Understanding SNMP Table Structure

This page explains how SNMP tables are organized and how their OID structure works. Understanding this structure is essential for configuring SNMP table data collection in NetXMS.

For practical instructions on creating SNMP DCIs, see SNMP Data Collection. For OID format reference and troubleshooting, see SNMP Data Collection Reference.

SNMP Table OID Structure

SNMP tables (e.g., interface table, routing table) require special handling because each column has multiple row instances indexed by a variable suffix.

When performing an SNMP walk, the resulting table item OIDs consist of three parts. Using the notation XXXYYYNNN:

  • XXX — the table base OID (the part that does not change)

  • YYY — the column identifier (represents different columns in the table)

  • NNN — the instance part (represents rows in the table)

For example, consider the interface table with base OID .1.3.6.1.2.1.2.2.1:

1.3.6.1.2.1.2.2.1 .1 .2 .3 .4 .5 .6

.1

1

lo

24

65536

10000000

.2

2

VMware VMXNET3

6

1500

4294967295

005056A5BA4D

In this table, the columns are YYY numbers (typically single numbers in ascending order), and the rows are identified by NNN values.

To get the value "lo", you would request OID 1.3.6.1.2.1.2.2.1.2.1, where:

  • 1.3.6.1.2.1.2.2.1 is the XXX (table base)

  • .2 is the YYY (column for ifDescr)

  • .1 is the NNN (first row instance)

Instance Columns

Instance (key) columns uniquely identify table rows so that NetXMS can match rows between collections — this is needed for row history in general, not just for thresholds. An instance column acts as a primary key; multiple columns can be marked as instance columns (similar to composite keys in databases).

If instance columns are not defined and rows change order between polling periods, row history becomes unreliable and thresholds can activate falsely — values may be attributed to the wrong row.

Complex Instance OIDs

The instance part (NNN) is not always a single number. For some tables (e.g., IP address maps), the instance OID is a string of multiple numbers with dots. For example, in the IP-to-physical address table (ipNetToPhysicalTable, with entries under base OID .1.3.6.1.2.1.4.35.1), instances might look like .2.1.4.10.5.5.1 where the instance contains the IP address.

The Add instance part of SNMP OID as first table column option, available for SNMP-origin table DCIs, exists precisely for such tables: it exposes the instance suffix as the first table column, already marked as the instance (key) column — no further configuration is needed.

Only columns that return values during an SNMP walk can be used as the metric field. If a particular column OID returns empty results, choose a different column for the metric.

Combining Tables

If two tables share the same instances (rows), they can be shown in one combined table DCI by adding columns from both tables.