RMON Monitoring

RMON (Remote Network Monitoring) is an SNMP-based standard that extends basic SNMP monitoring with historical data collection, traffic statistics, and alarm capabilities built into the network device itself. NetXMS has no RMON-specific functionality: RMON objects are ordinary SNMP objects, collected with regular SNMP DCIs like any other SNMP data. This page provides general guidance on collecting data from devices that support the RMON MIB (RFC 2819).

Overview

RMON provides nine monitoring groups in the original RMON1 standard:

Group Name Description

1

Statistics

Real-time Ethernet statistics per interface (packets, bytes, errors, collisions)

2

History

Historical samples of group 1 statistics at configurable intervals

3

Alarm

Threshold-based alarms on any SNMP variable

4

Host

Per-host traffic statistics (packets sent/received per MAC address)

5

HostTopN

Sorted host statistics for top-N reports

6

Matrix

Traffic matrix between host pairs

7

Filter

Packet capture filter definitions

8

Capture

Packet capture buffer management

9

Event

RMON event generation and notification

Not all devices implement every RMON group. Groups 1 and 2 (Statistics and History) are most commonly available.

Collecting RMON Statistics

RMON statistics are exposed as standard SNMP objects and can be collected using regular SNMP DCIs.

Ethernet Statistics (Group 1)

The RMON statistics group provides per-interface counters in etherStatsTable (.1.3.6.1.2.1.16.1.1); table rows are etherStatsEntry (.1.3.6.1.2.1.16.1.1.1) objects:

OID (etherStatsEntry) Description

etherStatsDropEvents

Frames dropped due to lack of resources

etherStatsOctets

Total bytes received (including errors)

etherStatsPkts

Total packets received

etherStatsBroadcastPkts

Broadcast packets received

etherStatsMulticastPkts

Multicast packets received

etherStatsCRCAlignErrors

Packets with CRC or alignment errors

etherStatsUndersizePkts

Packets smaller than 64 bytes

etherStatsOversizePkts

Packets larger than 1518 bytes

etherStatsFragments

Undersized packets with CRC errors

etherStatsJabbers

Oversized packets with CRC errors

etherStatsCollisions

Collision events

To collect these statistics:

  1. Verify the device supports RMON (walk OID .1.3.6.1.2.1.16.1)

  2. Use the MIB Explorer to browse available RMON objects (see MIB Management)

  3. Create SNMP DCIs for the desired counters

  4. For counter-type values, enable Delta calculation (e.g., average delta per second) on the DCI to convert raw counters into rates; Counter data types do not compute rates by themselves — they only ensure correct handling of counter wraparound

History (Group 2)

The RMON history group stores periodic samples of interface statistics. The history control table (.1.3.6.1.2.1.16.2.1) defines the sampling configuration, and the history table (.1.3.6.1.2.1.16.2.2) stores the samples.

Since NetXMS has its own data collection and storage engine, collecting RMON history data directly is generally unnecessary — create DCIs for the group 1 statistics and let NetXMS handle the historical data.

Host Traffic (Group 4)

The host table tracks traffic statistics per MAC address:

OID (hostEntry) Description

hostInPkts

Packets received by this host

hostOutPkts

Packets sent by this host

hostInOctets

Bytes received by this host

hostOutOctets

Bytes sent by this host

hostOutErrors

Errored packets sent by this host

RMON Alarms and Events

RMON Alarms (Group 3)

RMON alarms are configured on the device itself to monitor any SNMP variable and trigger when rising or falling thresholds are crossed. These are separate from NetXMS thresholds.

In most deployments, NetXMS thresholds (see Thresholds) are preferred over RMON alarms because:

  • Centralized threshold management across all devices

  • More flexible threshold types (absolute, delta, average, script-based)

  • Integration with NetXMS event processing and notification system

RMON Events (Group 9)

RMON events can generate SNMP traps when RMON alarms trigger. Configure trap mappings in NetXMS to process these events (see SNMP Traps).

Practical Use Cases

Network Error Monitoring

Create DCIs for RMON error counters to detect network quality issues:

  • etherStatsCRCAlignErrors — indicates physical layer problems (bad cables, failing ports)

  • etherStatsCollisions — high collision rates suggest network congestion or duplex mismatch

  • etherStatsFragments and etherStatsJabbers — indicate hardware problems

Set thresholds on delta values (change per polling interval) rather than absolute counter values.

Traffic Analysis

Use RMON statistics for basic traffic analysis:

  • etherStatsPkts and etherStatsOctets for overall traffic volume

  • etherStatsBroadcastPkts for broadcast storm detection

  • etherStatsMulticastPkts for multicast traffic monitoring

Device Support

RMON support varies by device manufacturer and model:

  • Most managed switches support at least RMON groups 1 and 2

  • Full RMON1 support (all 9 groups) is less common

  • RMON2 (RFC 2021) adds network-layer and application-layer monitoring but is rarely implemented

Check your device documentation or walk the RMON OID tree (.1.3.6.1.2.1.16) to determine which groups are supported.