ThreadNetworkDiagnostics Cluster
Cluster ID: 0x0035 |
Endpoint: Endpoint 0 (Root Endpoint)
ThreadNetworkDiagnostics is the network diagnostics cluster for Thread devices, providing the complete operational status of the Thread Mesh network. It contains 60+ attributes covering network identification, topology routing, packet statistics, and error counts — the core tool for troubleshooting Thread device connectivity and analyzing network quality.
This cluster is primarily for diagnostics and debugging and does not control device functionality. When Thread devices have unstable connections, high latency, or severe packet loss, reading this cluster can quickly locate the issue — poor signal (check RSSI/LQI), suboptimal routing (check RouteTable), or excessive link errors (check error counters).
Feature Bitmap
ThreadNetworkDiagnostics declares which counter categories the device supports through FeatureMap (0xFFFC).
Different features control the availability of different groups of counter attributes.
Basic network information (Channel, RoutingRole, NeighborTable, etc.) is supported by all Thread devices and requires no features.
Counter attributes are grouped by feature — for example, only devices with PKTCNT enabled will report TxTotalCount and other packet statistics.
Check FeatureMap before reading to avoid errors from unsupported attributes.
Commands
ThreadNetworkDiagnostics has only one command, used to reset all counters.
| ID | Name | Description | Required Feature |
|---|---|---|---|
0x00 |
ResetCounts | Reset all optional counters to zero | ERRCNT or MACCNT |
ResetCounts — Reset Counters (0x00)
Resets all counters corresponding to enabled features (including OverrunCount) to zero on the device. No parameters required. After execution, all statistics restart from 0.
Usage Scenarios
When diagnosing network issues, first call ResetCounts to clear counters, then observe counter growth over a period, to determine the current error rate and network quality. This avoids historical accumulated data from interfering with judgment.
Attributes
ThreadNetworkDiagnostics has 60+ attributes, organized into the following groups by function. Basic network information is supported by all Thread devices; counter attributes are grouped by feature.
Network Identity (0x0000 - 0x0005)
Basic identity information for the Thread network, identifying which Thread network the device belongs to.
| ID | Name | Type | Description |
|---|---|---|---|
0x0000 |
Channel Channel |
uint16 | Current IEEE 802.15.4 channel number used by the Thread network. Thread uses channels 11-26 in the 2.4GHz band |
0x0001 |
RoutingRole Routing Role |
RoutingRoleEnum / null | Current role of the device in the Thread network (see enum values). null means not yet determined |
0x0002 |
NetworkName Network Name |
string / null | Thread network name, UTF-8 string up to 16 bytes |
0x0003 |
PanId PAN ID |
uint16 / null | IEEE 802.15.4 16-bit PAN identifier |
0x0004 |
ExtendedPanId Extended PAN ID |
uint64 / null | 64-bit extended PAN identifier, used to distinguish different networks with the same PAN ID |
0x0005 |
MeshLocalPrefix Mesh Local Prefix |
octstr / null | Thread Mesh local IPv6 prefix (/64 prefix within the fd00::/8 range) |
Topology & Routing (0x0007 - 0x000D)
Topology structure and routing information of the Thread Mesh network, including neighbor table, route table, and partition data.
| ID | Name | Type | Description |
|---|---|---|---|
0x0007 |
NeighborTable Neighbor Table |
list<NeighborTableStruct> | Detailed information list of direct communication neighbors (see struct description) |
0x0008 |
RouteTable Route Table |
list<RouteTableStruct> | Network route entry list (see struct description) |
0x0009 |
PartitionId Partition ID |
uint32 / null | Identifier for the current Thread network partition. Different partitions have different IDs when the network splits |
0x000A |
Weighting Partition Weight |
uint16 / null | Weight of the current partition; partitions with higher weight are preferentially kept during network merges |
0x000B |
DataVersion Data Version |
uint16 / null | Version number of Thread network data, incremented with each network data change |
0x000C |
StableDataVersion Stable Data Version |
uint16 / null | Version number of stable network data (excluding volatile data such as temporary routes) |
0x000D |
LeaderRouterId Leader Router ID |
uint8 / null | Router ID of the current Thread network Leader |
NeighborTableStruct Structure
Each entry in the neighbor table describes a directly communicating neighbor node. Signal quality (LQI/RSSI) and error rate are key fields for assessing link health.
| Field | Type | Description |
|---|---|---|
| ExtAddress | uint64 | Neighbor's 64-bit extended MAC address |
| Age | uint32 | Seconds since last communication |
| Rloc16 | uint16 | Neighbor's 16-bit routing locator |
| LinkFrameCounter | uint32 | Link layer frame counter |
| MleFrameCounter | uint32 | MLE layer frame counter |
| LQI | uint8 | Link Quality Indicator (0-255, higher is better) |
| AverageRssi | int8 / null | Average RSSI (dBm), typical range -100 to 0 |
| LastRssi | int8 / null | RSSI of the most recent received packet (dBm) |
| FrameErrorRate | uint8 | Frame error rate (0-100%, scaled to 0-255) |
| MessageErrorRate | uint8 | Message error rate (0-100%, scaled to 0-255) |
| RxOnWhenIdle | bool | Whether receiver is on when idle (false = sleepy device) |
| FullThreadDevice | bool | Whether it is a Full Thread Device (FTD) |
| FullNetworkData | bool | Whether it receives full network data |
| IsChild | bool | Whether this neighbor is a child of this node |
RouteTableStruct Structure
Each entry in the route table describes routing information to a target Router.
| Field | Type | Description |
|---|---|---|
| ExtAddress | uint64 | Target router's 64-bit extended MAC address |
| Rloc16 | uint16 | Target router's 16-bit routing locator |
| RouterId | uint8 | Router ID (0-62) |
| NextHop | uint8 | Next hop Router ID |
| PathCost | uint8 | Path cost to reach the target (lower is better) |
| LQIIn | uint8 | Inbound link quality indicator |
| LQIOut | uint8 | Outbound link quality indicator |
| Age | uint8 | Route entry age |
| Allocated | bool | Whether this Router ID has been allocated |
| LinkEstablished | bool | Whether a bidirectional link has been established with this router |
Dataset Parameters (0x0006, 0x0038 - 0x003E)
Parameters related to the Thread Operational Dataset, including timestamps, security policy, and network fault information.
| ID | Name | Type | Required Feature | Description |
|---|---|---|---|---|
0x0006 |
OverrunCount Overrun Count |
uint64 | ERRCNT | Cumulative count of receive buffer overruns |
0x0038 |
ActiveTimestamp Active Timestamp |
uint64 / null | None | Timestamp of the current active operational dataset |
0x0039 |
PendingTimestamp Pending Timestamp |
uint64 / null | None | Timestamp of the pending operational dataset (for deferred network configuration updates) |
0x003A |
Delay Delay |
uint32 / null | None | Delay time before the pending dataset takes effect (milliseconds) |
0x003B |
SecurityPolicy Security Policy |
SecurityPolicy / null | None | Network security policy, including key rotation time and security flags |
0x003C |
ChannelPage0Mask Channel Mask |
octstr / null | None | Page 0 channel mask, identifying the set of channels the network is allowed to use |
0x003D |
OperationalDatasetComponents Dataset Components |
Struct / null | None | Identifies which components are present in the operational dataset (see struct description) |
0x003E |
ActiveNetworkFaultsList Active Network Faults |
list<NetworkFaultEnum> | None | List of currently active network faults (see enum values), empty list means no faults |
SecurityPolicy Structure
| Field | Type | Description |
|---|---|---|
| RotationTime | uint16 | Security key rotation period (hours) |
| Flags | uint16 | Security policy flags (controlling external Commissioner access, Native Commissioner, etc.) |
OperationalDatasetComponents Structure
Each field is a bool indicating whether the corresponding component is present in the operational dataset.
| Field | Description |
|---|---|
| ActiveTimestampPresent | Active timestamp |
| PendingTimestampPresent | Pending timestamp |
| MasterKeyPresent | Master Key (Network Key) |
| NetworkNamePresent | Network name |
| ExtendedPanIdPresent | Extended PAN ID |
| MeshLocalPrefixPresent | Mesh local prefix |
| DelayPresent | Delay timer |
| PanIdPresent | PAN ID |
| ChannelPresent | Channel number |
| PskcPresent | PSKc (Commissioner key) |
| SecurityPolicyPresent | Security policy |
| ChannelMaskPresent | Channel mask |
TX Counters (0x0016 - 0x0026) PKTCNT / MACCNT
Statistics for various types of transmitted packets. All fields are uint32, requiring PKTCNT or MACCNT Feature.
| ID | Name | Description |
|---|---|---|
0x0016 | TxTotalCount | Total transmitted packets |
0x0017 | TxUnicastCount | Unicast packets transmitted |
0x0018 | TxBroadcastCount | Broadcast packets transmitted |
0x0019 | TxAckRequestedCount | Packets transmitted with ACK requested |
0x001A | TxAckedCount | Packets transmitted with ACK received |
0x001B | TxNoAckRequestedCount | Packets transmitted without ACK requested |
0x001C | TxDataCount | Data frames transmitted |
0x001D | TxDataPollCount | Data poll frames transmitted (sleepy device wakeup data pulls) |
0x001E | TxBeaconCount | Beacon frames transmitted |
0x001F | TxBeaconRequestCount | Beacon request frames transmitted |
0x0020 | TxOtherCount | Other frame types transmitted |
0x0021 | TxRetryCount | Transmission retry count (retry rate = TxRetryCount / TxTotalCount) |
0x0022 | TxDirectMaxRetryExpiryCount | Packets that reached max retry count for direct transmission |
0x0023 | TxIndirectMaxRetryExpiryCount | Packets that reached max retry count for indirect transmission |
0x0024 | TxErrCcaCount | Transmission failures due to CCA (Clear Channel Assessment) failure |
0x0025 | TxErrAbortCount | Transmission abort count |
0x0026 | TxErrBusyChannelCount | Transmission failures due to busy channel |
Watch the TxRetryCount / TxTotalCount ratio — a retry rate above 10% indicates poor link quality.
TxErrCcaCount continuously increasing usually means channel congestion, may need to switch channels.
TxDirectMaxRetryExpiryCount being non-zero indicates packet loss, need to check if the target node is online.
RX Counters (0x0027 - 0x0031) PKTCNT / MACCNT
Statistics for various types of received packets. All fields are uint32, requiring PKTCNT or MACCNT Feature.
| ID | Name | Description |
|---|---|---|
0x0027 | RxTotalCount | Total received packets |
0x0028 | RxUnicastCount | Unicast packets received |
0x0029 | RxBroadcastCount | Broadcast packets received |
0x002A | RxDataCount | Data frames received |
0x002B | RxDataPollCount | Data poll frames received |
0x002C | RxBeaconCount | Beacon frames received |
0x002D | RxBeaconRequestCount | Beacon request frames received |
0x002E | RxOtherCount | Other frame types received |
0x002F | RxAddressFilteredCount | Received packets discarded by address filtering |
0x0030 | RxDestAddrFilteredCount | Packets filtered due to destination address mismatch |
0x0031 | RxDuplicatedCount | Duplicate received packets |
RX Error Counters (0x0032 - 0x0037) ERRCNT
Statistics for various receive errors. All fields are uint32, requiring ERRCNT Feature.
| ID | Name | Description |
|---|---|---|
0x0032 | RxErrNoFrameCount | Received error packets with no frame content |
0x0033 | RxErrUnknownNeighborCount | Packets from unknown neighbors (possibly network attack or new node) |
0x0034 | RxErrInvalidSrcAddrCount | Packets with invalid source address |
0x0035 | RxErrSecCount | Packets that failed security verification (decryption failure or MIC mismatch) |
0x0036 | RxErrFcsCount | Packets with FCS (Frame Check Sequence) errors — typically caused by radio interference |
0x0037 | RxErrOtherCount | Other types of receive errors |
RxErrFcsCount continuously increasing: Severe radio interference, check for 2.4GHz WiFi or microwave interference sources, consider switching channels.
RxErrSecCount non-zero: Security layer failure, possibly inconsistent network keys or unauthorized devices attempting communication.
RxErrUnknownNeighborCount spike: New devices joining or nearby Thread network interference.
MLE Counters (0x000E - 0x0015) MLECNT
MLE (Mesh Link Establishment) layer event counts, reflecting device role changes and attach behavior in the Thread network.
All fields are uint16, requiring MLECNT Feature.
| ID | Name | Description |
|---|---|---|
0x000E | DetachedRoleCount | Times entered Detached state |
0x000F | ChildRoleCount | Times changed to Child role |
0x0010 | RouterRoleCount | Times changed to Router role |
0x0011 | LeaderRoleCount | Times changed to Leader role |
0x0012 | AttachAttemptCount | Network attach attempts |
0x0013 | PartitionIdChangeCount | Partition ID change count (network split/merge) |
0x0014 | BetterPartitionAttachAttemptCount | Attempts to attach to a better partition |
0x0015 | ParentChangeCount | Parent node change count |
DetachedRoleCount frequently increasing: Device frequently disconnects from the network, check signal strength or parent node stability.
ParentChangeCount too high: Device frequently switches parent nodes, indicating unstable nearby routers or signal boundaries.
PartitionIdChangeCount non-zero: The network has experienced splits and merges, usually caused by communication interruptions between some nodes.
Enum Quick Reference
RoutingRoleEnum — Routing Role
Describes the role the device serves in the Thread Mesh network.
Roles in a Thread network from lowest to highest: SleepyEndDevice → EndDevice → REED → Router → Leader. A Leader is essentially also a Router, but with additional management responsibilities. When a Leader goes offline, other Routers automatically elect a new Leader.
ConnectionStatusEnum — Connection Status
NetworkFaultEnum — Network Fault Type
Events
ThreadNetworkDiagnostics defines 2 events for notifying network connection status changes and fault occurrences.
| Event | Priority | Field | Description |
|---|---|---|---|
| ConnectionStatus | Info | ConnectionStatus: ConnectionStatusEnum | Triggered when Thread network connection status changes (connected or disconnected) |
| NetworkFaultChange | Info |
Current: list<NetworkFaultEnum> Previous: list<NetworkFaultEnum> |
Triggered when the network fault list changes, carrying fault lists before and after the change |
Event Subscription Use Cases
ConnectionStatus event: App can subscribe to this event for real-time awareness of Thread device online/offline status changes, such as displaying connection status icons in the device list or showing prompts when disconnected.
NetworkFaultChange event: Used for monitoring network health. When the Current list changes from empty to non-empty, a fault has occurred; changing from non-empty to empty means the fault has recovered. Comparing Current and Previous determines whether it is a new fault or a recovery.
Example Data
Typical read results from a Thread Router device's ThreadNetworkDiagnostics Cluster (key attributes selected):
{
// --- Network Identity ---
"0x0000": 15, // Channel = 15 (Thread channel)
"0x0001": 5, // RoutingRole = Router
"0x0002": "MyThreadNet", // NetworkName
"0x0003": 4660, // PanId = 0x1234
"0x0004": "1111111122222222", // ExtendedPanId
"0x0005": "fd11:2233:4455::/64", // MeshLocalPrefix
// --- Topology Info ---
"0x0009": 12345678, // PartitionId (network partition identifier)
"0x000A": 64, // Weighting (partition weight)
"0x000D": 42, // LeaderRouterId (Leader router ID)
// --- TX Counters (PKTCNT) ---
"0x0016": 158432, // TxTotalCount (total transmitted)
"0x0017": 120050, // TxUnicastCount (unicast transmitted)
"0x0018": 38382, // TxBroadcastCount (broadcast transmitted)
"0x0021": 1024, // TxRetryCount (retry count)
// --- RX Counters (PKTCNT) ---
"0x0027": 203841, // RxTotalCount (total received)
"0x0028": 185200, // RxUnicastCount (unicast received)
"0x0029": 18641, // RxBroadcastCount (broadcast received)
// --- Error Counters (ERRCNT) ---
"0x0006": 0, // OverrunCount (buffer overrun count)
"0x0036": 3, // RxErrFcsCount (FCS check errors)
// --- Active Network Faults ---
"0x003E": [] // ActiveNetworkFaultsList = empty (no current faults)
}
In practice, you typically do not need to read all 60+ attributes at once. Read selectively based on diagnostic purpose:
For connection issues: read RoutingRole + NeighborTable + ActiveNetworkFaultsList;
For network quality: read various counters; for network config: read Channel + NetworkName + SecurityPolicy.
Check FeatureMap before reading to avoid requesting unsupported counter attributes.
Common Scenarios
Scenario 1: Troubleshooting Thread Device Offline
- Read
RoutingRole (0x0001)— ifnullorUnassigned, the device has not successfully joined the network - Read
ActiveNetworkFaultsList (0x003E)— check for LinkDown or HardwareFailure - Read
NeighborTable (0x0007)— check LQI and RSSI in the neighbor list to assess signal quality - Subscribe to ConnectionStatus events for real-time awareness of connection status changes
Scenario 2: Assessing Network Communication Quality
- Call
ResetCounts (0x00)to reset all counters - Wait for a period (e.g., 10 minutes), then read the counters
- Calculate retry rate:
TxRetryCount / TxTotalCount, above 10% indicates poor link quality - Check
RxErrFcsCount— non-zero indicates radio interference - Check
TxErrCcaCount— continuous growth indicates channel congestion, consider switching channels
Scenario 3: Understanding Network Topology
- Read
RoutingRole (0x0001)— confirm the device's network role - Read
LeaderRouterId (0x000D)— find the current Leader - Read
NeighborTable (0x0007)— get neighbor node list and link quality - Read
RouteTable (0x0008)— view routing topology and path costs - Read
PartitionId (0x0009)— confirm if all devices are in the same partition
Scenario 4: Monitoring Network Stability
- Read MLE counters (requires MLECNT Feature):
DetachedRoleCount (0x000E)— frequent detachment indicates unstable connectionParentChangeCount (0x0015)— frequent parent changes indicate unstable nearby routersPartitionIdChangeCount (0x0013)— non-zero means the network has split
- Subscribe to NetworkFaultChange events for timely awareness of fault occurrences and recoveries
- Periodically compare counter increments to establish a network quality baseline