Agent Policies

Agent policies allow centralized management of agent configuration through the NetXMS server. Instead of manually editing configuration files on each agent, you define policies on templates and the server pushes them to all agents that belong to those templates.

For agent configuration file syntax and parameters, see Agent Configuration. For template concepts, see Template Concepts.

Policy Types

NetXMS supports several policy types:

Type Description

Agent Configuration

Pushes configuration parameters (external metrics, actions, subagents) to agents

Log Parser

Deploys log parsing rules for log monitoring

File Delivery

Delivers files to managed hosts (see File Delivery)

User Support Application

Configures the User Support Application on managed hosts

Agent Configuration Policies

Agent configuration policies let you define configuration snippets that are deployed to agents automatically. This is the primary mechanism for managing agent settings at scale.

Creating a Configuration Policy

  1. Open the management client

  2. Navigate to the template object where you want to add the policy

  3. Right-click the template and select Properties, then go to the Policies tab

  4. Click Add and select Agent Configuration

  5. Enter the policy name and configuration content

The policy content uses the same syntax as nxagentd.conf:

ExternalMetric = Custom.DiskIO(*): iostat -d $1 1 2 | tail -1 | tr -s ' ' | cut -d' ' -f2
ExternalList = Custom.Processes: ps -eo comm --no-headers | sort -u
Action = Custom.RestartApp: systemctl restart $1
SubAgent = filemgr.nsm

How Configuration Policies Are Applied

When a node is bound to a template with a configuration policy:

  1. The server sends the policy content to the agent

  2. The agent stores the policy as a separate file in its configuration policy directory (config_ap under the agent data directory)

  3. The agent loads all policy files as additional configuration files (includes) on top of its local configuration file

  4. The agent applies the merged configuration (some changes take effect immediately, others require restart)

Policies are re-deployed during each configuration poll, ensuring agents always have the latest version.

Multiple Policies

A node can receive configuration policies from multiple templates. All policies are merged with the local configuration. If two policies define the same parameter, the last-applied policy takes precedence.

Log Parser Policies

Log parser policies deploy log monitoring rules to agents. See Log Monitoring for log parser syntax details.

Creating a Log Parser Policy

  1. Navigate to the template object

  2. Open Properties > Policies

  3. Click Add and select Log Parser

  4. Define the log parser XML:

<parser>
  <file>/var/log/syslog</file>
  <rules>
    <rule>
      <match>error|fail|critical</match>
      <severity>3</severity>
      <event>100000</event>
      <description>Error detected in syslog: %msg%</description>
    </rule>
  </rules>
</parser>

The policy is deployed to all agents bound through the template.

Policy Deployment Flow

The policy deployment process follows these steps:

  1. Administrator creates or modifies a policy on a template

  2. During the next configuration poll, the server detects a policy version mismatch

  3. The server pushes the updated policy to each agent bound to the template

  4. The agent stores the policy and applies the configuration

  5. The server records successful deployment

Forcing Policy Deployment

To deploy a policy immediately without waiting for the next configuration poll:

  • Right-click the node and select Poll > Configuration Poll

  • Or from the server debug console: poll configuration <node-id>

Checking Policy Status

To verify which policies are deployed on a node:

  1. Right-click the node and select Properties

  2. Go to the Policies tab

  3. The list shows all deployed policies, their versions, and deployment status

Policy Application

Agent policies belong to templates, so they are applied to nodes to which the corresponding template is applied. A node receives policies from all templates it is bound to. Removing a node from a template (or deleting the policy) automatically undeploys that template’s policies from the agent.

See Templates for more on templates.

Configuration Policies vs Server-Side Config Files vs Manual Configuration

There are three approaches to managing agent configuration. The following table compares them:

Feature Configuration Policy Server Config File (-M) Manual (nxagentd.conf)

Central management

Yes

Yes

No

Requires template binding

Yes

No

No

Auto-deployed on change

Yes

On agent restart

Manual restart

Supports multiple configs per agent

Yes (merged)

No (single file)

Yes (includes)

Overwrites local config

No (merged)

Yes

N/A

Works with tunnels

Yes

No

Yes

Audit trail

Yes

No

No

Rollback on template unbind

Yes (undeployed)

No

No

Requires agent restart

Some changes

Yes

Yes

Supports log parser policies

Yes

No

No

Supports file delivery

Yes

No

No

Supports NXSL filter scripts

No

Yes

No

Platform-aware delivery

Via templates

Via filter scripts

Manual

Config stored on agent

In config policy directory

Overwrites nxagentd.conf

nxagentd.conf

Agent version requirements

Any

Any

Any

Conflict handling

Last policy wins

N/A

N/A

Scale

Enterprise (thousands)

Medium (hundreds)

Small (tens)

Best for

Ongoing management

Initial provisioning

Development/testing

File Delivery Macros

File delivery policies support macro expansion in file and folder paths:

Macro Description

${ENV_VAR_NAME}

Expands to the value of the specified environment variable on the agent host

%Y, %m, %d, %H, %M, %S

Standard strftime(3C) date/time macros (year, month, day, hour, minute, second)

%a

Abbreviated weekday name

%b

Abbreviated month name

command

Backtick-enclosed command: executes the command on the agent and uses its output

Example file delivery path with macros:

/opt/configs/${APP_NAME}/%Y-%m-%d/settings.conf

This delivers the file to a path like /opt/configs/myapp/2026-03-08/settings.conf.

Backtick command execution requires the server to be listed in MasterServers on the agent.

Best Practices

  • Group related configuration into a single policy rather than creating many small policies

  • Use descriptive policy names that indicate their purpose (e.g., "Linux Custom Metrics", "Web Server Log Parsers")

  • Test policies on a small set of nodes before applying to production templates

  • Use agent configuration policies for external metrics rather than editing nxagentd.conf directly — this provides centralized management and audit trail

  • For initial agent provisioning at scale, consider using server-side config files (-M flag) to bootstrap agents, then switch to configuration policies for ongoing management

Conflicting parameters across multiple policies can cause unexpected behavior. Review all policies applied to a node’s templates to avoid conflicts.