Event Types Reference

This page lists the built-in event types in NetXMS and their properties.

Built-in Events

NetXMS includes a comprehensive set of built-in events. These events have codes below 100000 and cannot be deleted (but can be modified).

Node and Object Status Events

Event Severity Description

SYS_NODE_DOWN

Critical

Node is not responding to any polls

SYS_NODE_UP

Normal

Node recovered after being down

SYS_IF_DOWN

Minor

Network interface is down

SYS_IF_UP

Normal

Network interface is back up

SYS_IF_ADDED

Normal

New interface discovered on a node

SYS_IF_DELETED

Normal

Interface removed from a node

SYS_SERVICE_DOWN

Major

Monitored network service is not responding

SYS_SERVICE_UP

Normal

Network service recovered

SYS_NODE_UNREACHABLE

Critical

Node is unreachable by the management server because of a network failure; the root-cause node or interface is passed in event parameters

Threshold Events

Event Severity Description

SYS_THRESHOLD_REACHED

Warning

DCI threshold activated

SYS_THRESHOLD_REARMED

Normal

DCI threshold deactivated (value returned to normal)

SYS_TABLE_THRESHOLD_ACTIVATED

Minor

Table DCI threshold activated

SYS_TABLE_THRESHOLD_DEACTIVATED

Normal

Table DCI threshold deactivated

A threshold does not set event severity — it selects which activation and deactivation events to generate, and severity comes from those events' templates. To get different severities for different thresholds, configure the thresholds to generate different events.

Discovery Events

Event Severity Description

SYS_NODE_ADDED

Normal

New node added to the system (manually or via discovery)

SYS_SUBNET_ADDED

Normal

New subnet discovered

SYS_DUPLICATE_IP_ADDRESS

Warning

Duplicate IP address detected

SYS_MAC_ADDR_CHANGED

Warning

MAC address for an interface has changed

Agent Events

Event Severity Description

SYS_AGENT_UNREACHABLE

Major

Agent is not responding

SYS_AGENT_OK

Normal

Agent communication restored

SYS_TUNNEL_OPEN

Normal

Agent tunnel established

SYS_TUNNEL_CLOSED

Warning

Agent tunnel closed

Server Events

Event Severity Description

SYS_SERVER_STARTED

Normal

NetXMS server has started

SYS_DB_QUERY_FAILED

Critical

Database query failed

SYS_SNMP_UNREACHABLE

Major

SNMP agent on node is not responding

SYS_SNMP_OK

Normal

SNMP communication restored

Event Severity Levels

NetXMS uses five severity levels:

Severity Code Usage

Normal

0

Informational events, recovery events

Warning

1

Conditions that may require attention

Minor

2

Issues with limited impact

Major

3

Significant problems affecting functionality

Critical

4

Service-affecting conditions requiring immediate action

Severity is assigned at the event template level. During processing it can be changed only from NXSL scripts that receive the event object — an EPP rule filter script or the Hook::EventProcessor hook — by calling $event→setSeverity() or assigning $event→severity. EPP rule actions themselves cannot change event severity (the severity setting in alarm-creation actions applies to the alarm, not the event).

Event Properties

An event in NetXMS is a record with the following properties (some of which can be modified during processing from EPP rule scripts, using NXSL methods on $event):

Property Description

Event ID

Unique identifier of this event occurrence

Event Code

Unique numeric identifier for the event type

Event Name

Symbolic name (e.g., SYS_NODE_DOWN, SYS_THRESHOLD_REACHED)

Severity

Normal, Warning, Minor, Major, or Critical

Source

Object that generated the event (node, interface, etc.)

Zone

Zone UIN of the source object

DCI ID

Related DCI, for events generated by data collection (thresholds)

Message

Human-readable description with parameter substitution

Parameters

Array of event-specific values passed at generation time

Timestamp

When the event was generated

Origin

Where the event originated (system, syslog, SNMP trap, agent, client, etc.)

Origin Timestamp

Timestamp supplied by the origin (e.g., when a forwarded syslog message was produced); equals the generation time when not supplied

Root Event ID

For correlated events, the ID of the event this one is a consequence of

Tags

Optional labels for filtering and categorization