Netprobe Command-line Options

Overview Copied

Command-line options can either be passed to the Netprobe installer on Windows, or directly to the Netprobe binary.

Installer command-line options Copied

The installer command line options are available only to Windows platforms.

Option Use
/netport=<listen port> Sets the Netprobe listening port. Default: 7036
/servicename=<servicename> Sets the Netprobe service name. Default: NetprobeNT
/nopassword Allows commands to run on the Netprobe without any prompting for a password. For more information, see Set passwords on Netprobe commands.
/pass=<password> Sets a Netprobe password.

Note

The /nopassword option will override this option but ENCODED_PASSWORD will still be set in the registry.
/listenip Sets a specific IP address where the Netprobe will listen to incoming connections. This argument can be used to force Self-Announcing Netprobe not to listen for incoming connections. For more information, see Disable listening in Manage Self-Announcing Netprobes.
/listenoverride Used in conjunction with /listenip, overrides the previous value of /listenip if it exists.
/discovery=<full path to file>

Used in conjunction with /setup. If /setup is not defined, then this option is ignored.

If invoked, the Netprobe runs a discovery executable on the machine it is running on. This executable extracts JSON metadata from its environment, and updates the Netprobe setup file with the metadata through the use of macros.

If you specify a setup URL with the ? character, then the Netprobe appends the JSON metadata as query parameters and pulls the setup file from the URL specified.

When present, the discovery executable runs at Netprobe startup, before the Netprobe reads any setup file, and before it connects to any Gateway.

For more information, see Auto-discovery in Netprobe Overview.

Mandatory: No

/setup=<full path or URL to file>

Sets the setup file for a self-announcing or floating Netprobe. By default, the full path is <directory of installer>\\setup.netprobe.xml.

If you use the default setup file, then this will be copied into the installation directory (for example, C:\Program Files (x86)\NetprobeNT). This new path then becomes the value of the -setup argument of the Netprobe imagePath registry.

If you specify your own setup file, the file will be used in its respective directory. It will not be copied into the installation directory.

If you specify a remote file (<url>), the Netprobe saves a copy of this in the installation directory as netprobe.setup.xml. This overwrites the existing netprobe.setup.xml file in the installation directory. In this case, any local changes to the netprobe.setup.xml configuration are ignored as the Netprobe retrieves the configuration from the remote file every /setup-interval=<minutes>.

If you specify an invalid file from the <url>, or the <url> becomes inaccessible, then the Netprobe uses the existing netprobe.setup.xml file.

Auto-discovery

When used with /discovery, the Netprobe setup file generates its contents from JSON metadata pulled from its environment by the discovery script.

If you specify a setup URL with the ? character, then the Netprobe appends the JSON metadata as query parameters and pulls the setup file from the URL specified. For more information, see Auto-discovery in Netprobe Overview.

Note

/setup=<url> only supports HTTP links by default. If you need to set up an HTTPS connection, see the /setup-server-verify option. When using /setup= with multiple instances of the Netprobe, check that you install each probe in its own directory. Otherwise, the setup for each probe may interfere with one another. Do not use proxy servers for /setup=<url>. Proxy servers are not supported.
/setup-interval=<minutes>

Used in conjunction with /setup.

Defines the time interval before the floating or Self-Announcing Netprobe requests another configuration file and restarts the announcement process. If no new or valid file is discovered, then the Netprobe neither reloads the configuration file nor restarts the configuration process.

If no -setup-interval is defined, the Netprobe makes the request every 360 minutes (or 6 hours), by default.

Feature behavior

By default, this option only works for remote configurations defined through /setup=<url>. However, if used in conjunction with /discovery, then this option works for both /setup=<filename> and <url>.

Auto behavior

When used with /discovery, then this option defines the time interval before the Netprobe reruns the discovery executable to update the JSON metadata. If no updates are discovered from the extracted JSON metadata, then the Netprobe does not reload the Netprobe setup file. For more information, see Auto-discovery in Netprobe Overview.

/setup-server-verify=<file>

Used in conjunction with /setup=<url>. This option only takes effect when an HTTPS <url> is specified. Otherwise, this option is ignored.

When this option is invoked, the Netprobe verifies the remote server against the specified Certificate Authority (CA) bundle.

/secure Used to enable secure mode during installation.
/ssl-certificate=<full path to file>

Used in conjunction with /secure; sets the SSL certificate file which is used to allow the probe to run in secure mode (when accepting incoming connections) Default: <directory of installer>\\cert.netprobe.pem

If the default SSL certificate file is not used, then the file specified will be used in situ. It will not be copied into the installation destination.

If the default SSL certificate file is used then it will be copied to the installation destination (for example, C:\\Program Files (x86)\\NetprobeNT) and this new path will be set as the value of -ssl-certificate argument of Netprobe’s imagePath in registry.

/ssl-certificate-chain=<filename>

Used in conjunction with /secure; sets the SSL certificate chain file used by the Netprobe to check the certificate of the Gateway when a connection is made. Default: *<directory of installer>\\cert-chain.netprobe.pem*

If the default SSL certificate chain file is not used, then the file specified will be used in situ. It will not be copied into the installation destination. If the default SSL certificate chain file is used then it will be copied to the installation destination (for example, C:\\Program Files (x86)\\NetprobeNT) and this new path will be set as the value of *-ssl-certificate-chain* argument of Netprobe’s imagePath in registry.

/ssl-certificate-key=<path to key file>

Used in conjunction with /secure; used to explicitly define the signed SSL server private key in PEM format.

If this option is not specified, but the certificate is, the Netprobe will look for the private key in the same file as the server certificate.

/dir=<install dir> Sets the Netprobe installation path.
/log=<filename> Sets the Netprobe log filename.
/silent Runs the install with no user interaction, but you can see the installation progress.
/verysilent Does the same as /silent but it does not show the installer files being extracted.
/require-ssl-certificate-for This forces the Netprobe to require certain components connecting to the Netprobe port to provide a valid SSL certificate. If no certificate is provided or the certificate cannot be vaildated using the certificate authority provided by the -ssl-certificate-chain option, the connection will be rejected. Currently, this does not require any additional parameter as only the connection type EMF2 is supported.
/minTLSversion=<version> Specifies the minimum TLS version. The accepted values are the following:
  • 1
  • 1.0
  • 1.1
  • 1.2
  • 1.3

Set up a self-announcing or floating Netprobe Copied

To set up a Self-Announcing or Floating Netprobe from the installer wizard, check the Install as Self-Announcing or Floating Netprobe checkbox from the Configure Self-Announcing or Floating Netprobe screen. Select a configuration file from that screen.

You can also specify the Self-Announcing or Floating Netprobe configuration file through installer command-line switch. To do this, start a new Administrator command-line window and run geneos-netprobe-<version>.windows-<platform>.setup.exe.windows-x64.setup.exe /setup=<setup_xml_filename >, where <setup_xml_filename> specifies the full path to the Self-Announcing or Floating Netprobe configuration file:

geneos-netprobe-*<version>*.windows-<platform>.setup.exe

Set up a secure Netprobe Copied

To setup a secure Netprobe from the installer wizard, check the Run probe in Secure Mode checkbox from the Configure Netprobe Secure Connections screen. You can:

The certificate chain that is used to verify the certificates presented to the Netprobe can also be set either by using the wizard and setting the file on the Configure Netprobe Secure Chain page, or by using the /ssl-certificate-chain command flag. In both cases, a file containing the certificates with which the presented certificates have been signed must be provided.

If you’re doing a silent mode install using either /silent or /verysilent option, then:

Error

If any of the files specified do not exist, the installer will fail silently and an ‘Install Failed’ line will be logged in the setup log. You can specify the log file with the /log= switch in the installer.

Success

On completion, the Netprobe will have been installed and started running as a service. The relevant registry settings will also have been set up.

Note

If the Windows Win Apps Plug-in is to be run on a Windows 2008 Server, then it is necessary to alter the properties of the service to “Allow service to interact with desktop”. For more information, see Windows Win Apps Plugin.

Binary command-line options Copied

The binary command line options are applicable to all platforms, unless otherwise stated.

Binary command line option Description
-help Displays a list of command line options and exits.

-version

-ver

-v

Displays version information and exits.
port Sets the listening port for the Gateway connection.
-nolog Ignores any setting from the LOG_FILENAME variable and logs to the terminal instead.
-extract <key> <filename> Extracts data embedded in the binary, writing it to the <filename> specified.There are two supported values for <key>:
  • schema — extracts the Gateway Setup File schema embedded in the Netprobe binary.
  • npschema — extracts the Netprobe Setup File schema embedded in the Netprobe binary.
-noschema If invoked, the Netprobe does not publish the schema to the Gateway.
-discovery <file path>

Used in conjunction with -setup. If -setup is not defined, then this option is ignored.

If invoked, the Netprobe runs a discovery executable on the machine it is running on. This executable extracts JSON metadata from its environment, and updates the Netprobe setup file with the metadata through the use of macros.

If you specify a setup URL with the ? character, then the Netprobe appends the JSON metadata as query parameters and pulls the setup file from the URL specified. When present, the discovery executable runs at Netprobe startup, before the Netprobe reads any setup file, and before it connects to any Gateway.

For more information, see Auto-discovery in Netprobe Overview.

Mandatory: No

-setup

-setup <filename>

-setup <url>

Used when running the Netprobe in Floating or Self-Announcing mode. Specifies the Netprobe Setup File to use.

The Netprobe Setup File can be specified as a local file (<filename>) or a remote file (<url>).

If no <filename> or <url> is specified, then the Netprobe defaults to the netprobe.setup.xml file in the current working directory. The Netprobe Setup File needs to specify the connection details of one or more Gateways.

If you specify a remote file (<url>), the Netprobe saves a copy of this in the current working directory as netprobe.setup.xml. This overwrites the default Netprobe configuration. In this case, any local changes to the netprobe.setup.xml configuration are ignored as the Netprobe retrieves the configuration from the remote file every -setup-interval <minutes>.

If you specify an invalid file from the <url>, or the <url> becomes inaccessible, then the Netprobe uses the default configuration.

Auto-discovery

When used with -discovery, the Netprobe setup file generates its contents from JSON metadata pulled from its environment by the discovery script.

If you specify a setup URL with the ? character, then the Netprobe appends the JSON metadata as query parameters and pulls the setup file from the URL specified.

For more information, see Auto-discovery in Netprobe Overview.

Note

-setup <url> only supports HTTP links by default. If you need to set up an HTTPS connection, see the -setup-server-verify option. When using -setup <url> with multiple instances of the Netprobe, check that you run each probe in its own directory. Otherwise, the setup for each probe may interfere with one another. Do not use proxy servers for -setup <url>. Proxy servers are not supported. The -setup <url> option is not supported for IBM AIX platforms.
-setup-interval <minutes>

Used in conjunction with -setup.

Defines the time interval before the floating or Self-Announcing Netprobe requests another configuration file and restarts the announcement process. If no new or valid file is discovered, then the Netprobe neither reloads the configuration file nor restarts the configuration process.

If no -setup-interval is defined, the Netprobe makes the request every 360 minutes (or 6 hours), by default.

Feature behavior

By default, this option only works for remote configurations defined through -setup <url>. However, if used in conjunction with -discovery, then this option works for both -setup <filename> and <url>.

Auto-discovery

When used with -discovery, then this option defines the time interval before the Netprobe reruns the discovery executable to update the JSON metadata. If no updates are discovered from the extracted JSON metadata, then the Netprobe does not reload the Netprobe setup file.

For more information, see Auto-discovery in Netprobe Overview.

Note

For IBM AIX platforms, this option works when used in conjunction with -discovery and -setup <file path>.
-setup-server-verify <file>

Used in conjunction with -setup <url>. This option only takes effect when an HTTPS <url> is specified. Otherwise, this option is ignored.

When this option is invoked, the Netprobe verifies the remote server on the -setup <url> against the specified Certificate Authority (CA) bundle.

You can specify a CA bundle on the <file> argument in PEM format.

If no <file> is specified, then the Netprobe verifies the remote server against the operating system’s Certificate Authority (CA) bundle. In this case, the required certificates must be installed in the appropriate certificate stores.

Note

  • On Windows, the <file> argument is required.
  • On Linux, the Netprobe searches for the default CA bundle at /etc/pki/tls/certs/ca-bundle.crt. However, in Ubuntu and SLES platforms, the default CA bundle is not located at this path. For these platforms, you can either specify a CA bundle file for this option or create a symbolic link at /etc/pki/tls/certs/ca-bundle.crt to the platform’s default CA bundle.
    • For Ubuntu: The default CA bundle is at /etc/ssl/certs/ca-certificates.crt.
    • For SLES: The default CA bundle is at /var/lib/ca-certificates/ca-bundle.pem.
  • On IBM AIX, this option is not supported.
-mdmtest <lua_script> [params]

Test utility for Market Data Monitor Lua script prior to deployment.

Example: $./netprobe.linux-mdmtesttest.luaparam1param2

-listenip

Sets a specific IP address where the Netprobe will listen to incoming connections.

This argument can be used to force Self-Announcing Netprobes not to listen for incoming connections. For more information, see Disable listening in Manage Self-Announcing Netprobes.

-ssl-certificate This is the file that contains the signed SSL server certificate in PEM format.
-ssl-certificate-key

This is the file that contains the signed SSL server private key in PEM format.

If this is option not specified, but the certificate is, then the Netprobe will look for the private key in the same file as the server certificate.

-ssl-certificate-chain This is the file that contains the trusted certificate authority.
-require-ssl-certificate-for

This forces the Netprobe to require certain components connecting to the Netprobe port to provide a valid SSL certificate.

If no certificate is provided, or the certificate cannot be vaildated using the certificate authority provided by the -ssl-certificate-chain option, the connection will be rejected. The connection type of the connections to check must be provided.

This command line option only supports the emf2 argument, which covers all Geneos components connecting using the Geneos EMF2 protocol.

-secure

If this option is present, the Netprobe will listen on a secure port rather than an insecure port.

If -secure is specified, then an SSL server certificate and an server private key also need to be specified.

-nopassword Run commands on the Netprobe’s host. For more information, see Set passwords on Netprobe commands
-mq QM=<qm_name> MQSERVER=<conn_string> CHANTAB=<chan_table> KEYREPO=<ssl_keyrepo> CIPHER=<cipher_spec> Test MQ connection.
  • QM — queue manager, e.g. qm.test
  • MQSERVER — server connection string, e.g. CHAN/TCP/host(port)
  • CHANTAB — full path to the channel table file, e.g. /var/mqm/AMQCLCHL.TAB
  • KEYREPO — full path to SSL key repository, e.g. /var/mqm/ssl/key(.kdb)
  • CIPHER — SSL cipher specification, e.g.TRIPLE_DES_SHA_US
Example value: netprobe-mqQM=qm.testMQSERVER=CHAN/TCP/host
-minTLSversion <version> Specifies the minimum TLS version. The accepted values are:
  • 1
  • 1.0
  • 1.1
  • 1.2
  • 1.3
For more information, see Secure Communications.
-openssl-cipher <ciphers>

To set the available TLS ciphers use the -openssl-cipher command line option, replacing `` with a comma separated list of ciphers.

For more information, see TLS ciphers in Secure Communications.

-json2XML <filename> Converts JSON document specified by <filename> to XML and displays result to the console. This is applicable to Windows platforms only.
-jvm-libpath <path>

Specifies <path> of the JVM library to use.

If this option is invoked, the Netprobe does not attempt to locate the library in the PATH or LD_LIBRARY_PATH environment variable. In Windows, the JVM_LIBPATH registry key is ignored.

Example value: -jvm-libpath /usr/java/jdk/jre/lib/amd64/server/libjvm.so

-java-home <path> Specifies the <path> of the JRE to use. Overrides the JAVA_HOME environment variable.
-perf Show available performance monitor counters. This is applicable to Windows platforms only.
-cmd Run in the foreground, rather than as a service. This is applicable to Windows platforms only.
-install Installs the probe as a service. This is applicable to Windows platforms only.
-uninstall Uninstalls the probe as a service. This is applicable to Windows platforms only.
-showcpus Shows detected CPU information for this machine. This is applicable to Windows platforms only.
-disable-core-dump Disables creation of core dump files. This is applicable to Windows platforms only.
-ifconfig, -if Lists down the NICs present in the Windows machine. This should be used in configuring X-plugins send / recv interfaces. This is applicable to Windows platforms only.

Note

The Npcap packet capture library needs to be installed on the host. If Npcap is not installed using WinPcap API-compatible mode, then the Npcap installation directory must be added in the PATH environment variable or the DLL_PATH registry variable.
-perfdebug Dumps performance counter data into a file (i.e., perfout.dat). This is applicable to Windows platforms only.
-json2XML <filename> Converts JSON document specified by <filename> to XML and displays result to the console. This is applicable to Windows platforms only.
["Geneos"] ["Geneos > Netprobe"] ["User Guide"]

Was this topic helpful?