Systems Management
Learn how to create and manage systems in My platform.
Understanding Systems
A system in My represents a managed server or device (NethServer or NethSecurity) that:
- Belongs to an organization
- Sends inventory data automatically
- Sends heartbeat signals to indicate it's active
- Can be monitored and managed remotely
System Lifecycle
1. Created by Admin/Support → receives system_secret
2. Not registered yet → system_key is hidden
3. External system registers → system_key becomes visible
4. System sends inventory and heartbeat → monitored status
System Status
| Status | Meaning |
|---|---|
| Unknown | Created, but has never sent a heartbeat |
| Active | Last heartbeat younger than 20 minutes |
| Inactive | Last heartbeat older than 20 minutes |
| Suspended | Suspended by an administrator; it cannot send data |
| Unregistered | The appliance gave up its credentials -- terminal, see Registration |
| Deleted | Soft-deleted; restorable |
The 20-minute window comes from HEARTBEAT_TIMEOUT_MINUTES, and a cron re-evaluates every system every 5 minutes, so the flip to inactive is seen 20 to 25 minutes after the last heartbeat. See Inventory and Heartbeat.
Creating Systems
Prerequisites
- You must have Support or Admin role
- You need a customer organization to associate the system with
- System will be created in "not registered" state
Create a New System
- Navigate to Systems
- Click Create system
- Fill in the form:
- Name: Descriptive name for the system (e.g., "Production Server Milan")
- Organization: Select the customer organization
- Notes (optional): Additional information
- Click Create system
Example:
Name: Production Web Server Milano
Organization: Pizza Express Milano (Customer)
Notes: Main production server for Milan locations
System Secret
After creation, you will see:
{
"id": "sys_abc123",
"name": "Production Web Server Milano",
"system_key": "",
"system_secret": "my_a1b2c3.k1l2m3...",
"status": "unknown",
"registered_at": null,
"organization": "Pizza Express Milano"
}
The system_secret is shown only once during creation. Copy and save it immediately: you need it to register the system. If you lose it before registering, you can regenerate it -- but once the system has registered, regeneration is refused, and the only way forward is a new system.
Viewing Systems
System List
Navigate to Systems to see:
- System name
- Type (ns8, nsec, etc.)
- Version
- FQDN and IP addresses
- Organization
- Created by
- Status (unknown, active, inactive, suspended, deleted)
- Registration status
Filtering and Search
Use filters to find specific systems:
- Search: By name or system_key
- Product: Filter by type (NethServer or NethSecurity)
- Version: Filter by system version
- Organization: Filter by customer organization
- Created By: Filter by user who created the system
- Add-on: Filter by purchased add-on (see Add-ons)
- Status: unknown, active, inactive, suspended, deleted
- Sort By: Name, version, FQDN/IP address, Organization, Created By, Status
The Add-on menu lists the add-ons held by at least one of your systems, so an option never comes back empty. Selecting more than one widens the search: a system matches when it holds any of them. Only add-ons that are valid at that moment count, so an expired or cancelled one leaves the system out.
System Details
Click on a system to view comprehensive information:
Overview Tab
-
Basic Information:
- System name
- System type (auto-detected)
- Status
- Version
- Registration timestamp
-
Network Information:
- FQDN (Fully Qualified Domain Name)
- IPv4 address
- IPv6 address
-
Authentication:
- System key (visible only after registration)
- Registration status
- Last authentication time
-
Organization:
- Customer name
- Organization type
- Organization name
-
Heartbeat Status:
- Current status (active/inactive/unknown)
- Last heartbeat timestamp
- Last inventory timestamp
-
Audit Trail:
- Created by (user name and email)
- Creation date
- Deletion date (if soft-deleted)
Inventory Tab
View detailed system inventory:
- Latest Inventory: Most recent inventory snapshot
- Inventory History: All historical inventories with pagination
- Changes: List of detected changes between inventories
- Diff View: Detailed comparison between inventory versions
See Inventory and Heartbeat for details.
Managing Systems
Editing System Information
- Navigate to the system page
- Click Edit
- Update the fields:
- Name
- Organization
- Notes
- Click Save system
Changing the Organization moves the system to a different owner. The system's backups, alert history, and inventory follow the new owner; the previous owner loses access immediately. See Reassigning a system to another organization for the full behaviour, who is allowed to do it, and what happens to silences and app assignments.
Regenerating System Secret
:::danger Only before registration
The secret can be regenerated only while the system has not registered yet.
Once registered_at is set, Regenerate Secret answers HTTP 409: the
appliance authenticates with the secret it registered with, and there is no way
to install a new one on it from here.
:::
While the system is still unregistered:
- Navigate to the system page
- Click Regenerate Secret (using the kebab menu)
- Confirm the action
- Copy the new secret immediately -- it is shown only once
- Configure the new secret on the external system
The previous secret is invalidated at once.
When to regenerate:
- The secret was lost before the system could register
- The secret leaked before being used
- The system was prepared but never deployed, and you want fresh credentials
If the system is already registered and its credentials are compromised or lost, there is no rotation path: create a new system, register the machine with the new secret, then delete the old row. The appliance can also give up its own credentials from its side -- see Registration.
Soft Delete
Soft delete marks a system as deleted without removing data:
- Navigate to the system details page
- Click Delete (using kebab menu)
- Confirm the action
Effects:
- System marked as "deleted"
- Cannot send inventory or heartbeat
- Hidden from normal views
- Its applications are hidden from lists, totals and organization counters until the system is restored (they are kept, not deleted)
- Can be restored if needed
- All historical data is preserved
To view deleted systems:
- Apply filter: Status = "deleted"
- Select the deleted system
- Click Restore to undelete
Permanent Delete
This operation is irreversible!
To permanently delete:
- Soft delete the system first
- Navigate to deleted systems view
- Select the system
- Click Permanent Delete
- Type system name to confirm
- Click Delete
This will remove:
- System record
- All inventory history
- All heartbeat records
- All change detection data
This will preserve:
- Audit logs
- User activity logs
System Registration
After creating a system, the external system must register itself using the system_secret.
Registration Flow
- Admin creates system → receives
system_secret - Admin configures external system with the secret
- External system calls registration API with secret
- Platform validates and returns
system_key - External system stores both credentials for future use
See System Registration for detailed instructions.
Registration Status
Before Registration:
{
"system_key": "",
"registered_at": null,
"status": "unknown"
}
After Registration:
{
"system_key": "NOC-F64B-A989-C9E7-45B9-A55D-59EC-6545-40EE",
"registered_at": "2025-11-06T10:30:00Z",
"status": "unknown"
}
System Monitoring
Dashboard Overview
The Dashboard carries two relevant cards:
- Systems: the total across the organizations you can read, with badges for active, inactive and pending that open the list already filtered
- Alerts: open alerts across the same scope, with badges by severity
Exporting System Data
Export system information for reporting:
- Navigate to Systems
- Apply filters if needed
- Click Actions > Export
- Choose format: CSV or PDF
- Download the file
Best Practices
System Naming
- Use descriptive, consistent names
- Include location if relevant: "Server Milano Nord"
- Include purpose: "Production Web", "Backup Server"
- Avoid special characters
- Keep names under 50 characters
Organization
- Group systems by customer
- Use custom data for categorization
- Tag systems with environment (prod/staging/dev)
- Document system purpose in notes
Security
- Store secrets securely (password manager, vault)
- Never share secrets via email
- Revoke secrets immediately if compromised
- Monitor failed authentication attempts
Monitoring
- Check heartbeat status daily
- Review inventory changes weekly
- Set up alerts for critical systems
- Monitor system versions for updates
Troubleshooting
System Not Appearing in List
Problem: Expected system is not visible
Solutions:
- Check if system belongs to accessible organization
- Verify system is not soft-deleted (check deleted filter)
- Confirm you have Support or Admin role
- Check if filters are applied
- Refresh the page
Cannot Register System
Problem: Registration fails with "invalid system secret"
Solutions:
- Verify secret was copied correctly (no extra spaces)
- Check secret hasn't been regenerated
- Confirm system is not deleted
- Ensure system is not already registered
- See System Registration Troubleshooting
System Shows as "Inactive"
Problem: System heartbeat status is "inactive" (yellow)
Solutions:
- Check if system is actually running
- Verify network connectivity
- Check system logs for errors
- Confirm credentials are correct
- Test heartbeat endpoint manually
- See Inventory and Heartbeat
System_key is Hidden
Problem: Cannot see system_key field
Explanation:
- system_key is hidden until system is registered
- This is expected behavior for unregistered systems
- Register the system first to reveal system_key
Solution:
- Use system_secret to register the system
- After registration, system_key becomes visible
- See System Registration
Lost System Secret
Problem: System secret was not saved during creation
If the system has not registered yet:
- Regenerate the system secret
- Copy the new one immediately
- Configure the external system with it -- the old secret is invalid at once
If the system is already registered: Regeneration is refused with HTTP 409, and there is no rotation path. Create a new system, register the machine with its new secret, then delete the old row.
System Type Not Detected
Problem: System type shows as null or unknown
Explanation:
- System type is auto-detected from first inventory
- Shows null until first inventory is received
Solution:
- Ensure system is registered
- Send first inventory from external system
- Type will be detected automatically
- See Inventory and Heartbeat
Next Steps
After creating systems:
- Register external systems using system_secret
- Configure inventory collection
- Set up monitoring and alerts
- Review system statistics regularly