Operating System Monitoring

NetXMS provides comprehensive operating system monitoring through its native agent. The agent includes platform-specific subagents that expose hundreds of metrics for CPU, memory, disk, network, and process monitoring.

Platform Subagents

Each supported operating system has a dedicated platform subagent. All platform subagents are separate loadable modules; when subagent autoload is enabled (the default), the agent automatically loads the module matching the operating system it runs on (the name is derived from uname; winnt.nsm on Windows), so no explicit SubAgent entry is normally required.

Subagent Platform

linux.nsm

Linux

winnt.nsm

Windows

freebsd.nsm

FreeBSD

netbsd.nsm

NetBSD

openbsd.nsm

OpenBSD

sunos.nsm

Solaris

aix.nsm

AIX

darwin.nsm

macOS

See Subagents for details.

CPU Monitoring

CPU usage metrics are available in three averaging windows: 1-minute (default), 5-minute (suffix 5), and 15-minute (suffix 15). Per-core variants accept a core index as argument. Windows also provides CurrentUsage variants for instantaneous readings.

System.CPU.CacheSize(*)

CPU cache size in kilobytes.

Data Type

Integer

Platforms

Linux

Table 1. Arguments
Argument Type Description

index

Integer

CPU index (zero-based)

System.CPU.CoreId(*)

CPU core ID.

Data Type

Integer

Platforms

Linux

Table 2. Arguments
Argument Type Description

index

Integer

CPU index (zero-based)

System.CPU.Count

Number of CPU cores available to the system.

Data Type

Unsigned Integer (Integer on macOS and FreeBSD)

Platforms

Linux, Windows, FreeBSD, Solaris, AIX, macOS, NetBSD, OpenBSD

System.CPU.CountOnline

Number of currently online CPUs.

Data Type

Unsigned Integer

Platforms

Linux

System.CPU.CountOffline

Number of currently offline CPUs.

Data Type

Unsigned Integer

Platforms

Linux

System.CPU.Frequency(*)

CPU frequency in megahertz. On FreeBSD only the argument-less form System.CPU.Frequency is available.

Data Type

Float (Integer on FreeBSD)

Platforms

Linux, FreeBSD

Table 3. Arguments
Argument Type Description

index

Integer

CPU index (zero-based)

System.CPU.Model(*)

CPU model identification string. On FreeBSD only the argument-less form System.CPU.Model is available.

Data Type

String

Platforms

Linux, FreeBSD

Table 4. Arguments
Argument Type Description

index

Integer

CPU index (zero-based)

System.CPU.PhysicalId(*)

Physical CPU ID.

Data Type

Integer

Platforms

Linux

Table 5. Arguments
Argument Type Description

index

Integer

CPU index (zero-based)

System.CPU.VendorId

CPU vendor identification string.

Data Type

String

Platforms

Linux, Windows, FreeBSD

System.CPU.LoadAvg

1-minute load average.

Data Type

Float

Platforms

Linux, FreeBSD, Solaris, AIX, macOS, NetBSD, OpenBSD, Windows (via winperf, based on processor queue length)

System.CPU.LoadAvg5

5-minute load average.

Data Type

Float

Platforms

Linux, FreeBSD, Solaris, AIX, macOS, NetBSD, OpenBSD, Windows (via winperf, based on processor queue length)

System.CPU.LoadAvg15

15-minute load average.

Data Type

Float

Platforms

Linux, FreeBSD, Solaris, AIX, macOS, NetBSD, OpenBSD, Windows (via winperf, based on processor queue length)

System.CPU.ContextSwitches

Total context switch count since system boot.

Data Type

Unsigned Integer

Platforms

Linux, Windows, FreeBSD

System.CPU.Interrupts

Total interrupt count. Per-core variant accepts a core index argument (Windows only).

Data Type

Unsigned Integer

Platforms

Linux, Windows, FreeBSD

Per-Core Variant (Windows)

System.CPU.Interrupts(*) — returns interrupt count for a specific core.

Table 6. Arguments (per-core variant)
Argument Type Description

index

Integer

CPU core index (zero-based)

System.CPU.Usage

CPU usage percentage, available in 1-minute (default), 5-minute (suffix 5), and 15-minute (suffix 15) averaging windows. All variants report a Float value as a percentage.

Per-core variants accept a zero-based core index as argument (e.g., System.CPU.Usage(0)).

Data Type

Float

Platforms

Linux, Windows, macOS, FreeBSD, Solaris, AIX (per sub-type; not available on NetBSD and OpenBSD)

Table 7. Averaging Window Variants
Prefix Description

System.CPU.Usage

1-minute average

System.CPU.Usage5

5-minute average

System.CPU.Usage15

15-minute average

Table 8. Sub-Type Suffixes
Suffix Platforms Description

(none, overall)

Linux, Windows, macOS, FreeBSD, Solaris, AIX

Combined CPU utilization across all modes

.User

Linux, Windows, macOS, FreeBSD, Solaris, AIX

User mode time

.System

Linux, Windows, macOS, FreeBSD, Solaris, AIX

Kernel mode time

.Idle

Linux, Windows, macOS, FreeBSD, Solaris, AIX

Idle time

.IoWait

Linux, Solaris, AIX

I/O wait time

.Irq

Linux, Windows

Hardware interrupt time

.SoftIrq

Linux

Software interrupt time

.Steal

Linux

Hypervisor steal time

.Guest

Linux

Guest VM time

.Nice

Linux, macOS, FreeBSD

Nice process time

Each combination of averaging window and sub-type is a valid parameter. For example: System.CPU.Usage.User, System.CPU.Usage5.IoWait, System.CPU.Usage15.Steal.

All sub-types also have per-core variants by appending (core_index). For example: System.CPU.Usage.User(3), System.CPU.Usage5(0).

System.CPU.CurrentUsage

Instantaneous CPU usage (Windows only). Unlike the averaged variants, these report real-time CPU utilization.

Data Type

Float

Platforms

Windows

Table 9. Sub-Type Suffixes
Suffix Description

(none, overall)

Current CPU utilization

.Idle

Current idle time

.Irq

Current hardware interrupt time

.System

Current kernel mode time

.User

Current user mode time

All sub-types have per-core variants by appending (core_index).

System.CPU.PhysicalAverage

Average physical CPU utilization (AIX only), available in 1-minute (default), 5-minute (suffix 5), and 15-minute (suffix 15) averaging windows. Sub-type suffixes .User, .System, .Idle, and .IoWait report the corresponding CPU time share.

Data Type

Float

Platforms

AIX

Each combination of averaging window and sub-type is a valid metric. For example: System.CPU.PhysicalAverage, System.CPU.PhysicalAverage5.User, System.CPU.PhysicalAverage15.IoWait.

CPU Usage Types

Each CPU usage parameter reports a specific type of CPU time:

Type Description

Usage (overall)

Combined CPU utilization across all modes

User

Time executing user-space processes

System

Time executing kernel-mode code

Idle

Time with no work to do

IoWait

Time waiting for I/O operations to complete (Linux, Solaris, AIX)

Irq

Time handling hardware interrupts (Linux, Windows)

SoftIrq

Time handling software interrupts (Linux only)

Steal

Time stolen by hypervisor for other virtual machines (Linux only)

Guest

Time running virtual CPUs for guest operating systems (Linux only)

Nice

Time running user-space processes with positive nice value (Linux, macOS, FreeBSD)

Per-CPU Argument

Per-core variants of CPU usage parameters accept a single argument: the zero-based CPU core index. Use System.CPU.Count to determine the number of available cores, or System.CPU.Instances list for instance discovery.

Example
System.CPU.Usage(0)
System.CPU.Usage.User(3)
On Windows, System.CPU.Usage* metrics are provided by the platform subagent (winnt.nsm). The winperf subagent provides System.CPU.LoadAvg* (processor queue length), PDH.*, and System.ThreadCount.

Memory Monitoring

System.Memory.Physical.Available

Available physical memory in bytes.

Data Type

Unsigned Integer 64

Platforms

Linux, Windows, FreeBSD, AIX

System.Memory.Physical.AvailablePerc

Available physical memory as percentage.

Data Type

Float

Platforms

Linux, Windows, FreeBSD, AIX

System.Memory.Physical.Buffers

Buffer cache size in bytes.

Data Type

Unsigned Integer 64

Platforms

Linux

System.Memory.Physical.BuffersPerc

Buffer cache as percentage of total physical memory.

Data Type

Float

Platforms

Linux

System.Memory.Physical.Cached

Page cache size in bytes.

Data Type

Unsigned Integer 64

Platforms

Linux, Windows, FreeBSD, AIX

System.Memory.Physical.CachedPerc

Page cache as percentage of total physical memory.

Data Type

Float

Platforms

Linux, Windows, FreeBSD, AIX

System.Memory.Physical.Client

Physical memory used for client frames.

Data Type

Unsigned Integer 64

Platforms

AIX

System.Memory.Physical.ClientPerc

Percentage of physical memory used for client frames.

Data Type

Float

Platforms

AIX

System.Memory.Physical.Computational

Physical memory used for working segments.

Data Type

Unsigned Integer 64

Platforms

AIX

System.Memory.Physical.ComputationalPerc

Percentage of physical memory used for working segments.

Data Type

Float

Platforms

AIX

System.Memory.Physical.Free

Free physical memory in bytes.

Data Type

Unsigned Integer 64

Platforms

Linux, Windows, FreeBSD, NetBSD, OpenBSD, Solaris, AIX

System.Memory.Physical.FreePerc

Free physical memory as percentage.

Data Type

Float

Platforms

Linux, Windows, FreeBSD, Solaris, AIX

System.Memory.Physical.Total

Total physical memory in bytes.

Data Type

Unsigned Integer 64

Platforms

Linux, Windows, FreeBSD, NetBSD, OpenBSD, Solaris, AIX

System.Memory.Physical.Used

Used physical memory in bytes.

Data Type

Unsigned Integer 64

Platforms

Linux, Windows, FreeBSD, NetBSD, OpenBSD, Solaris, AIX

System.Memory.Physical.UsedPerc

Used physical memory as percentage.

Data Type

Float

Platforms

Linux, Windows, FreeBSD, Solaris, AIX

System.Memory.Virtual.Active

Active virtual memory in bytes.

Data Type

Unsigned Integer 64

Platforms

AIX

System.Memory.Virtual.ActivePerc

Active virtual memory as percentage.

Data Type

Float

Platforms

AIX

System.Memory.Virtual.Available

Available virtual memory in bytes.

Data Type

Unsigned Integer 64

Platforms

Linux

System.Memory.Virtual.AvailablePerc

Available virtual memory as percentage.

Data Type

Float

Platforms

Linux

System.Memory.Virtual.Free

Free virtual memory in bytes.

Data Type

Unsigned Integer 64

Platforms

Linux, Windows, FreeBSD, NetBSD, OpenBSD, Solaris, AIX

System.Memory.Virtual.FreePerc

Free virtual memory as percentage.

Data Type

Float

Platforms

Linux, Windows, FreeBSD, Solaris, AIX

System.Memory.Virtual.Total

Total virtual memory in bytes.

Data Type

Unsigned Integer 64

Platforms

Linux, Windows, FreeBSD, NetBSD, OpenBSD, Solaris, AIX

System.Memory.Virtual.Used

Used virtual memory in bytes.

Data Type

Unsigned Integer 64

Platforms

Linux, Windows, FreeBSD, NetBSD, OpenBSD, Solaris, AIX

System.Memory.Virtual.UsedPerc

Used virtual memory as percentage.

Data Type

Float

Platforms

Linux, Windows, FreeBSD, Solaris, AIX

System.Memory.Swap.Free

Free swap space in bytes.

Data Type

Unsigned Integer 64

Platforms

Linux, FreeBSD, NetBSD, OpenBSD, Solaris, AIX

System.Memory.Swap.FreePerc

Free swap space as percentage.

Data Type

Float

Platforms

Linux, FreeBSD, Solaris, AIX

System.Memory.Swap.Total

Total swap space in bytes.

Data Type

Unsigned Integer 64

Platforms

Linux, FreeBSD, NetBSD, OpenBSD, Solaris, AIX

System.Memory.Swap.Used

Used swap space in bytes.

Data Type

Unsigned Integer 64

Platforms

Linux, FreeBSD, NetBSD, OpenBSD, Solaris, AIX

System.Memory.Swap.UsedPerc

Used swap space as percentage.

Data Type

Float

Platforms

Linux, FreeBSD, Solaris, AIX

Available memory (on Linux) includes free memory plus memory that can be reclaimed from buffer and page caches. This is typically a better indicator of actual memory availability than Free, which only counts completely unused pages.

Disk / Storage Monitoring

File System Metrics

File system metrics use the mount point (Linux/Unix), device name (Linux), or drive letter (Windows) as an argument.

FileSystem.Avail(mountpoint)

Available space for non-root users (bytes).

Data Type

Unsigned Integer 64

Platforms

Linux, FreeBSD, Solaris, AIX, macOS, NetBSD, OpenBSD

Table 10. Arguments
Argument Type Description

mountpoint

String

Mount point, device name, or drive letter

FileSystem.AvailPerc(mountpoint)

Available space for non-root users (percentage).

Data Type

Float

Platforms

Linux, FreeBSD, Solaris, AIX, macOS, NetBSD, OpenBSD

Table 11. Arguments
Argument Type Description

mountpoint

String

Mount point, device name, or drive letter

FileSystem.Free(mountpoint)

Free space (bytes).

Data Type

Unsigned Integer 64

Platforms

Linux, Windows, FreeBSD, Solaris, AIX, macOS, NetBSD, OpenBSD

Table 12. Arguments
Argument Type Description

mountpoint

String

Mount point, device name, or drive letter

FileSystem.FreePerc(mountpoint)

Free space (percentage).

Data Type

Float

Platforms

Linux, Windows, FreeBSD, Solaris, AIX, macOS, NetBSD, OpenBSD

Table 13. Arguments
Argument Type Description

mountpoint

String

Mount point, device name, or drive letter

FileSystem.Total(mountpoint)

Total filesystem size (bytes).

Data Type

Unsigned Integer 64

Platforms

Linux, Windows, FreeBSD, Solaris, AIX, macOS, NetBSD, OpenBSD

Table 14. Arguments
Argument Type Description

mountpoint

String

Mount point, device name, or drive letter

FileSystem.Type(mountpoint)

Filesystem type (e.g., ext4, ntfs).

Data Type

String

Platforms

Linux, Windows, Solaris, AIX

Table 15. Arguments
Argument Type Description

mountpoint

String

Mount point, device name, or drive letter

FileSystem.Used(mountpoint)

Used space (bytes).

Data Type

Unsigned Integer 64

Platforms

Linux, Windows, FreeBSD, Solaris, AIX, macOS, NetBSD, OpenBSD

Table 16. Arguments
Argument Type Description

mountpoint

String

Mount point, device name, or drive letter

FileSystem.UsedPerc(mountpoint)

Used space (percentage).

Data Type

Float

Platforms

Linux, Windows, Solaris, AIX, macOS, NetBSD, OpenBSD

Table 17. Arguments
Argument Type Description

mountpoint

String

Mount point, device name, or drive letter

FileSystem.AvailInodes(mountpoint)

Available inode count.

Data Type

Unsigned Integer 64

Platforms

Linux, FreeBSD, Solaris, AIX, OpenBSD

Table 18. Arguments
Argument Type Description

mountpoint

String

Mount point or device name

FileSystem.AvailInodesPerc(mountpoint)

Available inode percentage.

Data Type

Float

Platforms

Linux, FreeBSD, Solaris, AIX, OpenBSD

Table 19. Arguments
Argument Type Description

mountpoint

String

Mount point or device name

FileSystem.FreeInodes(mountpoint)

Free inode count.

Data Type

Unsigned Integer 64

Platforms

Linux, FreeBSD, Solaris, AIX, OpenBSD

Table 20. Arguments
Argument Type Description

mountpoint

String

Mount point or device name

FileSystem.FreeInodesPerc(mountpoint)

Free inode percentage.

Data Type

Float

Platforms

Linux, FreeBSD, Solaris, AIX, OpenBSD

Table 21. Arguments
Argument Type Description

mountpoint

String

Mount point or device name

FileSystem.TotalInodes(mountpoint)

Total inode count.

Data Type

Unsigned Integer 64

Platforms

Linux, FreeBSD, Solaris, AIX, OpenBSD

Table 22. Arguments
Argument Type Description

mountpoint

String

Mount point or device name

FileSystem.UsedInodes(mountpoint)

Used inode count.

Data Type

Unsigned Integer 64

Platforms

Linux, FreeBSD, Solaris, AIX, OpenBSD

Table 23. Arguments
Argument Type Description

mountpoint

String

Mount point or device name

FileSystem.UsedInodesPerc(mountpoint)

Used inode percentage.

Data Type

Float

Platforms

Linux, FreeBSD, Solaris, AIX, OpenBSD

Table 24. Arguments
Argument Type Description

mountpoint

String

Mount point or device name

Examples
FileSystem.UsedPerc(/)
FileSystem.Free(C:)
FileSystem.UsedInodesPerc(/home)

The FileSystem.Volumes table provides a complete list of all mounted file systems with their properties. This table supports instance discovery for automatic DCI creation.

Disk I/O Metrics

Disk I/O metrics are available as system-wide aggregates and per-device variants. Per-device variants accept the device name as an argument (e.g., sda on Linux).

System.IO.BytesReadRate

Bytes read per second. Available as system-wide aggregate or per-device.

Data Type

Unsigned Integer 64

Platforms

Linux, Windows, macOS, FreeBSD, Solaris, AIX

Table 25. Arguments (per-device variant)
Name Type Description

Device

String

Device name (e.g., sda)

System.IO.BytesReadRate.Min

Minimum number of bytes read for last minute. Available as system-wide aggregate or per-device.

Data Type

Unsigned Integer 64

Platforms

Solaris

Table 26. Arguments (per-device variant)
Name Type Description

Device

String

Device name

System.IO.BytesReadRate.Max

Maximum number of bytes read for last minute. Available as system-wide aggregate or per-device.

Data Type

Unsigned Integer 64

Platforms

Solaris

Table 27. Arguments (per-device variant)
Name Type Description

Device

String

Device name

System.IO.BytesWriteRate

Bytes written per second. Available as system-wide aggregate or per-device.

Data Type

Unsigned Integer 64

Platforms

Linux, Windows, macOS, FreeBSD, Solaris, AIX

Table 28. Arguments (per-device variant)
Name Type Description

Device

String

Device name (e.g., sda)

System.IO.BytesWriteRate.Min

Minimum number of bytes written for last minute. Available as system-wide aggregate or per-device.

Data Type

Unsigned Integer 64

Platforms

Solaris

Table 29. Arguments (per-device variant)
Name Type Description

Device

String

Device name

System.IO.BytesWriteRate.Max

Maximum number of bytes written for last minute. Available as system-wide aggregate or per-device.

Data Type

Unsigned Integer 64

Platforms

Solaris

Table 30. Arguments (per-device variant)
Name Type Description

Device

String

Device name

System.IO.ReadRate

Read operations per second. Available as system-wide aggregate or per-device.

Data Type

Float

Platforms

Linux, Windows, macOS, FreeBSD, Solaris, AIX

Table 31. Arguments (per-device variant)
Name Type Description

Device

String

Device name (e.g., sda)

System.IO.ReadRate.Min

Minimum number of read operations for last minute. Available as system-wide aggregate or per-device.

Data Type

Unsigned Integer

Platforms

Solaris

Table 32. Arguments (per-device variant)
Name Type Description

Device

String

Device name

System.IO.ReadRate.Max

Maximum number of read operations for last minute. Available as system-wide aggregate or per-device.

Data Type

Unsigned Integer

Platforms

Solaris

Table 33. Arguments (per-device variant)
Name Type Description

Device

String

Device name

System.IO.WriteRate

Write operations per second. Available as system-wide aggregate or per-device.

Data Type

Float

Platforms

Linux, Windows, macOS, FreeBSD, Solaris, AIX

Table 34. Arguments (per-device variant)
Name Type Description

Device

String

Device name (e.g., sda)

System.IO.WriteRate.Min

Minimum number of write operations for last minute. Available as system-wide aggregate or per-device.

Data Type

Unsigned Integer

Platforms

Solaris

Table 35. Arguments (per-device variant)
Name Type Description

Device

String

Device name

System.IO.WriteRate.Max

Maximum number of write operations for last minute. Available as system-wide aggregate or per-device.

Data Type

Unsigned Integer

Platforms

Solaris

Table 36. Arguments (per-device variant)
Name Type Description

Device

String

Device name

System.IO.TransferRate

Total transfer rate (reads + writes) per second. Available as system-wide aggregate or per-device.

Data Type

Float

Platforms

AIX

Table 37. Arguments (per-device variant)
Name Type Description

Device

String

Device name (e.g., sda)

System.IO.DiskQueue

Average disk queue length. Available as system-wide aggregate or per-device.

Data Type

Float

Platforms

Linux, Windows, FreeBSD, Solaris, AIX

Table 38. Arguments (per-device variant)
Name Type Description

Device

String

Device name (e.g., sda)

System.IO.DiskQueue.Min

Minimum disk queue length for last minute. Available as system-wide aggregate or per-device.

Data Type

Unsigned Integer

Platforms

Solaris

Table 39. Arguments (per-device variant)
Name Type Description

Device

String

Device name

System.IO.DiskQueue.Max

Maximum disk queue length for last minute. Available as system-wide aggregate or per-device.

Data Type

Unsigned Integer

Platforms

Solaris

Table 40. Arguments (per-device variant)
Name Type Description

Device

String

Device name

System.IO.DiskTime

Disk active time percentage. Available as system-wide aggregate or per-device.

Data Type

Float

Platforms

Linux, Windows, macOS, FreeBSD, Solaris, AIX

Table 41. Arguments (per-device variant)
Name Type Description

Device

String

Device name (e.g., sda)

System.IO.DiskReadTime

Disk read time percentage. Available as system-wide aggregate or per-device.

Data Type

Float

Platforms

Windows

Table 42. Arguments (per-device variant)
Name Type Description

Device

String

Device name

System.IO.DiskWriteTime

Disk write time percentage. Available as system-wide aggregate or per-device.

Data Type

Float

Platforms

Windows

Table 43. Arguments (per-device variant)
Name Type Description

Device

String

Device name

System.IO.WaitTime

Average I/O wait time in milliseconds. Available as system-wide aggregate or per-device.

Data Type

Unsigned Integer (Integer on AIX)

Platforms

Linux, AIX

Table 44. Arguments (per-device variant)
Name Type Description

Device

String

Device name (e.g., sda)

System.IO.ReadWaitTime

Average read wait time in milliseconds. Available as system-wide aggregate or per-device.

Data Type

Unsigned Integer

Platforms

Linux

Table 45. Arguments (per-device variant)
Name Type Description

Device

String

Device name (e.g., sda)

System.IO.WriteWaitTime

Average write wait time in milliseconds. Available as system-wide aggregate or per-device.

Data Type

Unsigned Integer

Platforms

Linux

Table 46. Arguments (per-device variant)
Name Type Description

Device

String

Device name (e.g., sda)

Network Interface Monitoring

The Net.InterfaceList list returns one line per IP address, with fields: interface index, IP address with mask, type (MTU), MAC address, and interface name. Interfaces without an IP address are listed with 0.0.0.0/0.

The argument for all Net.Interface.* metrics is the interface name or interface index. Interface indices can be obtained from the Net.InterfaceList list.

Traffic counters are raw counter values. Use Counter32 or Counter64 data type in DCI configuration to get per-second rates automatically.

On NetBSD the 32-bit interface counter metrics are registered with data type Unsigned Integer 64; on OpenBSD they are registered as Unsigned Integer (the 64-bit variants as Unsigned Integer 64).

Net.Interface.BytesIn(ifName)

Inbound bytes. Available in 32-bit and 64-bit counter variants.

Data Type

Counter 32 / Counter 64

Platforms

Linux, Windows, Solaris, AIX, FreeBSD, NetBSD, OpenBSD, macOS (64-bit: Linux, Windows, Solaris, FreeBSD, OpenBSD, macOS)

Table 47. Arguments
Argument Type Description

ifName

String

Interface name or index

Table 48. Variants
Metric Description

Net.Interface.BytesIn(*)

32-bit counter

Net.Interface.BytesIn64(*)

64-bit counter

Net.Interface.BytesOut(ifName)

Outbound bytes. Available in 32-bit and 64-bit counter variants.

Data Type

Counter 32 / Counter 64

Platforms

Linux, Windows, Solaris, AIX, FreeBSD, NetBSD, OpenBSD, macOS (64-bit: Linux, Windows, Solaris, FreeBSD, OpenBSD, macOS)

Table 49. Arguments
Argument Type Description

ifName

String

Interface name or index

Table 50. Variants
Metric Description

Net.Interface.BytesOut(*)

32-bit counter

Net.Interface.BytesOut64(*)

64-bit counter

Net.Interface.InDrops(ifName)

Inbound dropped packets. Available in 32-bit and 64-bit counter variants.

Data Type

Counter 32 / Counter 64

Platforms

Linux, Windows, Solaris, AIX, FreeBSD, NetBSD, OpenBSD, macOS (64-bit: Linux, Windows, FreeBSD, OpenBSD, macOS)

Table 51. Arguments
Argument Type Description

ifName

String

Interface name or index

Table 52. Variants
Metric Description

Net.Interface.InDrops(*)

32-bit counter

Net.Interface.InDrops64(*)

64-bit counter

Net.Interface.OutDrops(ifName)

Outbound dropped packets. Available in 32-bit and 64-bit counter variants.

Data Type

Counter 32 / Counter 64

Platforms

Linux, Windows, Solaris, AIX, FreeBSD (64-bit: Linux, Windows, FreeBSD)

Table 53. Arguments
Argument Type Description

ifName

String

Interface name or index

Table 54. Variants
Metric Description

Net.Interface.OutDrops(*)

32-bit counter

Net.Interface.OutDrops64(*)

64-bit counter

Net.Interface.InErrors(ifName)

Inbound errors. Available in 32-bit and 64-bit counter variants.

Data Type

Counter 32 / Counter 64

Platforms

Linux, Windows, Solaris, AIX, FreeBSD, NetBSD, OpenBSD, macOS (64-bit: Linux, FreeBSD, OpenBSD, macOS)

Table 55. Arguments
Argument Type Description

ifName

String

Interface name or index

Table 56. Variants
Metric Description

Net.Interface.InErrors(*)

32-bit counter

Net.Interface.InErrors64(*)

64-bit counter

Net.Interface.OutErrors(ifName)

Outbound errors. Available in 32-bit and 64-bit counter variants.

Data Type

Counter 32 / Counter 64

Platforms

Linux, Windows, Solaris, AIX, FreeBSD, NetBSD, OpenBSD, macOS (64-bit: Linux, FreeBSD, OpenBSD, macOS)

Table 57. Arguments
Argument Type Description

ifName

String

Interface name or index

Table 58. Variants
Metric Description

Net.Interface.OutErrors(*)

32-bit counter

Net.Interface.OutErrors64(*)

64-bit counter

Net.Interface.PacketsIn(ifName)

Inbound packets. Available in 32-bit and 64-bit counter variants.

Data Type

Counter 32 / Counter 64

Platforms

Linux, Windows, Solaris, AIX, FreeBSD, NetBSD, OpenBSD, macOS (64-bit: Linux, Windows, Solaris, FreeBSD, OpenBSD, macOS)

Table 59. Arguments
Argument Type Description

ifName

String

Interface name or index

Table 60. Variants
Metric Description

Net.Interface.PacketsIn(*)

32-bit counter

Net.Interface.PacketsIn64(*)

64-bit counter

Net.Interface.PacketsOut(ifName)

Outbound packets. Available in 32-bit and 64-bit counter variants.

Data Type

Counter 32 / Counter 64

Platforms

Linux, Windows, Solaris, AIX, FreeBSD, NetBSD, OpenBSD, macOS (64-bit: Linux, Windows, Solaris, FreeBSD, OpenBSD, macOS)

Table 61. Arguments
Argument Type Description

ifName

String

Interface name or index

Table 62. Variants
Metric Description

Net.Interface.PacketsOut(*)

32-bit counter

Net.Interface.PacketsOut64(*)

64-bit counter

Net.Interface.AdminStatus(ifName)

Administrative status of the interface.

Data Type

Integer

Platforms

Linux, Windows, Solaris, AIX, FreeBSD, NetBSD, OpenBSD

Table 63. Arguments
Argument Type Description

ifName

String

Interface name or index

Table 64. Return values
Value Description

1

Up

2

Down

3

Testing

Net.Interface.Description(ifName)

Interface description.

Data Type

String

Platforms

Linux, Windows, Solaris, AIX

Table 65. Arguments
Argument Type Description

ifName

String

Interface name or index

Link status of the interface. Deprecated on all platforms except Linux — use Net.Interface.OperStatus instead.

Data Type

Integer

Platforms

Linux, Windows, Solaris, AIX, FreeBSD, NetBSD, OpenBSD, macOS

Table 66. Arguments
Argument Type Description

ifName

String

Interface name or index

Table 67. Return values
Value Description

0

Down

1

Up

Net.Interface.MaxSpeed(ifName)

Maximum interface speed in bits per second.

Data Type

Unsigned Integer 64

Platforms

Linux

Table 68. Arguments
Argument Type Description

ifName

String

Interface name or index

Net.Interface.MTU(ifName)

Maximum transmission unit.

Data Type

Unsigned Integer (Integer on AIX)

Platforms

Windows, AIX, OpenBSD

Table 69. Arguments
Argument Type Description

ifName

String

Interface name or index

Net.Interface.OperStatus(ifName)

Operational status of the interface.

Data Type

Integer

Platforms

Windows, Solaris, AIX, FreeBSD, NetBSD, OpenBSD, macOS

Table 70. Arguments
Argument Type Description

ifName

String

Interface name or index

Table 71. Return values
Value Description

0

Down

1

Up

Net.Interface.Speed(ifName)

Interface speed in bits per second.

Data Type

Unsigned Integer 64 (Unsigned Integer on Solaris, Integer on AIX)

Platforms

Linux, Windows, FreeBSD, OpenBSD, Solaris, AIX

Table 72. Arguments
Argument Type Description

ifName

String

Interface name or index

Net.Interface.64BitCounters

Indicates whether 64-bit interface counters are supported.

Data Type

Integer

Platforms

Windows, FreeBSD

Net.IP.Forwarding

Indicates whether IPv4 forwarding is enabled.

Data Type

Integer

Platforms

Linux, Windows, FreeBSD, NetBSD, OpenBSD, macOS

Table 73. Return values
Value Description

0

Disabled

1

Enabled

Net.IP6.Forwarding

Indicates whether IPv6 forwarding is enabled.

Data Type

Integer

Platforms

Linux, FreeBSD, NetBSD, OpenBSD, macOS

Table 74. Return values
Value Description

0

Disabled

1

Enabled

Net.IP.NextHop(ipAddress)

Next hop gateway for the given destination address. This is a server-side metric with Internal origin, available on nodes with an agent or SNMP; it is not collected through the agent.

Data Type

String

Origin

Internal (server-side)

Table 75. Arguments
Argument Type Description

ipAddress

String

Destination IP address

Net.IP.Stats.TCPConnections

Total number of TCP connections across all states and IP versions. Also available as a parameterized variant for filtered queries (added in 6.1).

Data Type

Integer

Platforms

Linux, Windows, Solaris, AIX, FreeBSD, NetBSD, OpenBSD, macOS

The parameterized variant Net.IP.Stats.TCPConnections(*) accepts named parameters passed as key=value pairs separated by semicolons.

Table 76. Filter parameters
Parameter Description

state

TCP connection state to count. If omitted, connections in all states are counted. Supported values: ESTABLISHED, SYN_SENT, SYN_RECV, FIN_WAIT1, FIN_WAIT2, TIME_WAIT, CLOSE, CLOSE_WAIT, LAST_ACK, LISTEN, CLOSING.

version

IP protocol version. Set to 4 for IPv4 only or 6 for IPv6 only. If omitted, connections on both IPv4 and IPv6 are counted.

Examples
Net.IP.Stats.TCPConnections(state=ESTABLISHED)
Net.IP.Stats.TCPConnections(state=LISTEN;version=4)
Net.IP.Stats.TCPConnections(version=6)

Net.RemoteShareStatus(path)

Check accessibility of a remote shared resource (Windows only). Net.RemoteShareStatus returns an integer code, Net.RemoteShareStatusText returns the same status as text.

Data Type

Integer (Net.RemoteShareStatus) / String (Net.RemoteShareStatusText)

Platforms

Windows

Table 77. Arguments
# Type Description

1

String

UNC path to the share (e.g., \\server\share)

2

String

Domain name (optional)

3

String

Login name (optional)

4

String

Password (optional)

Net.Resolver.AddressByName(hostname)

DNS forward resolution - resolves hostname to IP address.

Data Type

String

Platforms

All

Table 78. Arguments
Argument Type Description

hostname

String

Hostname to resolve

Net.Resolver.NameByAddress(ipAddress)

DNS reverse resolution - resolves IP address to hostname.

Data Type

String

Platforms

All

Table 79. Arguments
Argument Type Description

ipAddress

String

IP address to resolve

Process Monitoring

The System.ProcessList list returns all running processes with PID and name information.

Process.Count(processName)

Number of running processes matching the given name.

Data Type

Integer (Unsigned Integer on NetBSD and OpenBSD)

Platforms

Linux, Windows, macOS, Solaris, AIX, FreeBSD, NetBSD, OpenBSD

Table 80. Arguments
Argument Type Description

processName

String

Process name to match

Example
Process.Count(httpd)

Process.CountEx(processName)

Extended process count with optional filtering by command line, owner, and window title.

Data Type

Integer (Unsigned Integer on NetBSD)

Platforms

Linux, Windows, macOS, Solaris, AIX, FreeBSD, NetBSD

Table 81. Arguments
Argument Type Description

processName

String

Process name

cmdLine

String

Command line regular expression (optional). Matches against the full command line. If not set, matches any command line.

userName

String

Process owner username regular expression (optional). If not set, matches any user.

windowTitle

String

Window title regular expression (optional, Windows only). If not set, matches any window title.

Examples
Process.CountEx(httpd)
Process.CountEx(java,.*-server.*)
Process.CountEx(python,.*myapp.*,appuser)

Process.CPUTime(processName)

Total CPU time consumed by matching processes (milliseconds).

Data Type

Counter 64 (Integer 64 on NetBSD)

Platforms

Linux, Windows, macOS, Solaris, AIX, FreeBSD, NetBSD

See common process metric arguments for argument details.

Process.GDIObjects(processName)

Number of GDI objects used by matching processes.

Data Type

Integer 64

Platforms

Windows

See common process metric arguments for argument details.

Process.Handles(processName)

Number of open handles or file descriptors for matching processes.

Data Type

Integer

Platforms

Linux, Windows, Solaris, AIX

See common process metric arguments for argument details.

Process.IO.OtherB(processName)

Other I/O bytes transferred by matching processes.

Data Type

Counter 64

Platforms

Windows

See common process metric arguments for argument details.

Process.IO.OtherOp(processName)

Other I/O operations performed by matching processes.

Data Type

Counter 64

Platforms

Windows

See common process metric arguments for argument details.

Process.IO.ReadB(processName)

Bytes read by matching processes.

Data Type

Counter 64

Platforms

Windows

See common process metric arguments for argument details.

Process.IO.ReadOp(processName)

Read operations performed by matching processes.

Data Type

Counter 64

Platforms

Windows, AIX

See common process metric arguments for argument details.

Process.IO.WriteB(processName)

Bytes written by matching processes.

Data Type

Counter 64

Platforms

Windows

See common process metric arguments for argument details.

Process.IO.WriteOp(processName)

Write operations performed by matching processes.

Data Type

Counter 64

Platforms

Windows, AIX

See common process metric arguments for argument details.

Process.KernelTime(processName)

Kernel mode CPU time consumed by matching processes (milliseconds).

Data Type

Counter 64 (Integer 64 on NetBSD)

Platforms

Linux, Windows, Solaris, AIX, NetBSD

See common process metric arguments for argument details.

Process.MemoryUsage(processName)

Memory usage as a percentage of total system memory for matching processes.

Data Type

Float

Platforms

Linux, Windows, macOS, Solaris, AIX, FreeBSD

See common process metric arguments for argument details.

Process.PageFaults(processName)

Number of page faults for matching processes.

Data Type

Counter 64 (Integer 64 on NetBSD)

Platforms

Linux, Windows, Solaris, AIX, NetBSD

See common process metric arguments for argument details.

Process.RSS(processName)

Resident set size in bytes for matching processes. Alias for Process.WkSet(*).

Data Type

Integer 64

Platforms

Linux, Windows, macOS, Solaris, AIX, FreeBSD

See common process metric arguments for argument details.

Process.Syscalls(processName)

Number of system calls made by matching processes.

Data Type

Counter 64

Platforms

Solaris

See common process metric arguments for argument details.

Process.Threads(processName)

Number of threads for matching processes.

Data Type

Integer (Integer 64 on NetBSD)

Platforms

Linux, Windows, macOS, Solaris, AIX, FreeBSD, NetBSD

See common process metric arguments for argument details.

Process.UserObjects(processName)

Number of USER objects used by matching processes.

Data Type

Integer 64

Platforms

Windows

See common process metric arguments for argument details.

Process.UserTime(processName)

User mode CPU time consumed by matching processes (milliseconds).

Data Type

Counter 64 (Integer 64 on NetBSD)

Platforms

Linux, Windows, Solaris, AIX, NetBSD

See common process metric arguments for argument details.

Process.VMRegions(processName)

Number of virtual memory regions for matching processes.

Data Type

Integer

Platforms

Linux

See common process metric arguments for argument details.

Process.VMSize(processName)

Virtual memory size in bytes for matching processes.

Data Type

Integer 64

Platforms

Linux, Windows, macOS, Solaris, AIX, FreeBSD, NetBSD

See common process metric arguments for argument details.

Process.WkSet(processName)

Working set size in bytes for matching processes.

Data Type

Integer 64

Platforms

Linux, Windows, macOS, Solaris, AIX, FreeBSD, NetBSD

See common process metric arguments for argument details.

Process.ZombieCount(processName)

Number of zombie processes. Without arguments, counts all zombie processes; with the optional process name argument, counts only zombie processes matching the given name.

Data Type

Integer

Platforms

Solaris

Table 82. Arguments
Argument Type Description

processName

String

Process name to match (optional)

Common Process Metric Arguments

Most process metrics (except Process.Count and Process.CountEx) accept the following arguments:

Table 83. Arguments
Argument Type Description

processName

String

Process name

function

String

Aggregation function when multiple processes match. Default: sum. Options: min, max, avg, sum.

cmdLine

String

Command line regular expression (optional). If not set, matches any command line.

userName

String

Process owner username regular expression (optional). If not set, matches any user.

windowTitle

String

Window title regular expression (optional, Windows only). If not set, matches any window title.

Examples
Process.VMSize(java)
Process.CPUTime(httpd,max)
Process.Handles(python,sum,.*myapp.*)
Process.MemoryUsage(node,avg,,appuser)

Process Monitoring Examples

To monitor a specific application process:

  1. Create a DCI with origin Agent and metric Process.Count(httpd).

  2. Set a threshold: if the value equals 0, generate an alert (process not running).

  3. Optionally monitor memory usage with Process.MemoryUsage(httpd).

System Information

Parameter Description

System.Hostname

System hostname

System.FQDN

Fully qualified domain name

System.Uname

System identification string (kernel version, architecture)

System.PlatformName

Operating system platform identifier

System.Uptime

System uptime in seconds

System.CurrentTime

Current system time (epoch)

Hardware.System.MachineId

Machine unique identifier (when available)

WMI Subagent (Windows)

The WMI subagent (wmi.nsm) provides access to Windows Management Instrumentation data. It exposes ACPI thermal zone temperatures, hardware network adapter properties, security product status, and a generic interface for arbitrary WMI queries.

Loading the Subagent

Add the following line to the agent configuration file:

SubAgent = wmi.nsm

ACPI Thermal Zone Metrics

These metrics read temperature data from ACPI thermal zones using the MSAcpi_ThermalZoneTemperature WMI class in the root\WMI namespace. Temperature values are returned in degrees Celsius.

Table 84. ACPI thermal zone parameters
Parameter Description

ACPI.ThermalZone.CurrentTemp

Current temperature in the first ACPI thermal zone found (Celsius)

ACPI.ThermalZone.CurrentTemp(zone)

Current temperature in the specified ACPI thermal zone (Celsius). Argument is the thermal zone instance name, as returned by the ACPI.ThermalZones list.

Table 85. ACPI thermal zone lists
List Description

ACPI.ThermalZones

Returns instance names of all available ACPI thermal zones

Not all systems expose ACPI thermal zone data through WMI. This depends on the hardware and BIOS/UEFI implementation.

Hardware Network Adapter Metrics

These metrics expose physical network adapter properties from the Win32_NetworkAdapter WMI class. Adapters whose hardware is not present (WMI NetConnectionStatus = 4), TAP-Windows adapters, and Fortinet PPP adapters are filtered out automatically.

The argument for all metrics is the adapter index, which can be obtained from the Hardware.NetworkAdapters list or table.

Table 86. Hardware network adapter parameters
Parameter Description

Hardware.NetworkAdapter.Availability(index)

Adapter availability status code

Hardware.NetworkAdapter.Description(index)

Adapter description

Hardware.NetworkAdapter.InterfaceIndex(index)

Windows network stack interface index

Hardware.NetworkAdapter.MACAddress(index)

MAC address

Hardware.NetworkAdapter.Manufacturer(index)

Adapter manufacturer

Hardware.NetworkAdapter.Product(index)

Adapter product name

Hardware.NetworkAdapter.Speed(index)

Adapter speed in bits per second

Hardware.NetworkAdapter.Type(index)

Adapter type (e.g., "Ethernet 802.3")

Table 87. Hardware network adapter lists and tables
Name Description

Hardware.NetworkAdapters (list)

Returns adapter index values for all physical network adapters

Hardware.NetworkAdapters (table)

Returns a table with columns: INDEX, PRODUCT, MANUFACTURER, DESCRIPTION, TYPE, MAC_ADDRESS, IF_INDEX, SPEED, AVAILABILITY

Security Product Metrics

These metrics report the status of security products registered with Windows Security Center (the root\SecurityCenter2 WMI namespace).

Table 88. Antivirus product parameters
Parameter Description

System.AntiVirusProduct.Active

Returns 1 if the antivirus product is active/running, 0 otherwise

System.AntiVirusProduct.DisplayName

Display name of the registered antivirus product

System.AntiVirusProduct.UpToDate

Returns 1 if the antivirus definitions are up to date, 0 otherwise

Table 89. Anti-spyware product parameters
Parameter Description

System.AntiSpywareProduct.Active

Returns 1 if the anti-spyware product is active/running, 0 otherwise

System.AntiSpywareProduct.DisplayName

Display name of the registered anti-spyware product

System.AntiSpywareProduct.UpToDate

Returns 1 if the anti-spyware definitions are up to date, 0 otherwise

Table 90. Firewall product parameters
Parameter Description

System.FirewallProduct.Active

Returns 1 if a firewall is active, 0 otherwise

System.FirewallProduct.DisplayName

Display name of the active firewall product

System.FirewallProduct.UpToDate

Returns 1 if the firewall is up to date, 0 otherwise

If no third-party firewall is registered with Windows Security Center, the subagent falls back to reporting the built-in Windows Firewall status for System.FirewallProduct.Active and System.FirewallProduct.DisplayName only. System.FirewallProduct.UpToDate has no such fallback and is not supported for the built-in Windows Firewall.

Generic WMI Queries

The WMI.Query(*) parameter provides a flexible interface for executing arbitrary WMI queries. It is available as a parameter (single value), list (multiple values), and table (full result set).

Parameter Query

Returns a single property value from a WMI query result.

WMI.Query(namespace, query, property)
  • namespace — WMI namespace (e.g., root\cimv2)

  • query — WQL query string

  • property — property name to return from the result, or %%count%% to return the number of matching objects. For array properties, an index can be appended (e.g., Property[0] returns the first element); without an index, an array property is returned as [v1,v2,…​].

Example — get the caption of process with PID 252:

WMI.Query(root\cimv2, SELECT * FROM Win32_Process WHERE ProcessId=252, Caption)

List Query

Returns all values of a single property from matching WMI objects.

WMI.Query(namespace, query, property)

Example — get names of all running processes:

WMI.Query(root\cimv2, SELECT * FROM Win32_Process, Caption)

Table Query

Returns a full table with all properties from matching WMI objects as columns.

WMI.Query(namespace, query)

Example — get complete process information:

WMI.Query(root\cimv2, SELECT * FROM Win32_Process)

WMI Namespace and Class Discovery

Table 91. Discovery lists
List Description

WMI.NameSpaces

Lists the immediate child namespaces of the root WMI namespace (names returned without the root\ prefix; nested namespaces are not enumerated)

WMI.Classes(namespace)

Lists all WMI classes in the specified namespace (e.g., WMI.Classes(root\cimv2))

Common WMI Classes

Some commonly used WMI classes for monitoring:

Table 92. Static information classes
WMI Class Data

Win32_ComputerSystem

Computer system properties

Win32_OperatingSystem

OS version, install date, memory

Win32_Processor

CPU information

Win32_DiskDrive

Physical disk drives

Win32_DiskPartition

Disk partitions

Win32_LogicalDisk

Logical disks (drive letters)

Win32_PhysicalMemory

Physical memory modules

Win32_NetworkAdapter

Network adapters

Win32_NetworkAdapterConfiguration

Network adapter IP configuration

Table 93. Performance counter classes
WMI Class Data

Win32_PerfRawData_PerfOS_Processor

CPU utilization counters

Win32_PerfRawData_PerfOS_Memory

Memory utilization counters

Win32_PerfRawData_Tcpip_NetworkInterface

Network traffic counters

For standard OS monitoring, ready-to-import template files (linux.xml, windows.xml, generic_unix.xml, and others) are provided in the contrib/templates/ directory of the NetXMS source repository. These templates are not created at database initialization and must be imported manually. They create commonly needed DCIs:

  • CPU usage with thresholds

  • Memory usage with thresholds

  • Disk usage per volume with instance discovery

  • Network interface traffic with instance discovery

  • System uptime

See DCI Templates for details on applying templates to nodes.