Server Configuration Variables

Server configuration variables are stored in the database and can be modified at runtime without restarting the server (unless noted otherwise with *). They control server behavior, polling intervals, security settings, and feature toggles.

Use the management client (Configuration > Server Configuration) to view and modify variables, or nxdbmgr from the command line:

nxdbmgr set VariableName value

For operational guidance, see Server Configuration.

Variables marked with * require a server restart after modification. All other variables take effect immediately.

Agent

Settings for communication between the server and NetXMS agents.

Variable Default Description

Agent.CommandTimeout

4000

Timeout for commands sent to agent (milliseconds)

Agent.ConnectionTimeout

5000

Timeout for establishing connection with agent (milliseconds)

Agent.DefaultCacheMode *

2

Default agent cache mode for offline data collection (1 = on, 2 = off)

Agent.DefaultEncryptionPolicy *

1

Default encryption policy for agent communications (0 = disabled, 1 = allowed, 2 = preferred, 3 = required)

Agent.DefaultProtocolCompressionMode

1

Default agent protocol compression mode (1 = enabled, 2 = disabled)

Agent.EnableRegistration

1

Enable agent self-registration via nxagentd -r

Agent.RestartWaitTime

0

Period after agent restart during which the agent is not considered unreachable (seconds; 0 = disabled)

Agent.UploadBandwidthLimit

0

Bandwidth limit for file uploads to agent (KB/s; 0 = unlimited)

Agent.Upgrade.WaitTime

600

Maximum wait time for agent restart after upgrade (seconds)

AgentPolicy

Variable Default Description

AgentPolicy.MaxFileSize

134217728

Maximum file size for exported agent policies (bytes)

AgentTunnels

Settings for agent tunnel connections (certificate-based agent-to-server communication).

Variable Default Description

AgentTunnels.BindByIPAddress

0

Bind tunnels by IP address instead of system information

AgentTunnels.Certificates.ReissueInterval *

30

Interval between reissuing agent certificates (days)

AgentTunnels.Certificates.ValidityPeriod *

90

Validity period for newly issued agent certificates (days)

AgentTunnels.ListenPort *

4703

TCP port for incoming agent tunnel connections

AgentTunnels.NewNodesContainer

(empty)

Container name for automatically created nodes from unbound tunnels

AgentTunnels.TLS.MinVersion

2

Minimal TLS protocol version for agent tunnels (0 = TLS 1.0, 1 = TLS 1.1, 2 = TLS 1.2, 3 = TLS 1.3)

AgentTunnels.UnboundTunnelTimeout

3600

Inactivity timeout for unbound agent tunnels (seconds)

AgentTunnels.UnboundTunnelTimeoutAction

0

Action when unbound tunnel timeout expires (0 = reset tunnel, 1 = generate event, 2 = bind tunnel to existing node, 3 = bind tunnel to existing node or create new node)

AI

Settings for the AI assistant and AI operator subsystem.

Variable Default Description

AI.MaxBackgroundIterations

64

Maximum number of LLM tool-call iterations for background AI assistant requests (event processing, scheduled tasks, incident analysis) before the request is stopped

AI.MaxInteractiveIterations

30

Maximum number of LLM tool-call iterations for interactive AI assistant chats before the user is asked whether to continue

AIOperator.Enabled

1

Enable AI operator subsystem (global kill switch for all operator instances)

AIOperator.MaxConsecutiveFailures

3

Number of consecutive execution failures after which an AI operator instance is automatically disabled

AIOperatorExecutionLog.RetentionTime

90

Retention time for AI operator execution log records (days)

AIOperatorObservations.MaxRecordsPerInstance

1000

Default maximum number of retained observations per AI operator instance (can be overridden per operator instance)

AIOperatorObservations.RetentionTime

90

Default retention time for AI operator observations (days; can be overridden per operator instance)

AITaskExecutionLog.RetentionTime

90

Retention time for AI task execution log records (days)

Alarms

Variable Default Description

Alarms.DeleteAlarmsOfDeletedObject

1

Automatically delete alarms when the source object is deleted

Alarms.EnableTimedAck *

1

Enable timed alarm acknowledgment (auto-revert to outstanding after timeout)

Alarms.HistoryRetentionTime

180

Days to keep resolved/terminated alarms in history (0 = forever)

Alarms.IgnoreHelpdeskState

0

Ignore helpdesk state when resolving or terminating alarms

Alarms.ResolveExpirationTime

0

Auto-terminate resolved alarms after N seconds without changes (0 = disabled)

Alarms.StrictStatusFlow

0

Enforce strict alarm status transitions (Outstanding → Acknowledged → Resolved → Terminated)

Alarms.SummaryEmail.Enable

0

Enable alarm summary emails

Alarms.SummaryEmail.Recipients

(empty)

Semicolon-separated list of alarm summary email recipient addresses

Alarms.SummaryEmail.Schedule

0 0 * * *

Cron-style schedule for sending alarm summary emails

AuditLog

Variable Default Description

AuditLog.External.Facility *

13

Syslog facility code for audit log forwarding

AuditLog.External.Port *

514

Target syslog server UDP port

AuditLog.External.Server *

none

Syslog server address for external audit logging; the literal value none disables forwarding

AuditLog.External.Severity *

5

Syslog severity code

AuditLog.External.Tag *

netxmsd-audit

Syslog message tag

AuditLog.External.UseUTF8

0

Use UTF-8 encoding for external audit log messages

AuditLog.RetentionTime

90

Retention time for audit log records (days)

Beacon

Beacon hosts are used by the server to verify its own network connectivity. If all beacon hosts become unreachable, the server assumes it has lost connectivity and will not change node statuses. For an explanation of how beacon hosts work and when to configure them, see Beacon Hosts.

Variable Default Description

Beacon.Hosts *

(empty)

Comma-separated list of beacon host addresses

Beacon.PollingInterval *

1000

Interval between beacon host polls (milliseconds)

Beacon.Timeout *

1000

Timeout to consider a beacon host unreachable (milliseconds)

BusinessServices

Variable Default Description

BusinessServices.Check.AutobindClassFilter

AccessPoint,Cluster,Interface,NetworkService,Node

Comma-separated list of object classes for automatic business service check binding

BusinessServices.Check.Threshold.DataCollection

1

Default threshold for business service DCI checks (1 = warning, 2 = minor, 3 = major, 4 = critical)

BusinessServices.Check.Threshold.Objects

1

Default threshold for business service object checks (1 = warning, 2 = minor, 3 = major, 4 = critical)

BusinessServices.History.RetentionTime

90

Retention time for business service historical data (days)

CAS

Central Authentication Service (CAS) integration for single sign-on.

Variable Default Description

CAS.AllowedProxies

(empty)

Comma-separated list of allowed CAS proxy addresses

CAS.Host

localhost

CAS server DNS name or IP address

CAS.Port

8443

CAS server TCP port number

CAS.Service

https://127.0.0.1/nxmc

Service URL to validate (your NetXMS web UI URL)

CAS.TrustedCACert

(empty)

File system path to CAS trusted CA certificate

CAS.ValidateURL

/cas/serviceValidate

URL path for service validation on CAS server

Client

Settings affecting the management console (client) behavior and display.

Variable Default Description

Client.AlarmList.DisplayLimit

4096

Maximum number of alarms displayed in the alarm browser

Client.BaseURL

https://{server-name}

Base URL for forming direct access URLs to objects and alarms; the {server-name} macro is replaced with the name of the server the user is currently logged into

Client.DashboardDataExport.EnableInterpolation *

1

Enable data interpolation in dashboard data export

Client.DefaultConsoleDateFormat

dd.MM.yyyy

Default date display format in the management console

Client.DefaultConsoleShortTimeFormat

HH:mm

Default short time format in the management console

Client.DefaultConsoleTimeFormat

HH:mm:ss

Default long time format in the management console

Client.DefaultLineChartPeriod

60

Default time period for ad-hoc line charts (minutes)

Client.EnableWelcomePage

1

Enable the welcome page in the client application

Client.FirstPacketTimeout

2000

Timeout for receiving first packet from client (milliseconds)

Client.InactivityTimeout

0

User inactivity timeout (seconds; 0 = disabled)

Client.KeepAliveInterval *

60

Interval between keep-alive packets to connected clients (seconds)

Client.ListenerPort *

4701

Server port for incoming client connections

Client.MinVersion

(empty)

Minimum client version allowed for connection

Client.MinViewRefreshInterval

300

Minimum interval between view refresh in the client (milliseconds)

Client.ObjectBrowser.AutoApplyFilter

1

Auto-apply filter in object browser while typing

Client.ObjectBrowser.DragAndDropMode

0

Controls drag and drop behavior in the object browser (0 = enable, 1 = confirm, 2 = disable)

Client.ObjectBrowser.FilterDelay

300

Delay between typing and applying filter in object browser (milliseconds)

Client.ObjectBrowser.MinFilterStringLength

1

Minimum filter string length for automatic apply

Client.ObjectBrowser.ShowTargetsUnderTemplates

0

Show template target objects under templates in the object browser

Client.ObjectOverview.ShowCommentsOnlyIfPresent

1

Show comments section in object overview only when comments exist

Client.TileServerURL

https://tile.netxms.org/osm/

Base URL for the map tile server

DataCollection

Variable Default Description

DataCollection.Aggregation.BackfillOnEnable

1

When enabling aggregation, initialize per-DCI watermarks to the earliest retained raw timestamp so existing history is backfilled on the next rollup pass

DataCollection.Aggregation.DailyCloseWindow

1800

Lag before a closed day is rolled up into the daily aggregate, giving late samples time to arrive (seconds)

DataCollection.Aggregation.DefaultDailyRetentionTime

1825

Default retention time for daily DCI aggregates (days; individual DCIs can override)

DataCollection.Aggregation.DefaultHourlyRetentionTime

365

Default retention time for hourly DCI aggregates (days; individual DCIs can override)

DataCollection.Aggregation.Enabled *

0

Master switch for DCI data aggregation; when enabled, the server rolls up raw DCI values into hourly and daily aggregates for eligible items

DataCollection.Aggregation.HourlyCloseWindow

300

Lag before a closed hour is rolled up into the hourly aggregate, giving late samples time to arrive (seconds)

DataCollection.Aggregation.MaxAutoSelectPoints

5000

Upper bound on the number of points returned by auto-selected aggregate tier when serving DCI history queries

DataCollection.Aggregation.TSDB.RefreshScheduleInterval

600

TimescaleDB continuous aggregate refresh cadence (seconds)

DataCollection.Aggregation.TSDB.RefreshStartOffset

30

TimescaleDB continuous aggregate refresh lookback window (days); caps the outage length that can be recovered via late-arriving data on TimescaleDB backends

DataCollection.ApplyDCIFromTemplateToDisabledDCI *

1

Apply all DCIs from template including disabled ones

DataCollection.DefaultDCIPollingInterval

60

Polling interval for all DCIs whose collection schedule is set to Server default (seconds)

DataCollection.DefaultDCIRetentionTime

30

Data retention time for all DCIs whose history retention is set to Server default (days)

DataCollection.InstancePollingInterval

600

Instance discovery polling interval (seconds)

DataCollection.InstanceRetentionTime

7

Retention time for removed DCI instances (days; 0 = delete immediately)

DataCollection.OfflineDataRelevanceTime *

86400

Time period within which offline (cached) data is considered relevant (seconds)

DataCollection.OnDCIDelete.TerminateRelatedAlarms

1

Terminate related alarms when DCI is deleted

DataCollection.Scheduler.RequireConnectivity *

0

Skip DCI scheduling if communication with the node is unavailable

DataCollection.ScriptErrorReportInterval

86400

Minimum interval between reporting DCI script execution errors (seconds)

DataCollection.StartupDelay *

0

Enable randomized DCI polling delays on server startup

DataCollection.TemplateRemovalGracePeriod

0

Grace period before removing DCIs after template unbind (days; 0 = immediate)

DataCollection.ThresholdRepeatInterval *

0

System-wide interval for resending threshold violation events (seconds; 0 = disabled)

DBConnectionPool

Database connection pool settings. All require server restart.

Variable Default Description

DBConnectionPool.BaseSize *

10

Number of database connections created at startup

DBConnectionPool.CooldownTime *

300

Inactivity time before closing an extra database connection (seconds)

DBConnectionPool.MaxLifetime *

14400

Maximum lifetime for a single database connection (seconds)

DBConnectionPool.MaxSize *

30

Maximum number of connections in the pool

DBWriter

Database writer thread settings for DCI data persistence. All require server restart unless noted.

Variable Default Description

DBWriter.BackgroundWorkers *

1

Number of background worker threads for DCI data writer

DBWriter.DataQueues *

1

Number of queues for DCI data writer

DBWriter.HouseKeeperInterlock

0

Block background database writes during housekeeper deletion cycles (0 = auto, 1 = off, 2 = on; in auto mode the interlock is active only on Microsoft SQL Server)

DBWriter.InsertParallelismDegree *

1

Degree of parallelism for INSERT statements (useful for TimescaleDB)

DBWriter.MaxQueueSize

0

Maximum DCI data writer queue size (0 = unlimited)

DBWriter.MaxRecordsPerStatement *

100

Maximum records per SQL statement for delayed writes

DBWriter.MaxRecordsPerTransaction *

1000

Maximum records per transaction for delayed writes

DBWriter.RawDataFlushInterval *

30

Interval between flushing accumulated raw DCI data to the database (seconds)

DBWriter.UpdateParallelismDegree *

1

Degree of parallelism for UPDATE statements

DefaultNotificationChannel

Variable Default Description

DefaultNotificationChannel.SMTP.Html

SMTP-HTML

Default notification channel name for SMTP HTML formatted messages

DefaultNotificationChannel.SMTP.Text

SMTP-Text

Default notification channel name for SMTP text formatted messages

Events

Variable Default Description

Events.Correlation.TopologyBased

1

Enable topology-based event correlation (suppresses duplicate node-down events behind a failed router)

Events.DeleteEventsOfDeletedObject

1

Automatically delete events when the source object is deleted

Events.LogRetentionTime

90

Retention time for event log records (days)

Events.ProcessingMetadata

0

Record event processing metadata (matched event processing policy rules and the effects they produced) in the event log

Events.Processor.PoolSize *

1

Number of event processing threads (>1 enables parallel processing)

Events.Processor.QueueSelector *

%z

Queue selector expression for parallel event processing (determines which queue an event is placed in)

Events.ReceiveForwardedEvents

0

Accept events forwarded from other NetXMS servers

EventStorm

Event storm detection prevents runaway event generation from overwhelming the server.

Variable Default Description

EventStorm.Duration *

15

Time period for event rate to exceed threshold to trigger storm detection (seconds)

EventStorm.EnableDetection *

0

Enable event storm detection

EventStorm.EventsPerSecond *

1000

Events per second threshold for event storm condition

Housekeeper

The housekeeper runs periodic cleanup tasks to remove expired data from the database.

Variable Default Description

Housekeeper.DisableCollectedDataCleanup

0

Disable automatic DCI data cleanup during housekeeper runs

Housekeeper.StartTime *

02:00

Time when housekeeper starts daily (HH:MM)

Housekeeper.Throttle.HighWatermark

250000

Database writer queue depth (main or collected data writer queue) at which the housekeeper pauses deletions

Housekeeper.Throttle.LowWatermark

50000

Database writer queue depth below which a paused housekeeper resumes deletions

ICMP

Variable Default Description

ICMP.CollectPollStatistics

1

Collect ICMP statistics during status polls for all nodes

ICMP.PingSize

46

ICMP packet data size (bytes)

ICMP.PingTimeout

1500

ICMP ping timeout (milliseconds)

ICMP.PollingInterval

60

ICMP polling interval (seconds)

ICMP.StatisticPeriod

60

Number of polls over which to calculate ICMP statistics

Jira

Jira integration for helpdesk ticket management.

Variable Default Description

Jira.IssueType

Task

Default Jira issue type for new tickets

Jira.Login

netxms

Jira login name

Jira.Password

(empty)

Jira password (masked)

Jira.ProjectCode

NETXMS

Jira project code

Jira.ProjectComponent

(empty)

Jira project component for new tickets

Jira.ResolvedStatus

Done

Comma-separated Jira issue status codes indicating resolved state

Jira.ServerURL

https://jira.atlassian.com

URL of the Jira server

Jira.Webhook.Enable *

1

Enable Jira webhook on the web API listener

Jira.Webhook.Secret

(empty)

Secret used for validation of Jira webhook calls (validation disabled if empty)

LDAP

LDAP integration for user and group synchronization. See also User Management.

Variable Default Description

LDAP.ConnectionString

ldap://localhost:389

LDAP connection URI(s); multiple URIs can be space-separated

LDAP.GroupClass

(empty)

LDAP object class representing group objects (e.g., groupOfNames, group)

LDAP.GroupUniqueId

(empty)

LDAP attribute used as unique identifier for group objects (e.g., objectGUID, entryUUID)

LDAP.Mapping.Description

(empty)

LDAP attribute mapped to user description

LDAP.Mapping.Email

(empty)

LDAP attribute mapped to user email address

LDAP.Mapping.FullName

displayName

LDAP attribute mapped to user full name

LDAP.Mapping.GroupName

(empty)

LDAP attribute mapped to group login name

LDAP.Mapping.PhoneNumber

(empty)

LDAP attribute mapped to user phone number

LDAP.Mapping.UserName

(empty)

LDAP attribute mapped to user login name (e.g., sAMAccountName, uid)

LDAP.NewUserAuthMethod

5

Authentication method for LDAP-created user objects (5 = LDAP)

LDAP.PageSize

1000

Maximum records returned in one LDAP search page

LDAP.SearchBase

(empty)

DN for starting LDAP search (e.g., dc=example,dc=com)

LDAP.SearchFilter

(empty)

LDAP search filter string (e.g., (objectClass=person))

LDAP.SyncInterval

0

Synchronization interval with LDAP server (minutes; 0 = disabled)

LDAP.SyncUser

(empty)

User login (DN) for LDAP synchronization

LDAP.SyncUserPassword

(empty)

Password for LDAP synchronization user (masked)

LDAP.UserClass

(empty)

LDAP object class representing user objects (e.g., user, inetOrgPerson)

LDAP.UserDeleteAction

1

Action when an LDAP user/group is deleted during sync (0 = delete, 1 = disable)

LDAP.UserUniqueId

(empty)

LDAP attribute used as unique identifier for user objects (e.g., objectGUID, entryUUID)

NetworkDiscovery

Variable Default Description

NetworkDiscovery.ActiveDiscovery.BlockSize

1024

Number of addresses scanned in one block during active discovery

NetworkDiscovery.ActiveDiscovery.EnableSNMPProbing

1

Enable SNMP probing during active discovery

NetworkDiscovery.ActiveDiscovery.EnableTCPProbing

0

Enable TCP probing during active discovery

NetworkDiscovery.ActiveDiscovery.InterBlockDelay

0

Delay between scanning address blocks (milliseconds)

NetworkDiscovery.ActiveDiscovery.Interval

7200

Active discovery interval (seconds)

NetworkDiscovery.ActiveDiscovery.Schedule

(empty)

Cron-style schedule for active discovery (overrides interval)

NetworkDiscovery.DisableProtocolProbe.Agent

0

Disable NetXMS agent probing of discovered addresses

NetworkDiscovery.DisableProtocolProbe.EtherNetIP

0

Disable EtherNet/IP probing of discovered addresses

NetworkDiscovery.DisableProtocolProbe.SNMP.V1

0

Disable SNMP v1 probing of discovered addresses

NetworkDiscovery.DisableProtocolProbe.SNMP.V2

0

Disable SNMP v2c probing of discovered addresses

NetworkDiscovery.DisableProtocolProbe.SNMP.V3

0

Disable SNMP v3 probing of discovered addresses

NetworkDiscovery.DisableProtocolProbe.SSH

0

Disable SSH probing of discovered addresses

NetworkDiscovery.Filter.Flags

0

Discovery filter settings bitmask

NetworkDiscovery.MergeDuplicateNodes

0

Merge duplicate nodes if discovered with the same identity

NetworkDiscovery.PassiveDiscovery.Interval

900

Passive discovery interval (seconds)

NetworkDiscovery.Type *

0

Discovery type (0 = disabled, 1 = passive, 2 = active, 3 = both)

NetworkDiscovery.UseDNSNameForDiscoveredNodes

0

Use DNS name instead of IP address for newly discovered nodes

NetworkDiscovery.UseFQDNForNodeNames *

1

Use fully qualified domain names for discovered nodes

NetworkDiscovery.UseSNMPTraps *

0

Use SNMP trap information as a discovery source

NetworkDiscovery.UseSyslog *

0

Use syslog messages as a discovery source

NotificationChannels

Variable Default Description

NotificationChannels.MaxQueueSize

500

Maximum notification channel queue size (0 = unlimited)

NotificationChannels.MaxRetryCount

30

Maximum retry count for sending notification messages

NotificationChannels.RateLimit.ChannelBurst

0

Default channel-level burst size for rate limiting (messages; 0 = disabled)

NotificationChannels.RateLimit.ChannelRate

0

Default channel-level sustained rate for rate limiting (messages; 0 = disabled)

NotificationChannels.RateLimit.ChannelRateUnit

minute

Time unit for channel rate limit (second, minute, hour)

NotificationChannels.RateLimit.DigestInterval

300

Interval between digest notification deliveries (seconds)

NotificationChannels.RateLimit.DigestThreshold

50

Queue depth triggering digest mode (messages; 0 = disabled)

NotificationChannels.RateLimit.RecipientBurst

0

Default per-recipient burst size for rate limiting (messages; 0 = disabled)

NotificationChannels.RateLimit.RecipientRate

0

Default per-recipient sustained rate for rate limiting (messages; 0 = disabled)

NotificationChannels.RateLimit.RecipientRateUnit

minute

Time unit for recipient rate limit (second, minute, hour)

NXSL

Variable Default Description

NXSL.EnableContainerFunctions

1

Enable server-side NXSL functions for managing containers (CreateContainer, DeleteObject, etc.)

NXSL.EnableFileIOFunctions *

0

Enable server-side NXSL file I/O functions (security-sensitive)

Objects

Object management and polling settings. This is the largest category of server configuration variables.

General

Variable Default Description

Objects.AutobindOnConfigurationPoll

1

Evaluate auto-bind rules during configuration polls

Objects.AutobindPollingInterval

3600

Auto-bind/auto-apply rule evaluation interval (seconds)

Objects.ConfigurationPollingInterval

3600

Configuration poll interval (seconds)

Objects.Conditions.PollingInterval

60

Interval between polling condition objects (seconds)

Objects.DeleteUnreachableNodesPeriod

0

Delete unreachable nodes after specified number of days (0 = disabled)

Objects.EnableZoning *

1

Enable zoning support for overlapping IP address ranges

Objects.PollCountForStatusChange *

1

Consecutive unsuccessful polls required to declare an interface as down

Objects.StatusPollingInterval

60

Status poll interval (seconds)

Objects.SyncInterval *

60

Interval between writing object changes to the database (seconds)

Access Points

Variable Default Description

Objects.AccessPoints.ContainerAutoBind

0

Enable container auto-bind for access point objects

Objects.AccessPoints.RetentionTime

72

Retention time for disappeared access points (hours)

Objects.AccessPoints.TemplateAutoApply

0

Enable template auto-apply for access point objects

Assets

Variable Default Description

Objects.Assets.AllowDeleteIfLinked

0

Allow deletion of assets linked to nodes

Clusters

Variable Default Description

Objects.Clusters.ContainerAutoBind

0

Enable container auto-bind for cluster objects

Objects.Clusters.TemplateAutoApply

0

Enable template auto-apply for cluster objects

Collectors

Variable Default Description

Objects.Collectors.ContainerAutoBind

0

Enable container auto-bind for collector objects

Objects.Collectors.TemplateAutoApply

0

Enable template auto-apply for collector objects

Interfaces

Variable Default Description

Objects.Interfaces.ClearPeerOnUnmanage

0

Clear interface peer information when interface is set to unmanaged

Objects.Interfaces.DefaultExpectedState

1

Default expected state for new interface objects (0 = up, 1 = auto, 2 = ignore)

Objects.Interfaces.Enable8021xStatusPoll

1

Enable 802.1x port state checking during status polls

Objects.Interfaces.IgnoreIfNotPresent

0

Ignore interfaces with "NOT PRESENT" status from the device

Objects.Interfaces.NamePattern

(empty)

Custom name pattern for interface objects

Objects.Interfaces.PeerRetentionTime

30

Retention time for unconfirmed peer information (days)

Objects.Interfaces.UseAliases

0

Use interface aliases in display (0 = never, 1 = use alias when available, 2 = concatenate alias with name, 3 = concatenate name with alias)

Objects.Interfaces.UseIfXTable

1

Use SNMP ifXTable instead of ifTable for interface enumeration

Maintenance

Variable Default Description

Objects.Maintenance.PredefinedPeriods

1h,8h,1d

Predefined maintenance periods shown in the UI (use m, h, d suffixes)

Mobile Devices

Variable Default Description

Objects.MobileDevices.ContainerAutoBind

0

Enable container auto-bind for mobile device objects

Objects.MobileDevices.TemplateAutoApply

0

Enable template auto-apply for mobile device objects

Network Maps

Variable Default Description

Objects.NetworkMaps.DefaultBackgroundColor

0xffffff

Default background color for new network maps (hex RGB)

Objects.NetworkMaps.DefaultHeight

850

Default network map height (pixels)

Objects.NetworkMaps.DefaultWidth

1300

Default network map width (pixels)

Objects.NetworkMaps.UpdateInterval

60

Interval between automatic map updates (seconds)

Nodes

Variable Default Description

Objects.Nodes.CapabilityExpirationGracePeriod

3600

Grace period for capability expiration after node recovery (seconds)

Objects.Nodes.CapabilityExpirationTime

604800

Time before a detected protocol capability expires if unconfirmed (seconds)

Objects.Nodes.CheckIPConflictOnDNSResolve

0

Block primary IP update if DNS resolves to an IP already assigned to another node

Objects.Nodes.ClearIPAddressOnDNSFailure

0

Clear node primary IP address if DNS resolution fails

Objects.Nodes.ConfigurationPoll.AlwaysCheckSNMP

1

Always check SNMP credentials during configuration polls

Objects.Nodes.FallbackToLocalResolver

0

Fall back to local DNS resolver if zone proxy DNS resolution fails

Objects.Nodes.ReadWinPerfCountersOnDemand

1

Read Windows performance counters only when requested

Objects.Nodes.ResolveDNSToIPOnStatusPoll

0

Resolve DNS name to IP during status polls (0 = never, 1 = always, 2 = on failure only)

Objects.Nodes.ResolveDNSToIPOnStatusPoll.Interval

0

Number of polls between DNS-to-IP resolution attempts when Objects.Nodes.ResolveDNSToIPOnStatusPoll is set to always (0 = every poll)

Objects.Nodes.ResolveNames

1

Resolve node names using DNS, SNMP, or agent hostname

Objects.Nodes.Resolver.AddressFamilyHint

0

Address family hint for DNS resolution (0 = none, 1 = IPv4, 2 = IPv6)

Objects.Nodes.SyncNamesWithDNS

0

Continuously synchronize node names with DNS

Responsible Users

Variable Default Description

Objects.ResponsibleUsers.AllowedTags

(empty)

Comma-separated list of allowed tags for responsible user assignments

Security

Variable Default Description

Objects.Security.CheckTrustedObjects

0

Enable trusted objects check for cross-object access

Sensors

Variable Default Description

Objects.Sensors.ContainerAutoBind

0

Enable container auto-bind for sensor objects

Objects.Sensors.TemplateAutoApply

0

Enable template auto-apply for sensor objects

Status Calculation

Variable Default Description

Objects.StatusCalculation.CalculationAlgorithm *

1

Status calculation algorithm (1 = most critical, 2 = single threshold, 3 = multiple thresholds)

Objects.StatusCalculation.FixedStatusValue *

0

Value for fixed status propagation algorithm

Objects.StatusCalculation.PropagationAlgorithm *

1

Status propagation algorithm (1 = unchanged, 2 = fixed, 3 = relative, 4 = translated)

Objects.StatusCalculation.Shift *

0

Status shift value for relative propagation

Objects.StatusCalculation.SingleThreshold *

75

Threshold percentage for single threshold status calculation

Objects.StatusCalculation.Thresholds *

503C2814

Threshold values for multiple thresholds calculation (hex-encoded 4 bytes)

Objects.StatusCalculation.Translation *

01020304

Status translation values for translated propagation (hex-encoded 4 bytes)

Subnets

Variable Default Description

Objects.Subnets.DefaultSubnetMaskIPv4

24

Default subnet mask for synthetic IPv4 subnets (CIDR notation)

Objects.Subnets.DefaultSubnetMaskIPv6

64

Default subnet mask for synthetic IPv6 subnets (CIDR notation)

Objects.Subnets.DeleteEmpty

0

Automatically delete subnets with no child nodes

OTLP

Settings for OpenTelemetry Protocol (OTLP) data ingestion.

Variable Default Description

OTLP.Logs.EnableStorage

1

Store received OpenTelemetry log records in the database

OTLP.Logs.RetentionTime

90

Retention time for stored OpenTelemetry log records (days)

OTLP.LogUnmatchedResources

0

Log a warning when OTLP resources cannot be matched to any node

OTLP.MatchCacheTTL

300

TTL for the OTLP resource-to-node match cache (seconds)

OTLP.MetricCatalogRetention

86400

Retention time for observed OTLP metric names used by the metric selector (seconds); metrics not seen within this window are dropped from the catalog

PackageDeployment

Variable Default Description

PackageDeployment.JobHistorySize

1000

Maximum number of most recent completed package deployment jobs returned to clients from the deployment history

PackageDeployment.JobRetentionTime

7

Retention time for completed deployment jobs (days)

PackageDeployment.LogRetentionTime

90

Retention time for package deployment log entries (days)

PackageDeployment.MaxRetryCount

16

Maximum number of automatic retry attempts for a failed package deployment (for example, when the target node is offline) before the job is marked as permanently failed

PackageDeployment.MaxThreads *

25

Maximum threads for parallel package deployment

RADIUS

RADIUS server settings for external authentication. See also User Management.

Variable Default Description

RADIUS.AuthMethod

PAP

RADIUS authentication method (PAP, CHAP, MS-CHAPv1, MS-CHAPv2)

RADIUS.NASIdentifier

(empty)

NAS-Identifier attribute value sent in RADIUS requests

RADIUS.NumRetries

5

Number of retries for RADIUS authentication requests

RADIUS.Port

1645

UDP port for primary RADIUS server

RADIUS.SecondaryPort

1645

UDP port for secondary RADIUS server

RADIUS.SecondarySecret

netxms

Shared secret for secondary RADIUS server (masked)

RADIUS.SecondaryServer

none

Secondary RADIUS server hostname or IP address

RADIUS.Secret

netxms

Shared secret for primary RADIUS server (masked)

RADIUS.Server

none

Primary RADIUS server hostname or IP address

RADIUS.ServiceType

8

Service-Type attribute value in RADIUS requests (8 = Authenticate Only)

RADIUS.Timeout

3

Timeout for RADIUS server requests (seconds)

ReportingServer

Variable Default Description

ReportingServer.Enable *

0

Enable reporting server connection

ReportingServer.Hostname *

127.0.0.1

Hostname of the reporting server

ReportingServer.JDBC.Properties

(empty)

Additional JDBC connector properties for reporting

ReportingServer.Port *

4710

Port of the reporting server

ReportingServer.ResultsRetentionTime *

90

Retention time for report execution results (days)

Server

Variable Default Description

Server.AllowedCiphers *

63

Bitmask for allowed encryption algorithms (1 = AES-256, 2 = Blowfish-256, 4 = IDEA, 8 = 3DES, 16 = AES-128, 32 = Blowfish-128)

Server.Color

(empty)

Identification color for this server instance (hex RGB)

Server.CommandOutputTimeout

60

Timeout for local command object tool output (seconds)

Server.EscapeLocalCommands

0

Replace TAB and newline characters with escape sequences in local command output

Server.ImportConfigurationOnStartup *

1

Import configuration from local files on server startup (0 = never, 1 = only missing elements, 2 = always)

Server.MessageOfTheDay

(empty)

Message displayed when a user logs into the management console

Server.Name

(empty)

Display name of this server instance

Server.RoamingMode

1

Enable roaming mode (allows server to change its own IP address)

Server Security

Variable Default Description

Server.Security.2FA.GraceLoginCount

5

Number of grace logins allowed for users who have not configured two-factor authentication when enforcement is active

Server.Security.2FA.TokenTimeout

120

Time the user has to respond to a two-factor authentication challenge before the client cancels the prompt (seconds; 0 = disabled)

Server.Security.2FA.TrustedDeviceTTL

0

Time-to-live for two-factor authentication trusted device tokens (seconds; 0 = disabled)

Server.Security.CaseInsensitiveLoginNames *

0

Treat login names as case-insensitive

Server.Security.ExtendedLogQueryAccessControl

0

Enable extended access control for log queries

Server.Security.GraceLoginCount

5

Number of grace logins allowed after password expiration

Server.Security.IntruderLockoutThreshold

0

Failed login attempts before account lockout (0 = disabled)

Server.Security.IntruderLockoutTime

30

Account lockout duration (minutes)

Server.Security.MinPasswordLength

0

Minimum password length requirement (0 = no minimum)

Server.Security.PasswordComplexity

0

Password complexity enforcement bitmask (1 = digits, 2 = uppercase, 4 = lowercase, 8 = special chars, 16 = forbid alpha sequences, 32 = forbid keyboard sequences)

Server.Security.PasswordExpiration

0

Password expiration time (days; 0 = disabled)

Server.Security.PasswordHash.MemoryCostKB

65536

Argon2id memory cost used when hashing user passwords (KiB); higher values strengthen resistance to GPU/ASIC cracking at the cost of login latency and server memory

Server.Security.PasswordHash.Parallelism

1

Argon2id parallelism (lanes) used when hashing user passwords

Server.Security.PasswordHash.TimeCost

3

Argon2id iteration count used when hashing user passwords

Server.Security.PasswordHistoryLength

0

Number of previous passwords to keep for duplication checks

Server.Security.RestrictLocalConsoleAccess

1

Restrict local debug console access to authenticated users only

SNMP

Variable Default Description

SNMP.Agent.AllowedVersions

7

Bitmask for allowed SNMP versions for built-in agent (1 = v1, 2 = v2c, 4 = v3)

SNMP.Agent.CommunityString

public

Community string for built-in SNMPv1/v2c agent

SNMP.Agent.Enable *

0

Enable built-in SNMP agent

SNMP.Agent.ListenerPort *

161

Listening port for built-in SNMP agent

SNMP.Agent.V3.AuthenticationMethod

0

SNMPv3 authentication method for built-in agent (0 = none, 1 = MD5, 2 = SHA1, 3 = SHA224, 4 = SHA256, 5 = SHA384, 6 = SHA512)

SNMP.Agent.V3.AuthenticationPassword

(empty)

SNMPv3 authentication password for built-in agent (masked)

SNMP.Agent.V3.EncryptionMethod

0

SNMPv3 encryption method for built-in agent (0 = none, 1 = DES, 2 = AES-128, 3 = AES-192, 4 = AES-256)

SNMP.Agent.V3.EncryptionPassword

(empty)

SNMPv3 encryption password for built-in agent (masked)

SNMP.Agent.V3.UserName

netxms

SNMPv3 user name for built-in agent

SNMP.Codepage

(empty)

Default codepage for SNMP string conversions

SNMP.Discovery.SeparateProbeRequests

0

Use separate SNMP request for each test OID during discovery

SNMP.EngineId *

80:00:DF:4B:05:20:10:08:04:02:01:00

Server SNMP engine ID

SNMP.MinVersion

0

Minimum allowed SNMP version for node communication (0 = SNMPv1, 1 = SNMPv2c, 3 = SNMPv3); can be overridden per node using the SysConfig:SNMP.MinVersion custom attribute

SNMP.RequestTimeout *

1500

SNMP request timeout (milliseconds)

SNMP.RetryCount *

3

Number of SNMP request retries

SNMP.Traps.AllowVarbindsConversion

1

Allow automatic conversion of OCTET STRING trap varbinds to hex representation

SNMP.Traps.Enable *

1

Enable SNMP trap receiver

SNMP.Traps.ListenerPort *

162

UDP port for SNMP trap listener

SNMP.Traps.LogAll

0

Log all received SNMP traps including those from unknown sources

SNMP.Traps.LogRetentionTime

90

Retention time for logged SNMP traps (days)

SNMP.Traps.ProcessUnmanagedNodes

0

Process traps from unmanaged nodes

SNMP.Traps.RateLimit.Duration

15

Time period for SNMP trap flood detection (seconds)

SNMP.Traps.RateLimit.Threshold

0

Threshold for SNMP trap flood detection (traps per second; 0 = disabled)

SNMP.Traps.SourcesInAllZones *

0

Search all zones to match trap/syslog source address to node (instead of default zone only)

SNMP.Traps.UnmatchedTrapEvent

1

Generate a default event for unmatched SNMP traps

SNMP.Traps.ValidateCredentials

1

Validate credentials (community string or SNMPv3 user name) of incoming SNMP traps against node credentials and drop traps that fail validation; can be overridden per node using the SysConfig:SNMP.Traps.ValidateCredentials custom attribute

Syslog

Variable Default Description

Syslog.AllowUnknownSources

0

Process syslog messages from sources not registered in NetXMS

Syslog.Codepage

(empty)

Default codepage for syslog message decoding

Syslog.EnableListener *

0

Enable built-in syslog receiver

Syslog.EnableStorage

1

Store received syslog messages in the database

Syslog.IgnoreMessageTimestamp

0

Ignore syslog message timestamp and use server receive time instead

Syslog.ListenPort *

514

UDP port for syslog listener

Syslog.NodeMatchingPolicy *

0

Node matching policy for received syslog messages (0 = IP then hostname, 1 = hostname then IP)

Syslog.ParseUnknownSourceMessages

0

Parse syslog messages from unknown sources (for event generation)

Syslog.ResolverCacheTTL

300

TTL for syslog hostname resolver cache (seconds; 0 = disabled)

Syslog.RetentionTime

90

Syslog message retention time (days)

Syslog.TLS.EnableListener *

0

Enable built-in syslog over TLS (RFC 5425) listener

Syslog.TLS.ListenPort *

6514

TCP port for syslog over TLS listener

Syslog.TLS.MinVersion *

2

Minimal TLS protocol version accepted by the syslog over TLS listener (0 = TLS 1.0, 1 = TLS 1.1, 2 = TLS 1.2, 3 = TLS 1.3)

Syslog.TLS.RequireClientCertificate *

0

Require valid client certificate on syslog over TLS connections (connections without client certificate are dropped)

ThreadPool

Thread pool sizes control server concurrency for different task types. All require server restart.

Variable Default Description

ThreadPool.Agent.BaseSize *

32

Base thread count for agent connector pool

ThreadPool.Agent.MaxSize *

256

Maximum thread count for agent connector pool

ThreadPool.AIOperator.BaseSize *

4

Base thread count for AI operator pool

ThreadPool.AIOperator.MaxSize *

16

Maximum thread count for AI operator pool

ThreadPool.AITasks.BaseSize *

4

Base thread count for AI tasks pool

ThreadPool.AITasks.MaxSize *

16

Maximum thread count for AI tasks pool

ThreadPool.DataCollector.BaseSize *

10

Base thread count for data collector pool

ThreadPool.DataCollector.MaxSize *

250

Maximum thread count for data collector pool

ThreadPool.Discovery.BaseSize *

8

Base thread count for network discovery pool

ThreadPool.Discovery.MaxSize *

64

Maximum thread count for network discovery pool

ThreadPool.FileTransfer.BaseSize *

2

Base thread count for file transfer pool

ThreadPool.FileTransfer.MaxSize *

16

Maximum thread count for file transfer pool

ThreadPool.Main.BaseSize *

8

Base thread count for main server pool

ThreadPool.Main.MaxSize *

256

Maximum thread count for main server pool

ThreadPool.Poller.BaseSize *

10

Base thread count for poller pool

ThreadPool.Poller.MaxSize *

250

Maximum thread count for poller pool

ThreadPool.Scheduler.BaseSize *

1

Base thread count for scheduler pool

ThreadPool.Scheduler.MaxSize *

64

Maximum thread count for scheduler pool

ThreadPool.Syncer.BaseSize *

1

Base thread count for database syncer pool

ThreadPool.Syncer.MaxSize *

1

Maximum thread count for database syncer pool

Monitor thread pool utilization through Server Statistics in the management client. Increase maximum thread counts if pools show frequent exhaustion warnings.

Topology

Variable Default Description

Topology.AdHocRequest.ExpirationTime

900

Expiration time for ad-hoc topology requests (seconds)

Topology.AdHocRequest.IncludePhysicalLinks

0

Include physical links in ad-hoc Layer 2 topology maps

Topology.DefaultDiscoveryRadius

5

Default number of hops from seed node for topology discovery

Topology.EnableSTPDiscovery

1

Use Spanning Tree Protocol (STP) information for Layer 2 topology discovery; can be overridden per node using the SysConfig:Topology.EnableSTPDiscovery custom attribute

Topology.PollingInterval

1800

Interval between topology polls (seconds)

Topology.RoutingTable.MaxSize

4000

Maximum number of routing table entries to retrieve from a node

Topology.RoutingTable.UpdateInterval

300

Interval between routing table reads (seconds)

UserAgent

Settings for the NetXMS User Agent (desktop notification agent).

Variable Default Description

UserAgent.DefaultMessageRetentionTime

10080

Default retention time for user agent messages (minutes)

UserAgent.RetentionTime

30

Retention time for user agent message history (days)

WebAPI

Variable Default Description

WebAPI.AuthTokenMaxLifetime

86400

Maximum absolute lifetime for WebAPI authentication tokens (seconds)

WebAPI.AuthTokenWarningThreshold

3600

Time before token expiration when warning headers are sent to clients (seconds)

WindowsEvents

Variable Default Description

WindowsEvents.EnableStorage

1

Store received Windows events in the database

WindowsEvents.LogRetentionTime

90

Retention time for Windows event log records (days)

Miscellaneous

Standalone variables that do not belong to a specific category.

Variable Default Description

ActionExecutionLog.RetentionTime

90

Retention time for server action execution logs (days)

AssetChangeLog.RetentionTime

90

Retention time for asset change log records (days)

BlockInactiveUserAccounts

0

Block user accounts after specified days of inactivity (0 = disabled)

CertificateActionLog.RetentionTime

370

Retention time for certificate action log records (days)

DebugConsole.AllowedScriptLocations

@library

Ordered, comma-separated list of locations searched by the debug console exec command; use @library for the server script library or an absolute directory path (non-recursive); empty value disables exec

DowntimeLog.RetentionTime

90

Retention time for downtime log records (days)

EnableISCListener *

0

Enable Inter-Server Communications Listener (for event forwarding between servers)

Geolocation.History.RetentionTime

90

Retention time for object geolocation history (days)

LongRunningQueryThreshold *

0

Threshold for reporting long-running SQL queries (milliseconds; 0 = disabled)

MaintenanceJournal.RetentionTime

1826

Retention time for maintenance journal entries (days)

MobileDeviceListenerPort *

4747

Listener port for mobile agent connections

NetworkDeviceDrivers.BlackList *

(empty)

Comma-separated list of blacklisted network device driver names

NotificationLog.RetentionTime

90

Retention time for notification log records (days)

Scheduler.TaskRetentionTime

86400

Retention time for completed non-recurrent scheduled tasks (seconds)

Scripts.RestrictWriteAccess

1

Restrict write access for scripts evaluated automatically by the server (DCI transformations, scripted thresholds, auto-bind filters, conditions, EPP filter and RCA scripts, and others); when enabled, such scripts can only read data and cannot modify objects, post events, or send notifications — see Write Access Restrictions for the full list of affected scripts

TrafficObserver.HostRetentionTime

7

Retention time for observation point host match records (days); records not refreshed within this period are deleted by the housekeeping process