Event Types Reference
This page lists the built-in event types in NetXMS and their properties.
Built-in Events
NetXMS includes a comprehensive set of built-in events. These events have codes below 100000 and cannot be deleted (but can be modified).
Node and Object Status Events
| Event | Severity | Description |
|---|---|---|
|
Critical |
Node is not responding to any polls |
|
Normal |
Node recovered after being down |
|
Minor |
Network interface is down |
|
Normal |
Network interface is back up |
|
Normal |
New interface discovered on a node |
|
Normal |
Interface removed from a node |
|
Major |
Monitored network service is not responding |
|
Normal |
Network service recovered |
|
Critical |
Node is unreachable by the management server because of a network failure; the root-cause node or interface is passed in event parameters |
Threshold Events
| Event | Severity | Description |
|---|---|---|
|
Warning |
DCI threshold activated |
|
Normal |
DCI threshold deactivated (value returned to normal) |
|
Minor |
Table DCI threshold activated |
|
Normal |
Table DCI threshold deactivated |
A threshold does not set event severity — it selects which activation and deactivation events to generate, and severity comes from those events' templates. To get different severities for different thresholds, configure the thresholds to generate different events.
Discovery Events
| Event | Severity | Description |
|---|---|---|
|
Normal |
New node added to the system (manually or via discovery) |
|
Normal |
New subnet discovered |
|
Warning |
Duplicate IP address detected |
|
Warning |
MAC address for an interface has changed |
Event Severity Levels
NetXMS uses five severity levels:
| Severity | Code | Usage |
|---|---|---|
Normal |
0 |
Informational events, recovery events |
Warning |
1 |
Conditions that may require attention |
Minor |
2 |
Issues with limited impact |
Major |
3 |
Significant problems affecting functionality |
Critical |
4 |
Service-affecting conditions requiring immediate action |
Severity is assigned at the event template level.
During processing it can be changed only from NXSL scripts that receive the event object — an EPP rule filter script or the Hook::EventProcessor hook — by calling $event→setSeverity() or assigning $event→severity.
EPP rule actions themselves cannot change event severity (the severity setting in alarm-creation actions applies to the alarm, not the event).
Event Properties
An event in NetXMS is a record with the following properties (some of which can be modified during processing from EPP rule scripts, using NXSL methods on $event):
| Property | Description |
|---|---|
Event ID |
Unique identifier of this event occurrence |
Event Code |
Unique numeric identifier for the event type |
Event Name |
Symbolic name (e.g., |
Severity |
Normal, Warning, Minor, Major, or Critical |
Source |
Object that generated the event (node, interface, etc.) |
Zone |
Zone UIN of the source object |
DCI ID |
Related DCI, for events generated by data collection (thresholds) |
Message |
Human-readable description with parameter substitution |
Parameters |
Array of event-specific values passed at generation time |
Timestamp |
When the event was generated |
Origin |
Where the event originated (system, syslog, SNMP trap, agent, client, etc.) |
Origin Timestamp |
Timestamp supplied by the origin (e.g., when a forwarded syslog message was produced); equals the generation time when not supplied |
Root Event ID |
For correlated events, the ID of the event this one is a consequence of |
Tags |
Optional labels for filtering and categorization |