it is shown; Delete stays disabled until what you type matches.

Understanding the version number

The version shown in the header and in the Versions list is the SBN Services’ own version number -- for example 1.0.41.

The number increases every time a new version is published. A higher number is a newer version -- that is all you need to read from it. To confirm a server is running the latest version, compare the number shown here against the latest package published for download.

SBN Services is versioned independently, on the same scheme as SBN Search and SBN Tunnel. It is not tied to the SBN release numbering (the v95 / v96 build scheme) and does not need to match the SBN application release you run elsewhere. The number moving forward simply means the Services have been updated, not that your SBN release has changed. See Versioning on the Installing SBN Services page.

API Keys

The API Keys tab is where you issue and manage the keys that let a script, a scheduled job, or another application call the Dashboard's actions without a browser sign-in. The list shows every key with its name, prefix, when it was last used, when it expires, and whether it is active; the + button creates a new one, and each row can be edited or revoked.

When you create a key you set what it may do -- which features it is allowed to use and which services it may touch -- along with an expiry date and, optionally, the addresses it may be called from. The full secret is shown once, at the moment of creation; copy it then and store it safely.

Every action an API key can perform is a subset of what you can do signed in to the Dashboard. Some Dashboard actions are never available to an API key at all (see What API keys can never do).

Creating an API key

On the API Keys tab, use Add New Token to open the editor and fill in:

  1. Name -- a label to recognise the API key by. Letters, digits, spaces, hyphens, and underscores, up to 64 characters.
  2. Expires -- the date the API key stops working. An expiry is required -- there is no "never" -- and it can be at most 365 days from today.
  3. Access -- the features and services the API key may use, set in the scope editor below.
  4. Admin password -- your Dashboard administrator password, re-entered to confirm. Creating an API key is the highest-value action in the Dashboard, so it always asks for the password again.

Optionally, under Advanced, you can restrict by source address -- a comma-separated list of IP addresses or ranges that the API key may be used from. Leave it blank to allow any address. This is worth setting for API keys that hold install or diagnostics features. (Source-address restriction only has effect when callers reach the Dashboard directly; behind a reverse proxy every caller appears to come from the proxy, so the restriction cannot distinguish them.)

Select Create token to issue it.

The scope editor

The scope editor asks two questions.

Features -- a checklist of what the API key may do. Tick the features this API key needs. A feature applies to every service that is left included below.

Services -- which services the API key may act on. Every service is included by default; you untick the services this API key must not touch. This "all-by-default, exclude what you don't want" model means an API key naturally covers your whole server unless you deliberately narrow it.

Services are grouped by category. Each group has:

  1. A group All control that includes or excludes every service in the group at once.
  2. All future instances -- leave this ticked and the grant follows the group itself, so the API key also covers services added to that group later (including services created after the API key was issued). Unticking any single service in a group turns this off, because the API key no longer covers the whole group.

As you edit, a running summary shows what the API key will be able to do.

What each feature grants

The common features, and what each one allows:


Feature

What it grants

Install

Install a service, and create new service instances. Installs run under an account you supply -- a high-privilege action.

Start

Start a service.

Stop

Stop a service.

Uninstall

Remove an installed service from the machine.

Read Log

Tail and page through a service's log output.

Settings Read

Read a service's settings, including its connection details (hosts, ports, usernames). Passwords are returned masked.

Settings Write

Change a service's settings. This can change where the file browser reads from.

Download Logs

Download whole archived log files off the machine.

Clear Log

Delete a service's log content.

List Files

List the files under a service's output folders.

Download Files

Download file content off the machine.

Test Connection

Run connection and e-mail diagnostics for a service. This opens outbound connections to a host you supply.

Rename

Set or clear a service's display name.

Catalog Read

List services, their state, and version information. Applies across the whole Dashboard.

Visibility Read

Read which services are hidden from the Dashboard. Applies across the whole Dashboard.

Catalog Read and Visibility Read describe the Dashboard as a whole rather than one service, so they appear in their own section above the service list rather than as a per-service feature.

Grant only the features an API key genuinely needs. Features such as Install, Uninstall, Settings Write, Download Logs, Download Files, Clear Log, and Test Connection carry real weight -- they install or remove software, move data off the machine, delete content, or open outbound connections -- so treat them as you would a privileged account.

The secret -- shown once

When an API key is created (or rotated), its secret value is displayed once, on a confirmation panel. This is the only time the value is shown -- it is not stored anywhere and cannot be retrieved again.

  1. Copy the value immediately and store it somewhere secure (a secrets manager or the configuration of the tool that will use it).
  2. If you lose it, you cannot recover it -- rotate the API key to issue a new value.
  3. Treat the secret like a password: never paste it into e-mail, chat, source code, or a shared document.

Rotating an API key

The rotate action on an API key's row issues a new secret for the same API key -- its name, expiry, and access stay the same. The moment you rotate, the old secret stops working, so update whatever uses the API key with the new value. Rotate when a secret may have been exposed, or on a regular schedule for long-lived API keys. Rotating asks for your administrator password.

Disabling and revoking

Two levers turn an API key off:

  1. Disable -- the enable/disable control on an API key's row switches it off without deleting it. A disabled API key is refused until you switch it back on. Use this to pause an API key temporarily.
  2. Revoke -- the revoke action deletes the API key permanently. It stops working immediately and anything using it starts failing. Revoke asks you to type the API key's name to confirm.

Per-key revoke is the way to withdraw an API key -- there is no bulk "revoke everything" action.

What API keys can never do

Some Dashboard actions are deliberately never available to an API key, no matter what features it holds. An API key can never:

  1. Create, edit, rotate, enable, disable, or revoke an API key, or read the API key list -- all API key management is administrator-only.
  2. Start-all or stop-all across every service at once, or run the automatic catalog reconcile.
  3. Change the administrator e-mail or password, or the Dashboard's own e-mail settings.
  4. Change which services are hidden.
  5. Copy the SMTP settings onto all installed services at once.

These actions require a signed-in administrator session in the Dashboard.

Account

The Account tab holds settings for the Dashboard itself, on two sub-tabs.

SMTP -- the e-mail settings the Dashboard uses to send its own messages (such as verification e-mails):

  1. Save SMTP settings -- store the sender details and the list of SMTP servers, each with its host, port, credentials, timeout, retry, and SSL option.
  2. Test -- each server row carries its own test button, which sends a test message using the values on screen for that server.
  3. Apply to all installed services -- copy these SMTP servers onto every installed service on the server at once. Confirm before using it, and stop and start each updated service for the change to take effect.

Account & Security -- the Dashboard administrator identity:

  1. Change email -- set or change the administrator e-mail address; a verification link is sent to confirm it.
  2. Change password -- change the administrator password. If a verified e-mail address is on file the change is confirmed by e-mail; otherwise it applies immediately and signs you out.
  3. Resend -- re-send a pending verification e-mail.

Both the e-mail change and the confirm-by-e-mail password change need a working SMTP server, so set SMTP up first.

Related help

  1. SBN Services API Usage -- call the Dashboard's actions from your own scripts and tools.




Was this helpful?