Objects
NetXMS represents all monitored infrastructure as objects organized in hierarchical trees. Understanding the object model helps you navigate the console efficiently and find the information you need.
Object Trees
Object trees work like a file system — objects are nested inside other objects, and you navigate by expanding and collapsing branches. There is no single tree containing everything: each tree has its own root object and is shown in its own perspective of the console, with its own object browser.
- Infrastructure (rooted at Infrastructure Services)
-
Your main workspace. Contains containers and nodes organized by your administrator into a logical structure (e.g., by location, function, or business unit). This is where you will spend most of your time.
- Network (rooted at Entire Network)
-
The IP topology view. Contains zones (when zoning is enabled) or subnets automatically created from discovered device addresses. Useful for finding devices by their network location.
- Templates (rooted at Templates)
-
Contains data collection and policy templates. Templates are an administrative concept — they define what to monitor on groups of similar devices.
- Dashboards (rooted at Dashboards)
-
Contains dashboards — visual displays combining graphs, maps, and status indicators.
- Maps (rooted at Network Maps)
-
Contains custom and automatic network maps.
- Assets (rooted at Assets)
-
Contains hardware asset objects that can be linked to monitored objects.
- Business Services (rooted at Business Services)
-
Contains business service definitions for SLA/availability tracking.
Object Types
NetXMS uses the following object classes to represent monitored infrastructure:
| Object Class | Description | Valid Children |
|---|---|---|
Entire Network |
Root of IP topology tree. One per system. Contains zones when zoning is enabled, subnets otherwise. |
Zone (when zoning is enabled), Subnet (when zoning is disabled) |
Zone |
Group of interconnected IP networks without overlapping addresses. |
Subnet |
Subnet |
IP subnet, typically created automatically from discovered interface addresses. |
Node |
Service Root |
Root of your infrastructure service tree (named "Infrastructure Services" after installation). One per system. |
Access Point, Chassis, Circuit, Cloud Domain, Cluster, Collector, Condition, Container, Mobile Device, Node, Rack, Resource, Sensor, Subnet, Traffic Observer, Wireless Domain |
Container |
Organizational folder for grouping objects into a logical hierarchy (by location, function, or business unit). |
Access Point, Chassis, Circuit, Cloud Domain, Cluster, Collector, Condition, Container, Mobile Device, Node, Rack, Resource, Sensor, Subnet, Traffic Observer, Wireless Domain |
Collector |
Similar to container, but with data collection capabilities. |
Access Point, Chassis, Circuit, Cloud Domain, Cluster, Collector, Condition, Container, Mobile Device, Node, Rack, Resource, Sensor, Subnet, Traffic Observer, Wireless Domain |
Node |
Physical or virtual host — server, router, switch, firewall, workstation, VM, or appliance. Created manually or by network discovery. |
Interface, Network Service, VPN Connector |
Interface |
Network interface on a managed device. Created automatically during configuration polls. |
(none) |
Cluster |
Group of nodes working together. Aggregates monitoring data across cluster members. |
Node |
Circuit |
Reference of multiple interfaces representing network services — multilink interfaces, site-to-site links, virtual circuits. |
Interface |
Rack |
Physical rack. Same purpose as container, but allows visual representation of installed equipment. |
Node, Chassis |
Chassis |
Blade server enclosure or similar equipment housing. Can be part of a rack. |
Node |
Condition |
Represents a complex status check with an attached NXSL script. Evaluated periodically (default: every 60 seconds). |
(none) |
Sensor |
Logical object with data collection capabilities. Data is collected indirectly (e.g., via MQTT), not through direct network communication. |
(none) |
Wireless Domain |
Wireless network made up of one or more wireless controllers and managed access points. |
Access Point, Node |
Access Point |
Thin wireless access point managed by a central controller. Created automatically. |
(none) |
Network Service |
Network service running on a node (user-defined, SSH, POP3, SMTP, FTP, HTTP, HTTPS, or Telnet) that can be checked for availability. |
(none) |
VPN Connector |
VPN tunnel endpoint for interfaceless tunnels (e.g., IPsec). Used to add VPN connections to the network topology. |
(none) |
Mobile Device |
Monitored mobile device. |
(none) |
Cloud Domain |
Cloud infrastructure domain. Discovers and monitors cloud resources through a cloud connector. |
Resource |
Resource |
Cloud resource discovered within a cloud domain. Can be linked to a node object. Resources can be nested. |
Resource |
Traffic Observer |
External traffic analysis system instance. Discovers and monitors its observation points. |
Observation Point |
Observation Point |
Monitored interface (observation point) of a traffic observer. |
(none) |
Template Root |
Root of the template tree. |
Template, Template Group |
Template Group |
Grouping object for templates. |
Template, Template Group |
Template |
Data collection and agent policy template. When applied to an object, the template’s configuration is inherited. |
Access Point, Chassis, Circuit, Cloud Domain, Cluster, Collector, Mobile Device, Node, Observation Point, Resource, Sensor, Traffic Observer |
Asset Root |
Root of hardware asset management tree. |
Asset, Asset Group |
Asset Group |
Grouping object for assets. |
Asset, Asset Group |
Asset |
Hardware management asset. Can be linked to a node, access point, chassis, mobile device, rack, or sensor. |
(none) |
Network Map Root |
Root of the network map tree. |
Network Map, Network Map Group |
Network Map Group |
Grouping object for network maps. |
Network Map, Network Map Group |
Network Map |
Visual network map. |
(none) |
Dashboard Root |
Root of the dashboard tree. |
Dashboard, Dashboard Group, Dashboard Template |
Dashboard Group |
Grouping object for dashboards. |
Dashboard, Dashboard Group, Dashboard Template |
Dashboard |
Visual dashboard. Can contain other dashboards and dashboard groups. |
Dashboard, Dashboard Group |
Dashboard Template |
Template from which dashboards for matching objects are created automatically. |
(none) |
Business Service Root |
Root of the business service tree. One per system. |
Business Service, Business Service Prototype |
Business Service |
Logical service for SLA/availability tracking. Can contain other business services. |
Business Service, Business Service Prototype |
Business Service Prototype |
Prototype from which business service objects are automatically populated. |
(none) |
Nodes
Nodes are the most important object type. A node represents any monitored device: a server, router, switch, firewall, workstation, virtual machine, or appliance.
Each node has:
-
An IP address (primary address used for monitoring)
-
A name (auto-discovered or manually set)
-
A status reflecting its current health
-
Interfaces — network interfaces discovered during configuration polls
-
DCIs — data collection items that define what metrics are collected
-
Capabilities — what protocols the node supports (agent, SNMP, SSH, etc.)
To view a node’s details, select it in the Object Browser. The working area shows the node’s overview, interfaces, collected values, and other information.
Interfaces
Interface objects represent network interfaces on a node. They are created automatically when NetXMS polls the device configuration.
Interface information includes:
-
Interface name (e.g., eth0, GigabitEthernet0/1)
-
Operational status (up/down)
-
Administrative status (unknown, up, down, or testing)
-
IP address and subnet mask
-
MAC address
-
Interface type and speed
-
Traffic statistics (if collected)
Interface status is color-coded: green for up, red for down, brown for administratively disabled.
Containers
Containers are organizational folders that group objects logically. Your administrator creates containers to build a hierarchy that makes sense for your organization.
Common container structures:
-
By location: "Data Center 1" > "Rack A" > individual nodes
-
By function: "Web Servers", "Database Servers", "Network Equipment"
-
By business unit: "Finance", "HR", "Engineering"
Containers display an aggregated status — the worst status among their children. If any node in a container is in Critical status, the container shows Critical too.
Subnets
Subnet objects represent IP subnets. They appear under the Entire Network root and are typically created automatically from interface addresses discovered during configuration polls.
Subnets provide an alternative way to find nodes — by their network location rather than their organizational grouping.
Object Status
Every object has a status that reflects its current condition. Status is indicated by color throughout the console:
| Status | Color | Meaning |
|---|---|---|
Normal |
Green |
Operating correctly; all checks pass. |
Warning |
Cyan |
Minor issue detected; a threshold has been crossed but the condition is not critical. |
Minor |
Yellow |
Notable problem that should be investigated. |
Major |
Orange |
Significant problem requiring prompt attention. |
Critical |
Red |
Severe problem; the object or service may be down or seriously degraded. |
Unknown |
Dark blue |
Status cannot be determined — the object may be unreachable or not yet polled. |
Unmanaged |
Light gray |
Monitoring disabled by an administrator. |
Disabled |
Brown |
Object is administratively disabled (applies to interface objects). |
Testing |
Pink |
Object is in testing state (applies to interface objects). |
Status Propagation
Status propagates upward through the object tree. A container’s status reflects the worst status of any object within it.
This means you can see at a glance if anything in a branch of your infrastructure has a problem — the parent containers will show the elevated status even if the affected node is several levels deep.
Viewing Object Properties
Right-click any object and select Properties to view its configuration. Key property pages:
- General
-
Object name, alias, AI hint, category, and hidden flag. The primary host name is on the Communication page, and comments are on the Comments page.
- Status Calculation
-
How the object’s status is calculated and propagated.
- Access Control
-
Who can see and interact with this object (managed by administrators).
- Location
-
Geographic location (latitude/longitude) if configured.
- Custom Attributes
-
Administrator-defined key-value pairs attached to the object.
Finding Objects
Object Browser Filter
Use the filter field at the top of the object browser.
By default, the filter matches object names and aliases; entering * or ? switches to glob pattern matching.
Prefixes change what is searched:
-
>— part of an IP address -
^— exact IP address -
#— object ID -
/— comment -
@— zone ID
Find Object
Use the Find Object view in the Tools perspective to search for objects across the whole system.
Three matching modes are available: Normal, Pattern (with * and ? wildcards), and Regular expression.
Object Query
For advanced searching, administrators can configure object queries that find objects matching complex criteria. These are described in the Administrator Guide.
Working with Nodes
Common tasks when working with nodes:
- Viewing collected data
-
Select the node and open the Data Collection tab to see all collected metrics, or the Performance tab for quick graphs.
- Checking connectivity
-
The node’s status indicator shows reachability. For more detail, check the ICMP response time in the Data Collection tab.
- Viewing interfaces
-
Open the node and look at its interface list. Interface status shows which network connections are up or down.
- Viewing alarms
-
Select the node and open the Alarms tab to see all alarms related to this node.
- Viewing software inventory
-
Select the node and open the Software Inventory tab to see installed packages (requires agent on the node).
- Accessing tools
-
Right-click the node and select Tools for operator tools like ping, traceroute, or SSH terminal (if configured by your administrator).