Action Macro Reference

All action configurations, event message templates, alarm messages, alarm keys, and notification templates support macro substitution for dynamic content.

Event and Object Macros

Macro Description

%n

Name of event source object

%a

IP address of event source object

%i

Unique ID of event source object in hexadecimal form

%I

Unique ID of event source object in decimal form

%g

Globally unique identifier (GUID) of event source object

%c

Event code

%N

Event name

%u

IP address of event source object in URL-compatible form (bracketed for IPv6)

%U

User name associated with the event

%s

Event severity code as number (0=Normal, 1=Warning, 2=Minor, 3=Major, 4=Critical)

%S

Event severity code as text

%m

Event message text

%t

Event timestamp as day.Month.year hour:minute:second (e.g., 05.Aug.2026 14:30:00)

%T

Event timestamp as seconds since epoch (Unix time)

%v

NetXMS server version

%C

Comment of event source object

%L

Alias of event source object

%z

Zone UIN of event source object

%Z

Zone name of event source object

Alarm Macros

These macros are populated when the action is triggered from an alarm-generating or alarm-resolving EPP rule. %A and %K also resolve from the last-alarm data recorded for the event when no alarm is attached; only %y and %Y strictly require an alarm in context.

Macro Description

%A

Alarm message text

%K

Alarm key

%y

Alarm state (numeric): 0=Outstanding, 1=Acknowledged, 2=Resolved, 3=Terminated (state is the lower 4 bits, mask 0x0F; bit 0x10 indicates sticky acknowledgement)

%Y

Alarm ID

Event Parameter Macros

Macro Description

%1 through %99

Positional event parameters; when no event is in context (e.g., in object tools), positional object tool arguments are used instead

%<name>

Named event parameter

%<name:default_value>

Named event parameter with fallback default value if parameter is not set

%<{format-specifier}name>

Named event parameter with format specifier (supports units and multipliers)

%E

Comma-separated list of user tags associated with the event

Custom Attribute and Script Macros

Macro Description

%{name}

Custom attribute of the source object (the instance-specific attribute name::<instance> is tried first, then plain name)

%\{name:default_value\}

Custom attribute of the source object with fallback default value

%[name]

Return value of script library script named name

Special Context Macros

Macro Description

%d

Description of the associated Data Collection Item (available whenever the event or alarm carries a DCI reference, such as threshold and DCI state events)

%D

Comment of the Data Collection Item (same availability as %d)

%M

Custom message text set via CUSTOM_MESSAGE variable in EPP filtering script

Escape Sequences

Macro Description

%(nl)

Newline (CR+LF)

%(cr)

Carriage return

%(lf)

Line feed

%(tab)

Tab character

%(in:fieldname)

Value of the input field named fieldname (used in Object Tools)

%%

Literal percent sign