Server Configuration Variables
Server configuration variables are stored in the database and can be modified at runtime without restarting the server (unless noted otherwise with *). They control server behavior, polling intervals, security settings, and feature toggles.
Use the management client (Configuration > Server Configuration) to view and modify variables, or nxdbmgr from the command line:
nxdbmgr set VariableName value
For operational guidance, see Server Configuration.
|
Variables marked with * require a server restart after modification. All other variables take effect immediately. |
Agent
Settings for communication between the server and NetXMS agents.
| Variable | Default | Description |
|---|---|---|
|
4000 |
Timeout for commands sent to agent (milliseconds) |
|
5000 |
Timeout for establishing connection with agent (milliseconds) |
|
2 |
Default agent cache mode for offline data collection (1 = on, 2 = off) |
|
1 |
Default encryption policy for agent communications (0 = disabled, 1 = allowed, 2 = preferred, 3 = required) |
|
1 |
Default agent protocol compression mode (1 = enabled, 2 = disabled) |
|
1 |
Enable agent self-registration via |
|
0 |
Period after agent restart during which the agent is not considered unreachable (seconds; 0 = disabled) |
|
0 |
Bandwidth limit for file uploads to agent (KB/s; 0 = unlimited) |
|
600 |
Maximum wait time for agent restart after upgrade (seconds) |
AgentPolicy
| Variable | Default | Description |
|---|---|---|
|
134217728 |
Maximum file size for exported agent policies (bytes) |
AgentTunnels
Settings for agent tunnel connections (certificate-based agent-to-server communication).
| Variable | Default | Description |
|---|---|---|
|
0 |
Bind tunnels by IP address instead of system information |
|
30 |
Interval between reissuing agent certificates (days) |
|
90 |
Validity period for newly issued agent certificates (days) |
|
4703 |
TCP port for incoming agent tunnel connections |
|
(empty) |
Container name for automatically created nodes from unbound tunnels |
|
2 |
Minimal TLS protocol version for agent tunnels (0 = TLS 1.0, 1 = TLS 1.1, 2 = TLS 1.2, 3 = TLS 1.3) |
|
3600 |
Inactivity timeout for unbound agent tunnels (seconds) |
|
0 |
Action when unbound tunnel timeout expires (0 = reset tunnel, 1 = generate event, 2 = bind tunnel to existing node, 3 = bind tunnel to existing node or create new node) |
AI
Settings for the AI assistant and AI operator subsystem.
| Variable | Default | Description |
|---|---|---|
|
64 |
Maximum number of LLM tool-call iterations for background AI assistant requests (event processing, scheduled tasks, incident analysis) before the request is stopped |
|
30 |
Maximum number of LLM tool-call iterations for interactive AI assistant chats before the user is asked whether to continue |
|
1 |
Enable AI operator subsystem (global kill switch for all operator instances) |
|
3 |
Number of consecutive execution failures after which an AI operator instance is automatically disabled |
|
90 |
Retention time for AI operator execution log records (days) |
|
1000 |
Default maximum number of retained observations per AI operator instance (can be overridden per operator instance) |
|
90 |
Default retention time for AI operator observations (days; can be overridden per operator instance) |
|
90 |
Retention time for AI task execution log records (days) |
Alarms
| Variable | Default | Description |
|---|---|---|
|
1 |
Automatically delete alarms when the source object is deleted |
|
1 |
Enable timed alarm acknowledgment (auto-revert to outstanding after timeout) |
|
180 |
Days to keep resolved/terminated alarms in history (0 = forever) |
|
0 |
Ignore helpdesk state when resolving or terminating alarms |
|
0 |
Auto-terminate resolved alarms after N seconds without changes (0 = disabled) |
|
0 |
Enforce strict alarm status transitions (Outstanding → Acknowledged → Resolved → Terminated) |
|
0 |
Enable alarm summary emails |
|
(empty) |
Semicolon-separated list of alarm summary email recipient addresses |
|
|
Cron-style schedule for sending alarm summary emails |
AuditLog
| Variable | Default | Description |
|---|---|---|
|
13 |
Syslog facility code for audit log forwarding |
|
514 |
Target syslog server UDP port |
|
|
Syslog server address for external audit logging; the literal value |
|
5 |
Syslog severity code |
|
|
Syslog message tag |
|
0 |
Use UTF-8 encoding for external audit log messages |
|
90 |
Retention time for audit log records (days) |
Beacon
Beacon hosts are used by the server to verify its own network connectivity. If all beacon hosts become unreachable, the server assumes it has lost connectivity and will not change node statuses. For an explanation of how beacon hosts work and when to configure them, see Beacon Hosts.
| Variable | Default | Description |
|---|---|---|
|
(empty) |
Comma-separated list of beacon host addresses |
|
1000 |
Interval between beacon host polls (milliseconds) |
|
1000 |
Timeout to consider a beacon host unreachable (milliseconds) |
BusinessServices
| Variable | Default | Description |
|---|---|---|
|
|
Comma-separated list of object classes for automatic business service check binding |
|
1 |
Default threshold for business service DCI checks (1 = warning, 2 = minor, 3 = major, 4 = critical) |
|
1 |
Default threshold for business service object checks (1 = warning, 2 = minor, 3 = major, 4 = critical) |
|
90 |
Retention time for business service historical data (days) |
CAS
Central Authentication Service (CAS) integration for single sign-on.
| Variable | Default | Description |
|---|---|---|
|
(empty) |
Comma-separated list of allowed CAS proxy addresses |
|
|
CAS server DNS name or IP address |
|
8443 |
CAS server TCP port number |
|
|
Service URL to validate (your NetXMS web UI URL) |
|
(empty) |
File system path to CAS trusted CA certificate |
|
|
URL path for service validation on CAS server |
Client
Settings affecting the management console (client) behavior and display.
| Variable | Default | Description |
|---|---|---|
|
4096 |
Maximum number of alarms displayed in the alarm browser |
|
|
Base URL for forming direct access URLs to objects and alarms; the |
|
1 |
Enable data interpolation in dashboard data export |
|
|
Default date display format in the management console |
|
|
Default short time format in the management console |
|
|
Default long time format in the management console |
|
60 |
Default time period for ad-hoc line charts (minutes) |
|
1 |
Enable the welcome page in the client application |
|
2000 |
Timeout for receiving first packet from client (milliseconds) |
|
0 |
User inactivity timeout (seconds; 0 = disabled) |
|
60 |
Interval between keep-alive packets to connected clients (seconds) |
|
4701 |
Server port for incoming client connections |
|
(empty) |
Minimum client version allowed for connection |
|
300 |
Minimum interval between view refresh in the client (milliseconds) |
|
1 |
Auto-apply filter in object browser while typing |
|
0 |
Controls drag and drop behavior in the object browser (0 = enable, 1 = confirm, 2 = disable) |
|
300 |
Delay between typing and applying filter in object browser (milliseconds) |
|
1 |
Minimum filter string length for automatic apply |
|
0 |
Show template target objects under templates in the object browser |
|
1 |
Show comments section in object overview only when comments exist |
|
|
Base URL for the map tile server |
DataCollection
| Variable | Default | Description |
|---|---|---|
|
1 |
When enabling aggregation, initialize per-DCI watermarks to the earliest retained raw timestamp so existing history is backfilled on the next rollup pass |
|
1800 |
Lag before a closed day is rolled up into the daily aggregate, giving late samples time to arrive (seconds) |
|
1825 |
Default retention time for daily DCI aggregates (days; individual DCIs can override) |
|
365 |
Default retention time for hourly DCI aggregates (days; individual DCIs can override) |
|
0 |
Master switch for DCI data aggregation; when enabled, the server rolls up raw DCI values into hourly and daily aggregates for eligible items |
|
300 |
Lag before a closed hour is rolled up into the hourly aggregate, giving late samples time to arrive (seconds) |
|
5000 |
Upper bound on the number of points returned by auto-selected aggregate tier when serving DCI history queries |
|
600 |
TimescaleDB continuous aggregate refresh cadence (seconds) |
|
30 |
TimescaleDB continuous aggregate refresh lookback window (days); caps the outage length that can be recovered via late-arriving data on TimescaleDB backends |
|
1 |
Apply all DCIs from template including disabled ones |
|
60 |
Polling interval for all DCIs whose collection schedule is set to Server default (seconds) |
|
30 |
Data retention time for all DCIs whose history retention is set to Server default (days) |
|
600 |
Instance discovery polling interval (seconds) |
|
7 |
Retention time for removed DCI instances (days; 0 = delete immediately) |
|
86400 |
Time period within which offline (cached) data is considered relevant (seconds) |
|
1 |
Terminate related alarms when DCI is deleted |
|
0 |
Skip DCI scheduling if communication with the node is unavailable |
|
86400 |
Minimum interval between reporting DCI script execution errors (seconds) |
|
0 |
Enable randomized DCI polling delays on server startup |
|
0 |
Grace period before removing DCIs after template unbind (days; 0 = immediate) |
|
0 |
System-wide interval for resending threshold violation events (seconds; 0 = disabled) |
DBConnectionPool
Database connection pool settings. All require server restart.
| Variable | Default | Description |
|---|---|---|
|
10 |
Number of database connections created at startup |
|
300 |
Inactivity time before closing an extra database connection (seconds) |
|
14400 |
Maximum lifetime for a single database connection (seconds) |
|
30 |
Maximum number of connections in the pool |
DBWriter
Database writer thread settings for DCI data persistence. All require server restart unless noted.
| Variable | Default | Description |
|---|---|---|
|
1 |
Number of background worker threads for DCI data writer |
|
1 |
Number of queues for DCI data writer |
|
0 |
Block background database writes during housekeeper deletion cycles (0 = auto, 1 = off, 2 = on; in auto mode the interlock is active only on Microsoft SQL Server) |
|
1 |
Degree of parallelism for INSERT statements (useful for TimescaleDB) |
|
0 |
Maximum DCI data writer queue size (0 = unlimited) |
|
100 |
Maximum records per SQL statement for delayed writes |
|
1000 |
Maximum records per transaction for delayed writes |
|
30 |
Interval between flushing accumulated raw DCI data to the database (seconds) |
|
1 |
Degree of parallelism for UPDATE statements |
DefaultNotificationChannel
| Variable | Default | Description |
|---|---|---|
|
|
Default notification channel name for SMTP HTML formatted messages |
|
|
Default notification channel name for SMTP text formatted messages |
Events
| Variable | Default | Description |
|---|---|---|
|
1 |
Enable topology-based event correlation (suppresses duplicate node-down events behind a failed router) |
|
1 |
Automatically delete events when the source object is deleted |
|
90 |
Retention time for event log records (days) |
|
0 |
Record event processing metadata (matched event processing policy rules and the effects they produced) in the event log |
|
1 |
Number of event processing threads (>1 enables parallel processing) |
|
|
Queue selector expression for parallel event processing (determines which queue an event is placed in) |
|
0 |
Accept events forwarded from other NetXMS servers |
EventStorm
Event storm detection prevents runaway event generation from overwhelming the server.
| Variable | Default | Description |
|---|---|---|
|
15 |
Time period for event rate to exceed threshold to trigger storm detection (seconds) |
|
0 |
Enable event storm detection |
|
1000 |
Events per second threshold for event storm condition |
Housekeeper
The housekeeper runs periodic cleanup tasks to remove expired data from the database.
| Variable | Default | Description |
|---|---|---|
|
0 |
Disable automatic DCI data cleanup during housekeeper runs |
|
|
Time when housekeeper starts daily (HH:MM) |
|
250000 |
Database writer queue depth (main or collected data writer queue) at which the housekeeper pauses deletions |
|
50000 |
Database writer queue depth below which a paused housekeeper resumes deletions |
ICMP
| Variable | Default | Description |
|---|---|---|
|
1 |
Collect ICMP statistics during status polls for all nodes |
|
46 |
ICMP packet data size (bytes) |
|
1500 |
ICMP ping timeout (milliseconds) |
|
60 |
ICMP polling interval (seconds) |
|
60 |
Number of polls over which to calculate ICMP statistics |
Jira
Jira integration for helpdesk ticket management.
| Variable | Default | Description |
|---|---|---|
|
|
Default Jira issue type for new tickets |
|
|
Jira login name |
|
(empty) |
Jira password (masked) |
|
|
Jira project code |
|
(empty) |
Jira project component for new tickets |
|
|
Comma-separated Jira issue status codes indicating resolved state |
|
|
URL of the Jira server |
|
1 |
Enable Jira webhook on the web API listener |
|
(empty) |
Secret used for validation of Jira webhook calls (validation disabled if empty) |
LDAP
LDAP integration for user and group synchronization. See also User Management.
| Variable | Default | Description |
|---|---|---|
|
|
LDAP connection URI(s); multiple URIs can be space-separated |
|
(empty) |
LDAP object class representing group objects (e.g., |
|
(empty) |
LDAP attribute used as unique identifier for group objects (e.g., |
|
(empty) |
LDAP attribute mapped to user description |
|
(empty) |
LDAP attribute mapped to user email address |
|
|
LDAP attribute mapped to user full name |
|
(empty) |
LDAP attribute mapped to group login name |
|
(empty) |
LDAP attribute mapped to user phone number |
|
(empty) |
LDAP attribute mapped to user login name (e.g., |
|
5 |
Authentication method for LDAP-created user objects (5 = LDAP) |
|
1000 |
Maximum records returned in one LDAP search page |
|
(empty) |
DN for starting LDAP search (e.g., |
|
(empty) |
LDAP search filter string (e.g., |
|
0 |
Synchronization interval with LDAP server (minutes; 0 = disabled) |
|
(empty) |
User login (DN) for LDAP synchronization |
|
(empty) |
Password for LDAP synchronization user (masked) |
|
(empty) |
LDAP object class representing user objects (e.g., |
|
1 |
Action when an LDAP user/group is deleted during sync (0 = delete, 1 = disable) |
|
(empty) |
LDAP attribute used as unique identifier for user objects (e.g., |
NetworkDiscovery
| Variable | Default | Description |
|---|---|---|
|
1024 |
Number of addresses scanned in one block during active discovery |
|
1 |
Enable SNMP probing during active discovery |
|
0 |
Enable TCP probing during active discovery |
|
0 |
Delay between scanning address blocks (milliseconds) |
|
7200 |
Active discovery interval (seconds) |
|
(empty) |
Cron-style schedule for active discovery (overrides interval) |
|
0 |
Disable NetXMS agent probing of discovered addresses |
|
0 |
Disable EtherNet/IP probing of discovered addresses |
|
0 |
Disable SNMP v1 probing of discovered addresses |
|
0 |
Disable SNMP v2c probing of discovered addresses |
|
0 |
Disable SNMP v3 probing of discovered addresses |
|
0 |
Disable SSH probing of discovered addresses |
|
0 |
Discovery filter settings bitmask |
|
0 |
Merge duplicate nodes if discovered with the same identity |
|
900 |
Passive discovery interval (seconds) |
|
0 |
Discovery type (0 = disabled, 1 = passive, 2 = active, 3 = both) |
|
0 |
Use DNS name instead of IP address for newly discovered nodes |
|
1 |
Use fully qualified domain names for discovered nodes |
|
0 |
Use SNMP trap information as a discovery source |
|
0 |
Use syslog messages as a discovery source |
NotificationChannels
| Variable | Default | Description |
|---|---|---|
|
500 |
Maximum notification channel queue size (0 = unlimited) |
|
30 |
Maximum retry count for sending notification messages |
|
0 |
Default channel-level burst size for rate limiting (messages; 0 = disabled) |
|
0 |
Default channel-level sustained rate for rate limiting (messages; 0 = disabled) |
|
|
Time unit for channel rate limit ( |
|
300 |
Interval between digest notification deliveries (seconds) |
|
50 |
Queue depth triggering digest mode (messages; 0 = disabled) |
|
0 |
Default per-recipient burst size for rate limiting (messages; 0 = disabled) |
|
0 |
Default per-recipient sustained rate for rate limiting (messages; 0 = disabled) |
|
|
Time unit for recipient rate limit ( |
NXSL
| Variable | Default | Description |
|---|---|---|
|
1 |
Enable server-side NXSL functions for managing containers (CreateContainer, DeleteObject, etc.) |
|
0 |
Enable server-side NXSL file I/O functions (security-sensitive) |
Objects
Object management and polling settings. This is the largest category of server configuration variables.
General
| Variable | Default | Description |
|---|---|---|
|
1 |
Evaluate auto-bind rules during configuration polls |
|
3600 |
Auto-bind/auto-apply rule evaluation interval (seconds) |
|
3600 |
Configuration poll interval (seconds) |
|
60 |
Interval between polling condition objects (seconds) |
|
0 |
Delete unreachable nodes after specified number of days (0 = disabled) |
|
1 |
Enable zoning support for overlapping IP address ranges |
|
1 |
Consecutive unsuccessful polls required to declare an interface as down |
|
60 |
Status poll interval (seconds) |
|
60 |
Interval between writing object changes to the database (seconds) |
Access Points
| Variable | Default | Description |
|---|---|---|
|
0 |
Enable container auto-bind for access point objects |
|
72 |
Retention time for disappeared access points (hours) |
|
0 |
Enable template auto-apply for access point objects |
Assets
| Variable | Default | Description |
|---|---|---|
|
0 |
Allow deletion of assets linked to nodes |
Clusters
| Variable | Default | Description |
|---|---|---|
|
0 |
Enable container auto-bind for cluster objects |
|
0 |
Enable template auto-apply for cluster objects |
Collectors
| Variable | Default | Description |
|---|---|---|
|
0 |
Enable container auto-bind for collector objects |
|
0 |
Enable template auto-apply for collector objects |
Interfaces
| Variable | Default | Description |
|---|---|---|
|
0 |
Clear interface peer information when interface is set to unmanaged |
|
1 |
Default expected state for new interface objects (0 = up, 1 = auto, 2 = ignore) |
|
1 |
Enable 802.1x port state checking during status polls |
|
0 |
Ignore interfaces with "NOT PRESENT" status from the device |
|
(empty) |
Custom name pattern for interface objects |
|
30 |
Retention time for unconfirmed peer information (days) |
|
0 |
Use interface aliases in display (0 = never, 1 = use alias when available, 2 = concatenate alias with name, 3 = concatenate name with alias) |
|
1 |
Use SNMP ifXTable instead of ifTable for interface enumeration |
Maintenance
| Variable | Default | Description |
|---|---|---|
|
|
Predefined maintenance periods shown in the UI (use |
Mobile Devices
| Variable | Default | Description |
|---|---|---|
|
0 |
Enable container auto-bind for mobile device objects |
|
0 |
Enable template auto-apply for mobile device objects |
Network Maps
| Variable | Default | Description |
|---|---|---|
|
|
Default background color for new network maps (hex RGB) |
|
850 |
Default network map height (pixels) |
|
1300 |
Default network map width (pixels) |
|
60 |
Interval between automatic map updates (seconds) |
Nodes
| Variable | Default | Description |
|---|---|---|
|
3600 |
Grace period for capability expiration after node recovery (seconds) |
|
604800 |
Time before a detected protocol capability expires if unconfirmed (seconds) |
|
0 |
Block primary IP update if DNS resolves to an IP already assigned to another node |
|
0 |
Clear node primary IP address if DNS resolution fails |
|
1 |
Always check SNMP credentials during configuration polls |
|
0 |
Fall back to local DNS resolver if zone proxy DNS resolution fails |
|
1 |
Read Windows performance counters only when requested |
|
0 |
Resolve DNS name to IP during status polls (0 = never, 1 = always, 2 = on failure only) |
|
0 |
Number of polls between DNS-to-IP resolution attempts when |
|
1 |
Resolve node names using DNS, SNMP, or agent hostname |
|
0 |
Address family hint for DNS resolution (0 = none, 1 = IPv4, 2 = IPv6) |
|
0 |
Continuously synchronize node names with DNS |
Responsible Users
| Variable | Default | Description |
|---|---|---|
|
(empty) |
Comma-separated list of allowed tags for responsible user assignments |
Security
| Variable | Default | Description |
|---|---|---|
|
0 |
Enable trusted objects check for cross-object access |
Sensors
| Variable | Default | Description |
|---|---|---|
|
0 |
Enable container auto-bind for sensor objects |
|
0 |
Enable template auto-apply for sensor objects |
Status Calculation
| Variable | Default | Description |
|---|---|---|
|
1 |
Status calculation algorithm (1 = most critical, 2 = single threshold, 3 = multiple thresholds) |
|
0 |
Value for fixed status propagation algorithm |
|
1 |
Status propagation algorithm (1 = unchanged, 2 = fixed, 3 = relative, 4 = translated) |
|
0 |
Status shift value for relative propagation |
|
75 |
Threshold percentage for single threshold status calculation |
|
|
Threshold values for multiple thresholds calculation (hex-encoded 4 bytes) |
|
|
Status translation values for translated propagation (hex-encoded 4 bytes) |
Subnets
| Variable | Default | Description |
|---|---|---|
|
24 |
Default subnet mask for synthetic IPv4 subnets (CIDR notation) |
|
64 |
Default subnet mask for synthetic IPv6 subnets (CIDR notation) |
|
0 |
Automatically delete subnets with no child nodes |
OTLP
Settings for OpenTelemetry Protocol (OTLP) data ingestion.
| Variable | Default | Description |
|---|---|---|
|
1 |
Store received OpenTelemetry log records in the database |
|
90 |
Retention time for stored OpenTelemetry log records (days) |
|
0 |
Log a warning when OTLP resources cannot be matched to any node |
|
300 |
TTL for the OTLP resource-to-node match cache (seconds) |
|
86400 |
Retention time for observed OTLP metric names used by the metric selector (seconds); metrics not seen within this window are dropped from the catalog |
PackageDeployment
| Variable | Default | Description |
|---|---|---|
|
1000 |
Maximum number of most recent completed package deployment jobs returned to clients from the deployment history |
|
7 |
Retention time for completed deployment jobs (days) |
|
90 |
Retention time for package deployment log entries (days) |
|
16 |
Maximum number of automatic retry attempts for a failed package deployment (for example, when the target node is offline) before the job is marked as permanently failed |
|
25 |
Maximum threads for parallel package deployment |
RADIUS
RADIUS server settings for external authentication. See also User Management.
| Variable | Default | Description |
|---|---|---|
|
|
RADIUS authentication method ( |
|
(empty) |
NAS-Identifier attribute value sent in RADIUS requests |
|
5 |
Number of retries for RADIUS authentication requests |
|
1645 |
UDP port for primary RADIUS server |
|
1645 |
UDP port for secondary RADIUS server |
|
|
Shared secret for secondary RADIUS server (masked) |
|
|
Secondary RADIUS server hostname or IP address |
|
|
Shared secret for primary RADIUS server (masked) |
|
|
Primary RADIUS server hostname or IP address |
|
8 |
Service-Type attribute value in RADIUS requests (8 = Authenticate Only) |
|
3 |
Timeout for RADIUS server requests (seconds) |
ReportingServer
| Variable | Default | Description |
|---|---|---|
|
0 |
Enable reporting server connection |
|
|
Hostname of the reporting server |
|
(empty) |
Additional JDBC connector properties for reporting |
|
4710 |
Port of the reporting server |
|
90 |
Retention time for report execution results (days) |
Server
| Variable | Default | Description |
|---|---|---|
|
63 |
Bitmask for allowed encryption algorithms (1 = AES-256, 2 = Blowfish-256, 4 = IDEA, 8 = 3DES, 16 = AES-128, 32 = Blowfish-128) |
|
(empty) |
Identification color for this server instance (hex RGB) |
|
60 |
Timeout for local command object tool output (seconds) |
|
0 |
Replace TAB and newline characters with escape sequences in local command output |
|
1 |
Import configuration from local files on server startup (0 = never, 1 = only missing elements, 2 = always) |
|
(empty) |
Message displayed when a user logs into the management console |
|
(empty) |
Display name of this server instance |
|
1 |
Enable roaming mode (allows server to change its own IP address) |
Server Security
| Variable | Default | Description |
|---|---|---|
|
5 |
Number of grace logins allowed for users who have not configured two-factor authentication when enforcement is active |
|
120 |
Time the user has to respond to a two-factor authentication challenge before the client cancels the prompt (seconds; 0 = disabled) |
|
0 |
Time-to-live for two-factor authentication trusted device tokens (seconds; 0 = disabled) |
|
0 |
Treat login names as case-insensitive |
|
0 |
Enable extended access control for log queries |
|
5 |
Number of grace logins allowed after password expiration |
|
0 |
Failed login attempts before account lockout (0 = disabled) |
|
30 |
Account lockout duration (minutes) |
|
0 |
Minimum password length requirement (0 = no minimum) |
|
0 |
Password complexity enforcement bitmask (1 = digits, 2 = uppercase, 4 = lowercase, 8 = special chars, 16 = forbid alpha sequences, 32 = forbid keyboard sequences) |
|
0 |
Password expiration time (days; 0 = disabled) |
|
65536 |
Argon2id memory cost used when hashing user passwords (KiB); higher values strengthen resistance to GPU/ASIC cracking at the cost of login latency and server memory |
|
1 |
Argon2id parallelism (lanes) used when hashing user passwords |
|
3 |
Argon2id iteration count used when hashing user passwords |
|
0 |
Number of previous passwords to keep for duplication checks |
|
1 |
Restrict local debug console access to authenticated users only |
SNMP
| Variable | Default | Description |
|---|---|---|
|
7 |
Bitmask for allowed SNMP versions for built-in agent (1 = v1, 2 = v2c, 4 = v3) |
|
|
Community string for built-in SNMPv1/v2c agent |
|
0 |
Enable built-in SNMP agent |
|
161 |
Listening port for built-in SNMP agent |
|
0 |
SNMPv3 authentication method for built-in agent (0 = none, 1 = MD5, 2 = SHA1, 3 = SHA224, 4 = SHA256, 5 = SHA384, 6 = SHA512) |
|
(empty) |
SNMPv3 authentication password for built-in agent (masked) |
|
0 |
SNMPv3 encryption method for built-in agent (0 = none, 1 = DES, 2 = AES-128, 3 = AES-192, 4 = AES-256) |
|
(empty) |
SNMPv3 encryption password for built-in agent (masked) |
|
|
SNMPv3 user name for built-in agent |
|
(empty) |
Default codepage for SNMP string conversions |
|
0 |
Use separate SNMP request for each test OID during discovery |
|
|
Server SNMP engine ID |
|
0 |
Minimum allowed SNMP version for node communication (0 = SNMPv1, 1 = SNMPv2c, 3 = SNMPv3); can be overridden per node using the |
|
1500 |
SNMP request timeout (milliseconds) |
|
3 |
Number of SNMP request retries |
|
1 |
Allow automatic conversion of OCTET STRING trap varbinds to hex representation |
|
1 |
Enable SNMP trap receiver |
|
162 |
UDP port for SNMP trap listener |
|
0 |
Log all received SNMP traps including those from unknown sources |
|
90 |
Retention time for logged SNMP traps (days) |
|
0 |
Process traps from unmanaged nodes |
|
15 |
Time period for SNMP trap flood detection (seconds) |
|
0 |
Threshold for SNMP trap flood detection (traps per second; 0 = disabled) |
|
0 |
Search all zones to match trap/syslog source address to node (instead of default zone only) |
|
1 |
Generate a default event for unmatched SNMP traps |
|
1 |
Validate credentials (community string or SNMPv3 user name) of incoming SNMP traps against node credentials and drop traps that fail validation; can be overridden per node using the |
Syslog
| Variable | Default | Description |
|---|---|---|
|
0 |
Process syslog messages from sources not registered in NetXMS |
|
(empty) |
Default codepage for syslog message decoding |
|
0 |
Enable built-in syslog receiver |
|
1 |
Store received syslog messages in the database |
|
0 |
Ignore syslog message timestamp and use server receive time instead |
|
514 |
UDP port for syslog listener |
|
0 |
Node matching policy for received syslog messages (0 = IP then hostname, 1 = hostname then IP) |
|
0 |
Parse syslog messages from unknown sources (for event generation) |
|
300 |
TTL for syslog hostname resolver cache (seconds; 0 = disabled) |
|
90 |
Syslog message retention time (days) |
|
0 |
Enable built-in syslog over TLS (RFC 5425) listener |
|
6514 |
TCP port for syslog over TLS listener |
|
2 |
Minimal TLS protocol version accepted by the syslog over TLS listener (0 = TLS 1.0, 1 = TLS 1.1, 2 = TLS 1.2, 3 = TLS 1.3) |
|
0 |
Require valid client certificate on syslog over TLS connections (connections without client certificate are dropped) |
ThreadPool
Thread pool sizes control server concurrency for different task types. All require server restart.
| Variable | Default | Description |
|---|---|---|
|
32 |
Base thread count for agent connector pool |
|
256 |
Maximum thread count for agent connector pool |
|
4 |
Base thread count for AI operator pool |
|
16 |
Maximum thread count for AI operator pool |
|
4 |
Base thread count for AI tasks pool |
|
16 |
Maximum thread count for AI tasks pool |
|
10 |
Base thread count for data collector pool |
|
250 |
Maximum thread count for data collector pool |
|
8 |
Base thread count for network discovery pool |
|
64 |
Maximum thread count for network discovery pool |
|
2 |
Base thread count for file transfer pool |
|
16 |
Maximum thread count for file transfer pool |
|
8 |
Base thread count for main server pool |
|
256 |
Maximum thread count for main server pool |
|
10 |
Base thread count for poller pool |
|
250 |
Maximum thread count for poller pool |
|
1 |
Base thread count for scheduler pool |
|
64 |
Maximum thread count for scheduler pool |
|
1 |
Base thread count for database syncer pool |
|
1 |
Maximum thread count for database syncer pool |
| Monitor thread pool utilization through Server Statistics in the management client. Increase maximum thread counts if pools show frequent exhaustion warnings. |
Topology
| Variable | Default | Description |
|---|---|---|
|
900 |
Expiration time for ad-hoc topology requests (seconds) |
|
0 |
Include physical links in ad-hoc Layer 2 topology maps |
|
5 |
Default number of hops from seed node for topology discovery |
|
1 |
Use Spanning Tree Protocol (STP) information for Layer 2 topology discovery; can be overridden per node using the |
|
1800 |
Interval between topology polls (seconds) |
|
4000 |
Maximum number of routing table entries to retrieve from a node |
|
300 |
Interval between routing table reads (seconds) |
UserAgent
Settings for the NetXMS User Agent (desktop notification agent).
| Variable | Default | Description |
|---|---|---|
|
10080 |
Default retention time for user agent messages (minutes) |
|
30 |
Retention time for user agent message history (days) |
WebAPI
| Variable | Default | Description |
|---|---|---|
|
86400 |
Maximum absolute lifetime for WebAPI authentication tokens (seconds) |
|
3600 |
Time before token expiration when warning headers are sent to clients (seconds) |
WindowsEvents
| Variable | Default | Description |
|---|---|---|
|
1 |
Store received Windows events in the database |
|
90 |
Retention time for Windows event log records (days) |
Miscellaneous
Standalone variables that do not belong to a specific category.
| Variable | Default | Description |
|---|---|---|
|
90 |
Retention time for server action execution logs (days) |
|
90 |
Retention time for asset change log records (days) |
|
0 |
Block user accounts after specified days of inactivity (0 = disabled) |
|
370 |
Retention time for certificate action log records (days) |
|
|
Ordered, comma-separated list of locations searched by the debug console |
|
90 |
Retention time for downtime log records (days) |
|
0 |
Enable Inter-Server Communications Listener (for event forwarding between servers) |
|
90 |
Retention time for object geolocation history (days) |
|
0 |
Threshold for reporting long-running SQL queries (milliseconds; 0 = disabled) |
|
1826 |
Retention time for maintenance journal entries (days) |
|
4747 |
Listener port for mobile agent connections |
|
(empty) |
Comma-separated list of blacklisted network device driver names |
|
90 |
Retention time for notification log records (days) |
|
86400 |
Retention time for completed non-recurrent scheduled tasks (seconds) |
|
1 |
Restrict write access for scripts evaluated automatically by the server (DCI transformations, scripted thresholds, auto-bind filters, conditions, EPP filter and RCA scripts, and others); when enabled, such scripts can only read data and cannot modify objects, post events, or send notifications — see Write Access Restrictions for the full list of affected scripts |
|
7 |
Retention time for observation point host match records (days); records not refreshed within this period are deleted by the housekeeping process |
Related Pages
-
Server Configuration — operational guide for common variables
-
Configuration File Reference — startup configuration files
-
Agent Metrics — built-in agent metrics