Operating System Monitoring
NetXMS provides comprehensive operating system monitoring through its native agent. The agent includes platform-specific subagents that expose hundreds of metrics for CPU, memory, disk, network, and process monitoring.
Platform Subagents
Each supported operating system has a dedicated platform subagent.
All platform subagents are separate loadable modules; when subagent autoload is enabled (the default), the agent automatically loads the module matching the operating system it runs on (the name is derived from uname; winnt.nsm on Windows), so no explicit SubAgent entry is normally required.
| Subagent | Platform |
|---|---|
|
Linux |
|
Windows |
|
FreeBSD |
|
NetBSD |
|
OpenBSD |
|
Solaris |
|
AIX |
|
macOS |
See Subagents for details.
CPU Monitoring
CPU usage metrics are available in three averaging windows: 1-minute (default), 5-minute (suffix 5), and 15-minute (suffix 15).
Per-core variants accept a core index as argument.
Windows also provides CurrentUsage variants for instantaneous readings.
System.CPU.CacheSize(*)
CPU cache size in kilobytes.
Data Type |
Integer |
Platforms |
Linux |
| Argument | Type | Description |
|---|---|---|
index |
Integer |
CPU index (zero-based) |
System.CPU.CoreId(*)
CPU core ID.
Data Type |
Integer |
Platforms |
Linux |
| Argument | Type | Description |
|---|---|---|
index |
Integer |
CPU index (zero-based) |
System.CPU.Count
Number of CPU cores available to the system.
Data Type |
Unsigned Integer (Integer on macOS and FreeBSD) |
Platforms |
Linux, Windows, FreeBSD, Solaris, AIX, macOS, NetBSD, OpenBSD |
System.CPU.CountOffline
Number of currently offline CPUs.
Data Type |
Unsigned Integer |
Platforms |
Linux |
System.CPU.Frequency(*)
CPU frequency in megahertz.
On FreeBSD only the argument-less form System.CPU.Frequency is available.
Data Type |
Float (Integer on FreeBSD) |
Platforms |
Linux, FreeBSD |
| Argument | Type | Description |
|---|---|---|
index |
Integer |
CPU index (zero-based) |
System.CPU.Model(*)
CPU model identification string.
On FreeBSD only the argument-less form System.CPU.Model is available.
Data Type |
String |
Platforms |
Linux, FreeBSD |
| Argument | Type | Description |
|---|---|---|
index |
Integer |
CPU index (zero-based) |
System.CPU.PhysicalId(*)
Physical CPU ID.
Data Type |
Integer |
Platforms |
Linux |
| Argument | Type | Description |
|---|---|---|
index |
Integer |
CPU index (zero-based) |
System.CPU.VendorId
CPU vendor identification string.
Data Type |
String |
Platforms |
Linux, Windows, FreeBSD |
System.CPU.LoadAvg
1-minute load average.
Data Type |
Float |
Platforms |
Linux, FreeBSD, Solaris, AIX, macOS, NetBSD, OpenBSD, Windows (via |
System.CPU.LoadAvg5
5-minute load average.
Data Type |
Float |
Platforms |
Linux, FreeBSD, Solaris, AIX, macOS, NetBSD, OpenBSD, Windows (via |
System.CPU.LoadAvg15
15-minute load average.
Data Type |
Float |
Platforms |
Linux, FreeBSD, Solaris, AIX, macOS, NetBSD, OpenBSD, Windows (via |
System.CPU.ContextSwitches
Total context switch count since system boot.
Data Type |
Unsigned Integer |
Platforms |
Linux, Windows, FreeBSD |
System.CPU.Interrupts
Total interrupt count. Per-core variant accepts a core index argument (Windows only).
Data Type |
Unsigned Integer |
Platforms |
Linux, Windows, FreeBSD |
System.CPU.Interrupts(*) — returns interrupt count for a specific core.
| Argument | Type | Description |
|---|---|---|
index |
Integer |
CPU core index (zero-based) |
System.CPU.Usage
CPU usage percentage, available in 1-minute (default), 5-minute (suffix 5), and 15-minute (suffix 15) averaging windows. All variants report a Float value as a percentage.
Per-core variants accept a zero-based core index as argument (e.g., System.CPU.Usage(0)).
Data Type |
Float |
Platforms |
Linux, Windows, macOS, FreeBSD, Solaris, AIX (per sub-type; not available on NetBSD and OpenBSD) |
| Prefix | Description |
|---|---|
|
1-minute average |
|
5-minute average |
|
15-minute average |
| Suffix | Platforms | Description |
|---|---|---|
(none, overall) |
Linux, Windows, macOS, FreeBSD, Solaris, AIX |
Combined CPU utilization across all modes |
|
Linux, Windows, macOS, FreeBSD, Solaris, AIX |
User mode time |
|
Linux, Windows, macOS, FreeBSD, Solaris, AIX |
Kernel mode time |
|
Linux, Windows, macOS, FreeBSD, Solaris, AIX |
Idle time |
|
Linux, Solaris, AIX |
I/O wait time |
|
Linux, Windows |
Hardware interrupt time |
|
Linux |
Software interrupt time |
|
Linux |
Hypervisor steal time |
|
Linux |
Guest VM time |
|
Linux, macOS, FreeBSD |
Nice process time |
Each combination of averaging window and sub-type is a valid parameter. For example: System.CPU.Usage.User, System.CPU.Usage5.IoWait, System.CPU.Usage15.Steal.
All sub-types also have per-core variants by appending (core_index). For example: System.CPU.Usage.User(3), System.CPU.Usage5(0).
System.CPU.CurrentUsage
Instantaneous CPU usage (Windows only). Unlike the averaged variants, these report real-time CPU utilization.
Data Type |
Float |
Platforms |
Windows |
| Suffix | Description |
|---|---|
(none, overall) |
Current CPU utilization |
|
Current idle time |
|
Current hardware interrupt time |
|
Current kernel mode time |
|
Current user mode time |
All sub-types have per-core variants by appending (core_index).
System.CPU.PhysicalAverage
Average physical CPU utilization (AIX only), available in 1-minute (default), 5-minute (suffix 5), and 15-minute (suffix 15) averaging windows.
Sub-type suffixes .User, .System, .Idle, and .IoWait report the corresponding CPU time share.
Data Type |
Float |
Platforms |
AIX |
Each combination of averaging window and sub-type is a valid metric. For example: System.CPU.PhysicalAverage, System.CPU.PhysicalAverage5.User, System.CPU.PhysicalAverage15.IoWait.
CPU Usage Types
Each CPU usage parameter reports a specific type of CPU time:
| Type | Description |
|---|---|
|
Combined CPU utilization across all modes |
|
Time executing user-space processes |
|
Time executing kernel-mode code |
|
Time with no work to do |
|
Time waiting for I/O operations to complete (Linux, Solaris, AIX) |
|
Time handling hardware interrupts (Linux, Windows) |
|
Time handling software interrupts (Linux only) |
|
Time stolen by hypervisor for other virtual machines (Linux only) |
|
Time running virtual CPUs for guest operating systems (Linux only) |
|
Time running user-space processes with positive nice value (Linux, macOS, FreeBSD) |
Per-CPU Argument
Per-core variants of CPU usage parameters accept a single argument: the zero-based CPU core index.
Use System.CPU.Count to determine the number of available cores, or System.CPU.Instances list for instance discovery.
System.CPU.Usage(0) System.CPU.Usage.User(3)
On Windows, System.CPU.Usage* metrics are provided by the platform subagent (winnt.nsm). The winperf subagent provides System.CPU.LoadAvg* (processor queue length), PDH.*, and System.ThreadCount.
|
Memory Monitoring
System.Memory.Physical.Available
Available physical memory in bytes.
Data Type |
Unsigned Integer 64 |
Platforms |
Linux, Windows, FreeBSD, AIX |
System.Memory.Physical.AvailablePerc
Available physical memory as percentage.
Data Type |
Float |
Platforms |
Linux, Windows, FreeBSD, AIX |
System.Memory.Physical.Buffers
Buffer cache size in bytes.
Data Type |
Unsigned Integer 64 |
Platforms |
Linux |
System.Memory.Physical.BuffersPerc
Buffer cache as percentage of total physical memory.
Data Type |
Float |
Platforms |
Linux |
System.Memory.Physical.Cached
Page cache size in bytes.
Data Type |
Unsigned Integer 64 |
Platforms |
Linux, Windows, FreeBSD, AIX |
System.Memory.Physical.CachedPerc
Page cache as percentage of total physical memory.
Data Type |
Float |
Platforms |
Linux, Windows, FreeBSD, AIX |
System.Memory.Physical.Client
Physical memory used for client frames.
Data Type |
Unsigned Integer 64 |
Platforms |
AIX |
System.Memory.Physical.ClientPerc
Percentage of physical memory used for client frames.
Data Type |
Float |
Platforms |
AIX |
System.Memory.Physical.Computational
Physical memory used for working segments.
Data Type |
Unsigned Integer 64 |
Platforms |
AIX |
System.Memory.Physical.ComputationalPerc
Percentage of physical memory used for working segments.
Data Type |
Float |
Platforms |
AIX |
System.Memory.Physical.Free
Free physical memory in bytes.
Data Type |
Unsigned Integer 64 |
Platforms |
Linux, Windows, FreeBSD, NetBSD, OpenBSD, Solaris, AIX |
System.Memory.Physical.FreePerc
Free physical memory as percentage.
Data Type |
Float |
Platforms |
Linux, Windows, FreeBSD, Solaris, AIX |
System.Memory.Physical.Total
Total physical memory in bytes.
Data Type |
Unsigned Integer 64 |
Platforms |
Linux, Windows, FreeBSD, NetBSD, OpenBSD, Solaris, AIX |
System.Memory.Physical.Used
Used physical memory in bytes.
Data Type |
Unsigned Integer 64 |
Platforms |
Linux, Windows, FreeBSD, NetBSD, OpenBSD, Solaris, AIX |
System.Memory.Physical.UsedPerc
Used physical memory as percentage.
Data Type |
Float |
Platforms |
Linux, Windows, FreeBSD, Solaris, AIX |
System.Memory.Virtual.Active
Active virtual memory in bytes.
Data Type |
Unsigned Integer 64 |
Platforms |
AIX |
System.Memory.Virtual.Available
Available virtual memory in bytes.
Data Type |
Unsigned Integer 64 |
Platforms |
Linux |
System.Memory.Virtual.AvailablePerc
Available virtual memory as percentage.
Data Type |
Float |
Platforms |
Linux |
System.Memory.Virtual.Free
Free virtual memory in bytes.
Data Type |
Unsigned Integer 64 |
Platforms |
Linux, Windows, FreeBSD, NetBSD, OpenBSD, Solaris, AIX |
System.Memory.Virtual.FreePerc
Free virtual memory as percentage.
Data Type |
Float |
Platforms |
Linux, Windows, FreeBSD, Solaris, AIX |
System.Memory.Virtual.Total
Total virtual memory in bytes.
Data Type |
Unsigned Integer 64 |
Platforms |
Linux, Windows, FreeBSD, NetBSD, OpenBSD, Solaris, AIX |
System.Memory.Virtual.Used
Used virtual memory in bytes.
Data Type |
Unsigned Integer 64 |
Platforms |
Linux, Windows, FreeBSD, NetBSD, OpenBSD, Solaris, AIX |
System.Memory.Virtual.UsedPerc
Used virtual memory as percentage.
Data Type |
Float |
Platforms |
Linux, Windows, FreeBSD, Solaris, AIX |
System.Memory.Swap.Free
Free swap space in bytes.
Data Type |
Unsigned Integer 64 |
Platforms |
Linux, FreeBSD, NetBSD, OpenBSD, Solaris, AIX |
System.Memory.Swap.FreePerc
Free swap space as percentage.
Data Type |
Float |
Platforms |
Linux, FreeBSD, Solaris, AIX |
System.Memory.Swap.Total
Total swap space in bytes.
Data Type |
Unsigned Integer 64 |
Platforms |
Linux, FreeBSD, NetBSD, OpenBSD, Solaris, AIX |
System.Memory.Swap.Used
Used swap space in bytes.
Data Type |
Unsigned Integer 64 |
Platforms |
Linux, FreeBSD, NetBSD, OpenBSD, Solaris, AIX |
System.Memory.Swap.UsedPerc
Used swap space as percentage.
Data Type |
Float |
Platforms |
Linux, FreeBSD, Solaris, AIX |
Available memory (on Linux) includes free memory plus memory that can be reclaimed from buffer and page caches.
This is typically a better indicator of actual memory availability than Free, which only counts completely unused pages.
Disk / Storage Monitoring
File System Metrics
File system metrics use the mount point (Linux/Unix), device name (Linux), or drive letter (Windows) as an argument.
FileSystem.Avail(mountpoint)
Available space for non-root users (bytes).
Data Type |
Unsigned Integer 64 |
Platforms |
Linux, FreeBSD, Solaris, AIX, macOS, NetBSD, OpenBSD |
| Argument | Type | Description |
|---|---|---|
mountpoint |
String |
Mount point, device name, or drive letter |
FileSystem.AvailPerc(mountpoint)
Available space for non-root users (percentage).
Data Type |
Float |
Platforms |
Linux, FreeBSD, Solaris, AIX, macOS, NetBSD, OpenBSD |
| Argument | Type | Description |
|---|---|---|
mountpoint |
String |
Mount point, device name, or drive letter |
FileSystem.Free(mountpoint)
Free space (bytes).
Data Type |
Unsigned Integer 64 |
Platforms |
Linux, Windows, FreeBSD, Solaris, AIX, macOS, NetBSD, OpenBSD |
| Argument | Type | Description |
|---|---|---|
mountpoint |
String |
Mount point, device name, or drive letter |
FileSystem.FreePerc(mountpoint)
Free space (percentage).
Data Type |
Float |
Platforms |
Linux, Windows, FreeBSD, Solaris, AIX, macOS, NetBSD, OpenBSD |
| Argument | Type | Description |
|---|---|---|
mountpoint |
String |
Mount point, device name, or drive letter |
FileSystem.Total(mountpoint)
Total filesystem size (bytes).
Data Type |
Unsigned Integer 64 |
Platforms |
Linux, Windows, FreeBSD, Solaris, AIX, macOS, NetBSD, OpenBSD |
| Argument | Type | Description |
|---|---|---|
mountpoint |
String |
Mount point, device name, or drive letter |
FileSystem.Type(mountpoint)
Filesystem type (e.g., ext4, ntfs).
Data Type |
String |
Platforms |
Linux, Windows, Solaris, AIX |
| Argument | Type | Description |
|---|---|---|
mountpoint |
String |
Mount point, device name, or drive letter |
FileSystem.Used(mountpoint)
Used space (bytes).
Data Type |
Unsigned Integer 64 |
Platforms |
Linux, Windows, FreeBSD, Solaris, AIX, macOS, NetBSD, OpenBSD |
| Argument | Type | Description |
|---|---|---|
mountpoint |
String |
Mount point, device name, or drive letter |
FileSystem.UsedPerc(mountpoint)
Used space (percentage).
Data Type |
Float |
Platforms |
Linux, Windows, Solaris, AIX, macOS, NetBSD, OpenBSD |
| Argument | Type | Description |
|---|---|---|
mountpoint |
String |
Mount point, device name, or drive letter |
FileSystem.AvailInodes(mountpoint)
Available inode count.
Data Type |
Unsigned Integer 64 |
Platforms |
Linux, FreeBSD, Solaris, AIX, OpenBSD |
| Argument | Type | Description |
|---|---|---|
mountpoint |
String |
Mount point or device name |
FileSystem.AvailInodesPerc(mountpoint)
Available inode percentage.
Data Type |
Float |
Platforms |
Linux, FreeBSD, Solaris, AIX, OpenBSD |
| Argument | Type | Description |
|---|---|---|
mountpoint |
String |
Mount point or device name |
FileSystem.FreeInodes(mountpoint)
Free inode count.
Data Type |
Unsigned Integer 64 |
Platforms |
Linux, FreeBSD, Solaris, AIX, OpenBSD |
| Argument | Type | Description |
|---|---|---|
mountpoint |
String |
Mount point or device name |
FileSystem.FreeInodesPerc(mountpoint)
Free inode percentage.
Data Type |
Float |
Platforms |
Linux, FreeBSD, Solaris, AIX, OpenBSD |
| Argument | Type | Description |
|---|---|---|
mountpoint |
String |
Mount point or device name |
FileSystem.TotalInodes(mountpoint)
Total inode count.
Data Type |
Unsigned Integer 64 |
Platforms |
Linux, FreeBSD, Solaris, AIX, OpenBSD |
| Argument | Type | Description |
|---|---|---|
mountpoint |
String |
Mount point or device name |
FileSystem.UsedInodes(mountpoint)
Used inode count.
Data Type |
Unsigned Integer 64 |
Platforms |
Linux, FreeBSD, Solaris, AIX, OpenBSD |
| Argument | Type | Description |
|---|---|---|
mountpoint |
String |
Mount point or device name |
FileSystem.UsedInodesPerc(mountpoint)
Used inode percentage.
Data Type |
Float |
Platforms |
Linux, FreeBSD, Solaris, AIX, OpenBSD |
| Argument | Type | Description |
|---|---|---|
mountpoint |
String |
Mount point or device name |
FileSystem.UsedPerc(/)
FileSystem.Free(C:)
FileSystem.UsedInodesPerc(/home)
The FileSystem.Volumes table provides a complete list of all mounted file systems with their properties.
This table supports instance discovery for automatic DCI creation.
Disk I/O Metrics
Disk I/O metrics are available as system-wide aggregates and per-device variants.
Per-device variants accept the device name as an argument (e.g., sda on Linux).
System.IO.BytesReadRate
Bytes read per second. Available as system-wide aggregate or per-device.
Data Type |
Unsigned Integer 64 |
Platforms |
Linux, Windows, macOS, FreeBSD, Solaris, AIX |
| Name | Type | Description |
|---|---|---|
Device |
String |
Device name (e.g., |
System.IO.BytesReadRate.Min
Minimum number of bytes read for last minute. Available as system-wide aggregate or per-device.
Data Type |
Unsigned Integer 64 |
Platforms |
Solaris |
| Name | Type | Description |
|---|---|---|
Device |
String |
Device name |
System.IO.BytesReadRate.Max
Maximum number of bytes read for last minute. Available as system-wide aggregate or per-device.
Data Type |
Unsigned Integer 64 |
Platforms |
Solaris |
| Name | Type | Description |
|---|---|---|
Device |
String |
Device name |
System.IO.BytesWriteRate
Bytes written per second. Available as system-wide aggregate or per-device.
Data Type |
Unsigned Integer 64 |
Platforms |
Linux, Windows, macOS, FreeBSD, Solaris, AIX |
| Name | Type | Description |
|---|---|---|
Device |
String |
Device name (e.g., |
System.IO.BytesWriteRate.Min
Minimum number of bytes written for last minute. Available as system-wide aggregate or per-device.
Data Type |
Unsigned Integer 64 |
Platforms |
Solaris |
| Name | Type | Description |
|---|---|---|
Device |
String |
Device name |
System.IO.BytesWriteRate.Max
Maximum number of bytes written for last minute. Available as system-wide aggregate or per-device.
Data Type |
Unsigned Integer 64 |
Platforms |
Solaris |
| Name | Type | Description |
|---|---|---|
Device |
String |
Device name |
System.IO.ReadRate
Read operations per second. Available as system-wide aggregate or per-device.
Data Type |
Float |
Platforms |
Linux, Windows, macOS, FreeBSD, Solaris, AIX |
| Name | Type | Description |
|---|---|---|
Device |
String |
Device name (e.g., |
System.IO.ReadRate.Min
Minimum number of read operations for last minute. Available as system-wide aggregate or per-device.
Data Type |
Unsigned Integer |
Platforms |
Solaris |
| Name | Type | Description |
|---|---|---|
Device |
String |
Device name |
System.IO.ReadRate.Max
Maximum number of read operations for last minute. Available as system-wide aggregate or per-device.
Data Type |
Unsigned Integer |
Platforms |
Solaris |
| Name | Type | Description |
|---|---|---|
Device |
String |
Device name |
System.IO.WriteRate
Write operations per second. Available as system-wide aggregate or per-device.
Data Type |
Float |
Platforms |
Linux, Windows, macOS, FreeBSD, Solaris, AIX |
| Name | Type | Description |
|---|---|---|
Device |
String |
Device name (e.g., |
System.IO.WriteRate.Min
Minimum number of write operations for last minute. Available as system-wide aggregate or per-device.
Data Type |
Unsigned Integer |
Platforms |
Solaris |
| Name | Type | Description |
|---|---|---|
Device |
String |
Device name |
System.IO.WriteRate.Max
Maximum number of write operations for last minute. Available as system-wide aggregate or per-device.
Data Type |
Unsigned Integer |
Platforms |
Solaris |
| Name | Type | Description |
|---|---|---|
Device |
String |
Device name |
System.IO.TransferRate
Total transfer rate (reads + writes) per second. Available as system-wide aggregate or per-device.
Data Type |
Float |
Platforms |
AIX |
| Name | Type | Description |
|---|---|---|
Device |
String |
Device name (e.g., |
System.IO.DiskQueue
Average disk queue length. Available as system-wide aggregate or per-device.
Data Type |
Float |
Platforms |
Linux, Windows, FreeBSD, Solaris, AIX |
| Name | Type | Description |
|---|---|---|
Device |
String |
Device name (e.g., |
System.IO.DiskQueue.Min
Minimum disk queue length for last minute. Available as system-wide aggregate or per-device.
Data Type |
Unsigned Integer |
Platforms |
Solaris |
| Name | Type | Description |
|---|---|---|
Device |
String |
Device name |
System.IO.DiskQueue.Max
Maximum disk queue length for last minute. Available as system-wide aggregate or per-device.
Data Type |
Unsigned Integer |
Platforms |
Solaris |
| Name | Type | Description |
|---|---|---|
Device |
String |
Device name |
System.IO.DiskTime
Disk active time percentage. Available as system-wide aggregate or per-device.
Data Type |
Float |
Platforms |
Linux, Windows, macOS, FreeBSD, Solaris, AIX |
| Name | Type | Description |
|---|---|---|
Device |
String |
Device name (e.g., |
System.IO.DiskReadTime
Disk read time percentage. Available as system-wide aggregate or per-device.
Data Type |
Float |
Platforms |
Windows |
| Name | Type | Description |
|---|---|---|
Device |
String |
Device name |
System.IO.DiskWriteTime
Disk write time percentage. Available as system-wide aggregate or per-device.
Data Type |
Float |
Platforms |
Windows |
| Name | Type | Description |
|---|---|---|
Device |
String |
Device name |
System.IO.WaitTime
Average I/O wait time in milliseconds. Available as system-wide aggregate or per-device.
Data Type |
Unsigned Integer (Integer on AIX) |
Platforms |
Linux, AIX |
| Name | Type | Description |
|---|---|---|
Device |
String |
Device name (e.g., |
Network Interface Monitoring
The Net.InterfaceList list returns one line per IP address, with fields: interface index, IP address with mask, type (MTU), MAC address, and interface name.
Interfaces without an IP address are listed with 0.0.0.0/0.
The argument for all Net.Interface.* metrics is the interface name or interface index.
Interface indices can be obtained from the Net.InterfaceList list.
| Traffic counters are raw counter values. Use Counter32 or Counter64 data type in DCI configuration to get per-second rates automatically. |
On NetBSD the 32-bit interface counter metrics are registered with data type Unsigned Integer 64; on OpenBSD they are registered as Unsigned Integer (the 64-bit variants as Unsigned Integer 64).
Net.Interface.BytesIn(ifName)
Inbound bytes. Available in 32-bit and 64-bit counter variants.
Data Type |
Counter 32 / Counter 64 |
Platforms |
Linux, Windows, Solaris, AIX, FreeBSD, NetBSD, OpenBSD, macOS (64-bit: Linux, Windows, Solaris, FreeBSD, OpenBSD, macOS) |
| Argument | Type | Description |
|---|---|---|
ifName |
String |
Interface name or index |
| Metric | Description |
|---|---|
|
32-bit counter |
|
64-bit counter |
Net.Interface.BytesOut(ifName)
Outbound bytes. Available in 32-bit and 64-bit counter variants.
Data Type |
Counter 32 / Counter 64 |
Platforms |
Linux, Windows, Solaris, AIX, FreeBSD, NetBSD, OpenBSD, macOS (64-bit: Linux, Windows, Solaris, FreeBSD, OpenBSD, macOS) |
| Argument | Type | Description |
|---|---|---|
ifName |
String |
Interface name or index |
| Metric | Description |
|---|---|
|
32-bit counter |
|
64-bit counter |
Net.Interface.InDrops(ifName)
Inbound dropped packets. Available in 32-bit and 64-bit counter variants.
Data Type |
Counter 32 / Counter 64 |
Platforms |
Linux, Windows, Solaris, AIX, FreeBSD, NetBSD, OpenBSD, macOS (64-bit: Linux, Windows, FreeBSD, OpenBSD, macOS) |
| Argument | Type | Description |
|---|---|---|
ifName |
String |
Interface name or index |
| Metric | Description |
|---|---|
|
32-bit counter |
|
64-bit counter |
Net.Interface.OutDrops(ifName)
Outbound dropped packets. Available in 32-bit and 64-bit counter variants.
Data Type |
Counter 32 / Counter 64 |
Platforms |
Linux, Windows, Solaris, AIX, FreeBSD (64-bit: Linux, Windows, FreeBSD) |
| Argument | Type | Description |
|---|---|---|
ifName |
String |
Interface name or index |
| Metric | Description |
|---|---|
|
32-bit counter |
|
64-bit counter |
Net.Interface.InErrors(ifName)
Inbound errors. Available in 32-bit and 64-bit counter variants.
Data Type |
Counter 32 / Counter 64 |
Platforms |
Linux, Windows, Solaris, AIX, FreeBSD, NetBSD, OpenBSD, macOS (64-bit: Linux, FreeBSD, OpenBSD, macOS) |
| Argument | Type | Description |
|---|---|---|
ifName |
String |
Interface name or index |
| Metric | Description |
|---|---|
|
32-bit counter |
|
64-bit counter |
Net.Interface.OutErrors(ifName)
Outbound errors. Available in 32-bit and 64-bit counter variants.
Data Type |
Counter 32 / Counter 64 |
Platforms |
Linux, Windows, Solaris, AIX, FreeBSD, NetBSD, OpenBSD, macOS (64-bit: Linux, FreeBSD, OpenBSD, macOS) |
| Argument | Type | Description |
|---|---|---|
ifName |
String |
Interface name or index |
| Metric | Description |
|---|---|
|
32-bit counter |
|
64-bit counter |
Net.Interface.PacketsIn(ifName)
Inbound packets. Available in 32-bit and 64-bit counter variants.
Data Type |
Counter 32 / Counter 64 |
Platforms |
Linux, Windows, Solaris, AIX, FreeBSD, NetBSD, OpenBSD, macOS (64-bit: Linux, Windows, Solaris, FreeBSD, OpenBSD, macOS) |
| Argument | Type | Description |
|---|---|---|
ifName |
String |
Interface name or index |
| Metric | Description |
|---|---|
|
32-bit counter |
|
64-bit counter |
Net.Interface.PacketsOut(ifName)
Outbound packets. Available in 32-bit and 64-bit counter variants.
Data Type |
Counter 32 / Counter 64 |
Platforms |
Linux, Windows, Solaris, AIX, FreeBSD, NetBSD, OpenBSD, macOS (64-bit: Linux, Windows, Solaris, FreeBSD, OpenBSD, macOS) |
| Argument | Type | Description |
|---|---|---|
ifName |
String |
Interface name or index |
| Metric | Description |
|---|---|
|
32-bit counter |
|
64-bit counter |
Net.Interface.AdminStatus(ifName)
Administrative status of the interface.
Data Type |
Integer |
Platforms |
Linux, Windows, Solaris, AIX, FreeBSD, NetBSD, OpenBSD |
| Argument | Type | Description |
|---|---|---|
ifName |
String |
Interface name or index |
| Value | Description |
|---|---|
1 |
Up |
2 |
Down |
3 |
Testing |
Net.Interface.Description(ifName)
Interface description.
Data Type |
String |
Platforms |
Linux, Windows, Solaris, AIX |
| Argument | Type | Description |
|---|---|---|
ifName |
String |
Interface name or index |
Net.Interface.Link(ifName)
Link status of the interface.
Deprecated on all platforms except Linux — use Net.Interface.OperStatus instead.
Data Type |
Integer |
Platforms |
Linux, Windows, Solaris, AIX, FreeBSD, NetBSD, OpenBSD, macOS |
| Argument | Type | Description |
|---|---|---|
ifName |
String |
Interface name or index |
| Value | Description |
|---|---|
0 |
Down |
1 |
Up |
Net.Interface.MaxSpeed(ifName)
Maximum interface speed in bits per second.
Data Type |
Unsigned Integer 64 |
Platforms |
Linux |
| Argument | Type | Description |
|---|---|---|
ifName |
String |
Interface name or index |
Net.Interface.MTU(ifName)
Maximum transmission unit.
Data Type |
Unsigned Integer (Integer on AIX) |
Platforms |
Windows, AIX, OpenBSD |
| Argument | Type | Description |
|---|---|---|
ifName |
String |
Interface name or index |
Net.Interface.OperStatus(ifName)
Operational status of the interface.
Data Type |
Integer |
Platforms |
Windows, Solaris, AIX, FreeBSD, NetBSD, OpenBSD, macOS |
| Argument | Type | Description |
|---|---|---|
ifName |
String |
Interface name or index |
| Value | Description |
|---|---|
0 |
Down |
1 |
Up |
Net.Interface.Speed(ifName)
Interface speed in bits per second.
Data Type |
Unsigned Integer 64 (Unsigned Integer on Solaris, Integer on AIX) |
Platforms |
Linux, Windows, FreeBSD, OpenBSD, Solaris, AIX |
| Argument | Type | Description |
|---|---|---|
ifName |
String |
Interface name or index |
Net.Interface.64BitCounters
Indicates whether 64-bit interface counters are supported.
Data Type |
Integer |
Platforms |
Windows, FreeBSD |
Net.IP.Forwarding
Indicates whether IPv4 forwarding is enabled.
Data Type |
Integer |
Platforms |
Linux, Windows, FreeBSD, NetBSD, OpenBSD, macOS |
| Value | Description |
|---|---|
0 |
Disabled |
1 |
Enabled |
Net.IP6.Forwarding
Indicates whether IPv6 forwarding is enabled.
Data Type |
Integer |
Platforms |
Linux, FreeBSD, NetBSD, OpenBSD, macOS |
| Value | Description |
|---|---|
0 |
Disabled |
1 |
Enabled |
Net.IP.NextHop(ipAddress)
Next hop gateway for the given destination address. This is a server-side metric with Internal origin, available on nodes with an agent or SNMP; it is not collected through the agent.
Data Type |
String |
Origin |
Internal (server-side) |
| Argument | Type | Description |
|---|---|---|
ipAddress |
String |
Destination IP address |
Net.IP.Stats.TCPConnections
Total number of TCP connections across all states and IP versions. Also available as a parameterized variant for filtered queries (added in 6.1).
Data Type |
Integer |
Platforms |
Linux, Windows, Solaris, AIX, FreeBSD, NetBSD, OpenBSD, macOS |
The parameterized variant Net.IP.Stats.TCPConnections(*) accepts named parameters passed as key=value pairs separated by semicolons.
| Parameter | Description |
|---|---|
|
TCP connection state to count. If omitted, connections in all states are counted. Supported values: |
|
IP protocol version. Set to |
Net.IP.Stats.TCPConnections(state=ESTABLISHED) Net.IP.Stats.TCPConnections(state=LISTEN;version=4) Net.IP.Stats.TCPConnections(version=6)
Net.RemoteShareStatus(path)
Check accessibility of a remote shared resource (Windows only).
Net.RemoteShareStatus returns an integer code, Net.RemoteShareStatusText returns the same status as text.
Data Type |
Integer (Net.RemoteShareStatus) / String (Net.RemoteShareStatusText) |
Platforms |
Windows |
| # | Type | Description |
|---|---|---|
1 |
String |
UNC path to the share (e.g., |
2 |
String |
Domain name (optional) |
3 |
String |
Login name (optional) |
4 |
String |
Password (optional) |
Process Monitoring
The System.ProcessList list returns all running processes with PID and name information.
Process.Count(processName)
Number of running processes matching the given name.
Data Type |
Integer (Unsigned Integer on NetBSD and OpenBSD) |
Platforms |
Linux, Windows, macOS, Solaris, AIX, FreeBSD, NetBSD, OpenBSD |
| Argument | Type | Description |
|---|---|---|
processName |
String |
Process name to match |
Process.Count(httpd)
Process.CountEx(processName)
Extended process count with optional filtering by command line, owner, and window title.
Data Type |
Integer (Unsigned Integer on NetBSD) |
Platforms |
Linux, Windows, macOS, Solaris, AIX, FreeBSD, NetBSD |
| Argument | Type | Description |
|---|---|---|
processName |
String |
Process name |
cmdLine |
String |
Command line regular expression (optional). Matches against the full command line. If not set, matches any command line. |
userName |
String |
Process owner username regular expression (optional). If not set, matches any user. |
windowTitle |
String |
Window title regular expression (optional, Windows only). If not set, matches any window title. |
Process.CountEx(httpd) Process.CountEx(java,.*-server.*) Process.CountEx(python,.*myapp.*,appuser)
Process.CPUTime(processName)
Total CPU time consumed by matching processes (milliseconds).
Data Type |
Counter 64 (Integer 64 on NetBSD) |
Platforms |
Linux, Windows, macOS, Solaris, AIX, FreeBSD, NetBSD |
See common process metric arguments for argument details.
Process.GDIObjects(processName)
Number of GDI objects used by matching processes.
Data Type |
Integer 64 |
Platforms |
Windows |
See common process metric arguments for argument details.
Process.Handles(processName)
Number of open handles or file descriptors for matching processes.
Data Type |
Integer |
Platforms |
Linux, Windows, Solaris, AIX |
See common process metric arguments for argument details.
Process.IO.OtherB(processName)
Other I/O bytes transferred by matching processes.
Data Type |
Counter 64 |
Platforms |
Windows |
See common process metric arguments for argument details.
Process.IO.OtherOp(processName)
Other I/O operations performed by matching processes.
Data Type |
Counter 64 |
Platforms |
Windows |
See common process metric arguments for argument details.
Process.IO.ReadB(processName)
Bytes read by matching processes.
Data Type |
Counter 64 |
Platforms |
Windows |
See common process metric arguments for argument details.
Process.IO.ReadOp(processName)
Read operations performed by matching processes.
Data Type |
Counter 64 |
Platforms |
Windows, AIX |
See common process metric arguments for argument details.
Process.IO.WriteB(processName)
Bytes written by matching processes.
Data Type |
Counter 64 |
Platforms |
Windows |
See common process metric arguments for argument details.
Process.IO.WriteOp(processName)
Write operations performed by matching processes.
Data Type |
Counter 64 |
Platforms |
Windows, AIX |
See common process metric arguments for argument details.
Process.KernelTime(processName)
Kernel mode CPU time consumed by matching processes (milliseconds).
Data Type |
Counter 64 (Integer 64 on NetBSD) |
Platforms |
Linux, Windows, Solaris, AIX, NetBSD |
See common process metric arguments for argument details.
Process.MemoryUsage(processName)
Memory usage as a percentage of total system memory for matching processes.
Data Type |
Float |
Platforms |
Linux, Windows, macOS, Solaris, AIX, FreeBSD |
See common process metric arguments for argument details.
Process.PageFaults(processName)
Number of page faults for matching processes.
Data Type |
Counter 64 (Integer 64 on NetBSD) |
Platforms |
Linux, Windows, Solaris, AIX, NetBSD |
See common process metric arguments for argument details.
Process.RSS(processName)
Resident set size in bytes for matching processes. Alias for Process.WkSet(*).
Data Type |
Integer 64 |
Platforms |
Linux, Windows, macOS, Solaris, AIX, FreeBSD |
See common process metric arguments for argument details.
Process.Syscalls(processName)
Number of system calls made by matching processes.
Data Type |
Counter 64 |
Platforms |
Solaris |
See common process metric arguments for argument details.
Process.Threads(processName)
Number of threads for matching processes.
Data Type |
Integer (Integer 64 on NetBSD) |
Platforms |
Linux, Windows, macOS, Solaris, AIX, FreeBSD, NetBSD |
See common process metric arguments for argument details.
Process.UserObjects(processName)
Number of USER objects used by matching processes.
Data Type |
Integer 64 |
Platforms |
Windows |
See common process metric arguments for argument details.
Process.UserTime(processName)
User mode CPU time consumed by matching processes (milliseconds).
Data Type |
Counter 64 (Integer 64 on NetBSD) |
Platforms |
Linux, Windows, Solaris, AIX, NetBSD |
See common process metric arguments for argument details.
Process.VMRegions(processName)
Number of virtual memory regions for matching processes.
Data Type |
Integer |
Platforms |
Linux |
See common process metric arguments for argument details.
Process.VMSize(processName)
Virtual memory size in bytes for matching processes.
Data Type |
Integer 64 |
Platforms |
Linux, Windows, macOS, Solaris, AIX, FreeBSD, NetBSD |
See common process metric arguments for argument details.
Process.WkSet(processName)
Working set size in bytes for matching processes.
Data Type |
Integer 64 |
Platforms |
Linux, Windows, macOS, Solaris, AIX, FreeBSD, NetBSD |
See common process metric arguments for argument details.
Process.ZombieCount(processName)
Number of zombie processes. Without arguments, counts all zombie processes; with the optional process name argument, counts only zombie processes matching the given name.
Data Type |
Integer |
Platforms |
Solaris |
| Argument | Type | Description |
|---|---|---|
processName |
String |
Process name to match (optional) |
Common Process Metric Arguments
Most process metrics (except Process.Count and Process.CountEx) accept the following arguments:
| Argument | Type | Description |
|---|---|---|
processName |
String |
Process name |
function |
String |
Aggregation function when multiple processes match. Default: |
cmdLine |
String |
Command line regular expression (optional). If not set, matches any command line. |
userName |
String |
Process owner username regular expression (optional). If not set, matches any user. |
windowTitle |
String |
Window title regular expression (optional, Windows only). If not set, matches any window title. |
Process.VMSize(java) Process.CPUTime(httpd,max) Process.Handles(python,sum,.*myapp.*) Process.MemoryUsage(node,avg,,appuser)
System Information
| Parameter | Description |
|---|---|
|
System hostname |
|
Fully qualified domain name |
|
System identification string (kernel version, architecture) |
|
Operating system platform identifier |
|
System uptime in seconds |
|
Current system time (epoch) |
|
Machine unique identifier (when available) |
WMI Subagent (Windows)
The WMI subagent (wmi.nsm) provides access to Windows Management Instrumentation data.
It exposes ACPI thermal zone temperatures, hardware network adapter properties, security product status, and a generic interface for arbitrary WMI queries.
ACPI Thermal Zone Metrics
These metrics read temperature data from ACPI thermal zones using the MSAcpi_ThermalZoneTemperature WMI class in the root\WMI namespace.
Temperature values are returned in degrees Celsius.
| Parameter | Description |
|---|---|
|
Current temperature in the first ACPI thermal zone found (Celsius) |
|
Current temperature in the specified ACPI thermal zone (Celsius).
Argument is the thermal zone instance name, as returned by the |
| List | Description |
|---|---|
|
Returns instance names of all available ACPI thermal zones |
| Not all systems expose ACPI thermal zone data through WMI. This depends on the hardware and BIOS/UEFI implementation. |
Hardware Network Adapter Metrics
These metrics expose physical network adapter properties from the Win32_NetworkAdapter WMI class.
Adapters whose hardware is not present (WMI NetConnectionStatus = 4), TAP-Windows adapters, and Fortinet PPP adapters are filtered out automatically.
The argument for all metrics is the adapter index, which can be obtained from the Hardware.NetworkAdapters list or table.
| Parameter | Description |
|---|---|
|
Adapter availability status code |
|
Adapter description |
|
Windows network stack interface index |
|
MAC address |
|
Adapter manufacturer |
|
Adapter product name |
|
Adapter speed in bits per second |
|
Adapter type (e.g., "Ethernet 802.3") |
| Name | Description |
|---|---|
|
Returns adapter index values for all physical network adapters |
|
Returns a table with columns: INDEX, PRODUCT, MANUFACTURER, DESCRIPTION, TYPE, MAC_ADDRESS, IF_INDEX, SPEED, AVAILABILITY |
Security Product Metrics
These metrics report the status of security products registered with Windows Security Center (the root\SecurityCenter2 WMI namespace).
| Parameter | Description |
|---|---|
|
Returns 1 if the antivirus product is active/running, 0 otherwise |
|
Display name of the registered antivirus product |
|
Returns 1 if the antivirus definitions are up to date, 0 otherwise |
| Parameter | Description |
|---|---|
|
Returns 1 if the anti-spyware product is active/running, 0 otherwise |
|
Display name of the registered anti-spyware product |
|
Returns 1 if the anti-spyware definitions are up to date, 0 otherwise |
| Parameter | Description |
|---|---|
|
Returns 1 if a firewall is active, 0 otherwise |
|
Display name of the active firewall product |
|
Returns 1 if the firewall is up to date, 0 otherwise |
If no third-party firewall is registered with Windows Security Center, the subagent falls back to reporting the built-in Windows Firewall status for System.FirewallProduct.Active and System.FirewallProduct.DisplayName only.
System.FirewallProduct.UpToDate has no such fallback and is not supported for the built-in Windows Firewall.
|
Generic WMI Queries
The WMI.Query(*) parameter provides a flexible interface for executing arbitrary WMI queries.
It is available as a parameter (single value), list (multiple values), and table (full result set).
Parameter Query
Returns a single property value from a WMI query result.
WMI.Query(namespace, query, property)
-
namespace — WMI namespace (e.g.,
root\cimv2) -
query — WQL query string
-
property — property name to return from the result, or
%%count%%to return the number of matching objects. For array properties, an index can be appended (e.g.,Property[0]returns the first element); without an index, an array property is returned as[v1,v2,…].
Example — get the caption of process with PID 252:
WMI.Query(root\cimv2, SELECT * FROM Win32_Process WHERE ProcessId=252, Caption)
List Query
Returns all values of a single property from matching WMI objects.
WMI.Query(namespace, query, property)
Example — get names of all running processes:
WMI.Query(root\cimv2, SELECT * FROM Win32_Process, Caption)
Table Query
Returns a full table with all properties from matching WMI objects as columns.
WMI.Query(namespace, query)
Example — get complete process information:
WMI.Query(root\cimv2, SELECT * FROM Win32_Process)
WMI Namespace and Class Discovery
| List | Description |
|---|---|
|
Lists the immediate child namespaces of the |
|
Lists all WMI classes in the specified namespace (e.g., |
Common WMI Classes
Some commonly used WMI classes for monitoring:
| WMI Class | Data |
|---|---|
|
Computer system properties |
|
OS version, install date, memory |
|
CPU information |
|
Physical disk drives |
|
Disk partitions |
|
Logical disks (drive letters) |
|
Physical memory modules |
|
Network adapters |
|
Network adapter IP configuration |
| WMI Class | Data |
|---|---|
|
CPU utilization counters |
|
Memory utilization counters |
|
Network traffic counters |
Recommended Templates
For standard OS monitoring, ready-to-import template files (linux.xml, windows.xml, generic_unix.xml, and others) are provided in the contrib/templates/ directory of the NetXMS source repository.
These templates are not created at database initialization and must be imported manually.
They create commonly needed DCIs:
-
CPU usage with thresholds
-
Memory usage with thresholds
-
Disk usage per volume with instance discovery
-
Network interface traffic with instance discovery
-
System uptime
See DCI Templates for details on applying templates to nodes.