RMON Monitoring
RMON (Remote Network Monitoring) is an SNMP-based standard that extends basic SNMP monitoring with historical data collection, traffic statistics, and alarm capabilities built into the network device itself. NetXMS has no RMON-specific functionality: RMON objects are ordinary SNMP objects, collected with regular SNMP DCIs like any other SNMP data. This page provides general guidance on collecting data from devices that support the RMON MIB (RFC 2819).
Overview
RMON provides nine monitoring groups in the original RMON1 standard:
| Group | Name | Description |
|---|---|---|
1 |
Statistics |
Real-time Ethernet statistics per interface (packets, bytes, errors, collisions) |
2 |
History |
Historical samples of group 1 statistics at configurable intervals |
3 |
Alarm |
Threshold-based alarms on any SNMP variable |
4 |
Host |
Per-host traffic statistics (packets sent/received per MAC address) |
5 |
HostTopN |
Sorted host statistics for top-N reports |
6 |
Matrix |
Traffic matrix between host pairs |
7 |
Filter |
Packet capture filter definitions |
8 |
Capture |
Packet capture buffer management |
9 |
Event |
RMON event generation and notification |
| Not all devices implement every RMON group. Groups 1 and 2 (Statistics and History) are most commonly available. |
Collecting RMON Statistics
RMON statistics are exposed as standard SNMP objects and can be collected using regular SNMP DCIs.
Ethernet Statistics (Group 1)
The RMON statistics group provides per-interface counters in etherStatsTable (.1.3.6.1.2.1.16.1.1); table rows are etherStatsEntry (.1.3.6.1.2.1.16.1.1.1) objects:
| OID (etherStatsEntry) | Description |
|---|---|
|
Frames dropped due to lack of resources |
|
Total bytes received (including errors) |
|
Total packets received |
|
Broadcast packets received |
|
Multicast packets received |
|
Packets with CRC or alignment errors |
|
Packets smaller than 64 bytes |
|
Packets larger than 1518 bytes |
|
Undersized packets with CRC errors |
|
Oversized packets with CRC errors |
|
Collision events |
To collect these statistics:
-
Verify the device supports RMON (walk OID
.1.3.6.1.2.1.16.1) -
Use the MIB Explorer to browse available RMON objects (see MIB Management)
-
Create SNMP DCIs for the desired counters
-
For counter-type values, enable Delta calculation (e.g., average delta per second) on the DCI to convert raw counters into rates; Counter data types do not compute rates by themselves — they only ensure correct handling of counter wraparound
History (Group 2)
The RMON history group stores periodic samples of interface statistics.
The history control table (.1.3.6.1.2.1.16.2.1) defines the sampling configuration, and the history table (.1.3.6.1.2.1.16.2.2) stores the samples.
Since NetXMS has its own data collection and storage engine, collecting RMON history data directly is generally unnecessary — create DCIs for the group 1 statistics and let NetXMS handle the historical data.
Host Traffic (Group 4)
The host table tracks traffic statistics per MAC address:
| OID (hostEntry) | Description |
|---|---|
|
Packets received by this host |
|
Packets sent by this host |
|
Bytes received by this host |
|
Bytes sent by this host |
|
Errored packets sent by this host |
RMON Alarms and Events
RMON Alarms (Group 3)
RMON alarms are configured on the device itself to monitor any SNMP variable and trigger when rising or falling thresholds are crossed. These are separate from NetXMS thresholds.
In most deployments, NetXMS thresholds (see Thresholds) are preferred over RMON alarms because:
-
Centralized threshold management across all devices
-
More flexible threshold types (absolute, delta, average, script-based)
-
Integration with NetXMS event processing and notification system
RMON Events (Group 9)
RMON events can generate SNMP traps when RMON alarms trigger. Configure trap mappings in NetXMS to process these events (see SNMP Traps).
Practical Use Cases
Network Error Monitoring
Create DCIs for RMON error counters to detect network quality issues:
-
etherStatsCRCAlignErrors— indicates physical layer problems (bad cables, failing ports) -
etherStatsCollisions— high collision rates suggest network congestion or duplex mismatch -
etherStatsFragmentsandetherStatsJabbers— indicate hardware problems
Set thresholds on delta values (change per polling interval) rather than absolute counter values.
Traffic Analysis
Use RMON statistics for basic traffic analysis:
-
etherStatsPktsandetherStatsOctetsfor overall traffic volume -
etherStatsBroadcastPktsfor broadcast storm detection -
etherStatsMulticastPktsfor multicast traffic monitoring
Device Support
RMON support varies by device manufacturer and model:
-
Most managed switches support at least RMON groups 1 and 2
-
Full RMON1 support (all 9 groups) is less common
-
RMON2 (RFC 2021) adds network-layer and application-layer monitoring but is rarely implemented
Check your device documentation or walk the RMON OID tree (.1.3.6.1.2.1.16) to determine which groups are supported.