8.3 Log Analysis & Diagnostic Data Collection
Key Takeaways
ESXi hypervisor core system logs reside in /var/log/ (backed by the high-endurance OSDATA partition), with hostd.log logging local host agent tasks, vpxa.log tracking vCenter communication, and vmkernel.log recording low-level hypervisor, hardware, and storage events.
In vmkernel.log, H:, D:, and P: show host, device, and plug-in status, and 'Valid sense data' lists the sense key, ASC, and ASCQ; 0x5 0x25 0x0 (Illegal Request, Logical Unit Not Supported) is the classic Permanent Device Loss code.
Individual virtual machine lifecycle events, virtual hardware panics, and guest crashes are recorded in vmware.log located inside the VM's specific directory on the datastore alongside its .vmx configuration file.
Comprehensive diagnostic bundles are generated via command line using vm-support on ESXi hosts and vc-support on the vCenter Server Appliance, or exported via the vSphere Client HTML5 UI.
Remote syslog is set with esxcli system syslog config set --loghost (for example tcp://syslog.corp:514 or ssl://syslog.corp:1514), followed by esxcli system syslog reload and enabling the syslog firewall ruleset.
8.3 Log Analysis & Diagnostic Data Collection
When performance metrics and interactive dashboards fail to isolate the root cause of an infrastructure fault, log analysis serves as the primary investigative method. VMware ESXi and vCenter Server generate granular, timestamped operational telemetry across multiple architectural layers. Mastering the location, purpose, and structure of these logs—as well as deciphering low-level kernel warnings and SCSI sense codes—is an indispensable skill for enterprise operations and the VCP-DCV certification.
ESXi Host Log Directory Hierarchy (/var/log/)
On an ESXi 8.0 host, operational system logs reside in the directory /var/log/. In modern vSphere architectures, /var/log is a symlink pointing to /scratch/log/, which resides directly on the high-endurance ESX-OSDATA partition formatted with VMFS-L. This ensures that log entries persist across host reboots.
+-----------------------------------------------------------------------------------------+
| ESXi 8.0 /var/log/ Directory Structure |
| |
| /var/log/ -> /scratch/log/ (Persisted on OSDATA Partition) |
| | |
| +-- vmkernel.log : Core hypervisor events, device drivers, SCSI commands, NICs |
| +-- vmkwarning.log : Filtered warnings and errors extracted from vmkernel.log |
| +-- hostd.log : Local host management daemon (VM power, local tasks, UI) |
| +-- vpxa.log : vCenter Server agent daemon (vpxd communication & heartbeats) |
| +-- syslog.log : System initialization, management scripts, NTP daemon |
| +-- auth.log : Authentication, SSH sessions, PAM, DCUI logins |
| +-- shell.log : Command-line audit log of commands typed in ESXi Shell |
| +-- vobd.log : VMkernel Observation Daemon (broadcasts VOB events to vCenter) |
+-----------------------------------------------------------------------------------------+
Core ESXi Log Files and Diagnostic Functions
vmkernel.log: The foundational hypervisor log file. It records low-level operations from the core VMkernel operating system, including:- Physical hardware device detection, PCI initialization, and device driver loads.
- Network uplink link-state changes (link down/link up, speed negotiation, duplex mismatches).
- Storage commands, LUN discovery, path transitions, SCSI aborts, and SCSI sense codes.
- Memory allocation alerts and NUMA node placement messages.
vmkwarning.log: A filtered, high-signal subset ofvmkernel.log. It captures exclusively messages tagged with WARNING or ALERT severities. When beginning a hardware or storage triage session, reviewingvmkwarning.logallows administrators to bypass informational kernel noise.hostd.log: The log for the local host management daemon (hostd). It records:- Local virtual machine registration, power transitions, snapshot workflows, and configuration changes.
- ESXi Host Client (web UI) session activities.
- Internal host tasks, scheduled maintenance, and direct CIM provider interactions.
vpxa.log: The log for the vCenter Server Agent (vpxa). It records:- Communication exchanges between vCenter's
vpxddaemon and the host. - Task instructions issued from vCenter (e.g., vMotion migrations, distributed switch port reconfigurations).
- UDP heartbeat transmissions (port 902) confirming host liveness.
- Communication exchanges between vCenter's
auth.log: Security and authentication log recording:- User login attempts via SSH, DCUI, and ESXi Host Client.
- Pluggable Authentication Module (PAM) successes and failures.
- Privilege escalation and invalid credential lockouts.
shell.log: Audit logging for administrative compliance. Records every command entered into the ESXi Shell or SSH sessions, including timestamps and the originating user account.vobd.log: The VMkernel Observation Daemon log. VOB captures critical system events (e.g., storage path failures, network link drops, PSOD crash events) and broadcasts formatted event notifications to vCenter Server to trigger alarms.
Virtual Machine & vCenter Server Logging
Diagnostic telemetry extends beyond the ESXi hypervisor to individual virtual machines and the vCenter Server Appliance (vCSA).
Virtual Machine Directory Logs (vmware.log)
Every virtual machine maintains its own operational log named vmware.log. Crucially, this log does not reside in /var/log/ on the ESXi host. Instead, it is located inside the virtual machine's dedicated folder on the datastore, directly alongside the .vmx configuration file and .vmdk disk descriptors.
- Historical Archiving: When a virtual machine undergoes a power cycle (power off and power on), the active
vmware.logis closed and renamed sequentially tovmware-1.log,vmware-2.log, etc., and a freshvmware.logis initialized. By default, ESXi preserves up to 6 historical log files. - Diagnostic Content:
vmware.logrecords:- Virtual hardware initialization (virtual CPU count, virtual NVMe/LSI Logic controllers, E1000e/VMXNET3 adapters).
- Guest operating system BSOD (Windows Blue Screen) or kernel panic stack traces.
- Virtual Machine monitor (VMM) panics and crash dumps.
- Snapshot creation, delta disk opening, and disk consolidation timings.
- vMotion migration handoffs and stun times (the brief sub-second freeze during final memory copy).
vCenter Server Appliance (vCSA) Log Hierarchy
Within the vCenter Server Appliance (based on VMware Photon OS), log files reside under /var/log/vmware/ organized by microservice:
| Log File Path | Service / Component | Diagnostic Focus |
|---|---|---|
/var/log/vmware/vpxd/vpxd.log | vCenter Server Daemon (vpxd) | Core vCenter operations, database connection issues, DRS/HA calculations, task scheduling, host connection status. |
/var/log/vmware/vpxd/vpxd-alert.log | vpxd Alert Subsystem | High-priority warnings and error alerts triggered within vCenter. |
/var/log/vmware/sso/ | Single Sign-On (SSO / STS) | Identity provider federation, Active Directory/LDAP authentication, SAML token generation. |
/var/log/vmware/eam/eam.log | ESX Agent Manager | Lifecycle management of host solution agents (NSX vibs, storage appliances). |
/var/log/vmware/vmware-vmon/vmon.log | vCenter Service Lifecycle Manager | Service health monitoring, startup sequences, automated restarts of failed daemons. |
/var/log/vmware/applmgmt/ | Appliance Management (VAMI) | vCSA backups, patches, network configuration, port 5480 web console. |
SCSI Sense Code Diagnostics & Support Bundles
When storage errors occur, the VMkernel logs raw SCSI sense codes in vmkernel.log returned from the storage array. Deciphering these codes allows administrators to distinguish between transient fabric timeouts and catastrophic hardware failures.
Decoding SCSI Sense Codes
SCSI error lines in vmkernel.log typically appear in the following standard notation:
ScsiDeviceIO: 4056: Cmd(0x43a600) 0x28, CmdSN 0x80 from world 1024 to dev "naa.6005..." failed H:0x0 D:0x2 P:0x0 Valid sense data: 0x5 0x25 0x00
- Host Status (
H:): Status from the local HBA driver.0x0indicates Host OK;0x1indicates No Connect;0x5indicates Command Aborted. - Device Status (
D:): Status returned by the target array.0x0indicates Good;0x2indicates Check Condition (sense data follows). - Sense Key / ASC / ASCQ (
0xS 0xASC 0xASCQ): The three critical hex values defining the exact failure reason:- Sense Key (
0xS): General category of error (e.g.,0x2= Not Ready,0x5= Illegal Request,0x6= Unit Attention). - Additional Sense Code (
0xASC): Specific error description. - Additional Sense Code Qualifier (
0xASCQ): Granular sub-code detailing the error condition.
- Sense Key (
Critical SCSI Sense Code Diagnostic Matrix
| SCSI Sense Code | Sense Key Name | Additional Sense Description | Diagnostic Meaning & VMkernel Action |
|---|---|---|---|
0x5 0x25 0x00 | ILLEGAL REQUEST | LOGICAL UNIT NOT SUPPORTED | Permanent Device Loss (PDL). The LUN has been unmapped or destroyed on the array. ESXi ceases I/O immediately. |
0x2 0x04 0x01 | NOT READY | LOGICAL UNIT IN PROCESS OF BECOMING READY | The storage controller is initializing or spinning up. Hypervisor retries the command. |
0x2 0x04 0x03 | NOT READY | MANUAL INTERVENTION REQUIRED | Array hardware failure; human operator required to restore storage. |
0x6 0x29 0x00 | UNIT ATTENTION | POWER ON, RESET, OR BUS DEVICE RESET | Storage array controller rebooted or SAN path was reset. Normal during controller firmware failover. |
0x3 0x0C 0x00 | MEDIUM ERROR | WRITE ERROR | Underlying physical disk surface failure or flash cell write failure. |
0x5 0x20 0x00 | ILLEGAL REQUEST | INVALID COMMAND OPERATION CODE | Array does not support the issued SCSI opcode (common with unsupported VAAI primitives). |
Diagnostic Data Collection: Support Bundles
When escalating issues to VMware Support or conducting deep root-cause audits, administrators must generate comprehensive diagnostic bundles containing logs, configuration files, and state dumps:
- ESXi Host Diagnostic Bundle (
vm-support):- Executed via ESXi Shell / SSH:
vm-support - Best Practice Execution: Direct output to a shared datastore to avoid filling host ramdisk memory:
vm-support -w /vmfs/volumes/SAN-Datastore-01/support_bundles/ - Performance Snapshot Mode: Captures high-frequency performance counters over time:
(Captures performance data every 5 seconds for 30 seconds duration).vm-support -p -d 30 -i 5
- Executed via ESXi Shell / SSH:
- vCenter Server Diagnostic Bundle (
vc-support):- Executed from the appliance Bash shell:
vc-support - Packages
/var/log/vmware/, PostgreSQL configuration dumps, and SSO identity states into a compressed.tar.gzarchive.
- Executed from the appliance Bash shell:
- vSphere Client GUI Export:
- In the vSphere Client, right-click any ESXi host, cluster, or vCenter object -> select Export System Logs -> select specific log components -> download bundle directly through the web browser.
Centralized Syslog Forwarding & VMware Skyline
Because local host logs are subject to rotation and can be lost if system storage fails, enterprise vSphere deployments enforce centralized remote logging conforming to RFC 5424:
- Configuring Remote Syslog via
esxcli:# Configure remote syslog target (IP/FQDN, protocol, and port) esxcli system syslog config set --loghost='tcp://syslog.corp.local:514' # Reload the syslog daemon to apply configuration esxcli system syslog reload # Open the outgoing syslog port through the ESXi host firewall esxcli network firewall ruleset set --ruleset-id=syslog --enabled=true - VMware Skyline (Objective 5.11): Skyline used a Skyline Collector virtual appliance in the customer environment to send product usage data to VMware. The Skyline Advisor portal turned that data into proactive findings (known issues, VMSA security advisories, best-practice gaps) with remediation guidance, and Log Assist could upload support bundles to a support request. Status: Broadcom ended the Skyline Advisor service on October 4, 2024. Its findings are moving into VMware Cloud Foundation operations tooling (for example, Aria Operations 8.18 and VCF 5.2 surface critical findings), while vSphere and vSAN keep their in-product Skyline Health checks in the vSphere Client.
A storage array path experiences an unrecoverable failure. Which log file on the ESXi host should an administrator inspect to find the raw SCSI sense codes, HBA driver errors, and VMFS volume unmount warnings?
The /var/log/vpxa.log file
The /var/log/hostd.log file
The /var/log/vmkernel.log file
The /var/log/auth.log file
An administrator examines /var/log/vmkernel.log on an ESXi 8.0 host and discovers the following entry: 'ScsiDeviceIO: ... failed H:0x0 D:0x2 P:0x0 Valid sense data: 0x5 0x25 0x00'. How does the ESXi hypervisor interpret this specific SCSI sense code?
As an All Paths Down (APD) condition indicating a transient Fibre Channel switch zoning failure
As a Permanent Device Loss (PDL) condition indicating Logical Unit Not Supported
As a Unit Attention condition indicating that the storage array controller has rebooted
As a Not Ready condition indicating that the LUN is spinning up and becoming ready
An administrator needs to collect an ESXi diagnostic support bundle from the command line while ensuring that the resulting archive does not consume space on the local host ramdisk. Which command should be executed?
esxcli system support bundle generate --output=/tmp
tar -czvf /scratch/log/bundle.tar.gz /var/log/*
vc-support -l --dest=/vmfs/volumes/Datastore01/bundles/
vm-support -w /vmfs/volumes/Datastore01/bundles/
Sections you finish are checked off in the contents.