Alarm Configuration Reference
This page provides a reference for alarm properties, state transitions, and server configuration variables related to alarm management in NetXMS.
For an overview of the alarm system, see Alarms.
Alarm States
| State | Value | Description |
|---|---|---|
Outstanding |
0 |
Alarm has been created, no operator has acknowledged it |
Acknowledged |
1 |
An operator has acknowledged the alarm but it is not yet resolved |
Resolved |
2 |
The condition has cleared (automatically or manually), awaiting termination |
Terminated |
3 |
Alarm is closed and moved to history |
In the database and API, the numeric state occupies the lower four bits of the alarm state field (mask 0x0F); bit 0x10 is the sticky acknowledgement flag.
State Transitions
| From | To | Trigger |
|---|---|---|
Outstanding |
Acknowledged |
Operator acknowledges the alarm |
Outstanding |
Resolved |
Recovery event resolves the alarm, or operator manually resolves it |
Outstanding |
Terminated |
Operator terminates the alarm directly |
Acknowledged |
Resolved |
Recovery event resolves the alarm, or operator manually resolves it |
Acknowledged |
Terminated |
Operator terminates the alarm directly |
Acknowledged |
Outstanding |
New event with the same alarm key arrives (unless the acknowledgement was sticky), or a sticky acknowledgement’s timeout expires (requires |
Resolved |
Outstanding |
New event with the same alarm key arrives |
Resolved |
Terminated |
Operator terminates, or auto-termination timer expires |
Acknowledgement is possible only from the Outstanding state. A timed acknowledgement is a sticky acknowledgement with a timeout: the alarm stays acknowledged when new matching events arrive, and returns to Outstanding when the timeout expires.
| An acknowledged alarm that receives a recovery event transitions to Resolved, not back to Outstanding. |
Alarm Properties Reference
| Property | Description |
|---|---|
Alarm ID |
Unique identifier |
Alarm Key |
Correlation key (from EPP rule) |
State |
Outstanding, Acknowledged, Resolved, or Terminated |
Severity |
Normal, Warning, Minor, Major, or Critical |
Source |
Object that generated the triggering event |
Message |
Alarm text (from EPP rule template) |
Created |
Timestamp when the alarm was generated |
Last Change |
Timestamp of the most recent state change |
Ack By |
User who acknowledged the alarm (if applicable) |
Resolved By |
User who resolved the alarm (if applicable) |
Repeat Count |
Number of times the same alarm key has been triggered while alarm is active |
Rule |
EPP rule that created the alarm |
Related Events |
List of events associated with this alarm |
Severity Levels
| Severity | Description |
|---|---|
Normal |
Informational alarm, no impact |
Warning |
Potential issue that may require attention |
Minor |
Minor impact on service |
Major |
Significant impact on service |
Critical |
Critical service disruption |
Server Configuration Variables
| Variable | Default | Description |
|---|---|---|
|
1 |
Delete active alarms of an object when the object is deleted |
|
1 |
Enable timed alarm acknowledgement (the alarm returns to Outstanding when the acknowledgement time expires); server restart required |
|
180 |
Number of days to keep terminated alarms in the alarm history |
|
0 |
When enabled, alarm state operations ignore the state of the linked helpdesk ticket |
|
0 |
Seconds after resolution before automatic termination (0 = disabled) |
|
0 |
When enabled, an alarm can be terminated only after it has been resolved; acknowledgement is not required. When disabled (default), operators can terminate alarms from any state. The restriction is enforced by the management client; the server only distributes the setting. |
|
false |
Enable alarm summary email sending |
|
|
Cron-style schedule for sending summary emails (default: daily at midnight) |
|
(empty) |
Semicolon-separated list of email recipients |
|
|
Name of the HTML-capable SMTP notification channel used for alarm summary emails |
Alarm Browser Operations
| Operation | Description |
|---|---|
Acknowledge |
Mark as seen, indicates someone is aware of the problem |
Sticky acknowledge |
Acknowledge with sticky flag — alarm stays acknowledged even when new matching events arrive |
Timed acknowledge |
Sticky acknowledge for a limited time — when the timeout expires, the sticky flag is cleared and the alarm returns to Outstanding (requires |
Resolve |
Mark the underlying condition as fixed |
Terminate |
Close the alarm and move to history |
Add Comment |
Attach notes to the alarm for team communication |
View Related Events |
See all events associated with this alarm |
Create incident |
Create an incident linked to the alarm |
Create ticket in helpdesk system |
Create a ticket in the linked helpdesk system (if configured) |
Unlink from helpdesk ticket |
Remove the link between the alarm and its helpdesk ticket |
Show helpdesk ticket in web browser |
Open the linked helpdesk ticket in a web browser |
Go to object |
Navigate to the alarm’s source object |
Go to DCI |
Navigate to the DCI related to the alarm |