Windows Installation
This page covers installation of all NetXMS components on Windows.
Before proceeding, ensure your system meets the system requirements and that you have prepared the database for the server.
NetXMS components are distributed as separate Windows installers, downloadable from the official NetXMS website:
| Installer | Component |
|---|---|
|
Server (includes command-line tools and reporting server) |
|
Agent (also |
|
Desktop management client |
|
Web management console (bundles Java and Jetty) |
Server
Run the Installer
-
Launch the server installer and follow the setup wizard.
-
On the Component Selection screen, select:
-
NetXMS Server
-
Command Line Tools (optional)
-
Database client library, if your database is PostgreSQL, MariaDB, or MySQL (for MS SQL Server and Oracle, install the vendor’s client software separately)
-
Reporting Server (optional)
-
-
Keep the Initialize database task selected and enter the database connection parameters when prompted.
-
The installer creates the configuration file at
C:\NetXMS\etc\netxmsd.confand initializes the database schema. -
A random password is generated for the
adminuser and displayed on the final page of the wizard — use the Copy Password button and save it before closing the installer. -
The server is registered as a Windows service and started automatically.
Verify Installation
Open the Windows Services console (services.msc) and verify that the NetXMS Core service is running.
Check the log file at C:\NetXMS\log\netxmsd.log for any startup errors.
Post-Installation Steps
After the server is running:
-
Connect with the management client as
admin, using the password shown by the installer (see Initial Credentials) -
You will be asked to change the password on first login
-
Proceed to the Quick Start guide for initial configuration
Firewall Configuration
Ensure the following ports are open on the server host:
| Port | Protocol | Purpose |
|---|---|---|
4701 |
TCP |
Management client connections (desktop client and web management console) |
4700 |
TCP |
Agent connections (if agents connect to server) |
4703 |
TCP |
Agent tunnel connections |
162 |
UDP |
SNMP trap reception |
514 |
UDP |
Syslog reception (if enabled) |
8000 / 8443 |
TCP |
WebAPI HTTP / HTTPS listeners (only if the WebAPI is enabled and exposed beyond the local host) |
Open Windows Defender Firewall with Advanced Security and create inbound rules for each port, or use PowerShell:
New-NetFirewallRule -DisplayName "NetXMS Server" -Direction Inbound -Protocol TCP -LocalPort 4701 -Action Allow
New-NetFirewallRule -DisplayName "NetXMS Agent" -Direction Inbound -Protocol TCP -LocalPort 4700 -Action Allow
New-NetFirewallRule -DisplayName "NetXMS Tunnel" -Direction Inbound -Protocol TCP -LocalPort 4703 -Action Allow
New-NetFirewallRule -DisplayName "SNMP Traps" -Direction Inbound -Protocol UDP -LocalPort 162 -Action Allow
Agent
Installer
Download the NetXMS agent installer (nxagent-6.1.0-x64.exe) and run it on the target machine.
-
Enter the NetXMS server address when prompted.
-
The installer creates the configuration file at
C:\NetXMS\etc\nxagentd.confand registers the agent as a Windows service. -
The agent starts automatically after installation.
Silent Installation
For mass deployment, use silent installation with command-line parameters. The Windows Agent installer supports configuration, tunnel, subagent, and service options via the command line.
Basic silent install example:
nxagent-{product-version}-x64.exe /VERYSILENT /SUPPRESSMSGBOXES /SERVER=10.0.0.1
For the complete list of installer command-line options, examples, and uninstallation options, see Windows Agent Installer Reference.
Configuration
The configuration file is located at C:\NetXMS\etc\nxagentd.conf and uses the same format as the Linux agent:
MasterServers = 10.0.0.1
LogFile = {syslog}
On Windows, {syslog} directs log output to the Windows Event Log.
Key configuration parameters:
| Parameter | Default | Description |
|---|---|---|
|
(none) |
Comma-separated list of server addresses (IP, hostname, or CIDR) with full control over the agent, including configuration changes and upgrades. |
|
(none) |
Servers with intermediate access: read data and execute predefined actions. |
|
(none) |
Servers with read-only access. |
|
|
Shared secret for server-agent authentication; must match the secret configured on the server. Used when |
|
No |
Require shared secret authentication for all server connections. |
|
(none) |
Server address for an agent-initiated tunnel connection. See Agent Tunnels. |
|
(platform-dependent) |
Path to agent log file. Special values: |
|
|
Debug verbosity level (0-9); 0 disables debug output. |
For the full list of agent configuration parameters, see Agent Configuration.
Agent Tunnels
In environments where agents cannot accept inbound connections (firewalled hosts, NAT, cloud VMs), use agent tunnels. The agent initiates an outbound TLS connection to the server, eliminating the need for inbound port 4700.
Add the following to the agent configuration:
ServerConnection = server.example.com
MasterServers = server.example.com
ServerConnection defines the tunnel endpoint, but MasterServers (or ControlServers/Servers) is also required to authorize the server to communicate with the agent through the tunnel.
|
The agent connects to the server on port 4703 (TLS) and maintains a persistent tunnel. The server communicates with the agent through this tunnel for all polling and data collection operations.
For detailed tunnel configuration, see Agent Tunnels.
Verifying Agent Connectivity
After installing the agent, verify connectivity from the server using nxget:
nxget 10.0.0.50 System.PlatformName
This should return the agent’s platform information (e.g., windows-x64).
nxget opens a direct connection to the agent on port 4700, so it cannot reach agents that connect through an agent tunnel.
|
Web Management Console
The NetXMS web management console provides browser-based access to the monitoring system. It is a Java web application deployed on a Jakarta EE-compatible servlet container.
Prerequisites
-
Java Runtime Environment (JRE) 17 or later
-
Apache Tomcat 11 or later, Jetty 12 or later, or any servlet container supporting Jakarta Servlet API 6.0
-
Network access to the NetXMS server on port 4701
Using the Ready-Made Installer
A Windows installer is available that bundles Java, Jetty, and the web console into a single package. Download it from the NetXMS download page:
https://netxms.com/download/releases/6.1/netxms-webui-6.1.0-x64.exe
Run the installer and follow the on-screen prompts. The service starts automatically after installation.
Manual Deployment on Tomcat
Install Java and Tomcat
-
Download and install a JRE 17 or later from https://adoptium.net/ or the vendor of your choice.
-
Download Apache Tomcat 11 from https://tomcat.apache.org/ and use the Windows Service installer for production.
Deploy the Web Console WAR
Download the WAR file from the NetXMS download page:
https://netxms.com/download/releases/6.1/nxmc-6.1.0.war
Copy the downloaded file to the Tomcat webapps directory (e.g., C:\Program Files\Apache Software Foundation\Tomcat 11\webapps\nxmc.war).
Tomcat automatically extracts and deploys the application.
Configuration
The web console needs to know the NetXMS server address.
The quickest method for a manual Tomcat deployment is to place an nxmc.properties file on the Tomcat classpath (e.g., C:\Program Files\Apache Software Foundation\Tomcat 11\lib\):
server=10.0.0.1
Replace 10.0.0.1 with your NetXMS server address.
Alternatively, set the NXMC_SERVER environment variable in the Windows system environment or in the Tomcat service wrapper configuration.
For the full list of configuration properties, all supported configuration methods (JNDI, properties file, JVM properties, environment variables), and the server address resolution order, see Web Console Configuration Reference.
Restart the Tomcat service (or the ready-made installer service) after making configuration changes.
Access the web console at http://your-server:8080/nxmc (or https://your-server:8443/ for the ready-made installer).
Troubleshooting
Web Console Does Not Start
For Tomcat, check log files at C:\Program Files\Apache Software Foundation\Tomcat 11\logs\catalina.out.
Common issues:
-
Java not found — Ensure
JAVA_HOMEis set correctly and points to JRE 17 or later -
Port conflict — Tomcat default port 8080 may be in use by another application
-
Permission denied — Ensure the service account has read access to the WAR file
WebAPI
The NetXMS WebAPI provides RESTful HTTP access to the monitoring system, enabling integration with third-party tools, custom dashboards, and automation scripts.
The WebAPI is built into the server: REST endpoints are provided by the webapi server module (webapi.nxm, installed together with the server) and served by the server’s own HTTP listener.
No separate service or component is required.
The standalone WebAPI service (nxapisrv) used with older NetXMS versions is deprecated and has been removed.
|
Enabling the WebAPI
Load the module by adding the following line to C:\NetXMS\etc\netxmsd.conf and restarting the NetXMS Core service:
Module = webapi
By default the API listens for plain HTTP requests on 127.0.0.1:8000.
Listener settings are controlled by the [WEBAPI] section of netxmsd.conf:
[WEBAPI]
Port = 8000
# Listen address: loopback (default), any, or a specific IP address
Address = loopback
# Optional HTTPS listener
TLSEnable = yes
TLSPort = 8443
TLSCertificate = C:\NetXMS\etc\webapi.crt
TLSCertificateKey = C:\NetXMS\etc\webapi.key
Configuration Parameters
All parameters belong to the [WEBAPI] section of the server configuration file (netxmsd.conf).
| Parameter | Description |
|---|---|
|
Enable or disable the WebAPI listener. Default: |
|
HTTP listen address: |
|
HTTP port. Default: |
|
Enable the HTTPS listener. Default: |
|
HTTPS listen address. Default: |
|
HTTPS port. Default: |
|
Path to the TLS certificate file (PEM format). Required when |
|
Path to the TLS private key file (PEM format). Required when |
|
Path to the |
The HTTPS listener is provided by a reproxy helper process that the server starts and supervises automatically when TLSEnable is set.
|
API Usage
See the Linux installation page for authentication and request examples — API usage is identical on all platforms. For the complete API reference, see the REST API section.
Security Considerations
-
The plain HTTP listener binds to the loopback interface by default. To expose the API beyond the local host, enable the TLS listener (
TLSEnable) or keep the HTTP listener on loopback behind a reverse proxy. -
Always use TLS in production. Use certificates from a trusted CA or your internal PKI.
-
Restrict network access to the API port using firewall rules.
Desktop Management Client
The NetXMS desktop management client is distributed as a separate installer, netxms-client-6.1.0-x64.exe, with the following components:
-
NetXMS GUI Client — the desktop management client
-
NetXMS Python Scripting (nxshell) — see NXShell
-
Command Line Tools —
nxalarm,nxevent,nxnotify, andnxpush -
Java Runtime Environment — used by the GUI client and nxshell. Without it,
JAVA_HOMEmust point to a 64-bit Java 17 or later installation.
The desktop client offers the same functionality as the web console and may provide better responsiveness for daily administrative tasks.