Advanced setup
| Last modification: August 2026. | Version: 109 OUM |
Setup
Menu Setup → Setup.
After finishing modifying the token values, you must click the Update (Update) button in order to save the changes in the database.
General setup
Menu Setup → Setup →
General setup.
- Language: Global language for the system (by default English), each user can have a defined language and this prevails over the value defined here.
- Site name: Site name (by default Pandora ITSM), visible in the title of all windows and in the subject field of all messages.
- Enable error log: File with the error log, located by default in
/pandora_itsm.log. - Timezone for Pandora ITSM: Defines the time zone for the Web Console. Default value
Europe/Madrid. - List of IP with access to API: List of IP addresses with access to the API separated by commas. An asterisk (
*) means “any” (not recommended), default value127.0.0.1. - Default admin user: In Pandora ITSM there must always be an active superadmin. This option allows you to specify one of these super users or, by default, in automatic option it will choose the first active superadmin to execute periodic tasks for the PITSM system.
- API password: Password required to make requests via API.
- First day of the week: First day of the week for calendars and other uses of the application, Monday by default.
- Welcome view: Defines the time (by default the last 21 days) to show on the welcome screen if the user has activated the option Global dashboard in their profile.
- Login hash password: Used to generate a unique URL that will be used for pre-authentication.
- Enable HTTPS access: Configure Pandora ITSM to use HTTPS and thus encrypt communications.
When activating the HTTPS protocol and increasing security in the transport layers, it will be necessary to add a verification for the OpenSSL certificate. To do this, the following line must be added in the
php.inifile:openssl.cafile=/etc/ssl/certs/certificate_name.ca-bundle
- Use SSL certificate: To enable the use of Secure Socket Layer(SSL).
- Path of SSL certificate: Full path to the SSL certificate you want to use. By default located at:
/etc/ssl/certs/pandoraitsm.pem
- Access port: Configure the server's access port number, default value
80. - Public access to server: Public access URL to the server, it can be an IP address or a URL address. You must specify HTTP or HTTPS and the important suffix
pandoraitsm:https://mydomain.com/pandoraitsm.
If this field has been enabled and the public URL has been misconfigured, you will not be able to access the Web Console and you will have to disable this option by accessing the database directly via MySQL and inserting the following instruction:
UPDATE tconfig SET VALUE='http://URL/pandoraitsm' WHERE token='access_public';
- CSV encoding type: Default encoding type for
.csvfiles (see Separator data in CSV). - Chromium path: Location of the dependency for generating reports, by default
/usr/bin/chromium-browser. - Maximum direct download size (MB): Defines the maximum size of a file to download in the application.
- Max. upload file size (MB): Defines the maximum size of a file to upload to the application. If it has a lower size set in the system (
php.ini), this limit may not be respected. - Max. Upload file size in CRM (MB) and Max. Upload file size in incidents (MB): Defines the maximum size of a file to upload to the application in the ticket and CRM sections.
- Separator data in CSV: Data separator in CSV files, default value is the comma
,. - Temporary directory for PDF files: Directory to store temporary files in PDF type reports. Default value
/tmp/. - Hide version: Hides the version both in the footer and on the login screen.
- Show modal last time logged: Shows each user the date and time of their last login (modal form).
- Active automatic time tracking stop: Used to record the maximum time worked. It is active by default and stops automatically when adding up and reaching the value specified in Stop time tracking after (eight and a half hours by default).
See also Email setup.
User mail configuration (fields Client ID, Secret, Email processing blacklist):
All emails in this list will be ignored in synchronized incoming and outgoing mail (if enabled). You can enter a specific email or an entire domain (starts with @). If a domain is entered (starts with @) and the email is not part of an existing thread, and is sent from a user of that domain to another user of the same domain, the email will be ignored. These rules apply to emails sent from Gmail®; if sent from CRM, the rules are ignored and emails are processed. If an email individually included in Email processing blacklist appears in a message with multiple people in the TO field, it will be processed for the rest of the contacts and ignored for the one in the list. See also Email setup.
Visual setup
Menu Setup → Setup →
Visual setup.
Images, favorite icons, and custom logos can be stored in the directories
../images/custom_logos and
../images/favicon respectively.
As of OUM version 103, the Theme token is available for the color scheme (themes) in the Web Console, both for general configuration and user level. Default (Light) is set by default as the global theme and similarly for users. Unless otherwise specified, other configuration values refer to that particular theme. For the dark theme, specific tokens have been established.
- Favicon: Allows you to set an icon (usually 16 by 16 pixels) as a favorite.
- Block size for pagination: Number of items per page in listings. It is recommended to use low values to avoid performance impact.
- Global dashboard (welcome message): Allows you to place a dashboard as the initial welcome screen (optional).
- Font for ITSM: Default font type, both for interface and for PDF files.
- Tabs menu: Used in inventory objects and tickets, allows viewing options as a dropdown menu, as a tab, or as both options.
- Global search limit: Number of elements that will appear in listings when any search is used.
Global search performs a search for the keyword(s) introduced with the default search parameters in the following areas:
- Manage tickets (closed tickets are not shown).
- Project management.
- People.
- Contacts.
- Contracts.
- Companies.
- Invoices.
- Leads.
- Wiki (if it yields no result, it presents a link to create an article).
Keep in mind that the search results in each area are limited to the number of items established in Global search limit. Said limit value is not shown in the requested search result. Each user, according to their rights (ACL), will be able to see a greater or lesser amount of areas and results.
From version 106 onwards, custom CSS can be included which will be maintained when Pandora ITSM is updated.
Password policy setup
Menu Setup → Setup →
Password policy setup.
You must ensure that the Enable password policy token is enabled, otherwise none of the other tokens will work.
Allows you to set rules and features for user passwords. The password policy does not apply to administrator users.
- Min. size password: Minimum length the password must have, five characters by default.
- Password must have numbers: The password must contain numbers.
- Password must have symbols: The password must contain symbols.
- Password expiration (days): Expiration time of the password, in days, zero by default (never expires).
- Force password change on first login: Force password change on the first login.
- User blocked if login fails (minutes): User blocking time, in minutes (five by default), after having failed to log in (after the retries configured in the following field).
- Number of failed login attempts: Number of failed identification attempts.
- As of OUM 95, there is the option (disabled by default) to show the user their last login (token Show modal last time logged).
- As of OUM 108, if the password policy is activated, automatic password generation is subject to it.
Issue setup
Menu Setup → Setup →
Issue setup.
Ticket submission settings
Menu Setup → Setup →
Issue setup → Ticket submission settings.
Starting from version 109, the new Smart Ticketing and Simplified modes are added to the “Manual” creation mode (which has always been the standard). See «Ways to create tickets».
Visual options
Menu Setup → Setup →
Issue setup → Visual options.
- Show ticket owner and Show ticket creator: Show the ticket creator and show the ticket owner in list and search views for tickets.
- Max. tickets by search: Maximum number of tickets per search, this will limit the results in ticket searches to avoid performance impact. Recommended between
200and500(default value:300). - Enable quick edit mode: Allows you to quickly edit some elements of the ticket (owner user, criticality, status) without entering the full edit mode.
- Show user name instead of ID in the ticket search: Show the real user name instead of the identifier in the ticket search.
- Format date: There are two date format options, long
yyyy/mm/dd h:m:s(default option) and approximate (for example: 1 day, 2 hours). - Completion date WU: Checking this option will show the Completion date field in the Workunits (WU) of the tickets. That date may be different from the creation date of the Workunit.
- Sort work units by completion date: Sort WU by completion date (in the WU list of a ticket).
- Most recent comments at the bottom: When enabled, newer comments and the input field to add new ones will be displayed at the bottom of the incident view.
Ticket behaviour
Menu Setup → Setup →
Issue setup → Ticket behaviour.
Unless explicitly stated otherwise, the tokens in this section are disabled by default when installing PITSM.
- Disable ticket score: Disable incident scoring.
- Allow IW to change creator and Allow IW to change owner: Users with that access bit will be able to change the creator and/or owner of the ticket. Both tokens come activated by default.
- Editor adds a WU on ticket creation: A Workunit (WU) is added automatically when creating a ticket.
- Allow to change the ticket type: If deactivated, you will not be able to change the ticket type once created.
- Allow to configure the date/time when creating it: Allow defining the time and date of the ticket at the time of its creation.
- Ignore user defined by the group for the owner: Allows ignoring the predefined user by the group for the owner.
- Ticket type required: Forces you to choose a ticket type.
- Ignore creator user by default: If activated, it allows ignoring the default creator user and must be specified manually.
- Allow external users to modify their tickets: Allow external (non-grouped) users to modify their tickets. Activated by default.
- Ignore group template for the issue creator: Ignore group template for the incident creator.
- Creator can see every user: The creator user will be able to see all users, even from other groups.
- Automatically assign ticket: Based on the group assignment rules, allows self-assigning ticket. Activated by default.
- Assign ticket to the first editing user: If checked, the editing user of the ticket will always be set as the user who edited the ticket first.
- Enable client validation before closing ticket: When this token is active, the ticket creator can approve or reject the closure when the ticket is in the Pending to be closed status.
Work unit options (WU)
Menu Setup → Setup →
Issue setup → Work unit options (WU).
- Automatically close ticket: Number of days (
45by default) after which a ticket will be closed automatically. - Ticket WU default time: Default value used when entering a work unit, in hour units. The default value is
0.25, fifteen minutes. - Sending email when managing WU: Sending email when managing WU. As of OUM version 103, an email can also be sent to a user if they are mentioned in the WU.
- Default internal work units: Work units are configured as internal by default.
- New WU are always public: Activation of comments as always public.
Workflows
Menu Setup → Setup →
Issue setup → Workflows.
- Check closed tickets when running workflow rules: This option is used so that the Workflow rules process closed tickets.
- Days to check closed tickets: If the previous field is checked, tickets closed in the last
15days (default value) will be taken into account.
Email sending options
Menu Setup → Setup →
Issue setup → Email sending options.
With the exception of tokens 1, 2, and 15, all others are active by default.
- Masking email addresses: With this option activated, email addresses in the content of the ticket will not be shown.
- Send all attachments for each issue update by email: Send all attachments associated with the ticket in each update made via email.
- Send email for each created ticket: Send notification of each ticket that is created.
- Send email for each closed ticket: Send email for each incident closure.
- Send email for each update of the issue status: Send notification for each status change of the ticket. In case of changing its status to closed, sending the notification will depend on the configuration of the previous token.
- Send email for each update of the issue owner: If the owner of the incident is changed, an email will be sent.
- Send email for each update of the issue priority: Will send notification for each change in the priority of work in the incident.
- Send email for each update of the issue group: Send email for each update of the ticket group. This configuration can be general or specific by group. To be specific by group, it is necessary to configure it in the editing of the group itself.
- Send email for each update of the issue in other fields: Will send notification for each modification of any of the other fields of the incident.
- Send email for each created work unit: Send email for each Workunit created. As of OUM version 103, an email can also be sent to a user if they are mentioned in the WU.
- Send email for each added attachment: Send notification for each attached file added.
- Group work units for each ticket and email: In order to reduce the number of messages to send, this token groups several notifications (attached files and/or WU added within a 5-minute period) in a single notification.
- Send email for each validated work order: Send email for each validated work order.
- Send additional emails when the comment is internal: Email addresses other than those of participants and PITSM users can be added to a ticket. To prevent these mailboxes from being notified when adding an internal comment WU, you must disable this option.
- Send email to workunit creator: To prevent the loop behavior generated with automated email responses (vacations, out of office hours, etc.) to the creators of the work units.
Customization
Menu Setup → Setup →
Issue setup → Customization.
- Status and Resolution.
The status and resolution messages themselves are set by default in English language (at the time of installing PITSM). By changing the language of the Web Console and clicking the icon
you can reset the messages to the corresponding language.
You can modify the labels of the ticket statuses and resolutions. It is important to keep in mind that even if the label changes, the logic associated with the statuses remains the same, so SLA rules, Workflow, or colors of the tickets according to their status (new/closed) will remain the same.
- Priority.
As of version 107, you can edit the messages that describe the priorities of the tickets. The messages themselves are configured by default in English when installing PITSM. By changing the language of the Web Console and clicking the icon
you can reset the messages to the corresponding language.
- Special day.
Non-working days are used to define local/national holidays, etc. They are not taken into account in the SLA and are displayed differently in calendars.
With these tokens you can define weekends as working days (Weekends are working days) and you can add and/or delete holidays with the concept of special days (Select a new special day).
Annual special days must be configured at the beginning of each year (and delete those from the previous year): In fact, those that are recorded by default when installing PITSM can be deleted.
Default custom columns
Menu Setup → Setup →
Issue setup → Default custom columns.
As of version 105, you can configure the default columns to show in the incident listing. By default, the following fields are selected:
More system fields can be added (or removed) from this list, and even custom fields that are marked to be displayed in the incident list can be added.
If after a custom field has been added and it is unchecked from being shown in the incident list (deactivate the corresponding Show in the list of tickets token), this field will appear as an empty column, without title or content. This being the case, said field must be manually removed from the list of selected ones.
Survey Questions
Menu Setup → Setup →
Issue setup → Survey Questions.
By enabling this option, the ability to have a ticket evaluation survey is activated when the rating is negative.
Changes setup
Menu Setup → Setup →
Changes setup.
See «Types of notifications».
Email setup
Menu Setup → Setup →
Email setup.
Sending emails (email) is used when a change occurs in a ticket or an SLA is breached. Receiving emails is only necessary if the creation and management of tickets by email is used.
General section:
- Notification period: Notification period, minimum time in hours (
24by default) that must pass between two SLA notifications. - System email from address: Email address from the system, it will be the sender used when sending emails from Pandora ITSM.
The sending configuration and the receiving configuration with OAuth 2.0 has different handling and requires third-party credentials.
Sending email server configuration
Menu Setup → Setup →
Email setup → SMTP Parameters - Sending email server configuration.
The common fields, regardless of the encryption type (except when using OAuth 2.0 in the Encryption field), are:
- SMTP Host: Location of the post office. If left blank, it will attempt to use a local Postfix or Sendmail mail system (if it is installed and enabled).
- SMTP Port: Port number to send mail.
- SMTP user: User name.
- SMTP password: User password.
Some configurations:
The fields for Pandora ITSM internal configuration are:
- SMTP queue retries: Retries for sending the mail queue. If this number is exceeded, the mail in the queue will be marked as incorrect.
- Max. pending emails: Maximum number of pending emails. If this number is exceeded, a warning will show in the system alert zone to indicate there might be a problem sending emails.
- Max. emails sent per execution: Maximum number of mails sent per execution, thus limiting the maximum number of emails in each periodic execution of the maintenance script.
Gmail® (SMTP)
Gmail® only allows encrypted email sending.
Encrypted with SSL/TLS:
- Encryption method:
SSL/TLS - SMPT Host:
smtp.gmail.com - Port number:
465
Encrypted with STARTTLS:
- Encryption method:
STARTTLS. - SMTP Host:
smtp.gmail.com - Port number:
587(25could also be used).
To obtain a Google® app password (https://myaccount.google.com/apppasswords), an application entry must be created. A password will automatically be generated; it must be copied manually without spaces to the corresponding field.
Outlook (SMTP)
- MS Outlook® only allows encrypted email sending with STARTTLS.
- MS Outlook® does not allow using users of other mail services, only its own, so it is necessary to specify the same email used for the SMTP configuration.
- Encryption method:
STARTTLS. - SMTP Host:
smtp-mail.outlook.com. - Port number:
587(25could also be used). - Compatibility: Outlook.
Office 365 (OAuth 2.0)
Since January 2023, Microsoft® only allows sending emails through third-party authentication with OAuth 2.0.
See the topic «Integration with Microsoft Office 365® mail server protocols» for more configuration details.
- Encryption:
Microsoft OAuth 2.0. - User ID: User identifier.
- Client ID: Application identifier registered in Microsoft®.
- Tenant ID: Allowed values are tenant ID for the tenant identifier or domain name,
commonfor both Microsoft® accounts and work or school accounts,organizationsonly for work or school accounts, andconsumersonly for Microsoft® accounts. - Secret: Private user token.
Once the above tokens are correctly configured, it is necessary to click the Connect to Microsoft button and accept the requested permissions.
Others (SMTP)
- Encryption:
Nonefor unencrypted sending or encrypted with SSL/TLS, SSLv2, SSLv3, or STARTTLS. - Name: DNS name or IP address of the mail server.
- Port: Port number on which the mail server is listening.
- User: User configured on the mail server.
- Password: Password configured for the user indicated above.
Receiving email server configuration
Menu Setup → Setup →
Email setup → POP/IMAP Parameters - Receiving email server configuration.
Regarding the configuration, all fields are common except when Microsoft OAuth 2.0 is used in the Encryption field.
It is advisable, whenever possible, to avoid using the IMAP/POP account of any internal Pandora ITSM user, as this can cause some cyclical behavior when creating and updating tickets in Pandora ITSM.
Message delimiter:
Email replies will be cut off from this message:
##- Please type your reply above this line -##
Response threads will automatically be cut in the following email managers: Outlook®, Gmail®, Thunderbird®, and «eM Client»®.
Office 365 (OAuth 2.0)
See the topic «Integration with Microsoft Office 365® mail server protocols» for more configuration details.
- Encryption:
Microsoft OAuth 2.0. - User ID: User identifier.
- POP/IMAP Client ID: Application identifier registered in Microsoft®.
- POP/IMAP Tenant ID: Allowed values are tenant ID for the tenant identifier or domain name,
commonfor both Microsoft® accounts and work or school accounts,organizationsonly for work or school accounts, andconsumersonly for Microsoft® accounts. - POP/IMAP Secret: Private user token.
Once the above tokens are correctly configured, it is necessary to click the Connect to Microsoft button and accept the requested permissions.
Gmail (IMAP/POP)
Gmail® only allows encrypted receiving of email messages via SSL/TLS.
IMAP:
- POP/IMAP Host:
imap.gmail.com. - POP/IMAP Port number:
993. - POP/IMAP user: User's email inbox.
- Select IMAP or POP:
IMAP. - Compatibility:
Gmail.
POP:
- POP/IMAP Host:
pop.gmail.com. - POP/IMAP Port number:
995. - POP/IMAP user: User's email inbox.
- Select IMAP or POP:
POP. - Compatibility:
Gmail.
The Accept any certificate option is disabled by default since the certificate offered by the email server must always be verified. Only in very special cases could this option be activated.
To configure “Managing email queues by group” you must add a domain filter in the Email origin field that matches what is established here.
Outlook (IMAP/POP)
MS Outlook® only allows encrypted receiving with SSL/TLS.
IMAP:
- POP/IMAP Host:
imap-mail.outlook.com. - POP/IMAP Port number:
993. - Select IMAP or POP:
IMAP. - Compatibility:
Outlook.
POP:
- POP/IMAP Host:
pop-mail.outlook.com. - POP/IMAP Port number:
995. - Select IMAP or POP:
POP. - Compatibility:
Outlook.
- The Accept any certificate option is disabled by default since the certificate offered by the email server must always be verified. Only in very special cases could this option be activated.
- Within the MS Outlook® configuration, it is necessary to have the Let devices and apps use POP option activated.
To configure “Managing email queues by group” you must add a domain filter in the Email origin field.
Office 365 (IMAP/POP)
MS Office 365® only allows encrypted receiving with SSL/TLS.
IMAP:
- POP/IMAP Host:
outlook.office365.com(valid for both POP and IMAP). - POP/IMAP Port:
993. - Select IMAP or POP:
IMAP. - Compatibility:
Office 365.
POP:
- POP/IMAP Host:
outlook.office365.com(valid for both POP and IMAP). - POP/IMAP Port:
995. - Select IMAP or POP:
POP. - Compatibility:
Office 365.
The Accept any certificate option is disabled by default since the certificate offered by the email server must always be verified. Only in very special cases could this option be activated.
To configure “Managing email queues by group” you must add a domain filter in the Email origin field that matches what is established here.
DreamHost
IMAP:
- Encryption:
SSL/TLS. - POP/IMAP Host:
imap.dreamhost.com. - POP/IMAP Port:
993. - Select IMAP or POP:
IMAP. - Compatibility:
DreamHost.
POP:
- Encryption:
SSL/TLS. - POP/IMAP Host:
pop.dreamhost.com. - POP/IMAP Port:
995. - Select IMAP or POP:
POP. - Compatibility:
DreamHost.
The Accept any certificate option is disabled by default since the certificate offered by the email server must always be verified. Only in very special cases could this option be activated.
To configure “Managing email queues by group” you must add a domain filter in the Email origin field that matches what is established here.
Others (IMAP/POP)
Possible configurations are described accompanied by important recommendations:
- Encryption: The POP/IMAP server can be configured encrypted with SSL/TLS, SSLv2, SSLv3, or STARTTLS (any of these options are recommended). Although it can be used without encryption, avoid this option.
- Name: IP or DNS address of the POP/IMAP server.
- Port: Port number on which the POP/IMAP server is listening. Standardized values:
POP3/110,IMAP/143,IMAPS/993,SSL-POP/995. - User: User configured on the mail server.
- Password: Password configured for the user indicated above.
- Protocol: POP or IMAP.
- Compatibility: Others (
Others).
The Accept any certificate option is disabled by default since the certificate offered by the email server must always be verified. Only in very special cases could this option be activated.
General texts for emails
Menu Setup → Setup →
Email setup → General texts for emails.
The emails sent by Pandora ITSM are queued until the maintenance script sends them, by default every 5 minutes. To adjust this behavior there are a series of special parameters, as well as a pending sending queue manager.
- Email header: Email header to be used in any automatic Pandora ITSM email message.
- Email footer: Email footer to be used in any automatic Pandora ITSM email message.
The use of macros is not allowed in either of the two elements above.
Email queue control
Menu Setup → Setup →
Email setup → Email queue control.
Displays automatic email messages that are pending to be sent, with the option to check selection boxes for each element.
It also indicates the number of sending attempts and its status for each message. Messages can be massively selected either to reactivate their sending (button Reactivate pending emails) or definitely delete them (button Delete pending emails).
Email templates setup
Menu Setup → Setup →
Email templates setup.
Allows you to edit the email templates (.tpl files) that Pandora ITSM will use to compose emails as well as the subject templates of the message. The email templates are generic and are used for all groups.
To edit a template, click on its name or press the corresponding edit button in the actions column. Default templates (Templates predefined column) can also be duplicated, so it is recommended to do so if any customization or simply language translation is needed, with the possibility of making them default (column Default template). Unlike default templates, duplicated templates can be deleted at any time.
Macros are variables that will be replaced when composing the message with a specific real value:
| Macro name | Description |
|---|---|
_author_ | Creator of the ticket. |
_creation_timestamp_ | Date and time of the creation of the ticket. |
_fullname_ | Full name of the user receiving the email. |
_group_ | Group assigned to that ticket. |
_havecost_ | For project work unit reports exclusively. |
_incident_id_ | ticket identifier. |
_incident_main_text_ | Main descriptive text of the ticket. |
_incident_title_ | Title of the ticket. |
_owner_ | User that controls the ticket. |
_priority_ | Priority of the ticket. |
_projectname_ | For project reports exclusively. |
_resolution_ | Resolution of the ticket. |
_sitename_ | Site name, exactly as defined in the General setup. |
_status_ | Status of the ticket. |
_taskname_ | For project reports exclusively. |
_time_used_ | Total time spent on this ticket. |
_type_tickets_ | Type of ticket. |
_update_timestamp_ | The last time the ticket was updated. |
_url_ | URL of the ticket. |
_username_ | Name of the user receiving the email (login name). |
_wu_text_ | Work unit text. |
_wu_user_ | User that reports a work unit. |
| Custom field templates | This allows when creating an object type, the name of the fields added to be included as a macro, which will show the value of that field: “_custom field name_”. |
Macros used in email templates for Changes:
| Change |
|---|
_change_url_ |
_change_id_ |
_change_name_ |
_change_description_ |
_change_status_ |
_change_type_ |
_change_creator_ |
_change_manager_ |
_change_team_ |
_change_priority_ |
_change_risk_ |
_change_impact_ |
_change_template_ |
_change_created_at_ |
_change_updated_at_ |
_change_closed_at_ |
_change_closed_by_ |
_change_is_authorized_ |
| Change task |
|---|
_change_task_url_ |
_change_task_id_ |
_change_task_name_ |
_change_task_description_ |
_change_task_status_ |
_change_task_manager_ |
_change_task_start_ |
_change_task_end_ |
_change_task_estimated_hours_ |
_change_task_team_ |
_change_task_priority_ |
_change_task_risk_ |
_change_task_impact_ |
_change_task_created_at_ |
_change_task_updated_at_ |
| Change work unit |
|---|
_change_workunit_url_ |
_change_workunit_id_ |
_change_workunit_created_at_ |
_change_workunit_duration_ |
_change_workunit_creator_ |
_change_workunit_description_ |
_change_workunit_type_ |
Visibility management
Menu Setup → Setup →
Visibility management.
This option is used to “hide” certain parts of Pandora ITSM from user groups. You can set up the following visibility levels for each section and user group:
- Hidden: The section will not be shown to users who belong to the indicated group, even if accessed through the URL dedicated to it.
- Full: Users who belong to the indicated group will have full access to the section.
If a section has no visibility configuration, by default the access will be Full for all users.
Each section is associated with a profile, which is checked along with the user's group to determine whether they have visibility or not:
| Section | Profile |
|---|---|
| Projects | PR |
| Tickets | IR |
| Inventories | VR |
| BC | KR |
| File releases | KR |
| Section | Profile |
|---|---|
| Agenda | AR |
| People | Any profile |
| Work Orders | WOR |
| Setup | Any profile |
- If the user is a superadmin, they will always have full access regardless of the menu visibility setup.
- If a user has profiles in multiple groups that have different visibility levels in a section, the visibility for that user in that section will be the least restrictive.
- If a visibility level is created for a section by selecting all groups (All group), any other configuration previously registered for that section will be deleted, leaving only the newly introduced one.
Pandora FMS inventory
Menu Setup → Setup →
Pandora FMS inventory.
This section controls both inventory options and remote inventory management (processing of data sent by Pandora FMS agents to Pandora ITSM, without the need to install Pandora FMS).
Inventory options
- Duplicate inventory name: Allows the option to have inventory objects with the same name. Option enabled by default.
- CSV compatibility import: If the option is disabled, it allows CSVs to be displayed as a report showing the inventory objects previously selected by the user exactly as they appear on the list. Option enabled by default.
Menu Setup → Setup →
Pandora FMS inventory → Remote inventory.
Processing of inventory data from Pandora FMS agents:
- Default owner: Default owner for those objects.
- Associated company and Associated user: Companies and users with access to those objects.
Authentication configuration
Menu Setup → Setup →
Authentication configuration.
Super administrator (superadmin) type users are the only ones who always perform a local authentication, unlike the rest of the users who, if configured, can authenticate remotely with Active Directory® or LDAP® or Pandora FMS®.
- If the LDAP® or Active Directory® or Pandora FMS® (version 106 or later) method is set up, Pandora ITSM will first query these platforms to see if the user exists and if the password is correct.
- The Session timeout (secs) token configures the maximum session time (nine thousand seconds by default).
- It is recommended to activate Two-factor authentication to add an additional layer of security to user access.
Active Directory
Menu Setup → Setup →
Authentication configuration → Authentication method → Active directory.
Delegating user authentication to Microsoft Active Directory® (MS AD or simply AD) allows centralizing accounts and credentials in a single system, facilitating single sign-on and reducing the need to manage users separately in each application. Pandora ITSM is fully compatible with it.
- It can be configured so that, in case remote authentication with AD fails, it can authenticate locally with Pandora ITSM. To do this, the Fallback to local authentication token must be activated.
- In the Active Directory® advanced configuration (Advanced Configuration AD), new permissions can be added according to the profiles and groups held by each user.
- By activating the option to automatically create users (Automatically create remote users), you can configure the option to assign user level, profile, and group, and even specify a restricted user list (Automatically create blacklist).
- Active directory server, Active directory port, Domain, Start TLS are the fields that host the necessary connection parameters.
LDAP
Menu Setup → Setup →
Authentication configuration → Authentication method → LDAP.
Pandora ITSM incorporates a delegated authentication system in LDAP.
- In case remote authentication with LDAP fails, it can authenticate locally with Pandora ITSM by activating the Fallback to local authentication token.
- By activating the option to automatically create users (Automatically create remote users), you can configure the option to assign level, profile, and group. An automatic restricted user list can also be specified (Automatically create blacklist).
- When selecting LDAP® as remote authentication, you can choose between LDAPv1, LDAPv2, and LDAPv3, encrypting communications when activating the Start TLS token.
- With LDAP server, LDAP port, Base DN, Login attribute, the necessary parameters for the connection are established.
Pandora FMS
Menu Setup → Setup →
Authentication configuration → Authentication method → Pandora FMS.
When selecting this option, you must place the IP address or URL of the PFMS Server to connect and the generated token of the admin user for API v2. Such user is created by default when installing Pandora FMS.
In the URL to Pandora FMS setup field you must place the full link to the PFMS Server:
https://<URL_or_IP_address>/pandora_console/api/v2
With the Test button, you must verify the successful connection so that users can later authenticate through said PFMS instance.
Super administrator (superadmin) type users are the only ones who always perform local authentication in PITSM.
Optionally, you can activate the option to automatically create users (Automatically create remote users). Initially, this is the recommended option. Once the remote user has been created, their password must be managed in the respective PFMS Server.
You must always choose an option for group, profile, company, and user level. In the Profile option (Automatically create user level), it is always recommended to choose the least privilege option.
Two-factor authentication
Menu Setup → Setup →
Authentication configuration → Two-factor authentication.
Two-step authentication (or double authentication) has been positioning itself for years as one of the best options to increase the security of a user account. Pandora ITSM incorporates this functionality by performing an integration with the Google Authenticator® solution.
Requirements
It will be necessary to have the code generator application on a personal mobile device for each user.
You must have superadmin rights to access the PITSM configuration options.
In this way, each user will be able to activate two-step authentication with the Edit my user option. The option Force 2FA for all users is enabled, disabled by default, is also available to indicate to the rest of the users, at the beginning of each session, to activate two-step authentication. From version 108 onwards, you can choose to only warn users that they must configure this functionality for their access. Important: You must select one of the two options before saving.
It is extremely important that the PITSM Server has the exact time and date configured.
Process to follow for each user
Menu People → Edit my user.
When each user edits their own data and activates their Two-factor authentication, Pandora ITSM will generate an authentication key which it will also display via a QR code
(Pandora ITSM: <id-user> + key):
Using the installed application, this QR code can be read (or the key can be entered manually) and the resulting code must be entered in PITSM and click the Validate code button.
After the user logs out, they will have to enter their credentials again and, if they are validated, they will proceed to enter the code generated by the personal device, for that specific moment, and thus finalize the double authentication.
In case a non-superadmin user needs to reset their two-factor authentication key, they must request it directly with a superadmin who will use the Reset double factor authentication code option of the requesting user:
If a superadmin needs to reset their two-step authentication key, they must log in with their username and password and then press the Reset double factor authentication code button. An email message will be sent to them immediately, accompanied by a link, and they will have 15 minutes to click on that link.
The SMTP email sending must be active and fully functional to be able to reset the double authentication key of the superadmins.
CRM setup
Menu Setup → Setup →
CRM setup.
In the CRM tab, the parameters for invoicing, contract statuses, campaigns and their tracking, and Deals are configured.
Invoice generation parameters
Menu Setup → Setup →
CRM setup → Invoice generation parameters.
In this section, invoice parameters are configured such as the image for the header, payment methods, or tax acronyms. You can also hide the tax identifier (disabled by default), print in full color, and automate invoice numbering.
- Enable auto ID: The automatic generation of invoice IDs can be enabled (or disabled), and its structure can be modified.
- In the Invoice ID pattern field, a text string is saved that will be used as a pattern to generate the identifiers, by default
21/[1000]. This pattern will contain a fixed part and a variable part. The variable part must be numeric and will serve as the first element from which to calculate a sequence. The variable part will go between brackets. The rest will be constant in all invoices.
The generation of invoice identifiers is only applied to Sent type invoices.
- Invoice header logo: To upload custom logos, the
images/custom_logodirectory must be chosen, using the file manager.
Contract Statuses
Menu Setup → Setup →
CRM setup → Contract Statuses.
There are default contract statuses, which can be edited and even deleted, and as many statuses as needed can be added with the Add + button.
Campaigns Performance
Menu Setup → Setup →
CRM setup → Campaigns Performance.
Important values in the configuration of marketing campaigns are established here.
- Email batch campaigns: Number of emails to send per batch in campaigns (
500by default). - Web tracking JavaScript: This JavaScript code will be used for web tracking. It is preloaded with the default code so that the tracking of marketing campaigns works and can be modified as needed.
- Captcha: To use Cloudflare® Captcha you must have an account created there and set up a site key at:
https://dash.cloudflare.com
Deal
Menu Setup → Setup →
CRM setup → Deal.
A Deal represents a specific sales opportunity with a potential or existing customer. The parameters to fine-tune this functionality are:
- Default pipeline deal: The pipelines or funnels are the visual paths that deals or opportunities travel, divided into stages. After having created at least one of them, it can be configured as the default to use in each new deal.
- Time since last update (days): Number of days to consider an offer as obsolete. A warning icon will be displayed on offers that have not been updated during this period.
- Schedule reminder repeat hours: Number of hours to repeat schedule reminders.
0or empty means it does not repeat. Default value:24hours. - Days to expire schedule: Number of days after the expiration date in which a schedule will automatically be marked as expired. The default value is
7days. - Notification email (Deal Registrations): Email address that will receive a notification when an offer registration is created or updated.
Old data maintenance
Menu Setup → Setup →
Old data maintenance.
Allows you to specify to the system how to manage historical information. If the indicated value is zero 0 in a token, the data related to it will always be kept.
The Restore to default value button will change each and every one of the tokens and will save automatically. Said default values and relevant details are indicated:
- Days to delete events:
30. - Days to delete closed tickets:
0. Related data will also be deleted. - Days to delete Work Units:
0. Provided they belong to disabled projects, work hours older than the indicated days will also be deleted. - Days to delete work orders:
0. - Days to delete audit information:
15. - Days to delete sessions: 7.
- Days to delete workflow events:
900. - Days to delete attachments from tickets:
0. - Days to delete file tracking data:
30. - Days to delete backups:
30. - Days to delete invalid emails:
30. Messages that could not be sent. - Days to delete reports: 365. Reports that have been autogenerated periodically.
- Days to delete archived chat-bot rooms:
365(if the chat-bot is activated).
The Delete all data (Reset all data) option will eliminate ALL data from the database and also attached files. Use this option with caution and only to start fresh.
Project management
Menu Setup → Setup →
Project management.
Pandora ITSM allows dynamic management of projects which includes planning, tracking, and reports. Default values are included which must be adjusted as needed:
- Users without WU autocomplete: This is a specific list of users (separated by a space) without WU autocomplete.
- Work hours per day: This number represents the number of hours (eight by default) of a normal workday, in order to calculate WU autocomplete.
- WU autocomplete (days): The amount of days (by default zero) in a work cycle is specified. Time periods such as weekly, bi-weekly, or monthly are generally used, entering the amount of actual days to work. This feature will autocomplete WUs backwards from the current moment. These hours entered for users are not assigned to any task in any project, but to “Unjustified” hours.
- Default time for a project WU: four hours, default value for simple Work Units.
- Currency: € by default (
eu). - Default time for multiple WUs in projects: four hours, default value for multiple Work Units. The value of this token will appear by default in the Duration field when adding a multiple WU.
- Total number of vacation days: Number of vacation days (twenty-two by default) that will be used for the corresponding calculations in the vacation report section.
- Disable addition of tickets and work units for pending and verified tasks: In order to finish a verified project, this token is activated to stop adding work that causes delays.
- Send vacation request notifications to: Allows you to establish the default user for vacation approval. It must be verified that a valid user is specified (existing and enabled).
- Weekly work units notice: By default 40 hours per week, when activated it places an informational message for each user in the User information menu:
Pandora RC
Menu Setup → Setup →
.
To activate the Pandora RC remote management system.
ChatBot
Menu Setup → Setup →
ChatBot.
To activate ChatBot and configure the server and channels.
GitLab
Menu Setup → Setup →
GitLab.
For GitLab® integration, an access token that belongs to a GitLab user with permissions to view the tickets of a specific project is needed.
Once it has been configured, you will be able to consult the incidents registered in a project through the Pandora ITSM Web Console, only in read-only mode.
File manager
Menu Setup → Setup → File manager.
Allows you to store new files in the Integrated file distribution system in Pandora ITSM.
It also allows the creation and deletion of directories for better organization. These files and folders are located in the following directories:
/attachment./attachment/downloads./images: To add custom icons./images/custom_logos: To store custom logo images.
Diagnostic info
Menu Setup → Diagnostic info.
Some features are described:
- Pandora ITSM status info: With the version and the directory where it is installed, among other values.
- PHP Setup: With the installed version and the value of important parameters like the maximum dedicated memory and maximum file upload size.
- Database size statistics: Total tickets, users, and registered sessions.
- Database status info: Version and date of the database engine.
- System info: With basic info about the hardware where Pandora ITSM is running.
- MySQL performance metrics: Configured values, plus recommended values are shown as a measure of comparison.
- Pandora ITSM log dates.
- Attachment folder status: General amount of stored files.
- Date system: Date and time of Pandora ITSM (does not include time zone).
News board
Menu Setup → News board.
Allows adding short system news that will be visible to all users when they log in.
It is useful for notifying platform changes or notices about interventions, service disconnection, or others. It can be sent to specific groups and optionally set an expiration date after which the message will stop being shown on the notice board.
As of version 107, the unique macro _lastlogin_ can be used to indicate to the user the date and time of their penultimate successful login. By default, a welcome message without expiration is included where this macro can be included:
DB Manager
Menu Setup → DB Manager.
It is a direct interface against the system database, in SQL, which only superadmins and users with DM profile have access to.
For exclusive use of expert users as its misuse can cause irreversible damage to the tool and data loss.
Any incorrect SQL instruction should be looked up in the error log with the keyword dbmanager.php.
Links
Menu Setup → Links.
External links can be added, edited, and deleted that will be shown in the Links section of the main menu and will open in a new tab of the web browser.
To edit a link, you must click on the description, enter the changes, and save. The changes made will be recorded in the Audit log.
For internal links, subdirectories must be placed, just like for the Wiki:
wiki/operation/wiki/wiki
System events
Menu Setup → System events.
History of events that occurred in the system, such as sending scheduled reports, running cron tasks, system failures, etc.
User activity info is stored in the Audit log.
Audit log
Menu → Audit log.
In this registry, the actions of each user in each section will be reflected, all in a summary of 51 actions.
If someone modifies customer data, it will be known when and what was changed. If someone creates an invoice, it will be known when and which invoice, etc. The Extra info column provides information such as changed values, nature of the operation, etc.
It also allows searching by a specific substring and by date period and exporting to a CSV file.
Error log
Menu Setup → Error log.
Displays the error log (if it is activated), useful to identify possible system code errors.
By default it reads the last lines of the file:
/var/www/html/pandoraitsm/pandora_itsm.log
A button is also shown to definitively delete the registered data.
Translate strings
Menu Setup → Translate strings.
Allows making custom translations of any text that appears in the Pandora ITSM Web Console.
The search is performed on the original English language, all translations are based on this language. By selecting this same language in the list, text strings can be adjusted and/or corrected.
Other languages to modify can be selected and a free field to search for specific text or it can be left empty to view all strings.
When saving changes with the Update button, the Web Console will be displayed in the language being modified. You must click in the upper left corner to load the Dashboard (welcome screen) that the user has configured and with the language that they have configured.
Backup
Menu Setup → Backup.
The backup section allows Pandora ITSM users to make backups of attachments and the database, both manually and on a scheduled basis.
Backup list:
The first consists of a list of existing backups in the backup folder within the Pandora ITSM directory. From here you can delete a backup, download, or restore the PITSM system from any item in the list.
Special care must be taken when performing this action as the backup will replace the database info with the one it had in that backup, making the info added between the backup and the system in its current state disappear.
Backup programming:
The second section allows creating schedules so that, after a specific time has passed, a backup of the Pandora ITSM system is carried out. To create a backup schedule, you must include a name for the schedule, a backup mode (there are three modes, database only, attachments only, or both), and a backup frequency (weekly by default).
An email address can be added where notifications will arrive if something goes wrong in this process. Besides, in the same section, the list of schedules is available for editing or deletion, as appropriate.
To create a new backup task, you must click on the menu Setup → Backup again.
Backup manager:
The third and final section is in charge of carrying out manual backups at the current time, giving the possibility of creating a backup with the desired name and mode (and optionally an email address for error notifications). This data backup will be created in the backup folder within the Pandora ITSM directory and will then be available in the backup list.
It also has the possibility of uploading previously downloaded backups; these must have the same structure generated by the tool to maintain consistency and not be previously in the database. After successfully uploading a data backup, it will appear in the list and can be restored with the corresponding button located in the Restore backup column.
Warp update
Menu:
Warp update → Update offline.
Warp update → Update online.
Warp update → Options.
Warp update → Warp journal.
As of version 105, Warp update is part of Pandora ITSM. It helps system administrators update Pandora ITSM automatically since it handles the task of finding new modules, plugins, and functionalities (including migration tools for future versions) automatically.
License
Menu Warp update → License.
In this section, the limit of administrator users for the acquired license and the quota used so far will be indicated. For details see the section «Profiles and users».
The Pandora ITSM license must be introduced. Once introduced, click the Update license (Update license) button so that Pandora ITSM verifies if it is valid.
Request new license
When clicking the Request new license button, a form will open where the authorization key (Auth key) provided by the support department must be introduced.
You must click the online validation button (Online validation) and finally update the license with the Update license button.
In the event that the Web Console is isolated from the internet, the offline option can be used by copying the link (text here) which includes the request key (Request key).
Once in the web browser with internet access, introduce the authorization key (Auth key) provided by the support department, click Generate, and get a new license. This must be copied and returned to the Web Console, delete the previous license, paste the new license, and click the update license button.






















