Data & analysis

vmware-log-insight

Try it

Query centralized VMware syslog: search events, detect spikes, read alert history — read-only.

What it does

Connects to VMware Aria Operations for Logs to read, search, and aggregate syslog from ESXi hosts, vCenter, and VMs. Provides full-text log search over time windows, aggregation with z-score spike detection, field discovery, and alert history queries. All 7 tools are read-only — no ingest, no alert creation or modification. Feed results to vmware-debug for root-cause correlation across logs, events, and metrics.

When to use it

  • Investigating ESXi host errors from the last hour
  • Finding when a log volume spike occurred
  • Discovering available fields in logs from a specific source
  • Reviewing configured alert definitions without modifying them

The skill document

VMware Log Insight

Disclaimer: Community-maintained open-source project, not affiliated with, endorsed by, or sponsored by VMware, Inc. or Broadcom Inc. "VMware", "vSphere", and "Aria" are trademarks of Broadcom. Source is publicly auditable under the MIT license.

Read-only log search and aggregation for VMware Aria Operations for Logs (vRealize Log Insight) — the centralized-log data source for the VMware skill family. Strictly non-destructive: it queries, it never writes.

What This Skill Does

CategoryToolsCountRead or Write
Log searchlog_search1Read
Aggregation / spikeslog_aggregate1Read
Metadatalog_fields, log_version2Read
Alertsalert_list, alert_get, alert_history3Read

7 tools, all read-only. No ingest, no alert creation/edit/delete — zero write surface.

Quick Install

uv tool install vmware-log-insight
cp config.example.yaml ~/.vmware-log-insight/config.yaml   # then edit
vmware-log-insight doctor       # verify connectivity

When to Use This Skill

Use it to read the actual log lines behind an incident — what an ESXi host's vmkernel logged, vCenter vpxd errors, a login storm in VM syslog — and to find when log volume spiked.

  • vCenter events/alarms (not raw syslog)? → vmware-monitor
  • Performance metrics / anomalies / capacity? → vmware-aria
  • Correlate logs + events + metrics into one root-cause view? → vmware-debug

Do NOT use when there is no Log Insight appliance, or the user wants vCenter alarms (monitor) or metric anomalies (aria). This skill only reads the log store.

NeedSkill
Raw centralized logs + spikesvmware-log-insight (this)
vCenter events & alarmsvmware-monitor
Metrics, anomalies, capacityvmware-aria
Incident correlation / root causevmware-debug (feed it log_search output)
Network logs / DFW / traceflowvmware-nsx, vmware-nsx-security

Common Workflows

1. "Find the errors on a host in the last hour"

  1. log_search(text="error", last="1h", filters via CLI hostname=...) — or CLI: vmware-log-insight search -q error -l 1h.
  2. Read the events[] (timestamp + text + fields). Narrow with a more specific text if complete=False (result was truncated).
  3. Failure branch — auth/connection error: the teaching message names the cause (e.g. "503: appliance starting up"); run vmware-log-insight doctor. A 503 is a status, not a crash.

2. "Was there a log spike, and when?"

  1. log_aggregate(text="...", last="6h", bin_width_ms=300000) — counts per 5-minute bin + spikes[] (z-score flagged).
  2. Take a spike's timestamp_ms, then log_search(begin_ms=..., end_ms=...) around it to read what burst.
  3. Failure branch — empty bins: widen last or drop the text filter; confirm the appliance actually receives logs from the source.

3. Correlate logs into a root-cause timeline

  1. log_search / log_aggregate here for the log signal.
  2. Pull vCenter events (vmware-monitor) and metrics/anomalies (vmware-aria) for the same window/entity.
  3. Hand all of them to vmware-debug incident_timeline (normalise to its event envelope) to rank root causes.

Usage Mode

  • MCP (in an agent): call log_search/log_aggregate, then pass results to vmware-debug. Primary mode.
  • CLI (humans): vmware-log-insight search -q "apd" -l 2h.

MCP Tools (7 — 7 read, 0 write)

CategoryTools
Logslog_search (time window + text + filters), log_aggregate (COUNT/etc + spike detection), log_fields, log_version
Alertsalert_list, alert_get, alert_history

List envelope: log_fields, alert_list and alert_history return {items, returned, limit, total, truncated, hint} rather than a bare list — read the rows from items, and treat truncated: true as "there is more, raise limit or narrow the filter". total is a real count (the appliance returns each collection in one GET and limit is applied client-side), so a page that exactly fills limit is still reported truncated: false when it is genuinely complete.

Query model: time windows use a relative last ("1h", "30m", "7d") or an absolute begin_ms/end_ms (epoch ms); text is a CONTAINS search. See references/cli-reference.md for the full constraint grammar.

Read-Only by Design

All 7 tools here are reads — no ingest, no alert creation/edit/delete, zero write surface. Running with local or small models? See references/agent-guardrails.md.

CLI Quick Reference

vmware-log-insight search -q "scsi apd" -l 2h          # search events
vmware-log-insight search -q error -l 1h --json        # raw JSON
vmware-log-insight aggregate -q error -l 6h --bin-ms 300000   # spikes
vmware-log-insight fields --name host                  # discover fields
vmware-log-insight alert list                          # defined alerts
vmware-log-insight doctor                              # diagnostics
vmware-log-insight mcp                                  # start MCP server (proxy-safe)

Troubleshooting

  • POST /sessions returned HTTP 401 — wrong username/password/provider. Check config.yaml (provider: Local | ActiveDirectory) and the VMWARE_LOG_INSIGHT__PASSWORD env var.
  • HTTP 503 on every call — the appliance is starting or a service isn't ready; the error says so. Wait and retry; doctor reports it as a status, not a crash.
  • HTTP 400 on a search — a malformed constraint. Time/field filters are path-encoded as field/OPERATOR/value; let the CLI/tool build them rather than hand-crafting.
  • Empty results but logs exist — check the time window (last) and that the appliance actually ingests from that source; widen the window.
  • Default port is 9543, not 443 — set port in config.yaml if your appliance differs.

Audit & Safety

Read-only by construction (no write tools). MCP tools run through @vmware_tool(risk_level="low"), which records each call to the shared audit DB (~/.vmware/audit.db). Targets may declare environment: (production / staging / lab) in config.yaml to scope policy rules; reads are never gated by it, so this skill is unaffected either way, but declaring it keeps any future write tool correctly scoped. Credentials load from ~/.vmware-log-insight/.env (chmod 600); plaintext passwords there are auto-rewritten to a grep-safe b64: form on first load (obfuscation, not encryption — inject from a secret manager for real at-rest secrecy). All API text passes through sanitize() (prompt-injection defence). TLS verification is on by default; disable only for self-signed lab appliances. See references/setup-guide.md.

License

MIT.

Questions people ask

Does this create or modify alerts?
No. The alert tools (list, get, history) only read existing alert definitions and their trigger history. Alert creation, editing, and deletion are not available in this skill.
How is this different from vmware-monitor?
vmware-monitor reads vCenter events and alarms (structured state-change records). This skill reads raw syslog text stored in the Log Insight appliance. Use vmware-monitor for vCenter state, use this for actual log lines.
Can I detect anomalies or spikes in log volume?
Yes. log_aggregate bins log counts over time and returns a spikes array with z-score flags, letting you identify when log volume deviated significantly from baseline.

Related skills

Operate Kubernetes clusters with 55 audited tools — list resources, diagnose pod health, scale workloads, and manage rollouts safely.

by zw0081 installs1 stars

Join video meetings as a voice bot, visual avatar, or avatar with live screen sharing.

by johnpatternai22 installs8 stars

Escape the scarcity trap — diagnose bandwidth consumption and design protected slack to restore strategic capacity.

by deciqai1 installs2 stars

Diagnose which mental domain is holding you back before choosing a cognitive intervention.

by deciqai1 installs3 stars

Spot weak reasoning before you accept it — a structured audit for any argument

by deciqai2 stars

End-of-day options analytics ranked against each ticker's own history: IV rank, put/call percentile, skew, max pain, and unusually active contracts.

by thesentitrader2 installs2 stars

More from zw008

Browse all skills

Operate VMware VMs, deployments, clusters, guest tasks, and alarms with plan and rollback support.

by zw00878 installs1 stars

Inspect VMware health, inventory, alarms, events, and performance without changing infrastructure.

by zw00876 installs

Query Aria Operations metrics, alerts, capacity forecasts, anomalies, and reports from CLI or MCP.

by zw00853 installs

Manage AVI services and pools, and diagnose AKO ingress, sync, certificates, analytics, and health.

by zw00851 installs

Manage Supervisor Namespaces and TKC cluster lifecycles in vSphere Kubernetes Service.

by zw00851 installs

Manage NSX segments, gateways, routing, IP pools, health checks, and connectivity diagnostics.

by zw00850 installs