SSH Monitoring
NetXMS can collect monitoring data from remote systems by executing commands over SSH. This is useful for monitoring systems where installing the NetXMS agent is not possible or practical.
Overview
SSH monitoring allows NetXMS to:
-
Execute commands on remote hosts and collect their output as metrics
-
Run scripts and collect structured data
-
Monitor systems that only allow SSH access (appliances, embedded devices, hardened systems)
The NetXMS server has no SSH client of its own.
All SSH operations are executed by an agent with the ssh.nsm subagent loaded, selected via the node’s SSH proxy setting.
By default this is the agent on the management server itself, so out of the box SSH connections originate from the server host — but they are always made by an agent, not by the server process.
Configuring SSH on a Node
Configure SSH credentials on the target node:
-
Open the node properties in the management client
-
Go to the dedicated SSH property page
-
Configure SSH settings:
-
SSH proxy (agent that performs the SSH connections; default: management server’s agent)
-
SSH login
-
SSH password or key
-
SSH port (default: 22)
-
SSH Subagent (ssh.nsm)
The ssh.nsm subagent performs SSH commands on behalf of the server and must be loaded on whichever agent acts as the SSH proxy.
Loading it on an agent close to the target systems is useful when those systems are not directly reachable from the server network.
Configuration
SubAgent = ssh.nsm
[SSH]
ConnectTimeout = 2000
SessionIdleTimeout = 300
| Parameter | Default | Description |
|---|---|---|
|
2000 |
SSH connection timeout in milliseconds |
|
300 |
Idle session timeout in seconds (sessions are reused within this window) |
|
Path to SSH config file (default: |
SSH Metrics
The SSH subagent provides these metrics:
| Parameter | Description |
|---|---|
|
Execute command via SSH and return output |
|
Check SSH connectivity; returns 1 on success, 0 on failure |
|
Check SSH exec mode works; returns 1 if pattern matches output |
|
Check interactive shell channel; returns 1 if prompt detected |
SSH.Command arguments:
| Argument | Description |
|---|---|
|
Hostname or IP address, optionally with |
|
SSH username |
|
SSH password |
|
Shell command to execute via SSH exec channel |
|
(optional) PCRE regex. If set, returns the first matching line (or first capture group). If empty, returns the first line of output. |
|
(optional) Numeric ID of an SSH key pair stored in NetXMS configuration |
SSH.Command is also available as a list (returns all output lines) and as an action.
Note that the list form has no pattern argument — the SSH key ID is its fifth argument: SSH.Command(target[:port],login,password,command[,ssh_key_id]).
SSH Proxy Mode
SSH collection always follows this path:
-
The server sends the SSH command request to the proxy agent (the management server’s agent unless another proxy is configured)
-
The proxy agent connects to the target via SSH
-
The command is executed on the target
-
The output is returned through the proxy agent to the server
Configure the SSH proxy on the node’s SSH property page.
When using the SSH data origin for DCIs, the DCI metric name is the command itself. The server automatically constructs the full SSH.Command(…) call using the node’s SSH credentials and key configuration.
SSH Key Management
NetXMS provides centralized SSH key pair management in the SSH Keys view of the Configuration perspective:
-
Generate RSA key pairs directly in the management console
-
Store keys securely in the NetXMS database
-
Associate keys with nodes for passwordless authentication
-
Keys are automatically distributed to proxy agents when needed
To use SSH key authentication:
-
Create a key pair in the SSH Keys view (Configuration perspective)
-
Copy the public key to the target system’s
authorized_keys -
On the node’s SSH property page, select the SSH key
-
The key ID is passed automatically in all SSH operations for that node
Managing SSH keys requires the Manage SSH keys system access right. Deleting a key that is in use by any node is prevented (unless force-deleted).
Interactive SSH Sessions
NetXMS supports interactive SSH sessions for devices that do not support the exec channel (e.g. Cisco IOS, Juniper, MikroTik routers).
Interactive sessions use a PTY (pseudo-terminal) channel instead of the exec channel. Network device drivers (NDDs) provide device-specific hints for terminal type, prompt regex, and pagination patterns.
NXSL Integration
Interactive SSH sessions are available via NXSL:
$session = $node->openSSHSession()
$output = $session->execute("show interfaces")
$session->close()
openSSHSession accepts optional arguments user, password, and keyId to override the node’s configured SSH credentials.
The SSHSession NXSL object provides:
-
execute(command[,timeout])— run a command, returns array of output lines -
escalatePrivilege(password)— send enable/su password, returns boolean -
close()— close the channel -
.connected,.privileged— boolean attributes -
.nodeId— ID of the node the session belongs to -
.lastError,.lastErrorMessage— error information
Limitations
-
SSH connection overhead makes it slower than native agent monitoring
-
Sessions are cached and reused within the idle timeout window
-
Complex output parsing may require transformation scripts or patterns
-
Binary data and non-text output are not supported
-
The remote command must complete within the polling timeout