Agent Policies
Agent policies allow centralized management of agent configuration through the NetXMS server. Instead of manually editing configuration files on each agent, you define policies on templates and the server pushes them to all agents that belong to those templates.
For agent configuration file syntax and parameters, see Agent Configuration. For template concepts, see Template Concepts.
Policy Types
NetXMS supports several policy types:
| Type | Description |
|---|---|
Agent Configuration |
Pushes configuration parameters (external metrics, actions, subagents) to agents |
Log Parser |
Deploys log parsing rules for log monitoring |
File Delivery |
Delivers files to managed hosts (see File Delivery) |
User Support Application |
Configures the User Support Application on managed hosts |
Agent Configuration Policies
Agent configuration policies let you define configuration snippets that are deployed to agents automatically. This is the primary mechanism for managing agent settings at scale.
Creating a Configuration Policy
-
Open the management client
-
Navigate to the template object where you want to add the policy
-
Right-click the template and select Properties, then go to the Policies tab
-
Click Add and select Agent Configuration
-
Enter the policy name and configuration content
The policy content uses the same syntax as nxagentd.conf:
ExternalMetric = Custom.DiskIO(*): iostat -d $1 1 2 | tail -1 | tr -s ' ' | cut -d' ' -f2
ExternalList = Custom.Processes: ps -eo comm --no-headers | sort -u
Action = Custom.RestartApp: systemctl restart $1
SubAgent = filemgr.nsm
How Configuration Policies Are Applied
When a node is bound to a template with a configuration policy:
-
The server sends the policy content to the agent
-
The agent stores the policy as a separate file in its configuration policy directory (
config_apunder the agent data directory) -
The agent loads all policy files as additional configuration files (includes) on top of its local configuration file
-
The agent applies the merged configuration (some changes take effect immediately, others require restart)
Policies are re-deployed during each configuration poll, ensuring agents always have the latest version.
Log Parser Policies
Log parser policies deploy log monitoring rules to agents. See Log Monitoring for log parser syntax details.
Creating a Log Parser Policy
-
Navigate to the template object
-
Open Properties > Policies
-
Click Add and select Log Parser
-
Define the log parser XML:
<parser>
<file>/var/log/syslog</file>
<rules>
<rule>
<match>error|fail|critical</match>
<severity>3</severity>
<event>100000</event>
<description>Error detected in syslog: %msg%</description>
</rule>
</rules>
</parser>
The policy is deployed to all agents bound through the template.
Policy Deployment Flow
The policy deployment process follows these steps:
-
Administrator creates or modifies a policy on a template
-
During the next configuration poll, the server detects a policy version mismatch
-
The server pushes the updated policy to each agent bound to the template
-
The agent stores the policy and applies the configuration
-
The server records successful deployment
Policy Application
Agent policies belong to templates, so they are applied to nodes to which the corresponding template is applied. A node receives policies from all templates it is bound to. Removing a node from a template (or deleting the policy) automatically undeploys that template’s policies from the agent.
See Templates for more on templates.
Configuration Policies vs Server-Side Config Files vs Manual Configuration
There are three approaches to managing agent configuration. The following table compares them:
| Feature | Configuration Policy | Server Config File (-M) | Manual (nxagentd.conf) |
|---|---|---|---|
Central management |
Yes |
Yes |
No |
Requires template binding |
Yes |
No |
No |
Auto-deployed on change |
Yes |
On agent restart |
Manual restart |
Supports multiple configs per agent |
Yes (merged) |
No (single file) |
Yes (includes) |
Overwrites local config |
No (merged) |
Yes |
N/A |
Works with tunnels |
Yes |
No |
Yes |
Audit trail |
Yes |
No |
No |
Rollback on template unbind |
Yes (undeployed) |
No |
No |
Requires agent restart |
Some changes |
Yes |
Yes |
Supports log parser policies |
Yes |
No |
No |
Supports file delivery |
Yes |
No |
No |
Supports NXSL filter scripts |
No |
Yes |
No |
Platform-aware delivery |
Via templates |
Via filter scripts |
Manual |
Config stored on agent |
In config policy directory |
Overwrites nxagentd.conf |
nxagentd.conf |
Agent version requirements |
Any |
Any |
Any |
Conflict handling |
Last policy wins |
N/A |
N/A |
Scale |
Enterprise (thousands) |
Medium (hundreds) |
Small (tens) |
Best for |
Ongoing management |
Initial provisioning |
Development/testing |
File Delivery Macros
File delivery policies support macro expansion in file and folder paths:
| Macro | Description |
|---|---|
|
Expands to the value of the specified environment variable on the agent host |
|
Standard |
|
Abbreviated weekday name |
|
Abbreviated month name |
|
Backtick-enclosed command: executes the command on the agent and uses its output |
Example file delivery path with macros:
/opt/configs/${APP_NAME}/%Y-%m-%d/settings.conf
This delivers the file to a path like /opt/configs/myapp/2026-03-08/settings.conf.
Backtick command execution requires the server to be listed in MasterServers on the agent.
|
Best Practices
-
Group related configuration into a single policy rather than creating many small policies
-
Use descriptive policy names that indicate their purpose (e.g., "Linux Custom Metrics", "Web Server Log Parsers")
-
Test policies on a small set of nodes before applying to production templates
-
Use agent configuration policies for external metrics rather than editing
nxagentd.confdirectly — this provides centralized management and audit trail -
For initial agent provisioning at scale, consider using server-side config files (
-Mflag) to bootstrap agents, then switch to configuration policies for ongoing management
| Conflicting parameters across multiple policies can cause unexpected behavior. Review all policies applied to a node’s templates to avoid conflicts. |