<%NUMBERING1%>.<%NUMBERING2%>.<%NUMBERING3%> PRTG Manual: Core Server
Important Notice
As of PRTG 26.x.122, the former Core & Probes tab exists as two separate tabs. If you want to edit settings related to probes, see section Probes.
On the Core Server tab, you can define settings for the PRTG core server.
If you cannot save changes to Core Server settings because you get an Error (Bad Request) with the message Active Directory Domain not accessible, make sure that you provide the correct access type for your domain in section Active Directory Integration. For example, change Use the PRTG core server service account (usually Local System) (default) to Use explicit credentials and provide correct credentials for the domain. PRTG automatically sets the access type to Use the PRTG core server service account (usually Local System) (default) by default, so you might need to change this.
If 15 minutes (900) seconds have passed since your last credential-based login and you open a setup page from a different setup page, PRTG asks you to enter your credentials again for security reasons. A dialog box appears. Enter your Login Name and Password and click OK to continue.
This documentation refers to an administrator that accesses the PRTG web interface on a master node. Other user accounts, interfaces, or failover nodes might not have all of the options in the way described here. In a cluster, note that failover nodes are read-only by default.
This setting is only visible if you select Use a proxy server above
Enter the address of the proxy server that you use for outbound connections. Enter a valid address.
Port
This setting is only visible if you select Use a proxy server above
Enter the port number of the proxy server that you use for outbound connections. Enter an integer.
Proxy Authentication
This setting is only visible if you select Use a proxy server above
Determine whether the proxy server needs credentials or not:
Do not use authentication: Do not use credentials for proxy connections.
User name and password: Define credentials (user name and password) below. Use this setting if the proxy server requires credentials.
User Name
This setting is only visible if you select User name and password above.
Enter a user name for proxy authentication. Enter a string.
Password
This setting is only visible if you select User name and password above.
Enter a password for proxy authentication. Enter a string.
Audit Log
This feature is only available with a PRTG Network Monitor or PRTG Enterprise Monitor subscription license. For more information about how to buy or upgrade a subscription license, see the Paessler shop.
Audit Log
Setting
Description
Sensitive Data Handling
Define what details PRTG includes in the audit log
Do not log sensitive data (default): PRTG does not include sensitive data in the audit log entries.
Log sensitive data: PRTG includes sensitive data in the audit log. PRTG identifies the following data as sensitive in audit logs:
This setting is only available for PRTG 2500, PRTG 5000, PRTG 10000, and all PRTG Enterprise Monitor subscriptions.
Define if PRTG sends audit log entries to a syslog server:
Do not send audit log entries to syslog server (default)
Send audit log entries to syslog server
Syslog Payload Format
This setting is only visible if you select Send audit log entries to syslog server above.
Define the format of the syslog message's payload:
CEF (default): Use the Common Event Format (CEF).
LEEF: Use the Log Event Extended Format (LEEF).
Plain text: Messages that PRTG sends to the syslog server appear as they are written in the audit log file.
Syslog Network Protocol
This setting is only visible if you select Send audit log entries to syslog server above.
Define the network protocol PRTG uses for the syslog connection:
UDP (default): Use User Datagram Protocol (UDP) for the syslog conenction.
TCP: Use Transmission Control Protocol (TCP) for the syslog conenction.
TLS: Use Transport Layer Security (TLS) for the syslog conenction.
We recommend that you select Transport Layer Security (TLS) for an encrypted communication channel to the syslog server.
If you select TLS or TCP, PRTG attempts to deliver the audit log entry three times over 30 minutes if it cannot reach the syslog server.
Syslog Server Host
This setting is only visible if you select Send audit log entries to syslog server above.
Enter the IP address or the Domain Name System (DNS) name of the system that runs the syslog server.
Syslog Server Port
This setting is only visible if you select Send audit log entries to syslog server above.
Enter the port that PRTG sends the syslog messages to. The default port is 514. PRTG supports ports 1- 65535.
Syslog Server Certificate Verification
This setting is only visible if you select Send audit log entries to syslog server above.
Define if PRTG validates the syslog server certificate:
Verify server certificate (default)
Do not verify server certificate
Certificate Authority Handling
This setting is only visible if you select Verify server certificate (default) above.
Define where PRTG finds the syslog server certificate.
Use system certificate store (default): Find the certificate authority (CA) server certificate in your system's certificate store.
Specify a certificate authority server certificate: Define a CA server certificate from a file if the server certificate is not in your system's certificate store.
Syslog Server Certificate
This setting is only visible if you select Specify a certificate authority server certificate above.
Select a CA server certificate to use for the TLS connection validation. This file must match the CA server certificate that you used to set up the syslog server.
The certificate must be in the /cert folder in the PRTG program directory and must be in the PEM format.
Client Authentication
This setting is only visible if you select Send audit log entries to syslog server above.
Define if you want to authenticate your system with a client certificate.
Do not use client authentication (default)
Authenticate with a client certificate
Client Certificate Handling
This setting is only visible if you select Authenticate with a client certificate above.
Define where PRTG finds the client certificate and client certificate key:
Use system certificate store (default)
Enter a client certificate
Client Certificate Identification
This setting is only visible if you select Use system certificate store (default) above.
Define which identification PRTG uses to find the client certificate in the system certificate store:
Use the certificate's friendly name (default)
Use the certificate's thumbprint
We recommend that you use a friendly name so that you do not need to reconfigure PRTG every time you change your client certificate.
Friendly Name
This setting is only visible if you select Use the certificate's friendly name above.
Enter the friendly name of the client certificate.
You can set the friendly name in the properties of the client certificate in the Windows Certificate Manager.
Thumbprint
This setting is only visible if you select Use the certificate's thumbprint above.
Enter the thumbprint of the client certificate.
Client Certificate
This setting is only visible if you select Enter a client certificate above.
Enter the client certificate.
The certificate must be in the PEM format.
We recommend that you copy and paste it to avoid typing errors.
Client Certificate Key
This setting is only visible if you select Enter a client certificate above.
Enter the client certificate key.
We recommend that you copy and paste it to avoid typing errors.
Client Certificate Key Password
This setting is only visible if you select Enter a client certificate above.
Optionally, enter the password for the client certificate key.
Test Connection
This setting is only visible if you select TLS or TCP above.
Click Test Connection to test the connection to the syslog server endpoint using the current parameters.
Enter a list of access keys for remote probe connections. Enter one access key per line.
Every remote probe that wants to connect to this PRTG installation must use one of these keys.
For more information on how to set an access key for a classic remote probe, see section PRTG Administration Tool.
For more information on how to set an access key for a multi-platform probe, see the manual: Multi-Platform Probe for PRTG.
Allow IP Addresses
Enter a list of remote probe IP addresses or Domain Name System (DNS) names that you want to allow to connect to the PRTG core server. Enter one IP address or DNS name per line. The following options are also possible:
[Empty]: An empty field does not allow any remote probes (only the local probe). Enter IP addresses or DNS names to allow remote probe connections. We recommend that you use IP addresses instead of DNS names because DNS name resolution might be cached.
any: Enter the word any to automatically allow all remote probe connections. This is the default setting when you install a classic remote probe from the device tree. We recommend that you enter the IP addresses specific to your remote probes. We recommend that you only use this option in intranets in PRTG Network Monitor, not in PRTG Hosted Monitor.
PRTG always automatically allows the local probe (127.0.0.1). PRTG checks the list of allowed IP addresses before it checks the list of denied IP addresses.
If the IP address of a remote probe regularly changes (for example, because of an internet provider that dynamically assigns IP addresses), enter the potential IP address range for the remote probe or use any.
You can use the PRTG syntax for IP address ranges. For more information, see section Define IP Address Ranges.
This setting does not affect multi-platform probe connections.
Deny IP Addresses
Enter a list of remote probe IP addresses or DNS names that you do not want to allow to connect to the PRTG core server. Enter one IP address or DNS name per line.
You can use Deny IP Addresses to explicitly deny connections from remote probes that you do not want to include in your setup either at all or for a certain time. You can also use it to allow access to an IP address range under Allow IP Addresses, but to deny access to a single IP address from the IP address range.
You can use the PRTG syntax for IP address ranges. For more information, see section Define IP Address Ranges.
If you deny the IP address or DNS name of a remote probe, you must restart the PRTG core server to apply your changes.
We recommend that you use IP addresses rather than DNS names because DNS name resolution might be cached.
This setting does not affect multi-platform probe connections.
Deny GIDs
Enter a list of global IDs (GID). Enter one GID per line. PRTG denies access to matching GIDs.
If you remove a remote probe from the device tree or if you deny a remote probe after installation, PRTG automatically adds its GID to this list. The remote probe is no longer able to connect. Denying GIDs is more precise than denying IP addresses, where other remote probes at the same location could also be excluded.
A GID is the ID that PRTG attributes to every probe that you include in your monitoring.
Connection Security
Specify the security level that the PRTG application server accepts for connections to and from the PRTG core server:
High security (TLS 1.3, TLS 1.2): Only accept high security connections from probes.
Default security (TLS 1.3, TLS 1.2) (recommended): Only accept high security connections from probes.
Weakened security (TLS 1.3, TLS 1.2, TLS 1.1, TLS 1.0): Additionally accept TLS 1.1-secured and TLS 1.0-secured connections from probes. If you have probes that do not support -secured or TLS 1.2-secured connections because you updated from an older PRTG version, you can use this setting to connect to and to update older probes. After the update, we recommend that you change this setting to High security (TLS 1.3, TLS 1.2) or Default security (TLS 1.3, TLS 1.2) (recommended).
If you set a registry key in previous PRTG versions to override the Secure Sockets Layer (SSL)/Transport Layer Security (TLS) version and cipher suites of PRTG web server connections or probe connections, High security (TLS 1.3, TLS 1.2) overrides the registry setting and only TLS 1.3 and TLS 1.2 are allowed. If you select Default security (TLS 1.3, TLS 1.2) (recommended), the registry value overrides this setting and the connection security that you defined in the registry applies.
If you change this setting, PRTG needs to restart the PRTG core server to apply your changes. After you click Save, a dialog box appears that asks you to confirm the restart. Click OK to trigger the restart. During the restart, all users of the PRTG web interface, the PRTG app for desktop, or the PRTG Apps for Mobile Network Monitoring are disconnected and reconnected.
This option is not available in PRTG Hosted Monitor.
Active Directory Integration
This option is not available in PRTG Hosted Monitor.
Active Directory Integration
Setting
Description
Domain Name
To use the Microsoft Entra ID integration, enter the name of your local domain. Enter a string or leave the field empty.
PRTG does not support trusted domains or AD subdomains. For more important notes about AD integration, see section Active Directory Integration, section Notes and Restrictions.
Domain Access
Define how PRTG performs Active Directory (AD) queries:
Use domain name (default): Use the entry in the Domain Name field above.
Specify domain controllers: Use specific domain controllers. Specify the domain controllers below.
Primary Domain Controller
This setting is only visible if you select Specify domain controllers above.
Enter the DNS name of the primary domain controller.
Backup Domain Controller (optional)
This setting is only visible if you select Specify domain controllers above.
Optionally enter the DNS name of the backup domain controller or leave the field empty.
LDAP Connection Security
Define if you want to use a Secure Sockets Layer (SSL)/Transport Layer Security (TLS) secured connection to the LDAP server:
Use LDAP without connection security (default): Do not use an SSL/TLS-secured connection.
Use LDAP over SSL: Use an SSL/TLS-secured connection.
Access Type
Define which user account PRTG uses to configure AD access:
Use the PRTG core server service account (usually Local System) (default): Use the same Windows user account configured for the PRTG core server service. In a default installation, this is the "local system" Windows user account. If this account does not have the right to query all groups of your Active Directory, do not use this option.
Use explicit credentials: Define a user account that PRTG uses to authenticate against the Active Directory. This should be a user account with full access to all of your AD groups.
PRTG uses this account to query the AD for available groups.
User Name
This setting is only visible if you select Use explicit credentials above.
Enter the Windows user account name that PRTG uses to authenticate for AD configuration.
Password
This setting is only visible if you select Use explicit credentials above.
Enter the password for the Windows user account that PRTG uses to authenticate for AD configuration.
Historic Data Purging
Data purging enables you to automatically delete unnecessary data to free up disk space and to improve system performance. You can define different time spans for several kinds of data.
For more information on storage locations, see section Data Storage.
PRTG Hosted Monitor purges historic data using the default purging limits of PRTG Network Monitor with the exception of configuration auto-backups and report data. PRTG Hosted Monitor purges this data after 30 days. You cannot modify historic data purging limits in PRTG Hosted Monitor.
Historic Data Purging
Setting
Description
Log File Records
Define how long PRTG keeps records in the system log file Log Database.db. Enter a value in days. PRTG automatically deletes all entries that are older than this value. This also affects the content of the Logs tab of monitoring objects like sensors.
Keep this value as low as possible to enhance system performance.
The default value is 30 days.
PRTG Web Server Log Records
PRTG creates one PRTG web server log file every day. Define how many PRTG web server log files to keep. Enter a value in days. PRTG automatically deletes all PRTG web server log files that older than this value.
The default value is 30 days.
Historic Sensor Data
Define for how long PRTG keeps historic sensor data for all sensors. Enter a value in days.
Historic sensor data is the basis for reports on monitoring data. If you decrease this value, less historic monitoring data is available.
Depending on the scanning intervals and the number of sensors in your setup, the file that contains this data can become large. For smaller installations up to 500 sensors, 365 is usually appropriate.
Old toplist data is deleted automatically as soon as a limit of 2 GB is reached. The oldest data is deleted from the database first.
The default value is 30 days.
Closed Tickets
Define for how long PRTG keeps tickets that are in the Closed status. Enter a value in days.
The default value is 365 days.
Reports
Define the maximum age for PDF reports. Enter a value in days. PRTG automatically deletes all reports that are older than this value.
The default value is 365 days.
PRTG Hosted Monitor only retains this data for 30 days.
Configuration Auto-Backups
Define the maximum age for daily configuration backups. Enter a value in days. PRTG automatically deletes all configuration backup files that are older than this value.
The default value is 365 days.
PRTG Hosted Monitor only retains this data for 30 days.
Screenshots of HTTP Full Web Page Sensor
Define for how long PRTG keeps the screenshots of the HTTP Full Web Page sensor (PhantomJS browser engine). Enter a value in days. PRTG automatically deletes screenshots that are older than this value with every sensor scan.
The default value is 10 days.
Save your settings. If you change tabs or use the main menu without saving, all changes to the settings are lost.
PRTG MultiBoard Access
PRTG MultiBoard Access
Setting
Description
PRTG MultiBoard File Transfer
Select if you want to allow PRTG MultiBoard to access the PRTG data directories and PRTG program directories of the PRTG core servers connected to PRTG MultiBoard:
Disable (default): Do not allow PRTG MultiBoard to access, configure, and transfer PRTG files. You will not be able to use the Probe Transfer, Configuration Viewer, and Template Transfer features.
Enable: Allow PRTG MultiBoard to access, configure, and transfer PRTG files.
PRTG MultiBoard requires access to the PRTG Configuration.dat file for the Probe Transfer and Configuration Viewer features.
More
KNOWLEDGE BASE
I want to use the new UI and new API. What do I need to know?