ThreadNetworkDiagnostics Cluster

Cluster ID: 0x0035  |  Endpoint: Endpoint 0 (Root Endpoint)

ThreadNetworkDiagnostics is the network diagnostics cluster for Thread devices, providing the complete operational status of the Thread Mesh network. It contains 60+ attributes covering network identification, topology routing, packet statistics, and error counts — the core tool for troubleshooting Thread device connectivity and analyzing network quality.

Use Cases

This cluster is primarily for diagnostics and debugging and does not control device functionality. When Thread devices have unstable connections, high latency, or severe packet loss, reading this cluster can quickly locate the issue — poor signal (check RSSI/LQI), suboptimal routing (check RouteTable), or excessive link errors (check error counters).

Feature Bitmap

ThreadNetworkDiagnostics declares which counter categories the device supports through FeatureMap (0xFFFC). Different features control the availability of different groups of counter attributes.

Bit 0
PKTCNT(PacketCounts) Packet counters — cumulative statistics for various TX/RX packet types
Bit 1
ERRCNT(ErrorCounts) Error counters — receive error (FCS/security/source address, etc.) and buffer overflow statistics
Bit 2
MLECNT(MLECounts) MLE counters — MLE layer event statistics for role changes, attach attempts, partition switches, etc.
Bit 3
MACCNT(MACCounts) MAC counters — low-level link statistics for MAC layer retries, CCA failures, etc.
Relationship Between Features and Attributes

Basic network information (Channel, RoutingRole, NeighborTable, etc.) is supported by all Thread devices and requires no features. Counter attributes are grouped by feature — for example, only devices with PKTCNT enabled will report TxTotalCount and other packet statistics. Check FeatureMap before reading to avoid errors from unsupported attributes.

Commands

ThreadNetworkDiagnostics has only one command, used to reset all counters.

ID Name Description Required Feature
0x00 ResetCounts Reset all optional counters to zero ERRCNT or MACCNT

ResetCounts — Reset Counters (0x00)

Resets all counters corresponding to enabled features (including OverrunCount) to zero on the device. No parameters required. After execution, all statistics restart from 0.

Usage Scenarios

When diagnosing network issues, first call ResetCounts to clear counters, then observe counter growth over a period, to determine the current error rate and network quality. This avoids historical accumulated data from interfering with judgment.

Attributes

ThreadNetworkDiagnostics has 60+ attributes, organized into the following groups by function. Basic network information is supported by all Thread devices; counter attributes are grouped by feature.

Network Identity (0x0000 - 0x0005)

Basic identity information for the Thread network, identifying which Thread network the device belongs to.

IDNameTypeDescription
0x0000 Channel
Channel
uint16 Current IEEE 802.15.4 channel number used by the Thread network. Thread uses channels 11-26 in the 2.4GHz band
0x0001 RoutingRole
Routing Role
RoutingRoleEnum / null Current role of the device in the Thread network (see enum values). null means not yet determined
0x0002 NetworkName
Network Name
string / null Thread network name, UTF-8 string up to 16 bytes
0x0003 PanId
PAN ID
uint16 / null IEEE 802.15.4 16-bit PAN identifier
0x0004 ExtendedPanId
Extended PAN ID
uint64 / null 64-bit extended PAN identifier, used to distinguish different networks with the same PAN ID
0x0005 MeshLocalPrefix
Mesh Local Prefix
octstr / null Thread Mesh local IPv6 prefix (/64 prefix within the fd00::/8 range)

Topology & Routing (0x0007 - 0x000D)

Topology structure and routing information of the Thread Mesh network, including neighbor table, route table, and partition data.

IDNameTypeDescription
0x0007 NeighborTable
Neighbor Table
list<NeighborTableStruct> Detailed information list of direct communication neighbors (see struct description)
0x0008 RouteTable
Route Table
list<RouteTableStruct> Network route entry list (see struct description)
0x0009 PartitionId
Partition ID
uint32 / null Identifier for the current Thread network partition. Different partitions have different IDs when the network splits
0x000A Weighting
Partition Weight
uint16 / null Weight of the current partition; partitions with higher weight are preferentially kept during network merges
0x000B DataVersion
Data Version
uint16 / null Version number of Thread network data, incremented with each network data change
0x000C StableDataVersion
Stable Data Version
uint16 / null Version number of stable network data (excluding volatile data such as temporary routes)
0x000D LeaderRouterId
Leader Router ID
uint8 / null Router ID of the current Thread network Leader

NeighborTableStruct Structure

Each entry in the neighbor table describes a directly communicating neighbor node. Signal quality (LQI/RSSI) and error rate are key fields for assessing link health.

FieldTypeDescription
ExtAddressuint64Neighbor's 64-bit extended MAC address
Ageuint32Seconds since last communication
Rloc16uint16Neighbor's 16-bit routing locator
LinkFrameCounteruint32Link layer frame counter
MleFrameCounteruint32MLE layer frame counter
LQIuint8Link Quality Indicator (0-255, higher is better)
AverageRssiint8 / nullAverage RSSI (dBm), typical range -100 to 0
LastRssiint8 / nullRSSI of the most recent received packet (dBm)
FrameErrorRateuint8Frame error rate (0-100%, scaled to 0-255)
MessageErrorRateuint8Message error rate (0-100%, scaled to 0-255)
RxOnWhenIdleboolWhether receiver is on when idle (false = sleepy device)
FullThreadDeviceboolWhether it is a Full Thread Device (FTD)
FullNetworkDataboolWhether it receives full network data
IsChildboolWhether this neighbor is a child of this node

RouteTableStruct Structure

Each entry in the route table describes routing information to a target Router.

FieldTypeDescription
ExtAddressuint64Target router's 64-bit extended MAC address
Rloc16uint16Target router's 16-bit routing locator
RouterIduint8Router ID (0-62)
NextHopuint8Next hop Router ID
PathCostuint8Path cost to reach the target (lower is better)
LQIInuint8Inbound link quality indicator
LQIOutuint8Outbound link quality indicator
Ageuint8Route entry age
AllocatedboolWhether this Router ID has been allocated
LinkEstablishedboolWhether a bidirectional link has been established with this router

Dataset Parameters (0x0006, 0x0038 - 0x003E)

Parameters related to the Thread Operational Dataset, including timestamps, security policy, and network fault information.

IDNameTypeRequired FeatureDescription
0x0006 OverrunCount
Overrun Count
uint64 ERRCNT Cumulative count of receive buffer overruns
0x0038 ActiveTimestamp
Active Timestamp
uint64 / null None Timestamp of the current active operational dataset
0x0039 PendingTimestamp
Pending Timestamp
uint64 / null None Timestamp of the pending operational dataset (for deferred network configuration updates)
0x003A Delay
Delay
uint32 / null None Delay time before the pending dataset takes effect (milliseconds)
0x003B SecurityPolicy
Security Policy
SecurityPolicy / null None Network security policy, including key rotation time and security flags
0x003C ChannelPage0Mask
Channel Mask
octstr / null None Page 0 channel mask, identifying the set of channels the network is allowed to use
0x003D OperationalDatasetComponents
Dataset Components
Struct / null None Identifies which components are present in the operational dataset (see struct description)
0x003E ActiveNetworkFaultsList
Active Network Faults
list<NetworkFaultEnum> None List of currently active network faults (see enum values), empty list means no faults

SecurityPolicy Structure

FieldTypeDescription
RotationTimeuint16Security key rotation period (hours)
Flagsuint16Security policy flags (controlling external Commissioner access, Native Commissioner, etc.)

OperationalDatasetComponents Structure

Each field is a bool indicating whether the corresponding component is present in the operational dataset.

FieldDescription
ActiveTimestampPresentActive timestamp
PendingTimestampPresentPending timestamp
MasterKeyPresentMaster Key (Network Key)
NetworkNamePresentNetwork name
ExtendedPanIdPresentExtended PAN ID
MeshLocalPrefixPresentMesh local prefix
DelayPresentDelay timer
PanIdPresentPAN ID
ChannelPresentChannel number
PskcPresentPSKc (Commissioner key)
SecurityPolicyPresentSecurity policy
ChannelMaskPresentChannel mask

TX Counters (0x0016 - 0x0026) PKTCNT / MACCNT

Statistics for various types of transmitted packets. All fields are uint32, requiring PKTCNT or MACCNT Feature.

IDNameDescription
0x0016TxTotalCountTotal transmitted packets
0x0017TxUnicastCountUnicast packets transmitted
0x0018TxBroadcastCountBroadcast packets transmitted
0x0019TxAckRequestedCountPackets transmitted with ACK requested
0x001ATxAckedCountPackets transmitted with ACK received
0x001BTxNoAckRequestedCountPackets transmitted without ACK requested
0x001CTxDataCountData frames transmitted
0x001DTxDataPollCountData poll frames transmitted (sleepy device wakeup data pulls)
0x001ETxBeaconCountBeacon frames transmitted
0x001FTxBeaconRequestCountBeacon request frames transmitted
0x0020TxOtherCountOther frame types transmitted
0x0021TxRetryCountTransmission retry count (retry rate = TxRetryCount / TxTotalCount)
0x0022TxDirectMaxRetryExpiryCountPackets that reached max retry count for direct transmission
0x0023TxIndirectMaxRetryExpiryCountPackets that reached max retry count for indirect transmission
0x0024TxErrCcaCountTransmission failures due to CCA (Clear Channel Assessment) failure
0x0025TxErrAbortCountTransmission abort count
0x0026TxErrBusyChannelCountTransmission failures due to busy channel
Transmission Quality Assessment

Watch the TxRetryCount / TxTotalCount ratio — a retry rate above 10% indicates poor link quality. TxErrCcaCount continuously increasing usually means channel congestion, may need to switch channels. TxDirectMaxRetryExpiryCount being non-zero indicates packet loss, need to check if the target node is online.

RX Counters (0x0027 - 0x0031) PKTCNT / MACCNT

Statistics for various types of received packets. All fields are uint32, requiring PKTCNT or MACCNT Feature.

IDNameDescription
0x0027RxTotalCountTotal received packets
0x0028RxUnicastCountUnicast packets received
0x0029RxBroadcastCountBroadcast packets received
0x002ARxDataCountData frames received
0x002BRxDataPollCountData poll frames received
0x002CRxBeaconCountBeacon frames received
0x002DRxBeaconRequestCountBeacon request frames received
0x002ERxOtherCountOther frame types received
0x002FRxAddressFilteredCountReceived packets discarded by address filtering
0x0030RxDestAddrFilteredCountPackets filtered due to destination address mismatch
0x0031RxDuplicatedCountDuplicate received packets

RX Error Counters (0x0032 - 0x0037) ERRCNT

Statistics for various receive errors. All fields are uint32, requiring ERRCNT Feature.

IDNameDescription
0x0032RxErrNoFrameCountReceived error packets with no frame content
0x0033RxErrUnknownNeighborCountPackets from unknown neighbors (possibly network attack or new node)
0x0034RxErrInvalidSrcAddrCountPackets with invalid source address
0x0035RxErrSecCountPackets that failed security verification (decryption failure or MIC mismatch)
0x0036RxErrFcsCountPackets with FCS (Frame Check Sequence) errors — typically caused by radio interference
0x0037RxErrOtherCountOther types of receive errors
Error Counter Troubleshooting Guide

RxErrFcsCount continuously increasing: Severe radio interference, check for 2.4GHz WiFi or microwave interference sources, consider switching channels.
RxErrSecCount non-zero: Security layer failure, possibly inconsistent network keys or unauthorized devices attempting communication.
RxErrUnknownNeighborCount spike: New devices joining or nearby Thread network interference.

MLE Counters (0x000E - 0x0015) MLECNT

MLE (Mesh Link Establishment) layer event counts, reflecting device role changes and attach behavior in the Thread network. All fields are uint16, requiring MLECNT Feature.

IDNameDescription
0x000EDetachedRoleCountTimes entered Detached state
0x000FChildRoleCountTimes changed to Child role
0x0010RouterRoleCountTimes changed to Router role
0x0011LeaderRoleCountTimes changed to Leader role
0x0012AttachAttemptCountNetwork attach attempts
0x0013PartitionIdChangeCountPartition ID change count (network split/merge)
0x0014BetterPartitionAttachAttemptCountAttempts to attach to a better partition
0x0015ParentChangeCountParent node change count
MLE Counter Interpretation

DetachedRoleCount frequently increasing: Device frequently disconnects from the network, check signal strength or parent node stability.
ParentChangeCount too high: Device frequently switches parent nodes, indicating unstable nearby routers or signal boundaries.
PartitionIdChangeCount non-zero: The network has experienced splits and merges, usually caused by communication interruptions between some nodes.

Enum Quick Reference

RoutingRoleEnum — Routing Role

Describes the role the device serves in the Thread Mesh network.

0
Unspecified Unspecified — role not determined
1
Unassigned Unassigned — device has joined but has not yet been assigned a role
2
SleepyEndDevice Sleepy End Device — mostly in sleep mode, periodically wakes to pull data, power-efficient but high latency
3
EndDevice End Device — always online but does not forward data, does not participate in routing
4
REED Router-Eligible End Device — has routing capability but not currently active, can auto-upgrade to Router when the network needs it
5
Router Router — forwards data for other devices, maintains route table, backbone of the Mesh network
6
Leader Leader — manages Router ID allocation and network data distribution, exactly one per partition
Thread Role Hierarchy

Roles in a Thread network from lowest to highest: SleepyEndDevice → EndDevice → REED → Router → Leader. A Leader is essentially also a Router, but with additional management responsibilities. When a Leader goes offline, other Routers automatically elect a new Leader.

ConnectionStatusEnum — Connection Status

0
Connected Connected to Thread network
1
NotConnected Not connected to Thread network

NetworkFaultEnum — Network Fault Type

0
Unspecified Unspecified fault
1
LinkDown Link down — lost connection to Thread network
2
HardwareFailure Hardware failure — radio module or Thread chip abnormality
3
NetworkJammed Network jammed — channel persistently occupied, unable to communicate normally

Events

ThreadNetworkDiagnostics defines 2 events for notifying network connection status changes and fault occurrences.

EventPriorityFieldDescription
ConnectionStatus Info ConnectionStatus: ConnectionStatusEnum Triggered when Thread network connection status changes (connected or disconnected)
NetworkFaultChange Info Current: list<NetworkFaultEnum>
Previous: list<NetworkFaultEnum>
Triggered when the network fault list changes, carrying fault lists before and after the change
Event Subscription Use Cases

ConnectionStatus event: App can subscribe to this event for real-time awareness of Thread device online/offline status changes, such as displaying connection status icons in the device list or showing prompts when disconnected.

NetworkFaultChange event: Used for monitoring network health. When the Current list changes from empty to non-empty, a fault has occurred; changing from non-empty to empty means the fault has recovered. Comparing Current and Previous determines whether it is a new fault or a recovery.

Example Data

Typical read results from a Thread Router device's ThreadNetworkDiagnostics Cluster (key attributes selected):

{
  // --- Network Identity ---
  "0x0000": 15,              // Channel = 15 (Thread channel)
  "0x0001": 5,               // RoutingRole = Router
  "0x0002": "MyThreadNet",   // NetworkName
  "0x0003": 4660,            // PanId = 0x1234
  "0x0004": "1111111122222222", // ExtendedPanId
  "0x0005": "fd11:2233:4455::/64", // MeshLocalPrefix

  // --- Topology Info ---
  "0x0009": 12345678,        // PartitionId (network partition identifier)
  "0x000A": 64,              // Weighting (partition weight)
  "0x000D": 42,              // LeaderRouterId (Leader router ID)

  // --- TX Counters (PKTCNT) ---
  "0x0016": 158432,          // TxTotalCount (total transmitted)
  "0x0017": 120050,          // TxUnicastCount (unicast transmitted)
  "0x0018": 38382,           // TxBroadcastCount (broadcast transmitted)
  "0x0021": 1024,            // TxRetryCount (retry count)

  // --- RX Counters (PKTCNT) ---
  "0x0027": 203841,          // RxTotalCount (total received)
  "0x0028": 185200,          // RxUnicastCount (unicast received)
  "0x0029": 18641,           // RxBroadcastCount (broadcast received)

  // --- Error Counters (ERRCNT) ---
  "0x0006": 0,               // OverrunCount (buffer overrun count)
  "0x0036": 3,               // RxErrFcsCount (FCS check errors)

  // --- Active Network Faults ---
  "0x003E": []               // ActiveNetworkFaultsList = empty (no current faults)
}
Developer Tip

In practice, you typically do not need to read all 60+ attributes at once. Read selectively based on diagnostic purpose: For connection issues: read RoutingRole + NeighborTable + ActiveNetworkFaultsList; For network quality: read various counters; for network config: read Channel + NetworkName + SecurityPolicy. Check FeatureMap before reading to avoid requesting unsupported counter attributes.

Common Scenarios

Scenario 1: Troubleshooting Thread Device Offline

  1. Read RoutingRole (0x0001) — if null or Unassigned, the device has not successfully joined the network
  2. Read ActiveNetworkFaultsList (0x003E) — check for LinkDown or HardwareFailure
  3. Read NeighborTable (0x0007) — check LQI and RSSI in the neighbor list to assess signal quality
  4. Subscribe to ConnectionStatus events for real-time awareness of connection status changes

Scenario 2: Assessing Network Communication Quality

  1. Call ResetCounts (0x00) to reset all counters
  2. Wait for a period (e.g., 10 minutes), then read the counters
  3. Calculate retry rate: TxRetryCount / TxTotalCount, above 10% indicates poor link quality
  4. Check RxErrFcsCount — non-zero indicates radio interference
  5. Check TxErrCcaCount — continuous growth indicates channel congestion, consider switching channels

Scenario 3: Understanding Network Topology

  1. Read RoutingRole (0x0001) — confirm the device's network role
  2. Read LeaderRouterId (0x000D) — find the current Leader
  3. Read NeighborTable (0x0007) — get neighbor node list and link quality
  4. Read RouteTable (0x0008) — view routing topology and path costs
  5. Read PartitionId (0x0009) — confirm if all devices are in the same partition

Scenario 4: Monitoring Network Stability

  1. Read MLE counters (requires MLECNT Feature):
    • DetachedRoleCount (0x000E) — frequent detachment indicates unstable connection
    • ParentChangeCount (0x0015) — frequent parent changes indicate unstable nearby routers
    • PartitionIdChangeCount (0x0013) — non-zero means the network has split
  2. Subscribe to NetworkFaultChange events for timely awareness of fault occurrences and recoveries
  3. Periodically compare counter increments to establish a network quality baseline