Working with Alarms
Alarms represent active problems that require operator attention. Reviewing and handling alarms is the core day-to-day activity in NetXMS, and this page covers the full operator workflow: finding alarms, understanding their states, and acting on them.
For how alarms are generated and configured — event processing rules, alarm keys, automatic resolution — see the Administrator Guide.
Where to Find Alarms
Alarms appear in two places:
-
The Alarms perspective shows all active alarms in the system.
-
The Alarms tab of a selected object shows only alarms for that object and its children. Select a container or node in the object tree and open its Alarms tab to see only alarms related to that branch.
Each alarm in the list shows:
-
Severity icon (color-coded)
-
State (Outstanding, Acknowledged, Resolved)
-
Source object name
-
Alarm message
-
Creation time
-
Last change time
The list can be filtered by severity, state, or source.
Alarm States
An alarm moves through the following states:
- Outstanding
-
A new alarm that no one has acted on yet.
- Acknowledged
-
An operator has seen the alarm and indicated they are aware of the problem. Acknowledgement is normally cleared when a new matching event arrives — the alarm returns to Outstanding to signal that the problem recurred. A sticky acknowledgement persists even when new matching events arrive; a timed sticky acknowledgement reverts to Outstanding automatically after the chosen duration.
- Resolved
-
The underlying problem is considered fixed, but the alarm record is kept visible for review.
- Terminated
-
The alarm is permanently closed and moves to the alarm log.
Some alarms are closed automatically when the underlying condition clears — for example, the default event processing policy terminates a node-down alarm when the node comes back online.
Typical Workflow
-
Review outstanding alarms in the Alarms perspective
-
Investigate the problem (check the source object, view related data)
-
Acknowledge the alarm to indicate you are working on it
-
Resolve or terminate the alarm once the problem is fixed
Alarm Operations
All operations are available from the alarm’s right-click menu:
-
Acknowledge — select Acknowledge
-
Sticky acknowledge — select Sticky acknowledge to keep the acknowledgement even if new matching events arrive, or pick a duration from the Sticky acknowledge for submenu (enabled by default) for a timed acknowledgement
-
Resolve — select Resolve
-
Terminate — select Terminate (permanently closes the alarm)
-
Show alarm details — double-click an alarm, or select Show alarm details
-
Go to source object — right-click a single alarm and select Go to object
Resolve and Terminate are available only when the alarm is in an appropriate state; depending on server configuration (strict status flow), an alarm may have to be resolved before it can be terminated.
Creating an Incident from an Alarm
When a problem needs tracked investigation beyond acknowledging the alarm, you can open an incident for it: right-click a single alarm and select Create incident. The new incident is linked to the alarm and uses the alarm message as its title. An alarm can be linked to only one incident.
See Working with Incidents for the incident workflow.