Configuration File Reference
This page provides a complete reference for NetXMS configuration files. For operational guidance, see Server Configuration and Agent Configuration.
Server Configuration File (netxmsd.conf)
The server configuration file controls startup behavior, database connectivity, and logging. It is read once at server startup; changes require a restart.
All boolean parameters accept yes/no, on/off, and true/false values.
Configuration File Search Order
If no configuration file is specified with -c, the server searches automatically:
UNIX/Linux/macOS:
-
$NETXMS_HOME/etc/netxmsd.conf(ifNETXMS_HOMEenvironment variable is set) -
SYSCONFDIR/netxmsd.conf(compile-time prefix, typically/usr/local/etcor/etc) -
/etc/netxmsd.conf(fallback)
The NETXMSD_CONFIG environment variable can also be set to override the search (honored by both netxmsd and nxdbmgr).
Windows:
-
<InstallDir>\etc\netxmsd.conf(installation directory from registry) -
C:\netxmsd.conf(fallback)
Syntax
The file uses simple Key = Value format, one parameter per line.
Lines starting with # are comments.
Parameters that accept multiple values (such as Module, TrustedCertificate, CRL) can be specified multiple times.
Size parameters support K, M, G, T suffixes (e.g., 16M for 16 megabytes).
The file supports optional sections in [SectionName] format.
The default section is [server].
Additional sections include [VAULT], [ENV], [WEBAPI], [CLUSTER], and [AI].
Loaded server modules and fanout drivers may read their own additional sections.
Database Connection Parameters
| Parameter | Default | Description |
|---|---|---|
|
(none) |
Database driver module ( |
|
|
Database server address (hostname or IP). For ODBC driver, this is the ODBC data source name. |
|
|
Database name (not used by ODBC driver) |
|
|
Database login name |
|
(empty) |
Database password, plain text or obfuscated with |
|
(none) |
Deprecated alias for |
|
(empty) |
External command to retrieve the database password. The command is executed at startup with a 30-second timeout; its stdout (trimmed) is used as the password. |
|
(default) |
Database schema name (PostgreSQL and Oracle only) |
|
(empty) |
Additional driver-specific parameters |
|
(empty) |
Deprecated. Use |
|
(empty) |
Path to a plain text file containing SQL commands executed on every new database connection, including the initial connection on server startup. |
|
|
Cache configuration tables to in-memory SQLite database to speed up server startup |
|
(empty) |
Path to a plain text file containing SQL commands executed once on server startup |
Server Network and Security Parameters
| Parameter | Default | Description |
|---|---|---|
|
|
IP address to listen on for client and agent connections. Use |
|
(empty) |
Alternate address for connecting to the agent on the local management node. Useful when running server and agent in Docker containers where the internal container IP differs from the accessible address. |
|
|
Maximum number of concurrent client sessions |
|
|
Maximum client message size. Supports K, M, G, T suffixes. Advanced — contact support before changing. |
|
(none) |
Comma-separated list of peer node addresses or hostnames in high availability setup. The server will verify no other instance is running on these addresses before removing a stale database lock. |
|
(empty) |
Path to server TLS certificate file (PEM format) |
|
(empty) |
Path to server TLS private key file. Can be omitted if key is included in the certificate file. |
|
(empty) |
Password for encrypted server private key. Can be omitted if key is not encrypted. |
|
(empty) |
Path to server certificate file used specifically for agent tunnel connections |
|
(empty) |
Private key for the tunnel certificate. Can be omitted if key is included in the certificate file. |
|
(empty) |
Password for encrypted tunnel certificate private key |
|
(empty) |
Path to server CA certificate used to issue agent certificates. This certificate is also automatically trusted when verifying agent certificate validity. |
|
(empty) |
Private key for the internal CA certificate. Can be omitted if key is included in the certificate file. |
|
(empty) |
Password for the internal CA certificate key |
|
(empty) |
Path to a trusted CA certificate or self-signed certificate. If the certificate chain is longer than one level, add all upper-level certificates using multiple |
|
(none) |
Certificate Revocation List — path to a local file or HTTP/HTTPS URL. Supports and autodetects PEM and DER formats. Multiple |
|
(empty) |
HMAC key used for signing audit log entries |
|
(empty) |
Deprecated. Use |
Logging Parameters
| Parameter | Default | Description |
|---|---|---|
|
(platform-dependent) |
Path to log file. Default is |
|
|
Log rotation mode: 0 = no rotation, 1 = daily rotation (at midnight), 2 = rotation by size (when file exceeds |
|
|
Maximum log file size before rotation (mode 2 only). Supports K, M, G, T suffixes. |
|
|
Number of rotated log files to keep; older files are discarded |
|
(empty) |
Suffix appended to daily log file names (mode 1). Supports strftime(3) format macros. When empty, |
|
|
Write server log entries in JSON format |
|
|
Use a separate background thread to write log entries in batches, improving performance under heavy logging |
|
|
Global debug verbosity (0-9). Value 0 disables debug logging, 9 enables very detailed logging. Can also be set with command-line option |
|
(empty) |
Comma-separated list of debug tags with levels (e.g., |
Directory Parameters
| Parameter | Default | Description |
|---|---|---|
|
(platform-dependent) |
Server data directory for MIB files, encryption keys, and persistent state. Linux default: |
|
(platform-dependent) |
Directory containing database drivers (.ddr) and network device driver files (.ndd). It is generally recommended not to change this parameter. |
|
|
Directory for storing server crash dump files |
Performance and System Parameters
| Parameter | Default | Description |
|---|---|---|
|
|
CPU affinity bitmask for the server process (Windows only). Each bit represents a logical processor on which server threads are allowed to run. |
|
(system default) |
Character encoding for non-Unicode text conversion. Has no effect on Windows or if the server was compiled without iconv support. |
|
|
Default stack size for server threads. Supports K, M, G, T suffixes. Advanced — contact support before changing. |
|
|
Enable creation of crash dump files when the server encounters a fatal error (Windows only) |
|
|
Write full memory dumps instead of minidumps (Windows only). Requires |
Module and Driver Parameters
| Parameter | Default | Description |
|---|---|---|
|
(none) |
Additional server module to load at startup. Can be specified multiple times to load multiple modules. |
|
(empty) |
Fanout driver for sending collected performance data to an additional storage backend (e.g., InfluxDB, ClickHouse). Multiple entries can be specified. See Fanout Drivers for details. |
VAULT Section
The [VAULT] section configures integration with HashiCorp Vault for retrieving database credentials securely.
| Parameter | Default | Description |
|---|---|---|
|
(empty) |
Vault server URL (e.g., |
|
(empty) |
Vault AppRole role ID for authentication |
|
(empty) |
Vault AppRole secret ID for authentication |
|
(empty) |
Path to database credentials secret in Vault |
|
|
Vault request timeout in milliseconds |
|
|
Verify Vault server’s TLS certificate |
WEBAPI Section
The [WEBAPI] section configures the built-in web API (REST) listener.
| Parameter | Default | Description |
|---|---|---|
|
|
Enable the built-in web API listener |
|
|
IP address to listen on. Accepts an IP address, |
|
|
HTTP listener port |
|
|
Enable HTTPS listener. Silently disabled if |
|
|
IP address for the HTTPS listener |
|
|
HTTPS listener port |
|
(empty) |
Path to TLS certificate for the HTTPS listener |
|
(empty) |
Path to TLS private key for the HTTPS listener |
|
|
Path to the |
CLUSTER Section
The [CLUSTER] section configures the built-in high availability cluster.
See High Availability for setup instructions.
| Parameter | Default | Description |
|---|---|---|
|
|
Enable cluster mode |
|
(empty) |
This node’s name in the cluster |
|
(empty) |
This node’s client-reachable address, advertised to redirected clients when this node is active (cluster channel addressing uses |
|
(empty) |
Peer node address |
|
|
TCP port for the cluster communication channel |
|
(ChannelPort) |
Peer node’s cluster channel port, if different |
|
|
Replicate collected data to the standby node |
|
|
Cluster lease validity time (seconds) |
|
|
Cluster lease refresh interval (seconds) |
|
|
Fencing margin (seconds) |
|
|
Cluster journal retention time (seconds) |
|
(empty) |
Command executed when this node is promoted to primary |
|
(empty) |
Command executed when this node is demoted to standby |
AI Section
The [AI] section configures AI assistant providers.
See AI Assistant for details.
ENV Section
The [ENV] section allows setting environment variables for the server process.
Any key-value pair in this section is set as an environment variable before server initialization.
[ENV]
ORACLE_HOME = /opt/oracle/instantclient
LD_LIBRARY_PATH = /opt/oracle/instantclient
Example
# Database configuration
DBDriver = pgsql.ddr
DBServer = db.example.com
DBName = netxms_db
DBLogin = netxms
# Obfuscated with nxencpasswd; plain text works as well
DBPassword = hP3fIE7/w/rCpgp+8SvHuMKmCn7xK8e4wqYKfvErx7g=
# Logging
LogFile = /var/log/netxmsd.log
LogRotationMode = 1
LogHistorySize = 7
WriteLogAsJson = no
# Directories
DataDirectory = /var/lib/netxms
# Load additional modules
Module = nxleef.nsm
# Fanout driver for InfluxDB
PerfDataStorageDriver = influxdb
# Tunnel certificates
TunnelCertificate = /etc/netxms/tunnel.crt
TunnelCertificateKey = /etc/netxms/tunnel.key
[VAULT]
URL = https://vault.example.com:8200
AppRoleId = my-app-role
AppRoleSecretId = my-secret-id
DBCredentialPath = secret/data/netxms/db
[ENV]
ORACLE_HOME = /opt/oracle/instantclient
netxmsd Command-Line Options
| Option | Description |
|---|---|
|
Use alternate configuration file instead of default search path |
|
Check configuration file for errors and exit |
|
Run as daemon (UNIX) or service (Windows) |
|
Set debug level (0-9). Overrides |
|
Run database consistency check before startup (invokes |
|
Generate sample configuration file and exit |
|
Display help message and exit |
|
Show log file location (from configuration) and exit |
|
Disable interactive debug console |
|
Set debug level for a specific log tag (e.g., |
|
Enable SQL query tracing (sets |
|
Display version information and exit |
|
Add a configuration file entry at startup (e.g., |
UNIX/Linux only:
| Option | Description |
|---|---|
|
Path to PID file (default: |
|
Run as systemd daemon (use |
Windows only:
| Option | Description |
|---|---|
|
Install as Windows service |
|
Remove Windows service |
|
Start Windows service |
|
Stop Windows service |
|
Login name for service account (use with |
|
Password for service account (use with |
|
Create service with manual start type (use with |
|
Ignore service start command if service is configured for manual start |
Agent Configuration File (nxagentd.conf)
The agent configuration file controls agent behavior, security, metrics collection, and server connectivity. It is read at agent startup; most changes require an agent restart (exception: policies pushed from server).
For the complete configuration guide, see Agent Configuration.
Configuration File Search Order
If no configuration file is specified with -c, the agent searches automatically:
UNIX/Linux/macOS:
-
$NETXMS_HOME/etc/nxagentd.conf(ifNETXMS_HOMEenvironment variable is set) -
SYSCONFDIR/nxagentd.conf(compile-time prefix, typically/usr/local/etc) -
/etc/nxagentd.conf(fallback)
Windows:
-
<InstallDir>\etc\nxagentd.conf(from registry:HKEY_LOCAL_MACHINE\SOFTWARE\NetXMS\Agent) -
C:\nxagentd.conf(fallback)
Syntax
Same Key = Value format as the server configuration.
Lines starting with # are comments.
Boolean parameters accept yes/no, true/false, or 1/0.
Additional configuration files are loaded from the directory specified by the ConfigIncludeDir parameter; by default the agent searches for an nxagentd.conf.d directory in the standard configuration file locations.
Server Access Control
| Parameter | Default | Description |
|---|---|---|
|
(none) |
Comma-separated list of server addresses (IP, hostname, or CIDR) with full control: read data, execute actions, modify config, restart agent, upgrade agent, install packages, upload files. |
|
(none) |
Servers with intermediate access: read data and execute predefined actions (including agent restart via the |
|
(none) |
Servers with read-only access: query metrics and agent metadata, browse and download files, use enabled proxy functions. Cannot execute actions. |
|
(none) |
Servers allowed to perform remote agent upgrades and install software packages without full master access. |
|
|
Shared secret for server-agent authentication. Must match the secret configured on the server for this node. |
|
No |
Require shared secret authentication for all server connections. When disabled, any server in the access list can connect without authentication. |
|
Yes |
Require encryption for incoming server connections (NXCP session encryption). When enabled, unencrypted connections are rejected. |
|
No |
Accept only TLS-protected incoming server connections. Non-TLS connections are rejected when enabled. |
Certificate and TLS
| Parameter | Default | Description |
|---|---|---|
|
(none) |
Path to trusted CA certificate file(s) for verifying server identity. Can be specified multiple times to add multiple trusted CAs. |
|
No |
Verify server TLS certificate against trusted root certificates. When enabled, connections from servers with untrusted certificates are rejected. |
|
(none) |
Path to a CA certificate bundle file for TLS verification. |
|
(none) |
Path to Certificate Revocation List file(s). Can be specified multiple times. Used for certificate-based authentication. |
|
|
Interval in seconds to reload CRL files. Default is 4 hours. |
|
No |
Enable certificate revocation checks when verifying digital signatures of executable files (User Support Application executable, software packages). Windows only. |
|
No |
Enable detailed SSL/TLS protocol tracing in agent log. Useful for debugging TLS connection issues. |
|
(unset) |
Semicolon-separated list of trusted Authenticode publisher names for validating software packages deployed through the agent. When unset, packages signed with the Raden Solutions release signing certificate are trusted. Windows only. |
Tunnel Configuration
| Parameter | Default | Description |
|---|---|---|
|
(none) |
Server address for establishing a tunnel connection, in the format |
|
|
Interval in seconds between tunnel keepalive messages. Helps detect broken connections through firewalls. |
Logging
| Parameter | Default | Description |
|---|---|---|
|
(platform-dependent) |
Path to agent log file. Default is |
|
|
Number of rotated log files to keep when using file-based logging. |
|
|
Log rotation mode: 0 = no rotation, 1 = daily rotation, 2 = rotation by size (when file exceeds |
|
|
Maximum log file size in bytes before rotation (only applies when |
|
(empty) |
Suffix appended to daily log file name when using daily rotation mode. Supports strftime format specifiers. When empty, |
|
|
Global debug verbosity level (0-9). Level 0 disables debug output. Higher values produce more verbose output. |
|
(none) |
Comma-separated list of debug tags with specific levels, allowing fine-grained debug control. Format: |
|
No |
Write log entries in JSON format. Useful for integration with log aggregation tools like Elasticsearch or Splunk. |
|
No |
Use a background thread for writing log entries to reduce I/O impact on agent performance. |
Network
| Parameter | Default | Description |
|---|---|---|
|
|
IP address to listen on for incoming server connections. Use |
|
|
TCP port to listen on for incoming server connections. |
|
|
Maximum number of concurrent server sessions. 0 means auto-detect (32, or 1024 when proxy mode is enabled). |
|
|
Idle session timeout in seconds. Sessions with no activity for this duration are automatically closed. |
|
No |
Disable IPv4 protocol support. Agent will only use IPv6. |
|
No |
Disable IPv6 protocol support. Agent will only use IPv4. |
File and Directory Paths
| Parameter | Default | Description |
|---|---|---|
|
|
Directory used for file transfer operations between server and agent. On Windows, default is |
|
(platform-dependent) |
Directory for agent persistent data (agent ID, certificates, local database). Resolved at runtime based on installation prefix. |
|
(DataDirectory) |
Directory for writing crash dump files. Windows only. |
|
|
Limit on the total size of the crash dump directory. Accepts size suffixes (e.g., |
|
(auto) |
Directory from which additional configuration files are loaded. By default the agent searches for |
|
(none) |
File creation mode mask (umask) for files created by the agent. UNIX only. Specified as octal value (e.g., |
Agent Behavior
| Parameter | Default | Description |
|---|---|---|
|
|
Delay in seconds before the agent starts accepting connections after launch. Useful to wait for dependent services. |
|
(none) |
Process name to wait for before starting. Agent will not begin operation until this process is detected running. |
|
Yes |
Automatically load platform-appropriate subagents (e.g., |
|
Yes |
Allow execution of actions defined in the agent configuration. Set to |
|
No |
Allow arbitrary command execution through the agent. When disabled, only pre-configured actions can be executed. Enable with caution as it allows the server to run any command on the agent host. |
|
No |
Automatically start a user-mode session agent on Windows. Used for monitoring user sessions and desktop-level metrics. Windows only. |
|
No |
Report the User Support Application as installed even if its installation is not detected. Windows only. |
|
|
Name of the User Support Application executable started and monitored by the agent. Windows only. |
|
No |
Enable watchdog that restarts the User Support Application in active user sessions if it is not running. Windows only. |
|
Yes |
Enable the local push connector (named pipe or local socket) used by |
|
No |
Enable the watchdog process that automatically restarts the agent if it crashes. |
|
|
Time in seconds given to a freshly started external subagent to connect to the master agent before the watchdog considers it hung and restarts it. Values below 30 are raised to 30. Windows only. |
|
No |
Enable watchdog that restarts external subagent processes that terminate or fail to connect to the master agent. Windows only. |
|
No |
Synchronize agent system time with the NetXMS server. Only applies if the agent runs with sufficient privileges for time adjustment. |
|
Yes (Windows), No (other platforms) |
Create crash dump files when the agent process crashes. Useful for debugging. |
|
Yes (Windows) |
Write full memory crash dumps instead of minidumps. Produces larger files but provides more debugging information. Windows only. |
|
No |
Terminate agent on C runtime library errors. Windows only. |
|
No |
Log warnings about unresolved symbols in loaded subagent modules. Useful for debugging subagent load issues. |
|
(hostname) |
Custom system name reported by the agent. If empty, the operating system hostname is used. |
|
(none) |
Name of the master agent connection used when this agent process runs as an external subagent loader. When set, the agent registers itself with the specified master agent as an external subagent instead of operating standalone. |
|
(none) |
Custom suffix appended to the platform name reported by the agent. Used to distinguish custom agent builds or package variants. |
|
|
Zone UIN (Unique Identification Number) for this agent. Used in multi-zone deployments where agents in different zones may have overlapping IP addresses. Zone 0 is the default zone. |
Proxy Functions
| Parameter | Default | Description |
|---|---|---|
|
No |
Enable agent proxy mode. Allows this agent to forward NetXMS protocol requests to other agents in isolated network segments. |
|
No |
Enable SNMP proxy mode. Allows this agent to forward SNMP requests to devices not directly reachable from the server. |
|
No |
Enable SNMP trap proxy mode. The agent listens for SNMP traps and forwards them to the NetXMS server. |
|
No |
Enable syslog proxy mode. The agent listens for syslog messages and forwards them to the NetXMS server. |
|
No |
Enable TCP proxy mode. Allows the server to establish TCP connections through this agent to remote hosts. |
|
No |
Enable TFTP proxy mode. Allows forwarding TFTP requests through this agent. |
|
No |
Enable Modbus TCP proxy mode. Allows the server to query Modbus devices through this agent. |
|
No |
Enable EtherNet/IP proxy mode. Allows the server to query EtherNet/IP devices through this agent. |
|
No |
Enable web service proxy mode. Allows the server to make HTTP/HTTPS requests through this agent to web services not directly reachable. |
SNMP Proxy Settings
| Parameter | Default | Description |
|---|---|---|
|
|
SNMP request timeout in milliseconds for proxied SNMP requests. 0 means use the server-configured timeout. |
|
|
IP address to listen on for incoming SNMP traps. Only applies when |
|
|
UDP port to listen on for incoming SNMP traps. Only applies when |
|
|
UDP port to listen on for incoming syslog messages. Only applies when |
Connectors
| Parameter | Default | Description |
|---|---|---|
|
Yes (Windows), No (UNIX) |
Enable the control connector for local process communication. On Windows, enables named pipe for service control. On UNIX, enables a local socket. |
|
Yes |
Enable the event connector for receiving Windows events or session agent events. |
|
|
TCP port for user session agent communication. Set to 0 to disable the session agent listener. |
Data Collection
| Parameter | Default | Description |
|---|---|---|
|
|
Minimum number of threads in the data collection thread pool. |
|
|
Maximum number of threads in the data collection thread pool. |
|
|
Number of data values sent in a single reconciliation batch when reconnecting to the server after an outage. |
|
|
Timeout in milliseconds for data reconciliation operations. |
|
|
Interval in milliseconds between flushes of the local data cache to the server. |
|
|
Maximum number of data values in a single write transaction. |
|
|
Number of days to keep collected data in the local database when the server is unreachable. Data older than this is discarded. |
|
No |
Disable the local SQLite database used for offline data caching. When disabled, data collected during server outages is lost. |
|
No |
Disable the heartbeat listener used for connection monitoring. |
Execution Timeouts
| Parameter | Default | Description |
|---|---|---|
|
|
Default timeout in milliseconds for external process execution (external metrics, actions). If set to 0, defaults to 5000 (5 seconds). |
|
|
Timeout in milliseconds for external metric execution. Overrides |
|
|
Timeout in milliseconds for external metric provider execution. Default is 30 seconds. |
|
|
Timeout in milliseconds for external command (action) execution. 0 means use |
|
|
Threshold in milliseconds for logging slow database queries in the agent log. |
Web Service
| Parameter | Default | Description |
|---|---|---|
|
|
Time in seconds before cached web service responses expire. Default is 10 minutes. |
|
|
Maximum number of threads in the web service request thread pool. |
Subagent and Extension Loading
| Directive | Description |
|---|---|
|
Load a subagent module. Can be specified multiple times for multiple subagents. Example: |
|
Accept a connection from an external subagent process via named pipe or local socket. |
|
Register a generic agent extension: the agent spawns the specified command as an extension process and communicates with it. Can be specified multiple times. |
External Metrics and Actions
| Directive | Description |
|---|---|
|
Define a metric collected by running an external command. Arguments from the DCI are substituted as |
|
Define a parameterized metric. The |
|
Define a list metric. Each line of command output becomes a list item. |
|
Define a table metric. |
|
Define a metric provider that runs periodically and caches results for multiple metrics. |
|
Define an external metric that runs in the background and caches results. Unlike regular external metrics, the cached value is returned immediately without waiting for command execution. |
|
Define an action that can be executed remotely by the server. Arguments are substituted as |
|
Comma-separated list of environment variable names that can be passed to externally executed commands. By default, the agent sanitizes the environment for security. |
Deprecated Parameters
These parameters are supported for backward compatibility but should be replaced with their current equivalents.
| Deprecated Parameter | Current Equivalent | Notes |
|---|---|---|
|
|
Renamed for consistency. |
|
|
Shell execution is now handled automatically based on platform. |
|
|
Shell execution is now handled automatically based on platform. |
|
|
Shell execution is now handled automatically based on platform. |
|
|
Renamed for consistency. |
|
|
Alternate deprecated name. |
|
|
Renamed for consistency. |
|
|
Renamed for consistency. |
|
|
Renamed for clarity. |
|
|
Renamed to distinguish from min pool size. |
|
|
Obfuscated secrets are now put into |
|
|
Renamed to Zone UIN (Unique Identification Number). |
Example
MasterServers = 10.0.0.1
LogFile = /var/log/nxagentd.log
FileStore = /tmp
RequireEncryption = yes
RequireAuthentication = yes
SharedSecret = MySecretPhrase
SubAgent = linux.nsm
SubAgent = logwatch.nsm
ExternalMetric = Hardware.SerialNumber: dmidecode -s system-serial-number
ExternalMetric = Disk.UsedPercent(*): df --output=pcent $1 | tail -1 | tr -d ' %'
Action = RestartService: systemctl restart $1
Related Pages
-
Server Configuration — operational guide for server setup
-
Agent Configuration — operational guide for agent setup
-
Server Configuration Variables — runtime configuration variables
-
Agent Metrics — built-in agent metrics