Unlock a world of possibilities! Login now and discover the exclusive benefits awaiting you.
Environment
Hello everyone and welcome to the June edition of Techspert Talks. I'm Troy Raney and I'll be your host for today's session. Today's Techspert Talk session is Qlik Cloud Admin 101 with our own Umberto De Domenico. Umberto, why don't you tell us a little bit about yourself?
Hello, thanks Troy for inviting me. I'm a Technical Adoption Specialist in Barcelona and my main focus is Qlik Cloud Qlik Sense Enterprise and helping out our customers for any onboarding issues that may experience.
Fantastic. All right. Today, Umberto is going to walk us through users and groups in Qlik Cloud. We're going to talk about apps and spaces, the differences and the workflows, and we're going to be viewing some different Administration tools that are available. Umberto, can we get started with the hub? Can you give us a quick feel for where things are?
Sure, this is the hub.
Okay.
Basically we have the Insights, Analytics, and Administration contexts the Data Integration is out of scope of this.
Sure.
And the idea is these three contexts reflects three different types of business users. Business users: the ones explore data within apps and make decision based on their selections; and then we have the Analytics: users, developers if you like; last ones are the administrators, the tenant admins.
And most users won't be able to see all those options, because they'll have slightly limited rights, but we're targeting Qlik Cloud administrators so hopefully they'll have rights to see the Administration section?
Yes.
How do we customize this tenant?
Of course. This is the tenant host name. You can rename this host name by going to Administration context; in here you have different options and we're going to go through some of those.
Mhm.
The main one we should be looking at now is Settings.
All right, Display Name.
Display Name is the name displayed within the cloud; but the host name is what you want to change.
So that alias host name is what you could actually put in the URL?
Yes.
Very nice. I think one of the first things that admins need to provision when they're starting up their new tenant is to get users on the tenant. Can you tell us about the IDP that you set up on this tenant?
Yes. In Qlik Cloud, we use OIDC and for this tech talk, we have chosen Azure Microsoft Entra ID IDP because it's the most popular and easy to show, but you can use any IDP you want. There is a very useful article in our Qlik Community.
This article goes through how to set that up?
Yes. It's very easy to follow and it's just matter of going through each step provided here.
I’ll provide the link to this so people can visit this, yeah it's very detailed on how to set all that up. Great, and what license model is this tenant using?
Okay. Here we are using a Capacity license.
Okay. In Qlik, we have two different type of licensing or subscription. One is a user based, and the other one is a Capacity license.
What is the big difference there?
The main difference is that in the user based license are based on the number of users; whereas the Capacity model, the license is based on the amount of data that you use.
So what's the advantage of Capacity licensing?
Gives more flexibility for our customers, because rather than focusing on the number of users, you can have unlimited free basic users.
And that's just people who want to use apps, look at apps, analyze data; and that's - you can have an unlimited number of people for that?
Exactly.
Very cool.
And the full users are the developers. You purchase the license depending on the amount of full users you want; this is something you have to define with the sales.
So where do you get your users from?
Right in a blank tenant with no configuration whatsoever, there is a mechanism which allows you to invite users via mail.
I see. With Azure as the IDP, is there a way to push users to the tenant without having to have them go through that invite process?
Yes. We can put in place a mechanism which is called SCIM, so that Azure will push all the information related to every single users to Qlik Cloud.
Where do we find the documentation for using SCIM?
You go in here: Manage, and you start exploring this article. It's simple as that.
Oh, it's the Help page.
Yeah this is very easy, yeah. Press on the Enable; and copy the token and URL, because I’ll need it later for Azure.
Okay. Great and we're looking at Azure, and the first step is to create an enterprise application. Can you show us how to do that?
Yes. Go in here.
Okay. And we're creating a new application?
Yes. We create a new application.
Qlik Cloud is not listed there, that's fine.
Create your own application. Going to use the host name, and then I put SCIM.
And that's your Qlik tenant ID right before any customization?
This was the host name. Click on Create.
All right.
Go to Provisioning; click on New Configuration.
This looks right.
Okay, tenant URL and secret token, that's what you copied earlier right?
Yes. And I pasted into this notepad.
Okay.
And now secret token, paste it here.
All right,
Test connection?
Yeah. That looks good. Great.
Okay.
Okay next step from the documentation: Mappings.
Yes. This is the tricky bit. Attribute Mappings; Entra ID Users. And here we need to remove attribute which are not needed.
Okay.
The attributes that we need to keep are basically Username, Active, Mail and Formated will be kept.
Okay.
We don't need Delivery, Office Address, City, State, Postal Code, Country, Telephone Number, Mobile, Facsimile. I think if that was a trivia question ‘what does fax stand for’ I don't think I would be able to remember that. Facsimile.
We should be done: 1, 2, 3, 4, 5.
Okay. Any other changes we need to make?
First of all, we start with Username; first of all the source attribute should be Object ID; and the matching presence here should be 2. Then we have the Email; should be edited and the matching precedence should be set to 1. Mail nickname should be changed to Object ID.
Okay.
Yep. So let's recap: we have Username: 2. Email type value: 1. And External ID: Object ID. Okay. This is done. So we can save it. Now we need to populate this enterprise application with the?
Correct. user and groups.
Okay. Is it possible to just add the groups and if you add the groups will it provision all the users in that group?
It's enough to add the groups and the users within the groups will be also provisioned.
That's fantastic; so let's pick a couple groups and add them.
Let's pick up for instance: the Retail and Sales and Marketing.
Okay. So all the users in those groups will automatically get pushed to Qlik Cloud?
Correct. We want to double-check those groups: Retail for instance has three members assigned.
Okay. Henrietta, Miriam and Patti.
If we look at Sales and Marketing, we have add three members.
Megan, Nestor and Pradeep. So once this finishes, we should have 6 provisioned users and two groups?
Correct.
Great. Look at that.
And here we can also see the users.
Awesome.
If you want to see also the Provision users ready to login but not done yet; we can go to Provision.
There they are, great.
We can obviously configure it up front before they log in providing them the correct roles and entitlements.
So now that we've got some users in the tenant, how do we import apps?
Well, the first thing we have to do is to decide in which space the app is going to be stored.
Okay.
In Qlik Cloud, we have the concept of Spaces. Let's go to Analytics, Create and then in here we have the space option.
Can you tell us what the differences are between these two types?
Yes. Shared Space: when you want to co-develop an app, then the app should be stored in a Shared Space. The Managed Space is the place where user consume apps.
So that's where you would publish the finished apps ready for Analytics?
Yes. Let's create first a space called Space1 which is a Shared space.
All right.
Create new.
This allows to the same menu we had in the Create section. So I create Space2, Managed Space, and then Create.
All right, we've got our two spaces. Can you tell us about the Catalog that we're in?
Yes. The Catalog section is very useful, because it allows us to segment the content inside the tenant based on spaces, and we see Space1, Space2 and Personal (the working area for just single users).
Okay.
And also we have the possibility of filtering based on the type of objects; and as you can see in Qlik Cloud, we have many objects not just apps.
Right.
Let's say that we want to upload two apps inside Space1. Click on the Create New button then Upload.
Okay.
I have these two apps here, and I can - here you can select spaces; we don't see the Managed space.
Okay.
The Managed space is usually where the apps are published.
Okay. Well great.
Yep.
I know as an admin, an important thing is to keep the data fresh and updated can you show us how to schedule reloads?
Yes. In the three dots here, you can see that we have a Reload Now option, but we can also Schedule the reload; and then you can Create a new task.
Right.
We have different options here: the day when the reload needs to take place; time zone; time; the day; and run this continually; from start date; until end date; or between start and end dates.
That's a lot of options there. Okay.
Mhm.
We got our first task.
Close this and we can Create a new task to Consumer Sales. Click on schedule here; Create a new task. I’m gonna go a Full Reload, based on What? On the Success of Another Task: The task we created earlier; which is in Space1; the app. And then as you can see here, we can implement a task chain very similar to what we used to have in Qlik Sense for Windows. So this is the task chain based on a successful reload.
Say that we now want to launch the reload; we see the reload has started, reload has been completed.
Okay one point I would like to discuss is Performance Evaluation: allows tenant admins to understand how demanding this app is.
Okay.
So, by clicking on this, you can evaluate the app. You can launch an evaluation app; it will allow (eventually) for the user to understand how demanding the app is.
Very cool. Now both of these apps are currently in a shared space. How do we publish these to the Managed Space so that users can consume them?
Yes. Go to the three dots; you have different options and one is Publish; you will publish it to a Managed space.
Okay.
Publish this to Space2. Now the original app is in Space1, but in Space2 will have a copy of it.
Okay. How are the rights different between the app in the shared space and the app in the managed space?
Yes. The permissions for Managed space and Shared space are different. And let me show you what type of permissions we have for the Space1. These are the different type of permissions we have for Shared spaces.
Mhm.
If we go to the Managed space, we'll see that we have other type of permissions because those relate to different type of actions.
Okay. So, it's slightly different terms here?
Yes. So in the online Help, please see what type of space action are available depending on the type of permissions. Keep in mind that you have actions inside the space and inside the apps.
Okay. I’ll definitely include the link.
You can add members the Space1 both in terms of users or groups. Say for instance you want to add the Retail group. So now the retail people (once I click on add) will be able to view, create notes, alert, subscription, and export data and view content.
An any apps inside this space?
Correct. You can select other options. The difference between these two is that the Can Edit Data in Apps would allow the user to develop apps which belong to other users. Can click on Add; the users who belong to the Retail group will have access to this space. In the Manage Users; Groups tab, you can create Custom Groups, not just using the existing from the IDP, but you can create inside Qlik Cloud Custom Group. So create on this one. So this is a Custom Group, and you can give permission to these Custom Groups which may have users belonging to different groups in the IDP.
Very cool. What other ways are there for users to share spaces and apps?
Sometimes you just want to share one app. I can go to the app I want to share in here, three dots, the Share option, Manage Access. For instance, if I put Miriam, I can provide her with different type of permission. As you can see, we have Restricted by default.
So, you can directly share specific rights to just the app or even rights to the whole space?
Right. If I go here and click on Send, the system will send a notification to the user.
How does she receive that notification?
Every user can define notification setup on the top right Notification section where you can tune the way you want to be notified.
So it's a personal setting. That's great. Can we jump back to the share options for the app? There's one there, Copy Link. How does that work?
Copy Link is a handy way for the person who has Manage Space permissions to send the link to another user.
So that's a link to the app. But what if someone who doesn't have permission clicks on that link?
The user gets the Need Access alert.
So in this scenario, a user has done that copy link button and shared that link with this user, but they don't have permissions yet?
Right.
All right. So we're assuming Henrietta here is saying please give me access. And that will go to the admin?
Yes, Henrietta Mueller would like to view the application Capital Management. We can see Henrietta Mueller but also another one. So we can Approve and define what type of permission we're going to give to this user.
Ah so this gives you another opportunity to set permissions for just the app or the entire space the app is in?
Correct.
Very nice.
If you want, Deny access to Adele Vance.
Okay.
In View Members. Now you'll see what type of permission we have in space 2.
And is there a way to prevent users from requesting access if the admin doesn't want to deal with a request like this?
This is a good question. So if you want to tune this, you go to the Administration, Manage Users, and you go to the Permissions tab where you have the user default settings. In the user default settings, you have a hell of a lot options. In our case, prevent people to be able to request access to the content.
Okay.
By default is allowed, but you can set it to not allowed and confirm.
All right, so that will prevent everybody from being allowed to request access, but perhaps you could set up some permissions for just the developers to request access?
This can be done by creating a new custom role.
Should we call this role app developer, maybe?
Okay. Going to have request access. Set it to allowed.
Are there any other specific permissions you think would be good to add to this developer role?
Oh, yes. We're going to use an automation. The automation requires the ability for the user to create API keys.
Okay.
So check for API manage API key set it to allowed. And in the custom role you cannot revoke permissions.
Ah okay.
To revoke permission you need to go to user default.
Okay. So if there's any permissions you don't want people to have you revoke those by changing the default and then raising permissions with a custom role. Okay.
Right.
Very cool. Now I heard about a new feature in Qlik Cloud that allows you to build folder structures. How does that work?
Oh yeah. If you click on Analytics section; say you want to add folder structure in this space; you can click on Space Details, then Details, then Data Files; and in here you can set up a folder structure. Let's put Folder1, Create. You can Upload data sets of any sort inside this Folder1 and so on and so forth.
So, it allows you to organize all your data files in a folder structure on the cloud?
Yes. And the permissions will apply to the folders the same way as for a space.
Okay. Very cool. Umberto, How can admins get a view of the tasks they have on the tenant? In the admin console, there is a section which is Content. Content includes apps, scripts, data flows, data connections, and data file or data sets.
Okay.
So for each app you have the option to click on the right hand side and see the schedule and also see the history.
Okay. But is there a way to see the full schedule of reloads happening on the tenant at once?
Oh, of course. You can go to the Analytics context here. You scroll down. You have the task section which gives you an overview of all tasks created in the tenant depending on the permissions you have for different spaces of course and different apps.
Very cool.
In this case, this this is a tenant admin. So we can see everything for each app. That's great. Now I know there's a lot of monitoring tools that are available for admins. Is there an easy way to get them all at once?
That takes us to automations. Before we do that, there is also one more permission. Because the monitoring apps are accessing to some specific information, and for that the Audit Admin role is also need to be added.
Okay. So let's go in and make sure we get that assigned.
So let me go to the user who is going to run the automation, Manage Role, the App Developer (custom role we just created).
Right. The one for API keys.
And then go to the Admin tab and add the Audit Admin security role.
Great. All right. So now we can go to automations?
Yes. Now we can go to automation. Create a new automation. Let's look for a monitoring template.
There it is.
We have a very handy article in the Qlik Community.
Very cool. So, this goes through all the steps we're about to do to import all the cloud monitoring apps that are helpful for admins.
Correct. And we can use this template.
All right, real quick: on the left we've got a bunch of different blocks to help build connections; in the center is our canvas where we're building out that workflow; and on the right are all the settings details. And basically if there's a red dot, it's looking for some input from us.
Right. This template is ready to be launched. Shall we go ahead and do it?
Yeah, let's see it in action. Automation saved, so it's nice it does the saving.
Okay. So, there's six different apps it's going to import?
Yes. And which one was it allows you to see all the tasks on the tenant?
The Reload Analyzer.
Okay.
Auto apply require roles? Yes. We can say Create New spaces. One is a Shared space.
Okay.
And the other one is a Managed Space. One of the best practice we recommend is to have the apps which needs to be co-developed inside the Shared space. And when the app is ready to be consumed, will be published to the Managed space. Monitoring apps for the Managed space.
Great. Okay. Reload it. Yeah. Creating a reload schedule. This is so cool; so it's asking you what that schedule is specifically.
Yeah, really cool. This a recap.
Okay. So that's all the settings we've chosen.
And now it's going to go through the installation of the app. And every time you run the automation again, it's going to check if the app already exist, and if it needs to be updated.
Okay. So if Qlik makes any improvements to the apps, running this automation again will update them?
Correct. Yes.
Okay. While this is running, what app would you like to show us on a different tenant that's perhaps been running for a while and has some data to look at?
Okay. I think it's good to check the Reload Analyzer. The Reload Analyzer allows us to distinguish between different type of reloads. These are total reloads but the reloads can be scheduled, launched on the hub, by using an API call, inside the app, and reloaded manually, task reload, and finally it could be an automation reload.
Very cool. And this table has a list of all the reloads on the tenant and a lot of information there as well?
Yes. We have very important points for the tenant admins. For instance, the Latest Reload Peak RAM.
Right because during a reload, the tables are expanded, the data model is reconstructed, and it can consume more data than normal usage.
That's why we need to keep an eye on the Reload Peak RAM because there are guard rails that have to be considered.
Right, depending on your subscription, there might be limits that - can you show us where that's documented?
Yes. This is for the Capacity tenants. If you scroll down here you'll see that: we have different type of editions and you see the Peak Reload memory can be can be up to 34 GB when you launch the reload within the hub.
Well, it's good to know that the guard rails exist, and I’ll provide the link to this for reference.
It's a long list, so we don't have the time to go through that, but let me add one thing.
Sure.
Sometimes apps are bigger than the limitation provided here. In that case, tenants can request a Large App Support. We have packages which go from 20 GB to 100 GB.
That's good to know. I would recommend that if you are running up against one of these guard rail limits, just reach out to your account manager, because there's always something that can be done.
Absolutely.
Is there another admin app you'd like to highlight?
Yes. Let's have a look at the App Analyzer. We have very useful information inside the app. So in the Session Overview for instance; in here I see which are the most used apps.
So this is a really cool app. Looks like it's helping you really analyze the user activity on your tenant?
Yes. For the apps specifically. There's also information about the metadata it gives us; the app memory footprint; app Reload Peak RAM.
Great. So what other tools are there to help understand the amount of data that a tenant is using?
The Detailed Consumption Report. There is a great Techspert Talk about capacity licensing and how to use this report and even how to automate the process.
Yeah, I remember this session. This was really fantastic by Tyler Waterfall. So, I'll include a link to this so people can check that out.
Great. Umberto, thank you so much for going through all these details with us and demonstrating all the basics of how to administrate a Qlik Cloud tenant on the analytic side. I really appreciate it and I think it'll be valuable for people going forward.
Thank you, Troy. Thank you all to join this Tech Talk. I hope you find it useful, and don't miss other Tech Talks we're going to have because there's an amazing amount of knowledge there.
Great. Thank you everyone. We hope you enjoyed this session and special thank you to Umberto for presenting. We always appreciate getting experts like Umberto to share with us. Here's our legal disclaimer and thank you once again. Have a great rest of your day.