Alarm Configuration Reference

This page provides a reference for alarm properties, state transitions, and server configuration variables related to alarm management in NetXMS.

For an overview of the alarm system, see Alarms.

Alarm States

State Value Description

Outstanding

0

Alarm has been created, no operator has acknowledged it

Acknowledged

1

An operator has acknowledged the alarm but it is not yet resolved

Resolved

2

The condition has cleared (automatically or manually), awaiting termination

Terminated

3

Alarm is closed and moved to history

In the database and API, the numeric state occupies the lower four bits of the alarm state field (mask 0x0F); bit 0x10 is the sticky acknowledgement flag.

State Transitions

From To Trigger

Outstanding

Acknowledged

Operator acknowledges the alarm

Outstanding

Resolved

Recovery event resolves the alarm, or operator manually resolves it

Outstanding

Terminated

Operator terminates the alarm directly

Acknowledged

Resolved

Recovery event resolves the alarm, or operator manually resolves it

Acknowledged

Terminated

Operator terminates the alarm directly

Acknowledged

Outstanding

New event with the same alarm key arrives (unless the acknowledgement was sticky), or a sticky acknowledgement’s timeout expires (requires Alarms.EnableTimedAck)

Resolved

Outstanding

New event with the same alarm key arrives

Resolved

Terminated

Operator terminates, or auto-termination timer expires

Acknowledgement is possible only from the Outstanding state. A timed acknowledgement is a sticky acknowledgement with a timeout: the alarm stays acknowledged when new matching events arrive, and returns to Outstanding when the timeout expires.

An acknowledged alarm that receives a recovery event transitions to Resolved, not back to Outstanding.

Alarm Properties Reference

Property Description

Alarm ID

Unique identifier

Alarm Key

Correlation key (from EPP rule)

State

Outstanding, Acknowledged, Resolved, or Terminated

Severity

Normal, Warning, Minor, Major, or Critical

Source

Object that generated the triggering event

Message

Alarm text (from EPP rule template)

Created

Timestamp when the alarm was generated

Last Change

Timestamp of the most recent state change

Ack By

User who acknowledged the alarm (if applicable)

Resolved By

User who resolved the alarm (if applicable)

Repeat Count

Number of times the same alarm key has been triggered while alarm is active

Rule

EPP rule that created the alarm

Related Events

List of events associated with this alarm

Severity Levels

Severity Description

Normal

Informational alarm, no impact

Warning

Potential issue that may require attention

Minor

Minor impact on service

Major

Significant impact on service

Critical

Critical service disruption

Server Configuration Variables

Variable Default Description

Alarms.DeleteAlarmsOfDeletedObject

1

Delete active alarms of an object when the object is deleted

Alarms.EnableTimedAck

1

Enable timed alarm acknowledgement (the alarm returns to Outstanding when the acknowledgement time expires); server restart required

Alarms.HistoryRetentionTime

180

Number of days to keep terminated alarms in the alarm history

Alarms.IgnoreHelpdeskState

0

When enabled, alarm state operations ignore the state of the linked helpdesk ticket

Alarms.ResolveExpirationTime

0

Seconds after resolution before automatic termination (0 = disabled)

Alarms.StrictStatusFlow

0

When enabled, an alarm can be terminated only after it has been resolved; acknowledgement is not required. When disabled (default), operators can terminate alarms from any state. The restriction is enforced by the management client; the server only distributes the setting.

Alarms.SummaryEmail.Enable

false

Enable alarm summary email sending

Alarms.SummaryEmail.Schedule

0 0 * * *

Cron-style schedule for sending summary emails (default: daily at midnight)

Alarms.SummaryEmail.Recipients

(empty)

Semicolon-separated list of email recipients

DefaultNotificationChannel.SMTP.Html

SMTP-HTML

Name of the HTML-capable SMTP notification channel used for alarm summary emails

Alarm Browser Operations

Operation Description

Acknowledge

Mark as seen, indicates someone is aware of the problem

Sticky acknowledge

Acknowledge with sticky flag — alarm stays acknowledged even when new matching events arrive

Timed acknowledge

Sticky acknowledge for a limited time — when the timeout expires, the sticky flag is cleared and the alarm returns to Outstanding (requires Alarms.EnableTimedAck)

Resolve

Mark the underlying condition as fixed

Terminate

Close the alarm and move to history

Add Comment

Attach notes to the alarm for team communication

View Related Events

See all events associated with this alarm

Create incident

Create an incident linked to the alarm

Create ticket in helpdesk system

Create a ticket in the linked helpdesk system (if configured)

Unlink from helpdesk ticket

Remove the link between the alarm and its helpdesk ticket

Show helpdesk ticket in web browser

Open the linked helpdesk ticket in a web browser

Go to object

Navigate to the alarm’s source object

Go to DCI

Navigate to the DCI related to the alarm