# Unified CM RTMT alerts and monitoring

Canonical: https://warmtransfer.net/knowledge/cucm-rtmt-alerts

Last verified: 2026-09-25

Cisco Unified Real-Time Monitoring Tool (RTMT) runs as a client-side application that monitors the real-time behaviour of Unified CM system components by connecting over HTTPS and TCP[^12]. A single installation of RTMT can monitor Unified CM, IM and Presence Service, and Unity Connection clusters[^36].

## Client requirements and access control

The RTMT client is downloaded directly as a plugin from Unified CM Administration under Application > Plugins[^41]. The Release 15 RTMT client requires an installed JRE (Java 1.8), while Single Sign-On (SSO) logins require Oracle JDK or OpenJDK 1.8 with the JFX module[^31]. The client application requires at least 128 MB of memory on Windows and at least 300 MB of disk space on Windows and Linux[^11]. The Release 15 RTMT change log dated 2023-12-18 adds certificate-based authentication for RTMT on Windows and Linux, as well as Windows 11 client support[^9]. From Release 15SU2 onward, Unified CM supports TLS 1.3 for RTMT connections[^56].

Full RTMT access requires assignment to the Standard Audit Users and Standard CCM Super Users privilege groups[^1]. To restrict permissions, an RTMT-only user can be configured by adding an application user to the Standard RealtimeAndTraceCollection group[^1].

## Alert Central configuration

Alert Central displays preconfigured and user-defined alerts categorized under five tabs: System, Voice/Video, IM and Presence Service, Cisco Unity Connection, and Custom[^8]. Preconfigured alerts cannot be deleted and can only be enabled or disabled, whereas user-defined alerts can be added and deleted[^43]. An alert threshold is configured as an Over (maximum) or Under (minimum) value[^52]. When counter-based alerts are evaluated, the value can be calculated as Absolute, Delta, or Delta Percentage[^60]. 

- **Duration:** Triggers immediately or only when the measured value continuously exceeds the threshold for a configured number of seconds[^25].
- **Frequency:** Triggers on every poll or limits notifications up to a designated number of alerts within a specified number of minutes[^29].
- **Schedule:** Runs 24 hours daily or within a configured daily Start/Stop window[^47].
- **Suspension:** Alerts can be suspended cluster-wide or on an individual node at System > Tools > Alert > Suspend cluster/node Alerts, such as during scheduled maintenance[^50].

When an alert condition resolves, its display entry in Alert Central changes from red to black[^10].

For email dispatch, the SMTP server is configured under System > Tools > Alert > Config Email Server, which includes server address and port fields[^26]. This setup interface provides an Enable TLS mode check box for encrypted SMTP along with optional SMTP authentication credentials[^27]. The Default alert action routes email notifications to an administrator, and alert actions specify the recipient list invoked when an alert fires[^24].

## Common system and voice alerts

The Release 15 appendix categorizes alerts into System, Voice and Video, IM and Presence Service, Intercompany Media Engine, and Cisco Unity Connection alerts[^7]. CriticalServiceDown, DBReplicationFailure, and LogPartitionHighWaterMarkExceeded fall under System alerts, while CodeYellow, CallProcessingNodeCpuPegging, and RouteListExhausted are Voice and Video alerts[^7]. The Release 15 RTMT change log dated 2024-10-01 adds alert counter support for SmartLicenseCommunication[^49].

| Alert Name | Category | Trigger Condition |
| --- | --- | --- |
| CriticalServiceDown | System | Generated when any monitored service goes down[^23][^7]. |
| CoreDumpFileFound | System | Generated when the RTMT backend service detects a new core dump file[^16]. |
| CodeYellow | Voice and Video | Generated when Unified CM initiates call throttling due to unacceptably high call handling delays[^13][^7]. |

The RTMT backend checks service availability every 30 seconds by default, meaning any service that stops and recovers within that window may not raise a CriticalServiceDown alert[^22]. WarmTransfer's reading of the sources is that because CriticalServiceDown relies on a 30-second poll, short service restarts can be missed by Alert Central, making remote syslog forwarding of Serviceability alarms the likely complement to catch them[^28].

For automated triage, the Enable Trace Download action is offered exclusively for CriticalServiceDown, CodeYellow, and CoreDumpFileFound[^57]. Cisco warns that alert-triggered trace downloads can impact node services and that a high volume of downloads degrades service quality[^58].

In Unified CM 6.0, CodeYellow triggers when the AverageExpectedDelay counter exceeds the configured Code Yellow Entry Latency service parameter[^15]. Cisco's 6.0 guidance notes that CodeYellow can occur at only 25 to 35 percent total CPU utilization on a 4-virtual-processor server because call processing relies on a single processor[^14]. If IOWait is elevated or a node enters CodeYellow while CallManager tracing is set to Detailed, Cisco's 6.0 high-CPU guidance instructs lowering the trace level to Error[^59].

Regarding disk thresholds, Cisco TAC states that reaching LogPartitionHighWaterMarkExceeded automatically purges the oldest log files, whereas LogPartitionLowWaterMarkExceeded serves as an early warning for manual log purging[^33]. A 2018 Cisco TAC note recommends setting LogPartitionHighWaterMarkExceeded to 60 percent and LogPartitionLowWaterMarkExceeded to 50 percent for faster clearing, though this is a recommendation rather than a documented default[^34]. Cisco TAC also attributes LowAvailableVirtualMemory and LowSwapPartitionAvailableDiskSpace to memory accumulation over time and recommends rebooting the node to clear it[^35].

## Performance monitoring and data collection

RTMT's Server category supplies dedicated windows for CPU and Memory, Process, Disk Usage, and Critical Services, while the System Summary window displays virtual memory, CPU, common partition usage, and alert history[^48]. Polling in each precanned RTMT monitoring window is fixed at 30 seconds[^42].

Cisco Alert Manager and Collector (AMC) service parameters control cluster-wide telemetry, including Primary Collector, Failover Collector, Data Collection Enabled, Data Collection Polling Rate, Server Synchronization Period, RMI ports, Logger Enabled, Alarm Enabled, and AlertMgr Enabled[^6]. In the Perfmon Monitoring view, each category tab accommodates up to 6 charts with up to 3 counters per chart[^38]. Users can access counter instances and definitions via System > Performance > Counter Instances and System > Performance > Counter Description[^18]. A threshold alert can be placed on any perfmon counter by selecting Set Alert/Properties to configure severity, threshold, frequency, schedule, and email notification[^17].

Database replication status can be tracked using the Replicate_State counter, which reports the following values:
- 0: Initializing[^46]
- 1: Replication setup script fired from this node[^46]
- 2: Good Replication[^46]
- 3: Bad Replication[^46]
- 4: Replication setup did not succeed[^46]

Troubleshooting perfmon data logging defaults to a 15-second polling rate (configurable from 5 to 300 seconds), 50 maximum files, and a 2 MB maximum file size[^39]. These troubleshooting logs are saved to the active log partition under var/log/active/cm/log/ris/csv and are collected via Trace and Log Central or the CLI[^40]. In contrast, local perfmon logging initiated by an RTMT client user writes CSV files directly to the log folder inside the.jrtmt directory in the client user's home directory rather than to the server[^32].

## Trace collection and alarms

Trace collection is executed via Tools > Trace > Trace & Log Central > Collect Files, allowing administrators to pick services per node, define an absolute or relative time range, and choose active or inactive partitions[^54]. Trace and Log Central references the Selected Reference Server Time Zone and normalizes across nodes residing in different time zones so that all nodes collect logs for the identical time period[^55]. Trace and Log Central supports up to 6 concurrent trace collections, up to 10 scheduled collection jobs, and viewing up to 5 open files simultaneously[^53]. 

For live troubleshooting, Real-Time Trace View Real-Time Data refreshes every 5 seconds, and Monitor User Event polls every 5 seconds for a configured search string to raise an alert or trigger a file download[^44]. RTMT cannot download zipped crash dump files larger than 2 GB[^21]. Scheduled trace collection no longer supports FTP servers starting in Release 14SU3; SFTP must be used[^30].

Unified CM Serviceability alarms can be routed to Local Syslog (accessible via RTMT SysLog Viewer), Remote Syslog, SDL trace (limited to CallManager and CTIManager), and SDI trace[^4]. Alarm destinations and event levels are configured under Cisco Unified Serviceability > Alarm > Configuration, while alarm definitions are located at Alarm > Definitions[^2]. Alarm event levels span Emergency to Debug, and the default event level is Error[^3]. Up to 5 remote syslog servers (Server Name 1 through 5) can be defined as alarm destinations[^45]. 

Cisco Syslog Agent enterprise parameters (Remote Syslog Server Name 1-5 and Syslog Severity) forward alarms meeting or exceeding the chosen severity to remote syslog collectors[^51]. A Unified CM node must not be configured as a remote syslog server target because Unified CM does not accept syslog messages incoming from external systems[^37].

During investigations of high CPU or memory conditions, Cisco TAC uses the CLI commands show process load, show process using-most cpu, show status, and utils diagnose test[^19]. For post-incident analysis, TAC requests detailed CallManager traces, Cisco RISDC and Perfmon logs, Cisco AMC service logs, Tomcat and Tomcat Security logs, as well as Event Viewer application and system logs[^20].

## See also

- See also [CUCM CallManager SDL trace files](https://warmtransfer.net/knowledge/cucm-sdl-trace-files).
- See also [Unified CM backup and upgrade](https://warmtransfer.net/knowledge/cucm-backup-upgrade).
- See also [Unified CM certificate renewal](https://warmtransfer.net/knowledge/cucm-certificate-renewal).
- See also [Unified CM release trains and lifecycle dates](https://warmtransfer.net/knowledge/cucm-versions-lifecycle).

## Applicability

Applies to: Cisco Unified Communications Manager. Deployments: on-premises. Sources checked 2026-09-25. Release 15 and SUs cover the RTMT client and backend specifications, with certificate-based authentication added in a 2023-12-18 update and SmartLicenseCommunication counter support added in a 2024-10-01 update[^12][^9][^49]. TLS 1.3 client support requires Release 15SU2 or later[^56]. Scheduled trace collection requires SFTP rather than FTP starting in Release 14SU3[^30]. CodeYellow single-processor latency thresholds and high-CPU IOWait trace reduction guidance derive from Unified CM Release 6.0[^15][^14][^59]. Log partition high and low water mark recommendations, swap partition memory reboot procedures, and TAC CLI diagnostic commands originate from 2018 guidance where the specific release range is not stated[^34][^33][^35][^19][^20].

## What remains uncertain

Whether specific syslog message formats can be tailored per remote destination is not covered by the sources below. Whether the 2 GB crash dump download restriction applies to collections initiated via the command line is not covered by the sources below. How RTMT manages Alert Central notifications when connectivity to the AMC primary collector fails during failover is not covered by the sources below.

## Sources

[^1]: Full RTMT access requires Standard Audit Users and Standard CCM Super Users privileges; an RTMT-only user can be built by adding an application user to the Standard RealtimeAndTraceCollection group. Source: [Cisco Unified Real-Time Monitoring Tool Administration Guide, Release 15 and SUs - Getting Started](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/service/15/rtmt/cucm_b_cisco-unified-rtmt-administration-15/cucm_m_getting-started.html), Getting Started > Configure Unified RTMT access / administrator privileges. Checked 2026-09-25.
[^2]: Alarm destinations and levels are set at Cisco Unified Serviceability > Alarm > Configuration; alarm definitions are at Alarm > Definitions. Source: [Administration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Alarms](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/15/adminGd/cucm_b_administration-guide-15/cucm_b_test-adminguide_chapter_010011.html), Alarms > Set up alarms / Alarm definitions. Checked 2026-09-25.
[^3]: Alarm event levels run from Emergency to Debug, and the default alarm event level is Error. Source: [Administration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Alarms](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/15/adminGd/cucm_b_administration-guide-15/cucm_b_test-adminguide_chapter_010011.html), Alarms > Alarm event level. Checked 2026-09-25.
[^4]: Unified CM Serviceability alarms can be sent to Local Syslog (viewed in RTMT SysLog Viewer), Remote Syslog, SDL trace (CallManager and CTIManager only) and SDI trace. Source: [Administration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Alarms](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/15/adminGd/cucm_b_administration-guide-15/cucm_b_test-adminguide_chapter_010011.html), Alarms > Alarm configuration settings (destinations). Checked 2026-09-25.
[^5]: RTMT alert log files follow the name pattern AlertLog_MM_DD_YYYY_hh_mm.csv. Source: [Cisco Unified Real-Time Monitoring Tool Administration Guide, Release 15 and SUs - Getting Started](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/service/15/rtmt/cucm_b_cisco-unified-rtmt-administration-15/cucm_m_getting-started.html), Getting Started > alert log / AMC logging. Checked 2026-09-25.
[^6]: The Cisco AMC (Alert Manager and Collector) service parameters include Primary Collector, Failover Collector, Data Collection Enabled, Data Collection Polling Rate, Server Synchronization Period, RMI ports, Logger Enabled, Alarm Enabled and AlertMgr Enabled. Source: [Cisco Unified Real-Time Monitoring Tool Administration Guide, Release 15 and SUs - Getting Started](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/service/15/rtmt/cucm_b_cisco-unified-rtmt-administration-15/cucm_m_getting-started.html), Getting Started > Alert Manager and Collector service parameters. Checked 2026-09-25.
[^7]: The Release 15 appendix groups alerts as System, Voice and Video, IM and Presence Service, Intercompany Media Engine and Cisco Unity Connection alerts; CodeYellow, CallProcessingNodeCpuPegging and RouteListExhausted sit under Voice and Video, while CriticalServiceDown, DBReplicationFailure and LogPartitionHighWaterMarkExceeded sit under System. Source: [Cisco Unified Real-Time Monitoring Tool Administration Guide, Release 15 and SUs - Performance Counters and Alerts](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/service/15/rtmt/cucm_b_cisco-unified-rtmt-administration-15/cucm_m_performance-counters-and-alerts-15.html), Performance Counters and Alerts > section list and alert tables of contents. Checked 2026-09-25.
[^8]: Alert Central shows preconfigured and custom alerts under five tabs: System, Voice/Video, IM and Presence Service, Cisco Unity Connection and Custom. Source: [Cisco Unified Real-Time Monitoring Tool Administration Guide, Release 15 and SUs - Alerts](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/service/15/rtmt/cucm_b_cisco-unified-rtmt-administration-15/cucm_b_cisco-unified-rtmt-administration-1251su2_chapter_0111.html), Alerts > Alert Central overview. Checked 2026-09-25.
[^9]: The Release 15 RTMT guide's change log dated 2023-12-18 adds certificate-based authentication for RTMT on Windows and Linux and Windows 11 client support. Source: [Cisco Unified Real-Time Monitoring Tool Administration Guide, Release 15 and SUs - New and Changed Information](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/service/15/rtmt/cucm_b_cisco-unified-rtmt-administration-15/cucm_m_new-and-changed-information.html), New and Changed Information > entry dated December 18, 2023. Checked 2026-09-25.
[^10]: A cleared alert in Alert Central changes from red to black. Source: [Cisco Unified Real-Time Monitoring Tool Administration Guide, Release 15 and SUs - Alerts](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/service/15/rtmt/cucm_b_cisco-unified-rtmt-administration-15/cucm_b_cisco-unified-rtmt-administration-1251su2_chapter_0111.html), Alerts > Alert Central / clear alerts. Checked 2026-09-25.
[^11]: RTMT needs at least 128 MB memory on Windows and at least 300 MB of disk space on Windows and Linux. Source: [Cisco Unified Real-Time Monitoring Tool Administration Guide, Release 15 and SUs - Administration Overview](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/service/15/rtmt/cucm_b_cisco-unified-rtmt-administration-15/cucm_b_cisco-unified-rtmt-administration-1251su2_chapter_01.html), Administration Overview > Operating System Support / requirements. Checked 2026-09-25.
[^12]: Cisco Unified RTMT runs as a client-side application that monitors the real-time behaviour of Unified CM system components, connecting over HTTPS and TCP. Source: [Cisco Unified Real-Time Monitoring Tool Administration Guide, Release 15 and SUs - Administration Overview](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/service/15/rtmt/cucm_b_cisco-unified-rtmt-administration-15/cucm_b_cisco-unified-rtmt-administration-1251su2_chapter_01.html), Administration Overview > Cisco Unified Real-Time Monitoring Tool (opening paragraphs). Checked 2026-09-25.
[^13]: CodeYellow indicates that Unified CM has started call throttling because of unacceptably high delay in handling calls. Source: [Cisco Unified Real-Time Monitoring Tool Administration Guide, Release 15 and SUs - Alerts](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/service/15/rtmt/cucm_b_cisco-unified-rtmt-administration-15/cucm_b_cisco-unified-rtmt-administration-1251su2_chapter_0111.html), Alerts > CodeYellow. Checked 2026-09-25.
[^14]: Cisco's 6.0 guidance says CodeYellow can occur at only about 25-35 percent total CPU on a 4-virtual-processor server because call processing relies on one processor. Source: [Monitoring and Troubleshooting Cisco Unified Communications Manager 6.0 High CPU, using Real Time Monitoring Tool (RTMT)](https://www.cisco.com/c/en/us/support/docs/voice-unified-communications/unified-communications-manager-callmanager/97086-ccm6-cpu.html), Code Yellow / CPU discussion. Checked 2026-09-25.
[^15]: In Unified CM 6.0, CodeYellow is raised when the AverageExpectedDelay counter exceeds the Code Yellow Entry Latency service parameter. Source: [Monitoring and Troubleshooting Cisco Unified Communications Manager 6.0 High CPU, using Real Time Monitoring Tool (RTMT)](https://www.cisco.com/c/en/us/support/docs/voice-unified-communications/unified-communications-manager-callmanager/97086-ccm6-cpu.html), Code Yellow section. Checked 2026-09-25.
[^16]: CoreDumpFileFound is generated when the RTMT backend service detects a new core dump file. Source: [Cisco Unified Real-Time Monitoring Tool Administration Guide, Release 15 and SUs - Alerts](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/service/15/rtmt/cucm_b_cisco-unified-rtmt-administration-15/cucm_b_cisco-unified-rtmt-administration-1251su2_chapter_0111.html), Alerts > CoreDumpFileFound. Checked 2026-09-25.
[^17]: A threshold alert on any perfmon counter is created from the Perfmon Monitoring pane via Set Alert/Properties, choosing severity, threshold, frequency, schedule and email notification. Source: [Cisco Unified Real-Time Monitoring Tool Administration Guide, Release 15 and SUs - Performance Counters](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/service/15/rtmt/cucm_b_cisco-unified-rtmt-administration-15/cucm_b_cisco-unified-rtmt-administration-1251su2_chapter_0110.html), Performance Counters > Set Up Counter Alert Notification. Checked 2026-09-25.
[^18]: Counter instances and counter descriptions are reached at System > Performance > Counter Instances and System > Performance > Counter Description. Source: [Cisco Unified Real-Time Monitoring Tool Administration Guide, Release 15 and SUs - Performance Counters](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/service/15/rtmt/cucm_b_cisco-unified-rtmt-administration-15/cucm_b_cisco-unified-rtmt-administration-1251su2_chapter_0110.html), Performance Counters > Counter instances / counter description. Checked 2026-09-25.
[^19]: Cisco TAC uses the CLI commands show process load, show process using-most cpu, show status and utils diagnose test when investigating high CPU or memory alerts. Source: [Logs to be Collected for TAC when High CPU or Memory Issue is Noticed on CUCM](https://www.cisco.com/c/en/us/support/docs/unified-communications/unified-communications-manager-callmanager/213679-logs-to-be-collected-for-tac-when-high-c.html), Commands to run when the issue occurs. Checked 2026-09-25.
[^20]: For post-incident high CPU or memory analysis, Cisco TAC asks for detailed CallManager traces, Cisco RISDC and Perfmon logs, Cisco AMC service logs, Tomcat and Tomcat Security logs, and Event Viewer application and system logs. Source: [Logs to be Collected for TAC when High CPU or Memory Issue is Noticed on CUCM](https://www.cisco.com/c/en/us/support/docs/unified-communications/unified-communications-manager-callmanager/213679-logs-to-be-collected-for-tac-when-high-c.html), Logs to collect. Checked 2026-09-25.
[^21]: RTMT cannot download a zipped crash dump file larger than 2 GB. Source: [Cisco Unified Real-Time Monitoring Tool Administration Guide, Release 15 and SUs - Traces and Logs](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/service/15/rtmt/cucm_b_cisco-unified-rtmt-administration-15/cucm_b_cisco-unified-rtmt-administration-1251su2_chapter_01000.html), Traces and Logs > Collect Crash Dump. Checked 2026-09-25.
[^22]: The RTMT backend checks service status every 30 seconds by default, so a service that goes down and recovers within that period may not raise CriticalServiceDown. Source: [Cisco Unified Real-Time Monitoring Tool Administration Guide, Release 15 and SUs - Alerts](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/service/15/rtmt/cucm_b_cisco-unified-rtmt-administration-15/cucm_b_cisco-unified-rtmt-administration-1251su2_chapter_0111.html), Alerts > CriticalServiceDown. Checked 2026-09-25.
[^23]: CriticalServiceDown is generated when any monitored service is down. Source: [Cisco Unified Real-Time Monitoring Tool Administration Guide, Release 15 and SUs - Alerts](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/service/15/rtmt/cucm_b_cisco-unified-rtmt-administration-15/cucm_b_cisco-unified-rtmt-administration-1251su2_chapter_0111.html), Alerts > CriticalServiceDown. Checked 2026-09-25.
[^24]: The Default alert action sends email to an administrator; alert actions carry the recipient list used when an alert fires. Source: [Cisco Unified Real-Time Monitoring Tool Administration Guide, Release 15 and SUs - Alerts](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/service/15/rtmt/cucm_b_cisco-unified-rtmt-administration-15/cucm_b_cisco-unified-rtmt-administration-1251su2_chapter_0111.html), Alerts > Alert Action Configuration. Checked 2026-09-25.
[^25]: The alert Duration setting either triggers immediately or only when the value stays beyond the threshold continuously for a configured number of seconds. Source: [Cisco Unified Real-Time Monitoring Tool Administration Guide, Release 15 and SUs - Alerts](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/service/15/rtmt/cucm_b_cisco-unified-rtmt-administration-15/cucm_b_cisco-unified-rtmt-administration-1251su2_chapter_0111.html), Alerts > Set Alert Properties > Duration. Checked 2026-09-25.
[^26]: The SMTP server for RTMT alert email is configured at System > Tools > Alert > Config Email Server, with mail server and port fields. Source: [Cisco Unified Real-Time Monitoring Tool Administration Guide, Release 15 and SUs - Alerts](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/service/15/rtmt/cucm_b_cisco-unified-rtmt-administration-15/cucm_b_cisco-unified-rtmt-administration-1251su2_chapter_0111.html), Alerts > Configure Email Server for Alert Notification. Checked 2026-09-25.
[^27]: The email server dialog has an Enable TLS mode check box for encrypted SMTP and optional SMTP authentication credentials. Source: [Cisco Unified Real-Time Monitoring Tool Administration Guide, Release 15 and SUs - Alerts](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/service/15/rtmt/cucm_b_cisco-unified-rtmt-administration-15/cucm_b_cisco-unified-rtmt-administration-1251su2_chapter_0111.html), Alerts > Configure Email Server for Alert Notification. Checked 2026-09-25.
[^28]: Because CriticalServiceDown relies on a 30-second status check, short service restarts can be missed by Alert Central; forwarding Serviceability alarms to remote syslog is the likely complement for catching them (inferred). Source: [Cisco Unified Real-Time Monitoring Tool Administration Guide, Release 15 and SUs - Alerts](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/service/15/rtmt/cucm_b_cisco-unified-rtmt-administration-15/cucm_b_cisco-unified-rtmt-administration-1251su2_chapter_0111.html), Alerts > CriticalServiceDown, read with Alarms chapter of the Release 15 Administration Guide. Checked 2026-09-25.
[^29]: The alert Frequency setting either triggers on every poll or sends up to a set number of alerts within a set number of minutes. Source: [Cisco Unified Real-Time Monitoring Tool Administration Guide, Release 15 and SUs - Alerts](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/service/15/rtmt/cucm_b_cisco-unified-rtmt-administration-15/cucm_b_cisco-unified-rtmt-administration-1251su2_chapter_0111.html), Alerts > Set Alert Properties > Frequency (Trigger up to radio button). Checked 2026-09-25.
[^30]: From Release 14SU3 onward, scheduled trace collection no longer supports an FTP server; SFTP is used. Source: [Cisco Unified Real-Time Monitoring Tool Administration Guide, Release 15 and SUs - Traces and Logs](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/service/15/rtmt/cucm_b_cisco-unified-rtmt-administration-15/cucm_b_cisco-unified-rtmt-administration-1251su2_chapter_01000.html), Traces and Logs > Schedule Trace Collection. Checked 2026-09-25.
[^31]: The Release 15 RTMT client requires an installed JRE (Java 1.8); SSO logins need Oracle JDK or OpenJDK 1.8 with the JFX module. Source: [Cisco Unified Real-Time Monitoring Tool Administration Guide, Release 15 and SUs - Getting Started](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/service/15/rtmt/cucm_b_cisco-unified-rtmt-administration-15/cucm_m_getting-started.html), Getting Started > Install Unified RTMT (prerequisite note). Checked 2026-09-25.
[^32]: Local perfmon logging done by an RTMT user writes CSV files to the log folder of the .jrtmt directory in the client user's home directory, not to the server. Source: [Cisco Unified Real-Time Monitoring Tool Administration Guide, Release 15 and SUs - Performance Counters](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/service/15/rtmt/cucm_b_cisco-unified-rtmt-administration-15/cucm_b_cisco-unified-rtmt-administration-1251su2_chapter_0110.html), Performance Counters > Local perfmon counter data logging. Checked 2026-09-25.
[^33]: Per Cisco TAC, reaching the LogPartitionHighWaterMarkExceeded threshold automatically purges the oldest logs, while LogPartitionLowWaterMarkExceeded is an early warning for manual purging. Source: [Real-Time Monitoring Tool Alerts](https://www.cisco.com/c/en/us/support/docs/unified-communications/unified-communications-manager-callmanager/213291-real-time-monitoring-tool-alerts.html), LogPartitionHighWaterMarkExceeded / LogPartitionLowWaterMarkExceeded section. Checked 2026-09-25.
[^34]: A 2018 Cisco TAC note recommends setting LogPartitionHighWaterMarkExceeded to 60 percent and LogPartitionLowWaterMarkExceeded to 50 percent (lower for faster clearing); this is a recommendation, not a documented default. Source: [Real-Time Monitoring Tool Alerts](https://www.cisco.com/c/en/us/support/docs/unified-communications/unified-communications-manager-callmanager/213291-real-time-monitoring-tool-alerts.html), LogPartitionHighWaterMarkExceeded / LogPartitionLowWaterMarkExceeded section. Checked 2026-09-25.
[^35]: Cisco TAC attributes LowAvailableVirtualMemory and LowSwapPartitionAvailableDiskSpace to memory building up over time and recommends a node reboot to clear it. Source: [Real-Time Monitoring Tool Alerts](https://www.cisco.com/c/en/us/support/docs/unified-communications/unified-communications-manager-callmanager/213291-real-time-monitoring-tool-alerts.html), LowAvailableVirtualMemory and LowSwapPartitionAvailableDiskSpace section. Checked 2026-09-25.
[^36]: A single RTMT installation can monitor Unified CM, IM and Presence Service and Unity Connection clusters. Source: [Cisco Unified Real-Time Monitoring Tool Administration Guide, Release 15 and SUs - Administration Overview](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/service/15/rtmt/cucm_b_cisco-unified-rtmt-administration-15/cucm_b_cisco-unified-rtmt-administration-1251su2_chapter_01.html), Administration Overview > Cisco Unified Real-Time Monitoring Tool. Checked 2026-09-25.
[^37]: A Unified CM node must not be configured as a remote syslog server because it does not accept syslog messages from another server. Source: [Administration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Alarms](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/15/adminGd/cucm_b_administration-guide-15/cucm_b_test-adminguide_chapter_010011.html), Alarms > Alarm configuration settings (note under Remote Syslogs). Checked 2026-09-25.
[^38]: Each Perfmon Monitoring category tab shows up to six charts with up to three counters per chart. Source: [Cisco Unified Real-Time Monitoring Tool Administration Guide, Release 15 and SUs - Performance Counters](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/service/15/rtmt/cucm_b_cisco-unified-rtmt-administration-15/cucm_b_cisco-unified-rtmt-administration-1251su2_chapter_0110.html), Performance Counters > Display perfmon counters. Checked 2026-09-25.
[^39]: Troubleshooting perfmon data logging defaults to a 15-second polling rate (range 5-300), 50 maximum files and a 2 MB maximum file size. Source: [Cisco Unified Real-Time Monitoring Tool Administration Guide, Release 15 and SUs - Performance Counters](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/service/15/rtmt/cucm_b_cisco-unified-rtmt-administration-15/cucm_b_cisco-unified-rtmt-administration-1251su2_chapter_0110.html), Performance Counters > Troubleshooting Perfmon Data Logging > parameter table. Checked 2026-09-25.
[^40]: Troubleshooting perfmon logs are written to the active log partition under var/log/active/cm/log/ris/csv and are collected with Trace and Log Central or the CLI. Source: [Cisco Unified Real-Time Monitoring Tool Administration Guide, Release 15 and SUs - Performance Counters](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/service/15/rtmt/cucm_b_cisco-unified-rtmt-administration-15/cucm_b_cisco-unified-rtmt-administration-1251su2_chapter_0110.html), Performance Counters > Troubleshooting Perfmon Data Logging. Checked 2026-09-25.
[^41]: The RTMT client is downloaded as a plugin from Unified CM Administration under Application > Plugins. Source: [Cisco Unified Real-Time Monitoring Tool Administration Guide, Release 15 and SUs - Getting Started](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/service/15/rtmt/cucm_b_cisco-unified-rtmt-administration-15/cucm_m_getting-started.html), Getting Started > Install Unified RTMT. Checked 2026-09-25.
[^42]: Polling in each precanned RTMT monitoring window is fixed at 30 seconds. Source: [Cisco Unified Real-Time Monitoring Tool Administration Guide, Release 15 and SUs - System Performance Monitoring](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/service/15/rtmt/cucm_b_cisco-unified-rtmt-administration-15/cucm_b_cisco-unified-rtmt-administration-1251su2_chapter_011.html), System Performance Monitoring > predefined objects. Checked 2026-09-25.
[^43]: Preconfigured RTMT alerts cannot be deleted, only enabled or disabled; user-defined alerts can be added and deleted. Source: [Cisco Unified Real-Time Monitoring Tool Administration Guide, Release 15 and SUs - Alerts](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/service/15/rtmt/cucm_b_cisco-unified-rtmt-administration-15/cucm_b_cisco-unified-rtmt-administration-1251su2_chapter_0111.html), Alerts > Alert Central overview / preconfigured alerts. Checked 2026-09-25.
[^44]: Real Time Trace View Real-Time Data refreshes every 5 seconds, and Monitor User Event polls every 5 seconds for a search string to trigger an alert or download. Source: [Cisco Unified Real-Time Monitoring Tool Administration Guide, Release 15 and SUs - Traces and Logs](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/service/15/rtmt/cucm_b_cisco-unified-rtmt-administration-15/cucm_b_cisco-unified-rtmt-administration-1251su2_chapter_01000.html), Traces and Logs > Real-Time Trace. Checked 2026-09-25.
[^45]: Up to five remote syslog servers (Server Name 1-5) can be configured as alarm destinations. Source: [Administration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Alarms](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/15/adminGd/cucm_b_administration-guide-15/cucm_b_test-adminguide_chapter_010011.html), Alarms > Alarm configuration settings (Remote Syslogs). Checked 2026-09-25.
[^46]: The Replicate_State counter values mean 0 Initializing, 1 replication setup script fired from this node, 2 Good Replication, 3 Bad Replication and 4 replication setup did not succeed. Source: [Cisco Unified Real-Time Monitoring Tool Administration Guide, Release 15 and SUs - Performance Counters and Alerts](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/service/15/rtmt/cucm_b_cisco-unified-rtmt-administration-15/cucm_m_performance-counters-and-alerts-15.html), Performance Counters and Alerts > System Counters > Number of Replicates Created and State of Replication. Checked 2026-09-25.
[^47]: An alert Schedule is either 24 hours daily or a daily Start/Stop time window. Source: [Cisco Unified Real-Time Monitoring Tool Administration Guide, Release 15 and SUs - Alerts](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/service/15/rtmt/cucm_b_cisco-unified-rtmt-administration-15/cucm_b_cisco-unified-rtmt-administration-1251su2_chapter_0111.html), Alerts > Set Alert Properties > Schedule. Checked 2026-09-25.
[^48]: RTMT's Server category provides CPU and Memory, Process, Disk Usage and Critical Services windows; System Summary includes virtual memory, CPU, common partition usage and alert history. Source: [Cisco Unified Real-Time Monitoring Tool Administration Guide, Release 15 and SUs - System Performance Monitoring](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/service/15/rtmt/cucm_b_cisco-unified-rtmt-administration-15/cucm_b_cisco-unified-rtmt-administration-1251su2_chapter_011.html), System Performance Monitoring > System Summary / Server. Checked 2026-09-25.
[^49]: The Release 15 RTMT change log dated 2024-10-01 adds alert counter support for SmartLicenseCommunication. Source: [Cisco Unified Real-Time Monitoring Tool Administration Guide, Release 15 and SUs - New and Changed Information](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/service/15/rtmt/cucm_b_cisco-unified-rtmt-administration-15/cucm_m_new-and-changed-information.html), New and Changed Information > entry dated October 01, 2024. Checked 2026-09-25.
[^50]: Alerts can be suspended cluster-wide or per node at System > Tools > Alert > Suspend cluster/node Alerts, for example during maintenance. Source: [Cisco Unified Real-Time Monitoring Tool Administration Guide, Release 15 and SUs - Alerts](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/service/15/rtmt/cucm_b_cisco-unified-rtmt-administration-15/cucm_b_cisco-unified-rtmt-administration-1251su2_chapter_0111.html), Alerts > Suspend Alerts. Checked 2026-09-25.
[^51]: The Cisco Syslog Agent enterprise parameters (Remote Syslog Server Name 1-5 and Syslog Severity) forward alarms at or above the set severity to remote syslog servers. Source: [Administration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Alarms](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/15/adminGd/cucm_b_administration-guide-15/cucm_b_test-adminguide_chapter_010011.html), Alarms > Syslog agent enterprise parameters. Checked 2026-09-25.
[^52]: An RTMT alert threshold is configured as an Over (maximum) or Under (minimum) value that triggers notification. Source: [Cisco Unified Real-Time Monitoring Tool Administration Guide, Release 15 and SUs - Alerts](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/service/15/rtmt/cucm_b_cisco-unified-rtmt-administration-15/cucm_b_cisco-unified-rtmt-administration-1251su2_chapter_0111.html), Alerts > Set Alert Properties > Threshold. Checked 2026-09-25.
[^53]: Trace and Log Central runs up to six concurrent trace collections, allows up to ten scheduled jobs and opens at most five files at once for viewing. Source: [Cisco Unified Real-Time Monitoring Tool Administration Guide, Release 15 and SUs - Traces and Logs](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/service/15/rtmt/cucm_b_cisco-unified-rtmt-administration-15/cucm_b_cisco-unified-rtmt-administration-1251su2_chapter_01000.html), Traces and Logs > Collect Files / Schedule Collection / Open files. Checked 2026-09-25.
[^54]: Trace collection starts at Tools > Trace > Trace & Log Central > Collect Files, choosing services per node, an absolute or relative time range and active or inactive partition. Source: [Cisco Unified Real-Time Monitoring Tool Administration Guide, Release 15 and SUs - Traces and Logs](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/service/15/rtmt/cucm_b_cisco-unified-rtmt-administration-15/cucm_b_cisco-unified-rtmt-administration-1251su2_chapter_01000.html), Traces and Logs > Collect Files. Checked 2026-09-25.
[^55]: Trace and Log Central uses the Selected Reference Server Time Zone and adjusts for nodes in other time zones so all nodes return the same time period. Source: [Cisco Unified Real-Time Monitoring Tool Administration Guide, Release 15 and SUs - Traces and Logs](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/service/15/rtmt/cucm_b_cisco-unified-rtmt-administration-15/cucm_b_cisco-unified-rtmt-administration-1251su2_chapter_01000.html), Traces and Logs > Collect Files (time zone note). Checked 2026-09-25.
[^56]: From Release 15SU2 onward Unified CM supports TLS 1.3 for RTMT connections. Source: [Cisco Unified Real-Time Monitoring Tool Administration Guide, Release 15 and SUs - Administration Overview](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/service/15/rtmt/cucm_b_cisco-unified-rtmt-administration-15/cucm_b_cisco-unified-rtmt-administration-1251su2_chapter_01.html), Administration Overview > Operating System Support (TLS note). Checked 2026-09-25.
[^57]: Enable Trace Download is offered only for the CriticalServiceDown, CodeYellow and CoreDumpFileFound alerts. Source: [Cisco Unified Real-Time Monitoring Tool Administration Guide, Release 15 and SUs - Alerts](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/service/15/rtmt/cucm_b_cisco-unified-rtmt-administration-15/cucm_b_cisco-unified-rtmt-administration-1251su2_chapter_0111.html), Alerts > Enable Trace Download. Checked 2026-09-25.
[^58]: Cisco warns that alert-triggered trace download may affect services on the node and that a high number of downloads degrades service quality. Source: [Cisco Unified Real-Time Monitoring Tool Administration Guide, Release 15 and SUs - Alerts](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/service/15/rtmt/cucm_b_cisco-unified-rtmt-administration-15/cucm_b_cisco-unified-rtmt-administration-1251su2_chapter_0111.html), Alerts > Enable Trace Download (caution). Checked 2026-09-25.
[^59]: In Cisco's 6.0 high-CPU note, if IOWait is high or the node is in CodeYellow while CallManager tracing is Detailed, lower the trace level to Error. Source: [Monitoring and Troubleshooting Cisco Unified Communications Manager 6.0 High CPU, using Real Time Monitoring Tool (RTMT)](https://www.cisco.com/c/en/us/support/docs/voice-unified-communications/unified-communications-manager-callmanager/97086-ccm6-cpu.html), IOWait / trace setting guidance. Checked 2026-09-25.
[^60]: For counter-based alerts the value can be calculated as Absolute, Delta or Delta Percentage. Source: [Cisco Unified Real-Time Monitoring Tool Administration Guide, Release 15 and SUs - Alerts](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/service/15/rtmt/cucm_b_cisco-unified-rtmt-administration-15/cucm_b_cisco-unified-rtmt-administration-1251su2_chapter_0111.html), Alerts > Set Alert Properties > Value Calculated As. Checked 2026-09-25.
