Vanilla DayZ gives an administrator almost nothing in game. Remote administration comes from BattlEye RCon - configured in BEServer_x64.cfg, reached with an external client, good for listing players, kicking, banning, broadcasting and shutting down - and everything visual (teleport, spectate, spawn items, a map of players) comes from an admin mod such as VPP Admin Tools or Community Online Tools. Most servers end up running both: RCon for moderation that works even when nobody is logged in, and a mod for the things you can only do from inside the world. This guide sets up the first, explains its commands and ban files, compares the usual RCon tools, and shows how to add an admin mod without handing your server to whoever reads its config.
If the server itself is not running yet, start with the full DayZ server guide; for the main config file, see serverDZ.cfg explained.
The three layers of DayZ administration#
It helps to know which tool does what before installing anything, because each one has different credentials and a different blast radius.
| Layer | Configured in | What it can do |
|---|---|---|
In-game #login | passwordAdmin in serverDZ.cfg | A few chat commands: kick, shut down |
| BattlEye RCon | BEServer_x64.cfg | Players, kicks, bans, messages, shutdown, from anywhere |
| Admin mod | The mod's own files in the profiles folder | Teleport, spectate, spawn, heal, ESP, map |
The in-game layer is barely worth using: type #login and the passwordAdmin value into chat and you can kick a player or shut the server down, but you have to be connected and in the world to do it. RCon is the one you will use most. It works over the network, from your desktop or a phone, while the server is full and you are not playing. An admin mod is the only way to see and touch the world - a player stuck in a rock, a vehicle clipped under the map, a base that needs inspecting after a dispute.
Setting up BattlEye RCon#
BattlEye ships with the server and is on by default. Its working folder is created inside your profiles folder, so with -profiles=profiles on the launch line it is profiles/BattlEye/. A -BEpath= launch parameter can move it, which is worth knowing when you are looking for a file that is not where a guide says it is.
The RCon settings live in a plain text file in that folder:
RConPassword a-long-random-password-without-spacesRConPort 2310RestrictRCon 0| Line | What it does |
|---|---|
RConPassword | The only authentication RCon has. No spaces |
RConPort | UDP port the RCon listener binds to |
RConIP | Optional: bind to one address instead of all |
RestrictRCon | 1 allows only BattlEye commands, not # server commands |
There is no universal default port. Pick one that is actually allocated to your server and not used by anything else - on a panel host that means a port listed on the server's Network tab. The game uses 2302, the query port is usually 2305, so a free port in the same allocation is the natural choice.
Two details catch people:
- The file is copied at start. When the server starts, BattlEye works from a copy named
BEServer_x64_active_followed by a random suffix, and removes it again on a clean stop. Edit the originalBEServer_x64.cfg, with the server stopped. If a crash leaves stale_active_files behind, delete them before the next start so there is no doubt about which one is current. - RCon is UDP. A firewall rule that opens the port on TCP only does nothing. If your RCon client times out while the game itself is fine, check the protocol first.
RestrictRCon 1 is a reasonable setting when you hand RCon to moderators: they keep kicks, bans and messages but lose #shutdown and the other server commands. Most small servers leave it at 0 and keep RCon itself to the people who own the server.
BattlEye RCon commands#
These are the commands an RCon client sends. Most tools wrap them in buttons, but knowing the raw form makes every tool easier to use and lets you type them into a console when the buttons are missing one.
| Command | What it does |
|---|---|
players | Connected players: number, IP, ping, GUID, name |
admins | Connected RCon clients |
say -1 <message> | Broadcast to everyone |
say <n> <message> | Message one player by their number |
kick <n> [reason] | Kick player number n |
ban <n> [minutes] [reason] | Ban a connected player, 0 minutes is permanent |
addBan <GUID> [minutes] [reason] | Ban by GUID, player need not be online |
bans | List bans with their numbers |
removeBan <n> | Lift ban number n from that list |
loadBans | Re-read bans.txt after editing it |
writeBans | Write the current ban list to bans.txt |
loadScripts / loadEvents | Re-read BattlEye filter files |
MaxPing <ms> | Kick players above this ping |
#lock / #unlock | Stop or allow new joins |
#shutdown | Stop the server cleanly |
The player number n is the session number shown by players, not a permanent ID. It changes when the player reconnects, so run players immediately before a kick or ban, and never act on a number you read a few minutes ago - the slot may now belong to someone else.
#lock is underrated. Locking the server a few minutes before a restart stops people joining into a session that is about to end, and locking it during an incident (a cheater who keeps reconnecting on new accounts) buys time while you sort out bans.
GUIDs, bans.txt and ban workflow#
BattlEye identifies players by a GUID, a 32-character hexadecimal value derived from the SteamID64. It is not the SteamID and you cannot read one off a Steam profile. The reliable way to get it is from players, from the BattlEye section of the server log, or from an RCon tool that records every connection.
Bans are stored in bans.txt in the BattlEye folder, one per line:
0123456789abcdef0123456789abcdef -1 Cheating - aimbot, evidence in #bansfedcba9876543210fedcba9876543210 1767225600 Racism in global chat, 7 daysThe second field is -1 for a permanent ban or a Unix timestamp when the ban expires. The rest of the line is the reason, which the player sees when they are kicked - so write something you would be happy to see quoted in a Discord argument.
A workflow that keeps bans defensible:
- Before banning, find the evidence: the
.ADMadmin log in the profiles folder records connections, kills with weapon and distance, hits and positions. A ban without a timestamp from that file is a ban you cannot explain later. - Ban with a reason that names the rule and where the evidence is kept.
- If you edit
bans.txtby hand, runloadBansafterwards. If you ban through RCon, runwriteBansif your tool does not do it for you, so the file and memory agree. - Keep a copy of
bans.txtin your backups. Losing it after a reinstall means unbanning every cheater you ever caught.
DayZ also has its own ban.txt of SteamID64s, read by the server rather than BattlEye. Most communities use the BattlEye list because RCon tools manage it directly; using both is fine as long as everyone on the staff knows which one is authoritative. Server rules, moderation and staff covers the human side of this - written rules and an appeal path matter more than the tool.
Choosing an RCon tool#
Any client that speaks the BattlEye RCon protocol will work. The common choices fall into three groups:
- Desktop clients. DaRT (DayZ RCon Tool) is the long-standing Windows client: player list, chat log, kick and ban buttons, ban list management. It runs on your own PC, so it is only connected while your PC is on.
- Hosted services. BattleMetrics RCON and CFTools Cloud connect to your server from their infrastructure and stay connected, which gives you a permanent player history, ban lists shared across servers, scheduled messages and restarts, and a log of which staff member did what. They are the standard choice for public servers with several moderators. Both have free tiers and paid features; check their current terms.
- Discord bots. Several bots wrap RCon so moderators can kick and ban from a channel. Convenient, and also a way to put your RCon password on a third-party service you know less about. Treat it accordingly.
Whichever you choose, the RCon password is shared with that tool. If you use a hosted service, it holds a credential that can control your server - pick one with a track record, and give it the password for RCon only, never the account that owns the server. For staff access to files and the console, a separate panel account per person with only the permissions they need is safer than one shared login, as covered in subusers and least privilege. On RE:NODE that is the people section of the panel: roles hold permissions, teams hold people, and every server has an activity log, so a moderator can be given console access without file or billing access.
In-game admin mods#
An admin mod adds a menu inside the game for whoever is on its admin list: teleport, spectate, free camera, spawn items and vehicles, heal, repair, see players on the map, delete objects. Two are widely used.
VPP Admin Tools
VPP Admin Tools (folder @VPPAdminTools) is a self-contained admin menu. It is a client-and-server mod, so it goes in -mod= and its .bikey goes into the server's keys folder like any other. After its first start it writes its configuration into the profiles folder, including a list of super admins by SteamID64:
76561198012345678From there you build permission groups for moderators who should be able to teleport but not spawn items, which is exactly the distinction you want on a public server. The rest of its login flow and its permission names change between versions; follow the mod's own Workshop notes rather than an old video.
Community Online Tools
Community Online Tools (COT) is the other common choice. It depends on Community Framework, so the order is -mod=@CF;@Community-Online-Tools;..., with both keys copied. Its roles and per-player permissions are written into the profiles folder on first start. COT is popular with modded servers because many other CF-based mods integrate with it.
Rules for any admin mod
- Load it on the server you want administered, not on a whim. Every admin mod is a privileged script running on your server. Install it from its official Workshop item only, never from a re-upload.
- Give permissions by role. Spawning items is the permission most often abused by staff, and the one players notice first. Keep it to the owners.
- Log admin actions. Both mods write logs of admin actions to the profiles folder. Read them occasionally - it is the only way you will find out that a moderator has been spawning gear for friends.
- Expect an update lag. After a DayZ patch, admin mods need updating like any other mod, and until they are you may have only RCon. That is one more reason to set RCon up properly first. What to do when a mod update breaks has the routine.
Logs: where the evidence is#
Administration is mostly reading. The files in the profiles folder answer nearly every question you will be asked:
| File | What is in it |
|---|---|
*.ADM | Connections, kills, hits, positions, placements, build actions |
*.RPT | Engine and script output, errors, mod problems |
server_console.log | What the console printed, as named by logFile |
BattlEye/ logs | Script and filter kicks, RCon activity |
| Admin mod logs | Every action taken through the mod's menu |
What goes into the .ADM file depends on the adminLog* keys in serverDZ.cfg. Turn on placement and build action logging if you enforce raid rules; without them a raid dispute becomes one player's word against another's.
These files grow without limit. A daily scheduled task that deletes logs older than a few weeks keeps the disk from filling, and copying the ones you care about into a backup first keeps the evidence. The panel's file manager or SFTP is how you get them off the server; SFTP and the file manager covers both.
Scheduled messages and restarts#
RCon tools can broadcast restart warnings, but DayZ also has a built-in way: db/messages.xml in the mission folder. Each entry can repeat on an interval, or count down to a shutdown:
<messages> <message> <deadline>180</deadline> <shutdown>1</shutdown> <text>Server restarts in #tmin minutes.</text> </message> <message> <repeat>30</repeat> <text>Rules and Discord: example.gg/server</text> </message></messages>deadline is minutes after start, shutdown makes the server stop when it is reached, and #tmin is replaced with the minutes remaining. With a host that restarts a stopped server automatically, or a scheduler that starts it again, this gives a clean three-hour cycle with warnings, entirely from the mission files. Check the shipped messages.xml in your build for the exact element names before relying on it.
The alternative is to run restarts from the panel. On RE:NODE the Schedules tab takes a cron expression and an ordered list of tasks with delays, so one schedule can send #lock and a warning through the console, take a backup, and restart. Restart schedules that help covers how often is worth it; for DayZ the community norm is every three to four hours.
Securing the whole setup#
A checklist, in the order that matters:
- Different passwords for
passwordAdmin,RConPasswordand your panel account. Nothing shared, nothing reused from elsewhere. - RCon password rotated whenever someone with access leaves the staff.
- `RestrictRCon 1` if moderators connect with their own tools and should not be able to shut the server down.
- Admin mod permissions by role, with item spawning held back.
- Two-factor on the panel account. Whoever controls the panel controls every file, including
BEServer_x64.cfg. Two-factor on your panel account takes five minutes. - Backups that include the profiles folder, so bans and admin configuration survive a reinstall.
If something does go wrong - an admin account abused, the RCon password leaked - what to do when your server is hacked has the containment order: change credentials first, then look for what was done.
FAQ#
Where is BEServer_x64.cfg on a DayZ server?
In the BattlEye folder inside your profiles directory, so profiles/BattlEye/BEServer_x64.cfg with -profiles=profiles. If it is not there, check for a -BEpath= launch parameter that moves it, and create the file yourself if it does not exist yet.
Why does my RCon client connect but time out?
Usually the port is wrong, not allocated to the server, or opened on TCP when RCon is UDP. Also check that you edited the original config with the server stopped, not a stale _active_ copy.
How do I ban someone who is not online?
Use addBan with their BattlEye GUID, a duration in minutes (0 for permanent) and a reason. Find the GUID in your RCon tool's history or the server logs from when they last connected.
Is a BattlEye GUID the same as a SteamID?
No. It is derived from the SteamID64 but is a different value. Bans in bans.txt use GUIDs; whitelists and most admin mods use SteamID64s.
Do I need an admin mod at all?
Not for moderation - RCon covers kicks, bans and messages. You need one for anything inside the world: teleporting, spectating, fixing stuck players or vehicles, inspecting bases. Most public servers run one, held to a small group.
Can moderators have RCon without being able to shut down the server?
Yes. Set RestrictRCon 1, which limits RCon clients to BattlEye commands and blocks the # server commands such as #shutdown.




Comments
Completely anonymous: no account, no email, no cookie. We store the name you type, the text and the time - nothing else. Links are limited and markup is not rendered.