Ekalix Radar · install and licence guide

Installed in about ten minutes.

Everything the person installing Ekalix Radar needs: what to have ready, the installer, the setup page, the rights and ports, and the licence. The same guide is in the download as INSTALL.html.

1 · What you need
  • A Windows Server 2016 or later to run Ekalix - or Windows 10 or 11 for a trial. Windows PowerShell 5.1 and the .NET Framework are built in; nothing else is installed - no PowerShell modules, no Python, no agents - here or on the servers you watch.
  • A SQL Server 2016 SP1 or later for the Ekalix database, any edition. With none on the computer, the installer offers SQL Server 2022 Express, free from Microsoft. Allow about 30 MB per monitored server for two years of history - Express is enough up to about 300 servers.
  • One Windows account to run Ekalix, ideally a service account. It runs everything - the page, the collectors, the recorder and the alerts - so the rights below are all for this one account.
  • Your licence file from your account at ekalix.com. The free 14-day trial licence comes with the download.
  • Edge or Chrome to open the page, signing in with Windows - on the Ekalix server, or from people's own computers when Ekalix is opened to the network.
2 · Install

Unblock and extract

Right-click the downloaded zip, choose Properties, tick Unblock, press OK. Then right-click it again and choose Extract All. It holds one folder, Ekalix; put it where you like, for example D:\Ekalix. Do not run anything from inside the zip.

Run Install Ekalix.cmd

In that folder; Windows asks an administrator to approve once. It checks the computer, finds the SQL Server for Ekalix's data or installs SQL Server Express, asks which account runs Ekalix, gives that account its rights, and starts Ekalix with Windows. It can also give the account its read-only rights on the servers you name.

Connect its database

Open the Ekalix shortcut on the desktop, or http://localhost:8100. On the setup page enter the SQL Server the installer named (for Express, localhost\SQLEXPRESS), press Test, then Create the database. You become the first Owner.

Install your licence

Setup ends by asking for the licence file - nothing is collected until one is installed. Then press Export key file and keep it and its passphrase safe, apart.

Add servers and people

Press Add server for each SQL Server instance, Windows, IIS or MongoDB server - monitoring starts at once. In Administration, Access, give AD groups or people a role; keep at least two Owners.

3 · Rights and ports

What each part needs.

Who or whereNeedsFor
The Ekalix account, on the Ekalix serverAn ordinary user - no administrator rights. The installer gives it Log on as a batch job and Modify on the Ekalix folder. A service account, or a gMSA with no password to look afterRuns the page, the collectors, the recorder and the alerts
… on the SQL Server for the Ekalix databasedbcreator for setup, or db_owner of an empty database your DBA created; afterwards db_owner of the Ekalix databaseSettings, servers, history, the audit log and the licence
… on each SQL Server you watchThe read-only rights below, or sysadmin. Optional: ALTER ANY EVENT SESSION for the MonitorEx event session. A SQL login per server also works, stored encryptedHealth, jobs, backups, availability groups, waits and queries - read only
… on each Windows or IIS server you watchLocal Administrators group, and WinRM (TCP 5985); without WinRM, a reduced set over DCOMCounters, disks, services, event logs, IIS sites and pools
… on each MongoDB you watchThe read-only monitorex user belowServer, replication and operations - never a document
An administrator, onceApproves the installer - and, to open the page to colleagues, the page's address and its port in Windows Firewall. The installer can also apply the read-only rights above with that person's own rights on your serversSetting Ekalix up once
People who use the pageA role for AD groups or people: Owner, Admin, Operator or Viewer. Windows sign-in; no rights on the servers watchedWho sees and does what
PortFromTo
TCP 8100 (or the port you set)People's browsersThe Ekalix server - that server only, unless opened to the network
TCP 1433 or the instance's portThe Ekalix serverThe Ekalix database's SQL Server and each SQL Server you watch
TCP 5985 (WinRM), or TCP 135 and the RPC range (DCOM)The Ekalix serverEach Windows or IIS server you watch
TCP 27017The Ekalix serverEach MongoDB member you watch
HTTPS, outboundThe Ekalix serverOnly if you switch on AI explanations - nothing else leaves your network
4 · Read-only rights on a monitored SQL Server

The installer writes this for your account into config\access\grant-sql.sql, and can run it for you. By hand, on each SQL Server you monitor:

USE master;
CREATE LOGIN [DOMAIN\svc-ekalix] FROM WINDOWS;
GRANT VIEW SERVER STATE, VIEW ANY DEFINITION,
      CONNECT ANY DATABASE TO [DOMAIN\svc-ekalix];
CREATE USER [DOMAIN\svc-ekalix] FOR LOGIN [DOMAIN\svc-ekalix];
GRANT EXECUTE ON sys.xp_readerrorlog TO [DOMAIN\svc-ekalix];
USE msdb;
CREATE USER [DOMAIN\svc-ekalix] FOR LOGIN [DOMAIN\svc-ekalix];
ALTER ROLE SQLAgentReaderRole ADD MEMBER [DOMAIN\svc-ekalix];
ALTER ROLE db_datareader ADD MEMBER [DOMAIN\svc-ekalix];
5 · Read-only rights on a monitored MongoDB

Once per replica set, on its primary, in mongosh. Nothing it is given can change data, and Ekalix never reads a document from your collections.

use admin
db.createUser({
  user: "monitorex",
  pwd: passwordPrompt(),
  roles: [ { role: "clusterMonitor", db: "admin" },
           { role: "read", db: "local" } ]
})
6 · Your trial and your licence
  • The trial is a licence file that comes with the download from your account - 14 days, every feature, up to 100 units. Until a licence is installed, Ekalix collects nothing.
  • To buy, choose the number of units at checkout in your account. The same licence becomes paid - same id, nothing to reinstall.
  • Units: a SQL Server instance, an application server or a MongoDB member is 1; a Windows server is half, or free on the same machine as a monitored SQL Server or application server.
  • When a paid licence ends there are 30 days' grace with a warning; a trial simply ends. Everything collected stays readable.
7 · Looking after it
  • Back up the Ekalix database like any other database.
  • Moving to another server: copy the folder, run Install Ekalix.cmd, connect to the existing database, and give it the key file. The licence moves with the database.
  • A new version: back up the database, stop Ekalix, replace the scripts, web and db folders (keep config), and start it. An Owner is asked to upgrade the database.
  • Removing it: delete the scheduled task Ekalix, stop Ekalix, delete the folder, and drop the Ekalix database.

Ekalix only reads from the servers it monitors. It installs nothing on them and changes nothing - apart from the optional MonitorEx event session, where you allow it.

Ready to try it?

Fourteen days, every feature, up to 100 servers. Questions: sales@ekalix.com.