8.3 Log Analysis & Diagnostic Data Collection

Key Takeaways

  • ESXi hypervisor core system logs reside in /var/log/ (backed by the high-endurance OSDATA partition), with hostd.log logging local host agent tasks, vpxa.log tracking vCenter communication, and vmkernel.log recording low-level hypervisor, hardware, and storage events.

  • In vmkernel.log, H:, D:, and P: show host, device, and plug-in status, and 'Valid sense data' lists the sense key, ASC, and ASCQ; 0x5 0x25 0x0 (Illegal Request, Logical Unit Not Supported) is the classic Permanent Device Loss code.

  • Individual virtual machine lifecycle events, virtual hardware panics, and guest crashes are recorded in vmware.log located inside the VM's specific directory on the datastore alongside its .vmx configuration file.

  • Comprehensive diagnostic bundles are generated via command line using vm-support on ESXi hosts and vc-support on the vCenter Server Appliance, or exported via the vSphere Client HTML5 UI.

  • Remote syslog is set with esxcli system syslog config set --loghost (for example tcp://syslog.corp:514 or ssl://syslog.corp:1514), followed by esxcli system syslog reload and enabling the syslog firewall ruleset.

Last updated: September 2026

8.3 Log Analysis & Diagnostic Data Collection

When performance metrics and interactive dashboards fail to isolate the root cause of an infrastructure fault, log analysis serves as the primary investigative method. VMware ESXi and vCenter Server generate granular, timestamped operational telemetry across multiple architectural layers. Mastering the location, purpose, and structure of these logs—as well as deciphering low-level kernel warnings and SCSI sense codes—is an indispensable skill for enterprise operations and the VCP-DCV certification.


ESXi Host Log Directory Hierarchy (/var/log/)

On an ESXi 8.0 host, operational system logs reside in the directory /var/log/. In modern vSphere architectures, /var/log is a symlink pointing to /scratch/log/, which resides directly on the high-endurance ESX-OSDATA partition formatted with VMFS-L. This ensures that log entries persist across host reboots.

+-----------------------------------------------------------------------------------------+
| ESXi 8.0 /var/log/ Directory Structure                                                  |
|                                                                                         |
| /var/log/ -> /scratch/log/ (Persisted on OSDATA Partition)                              |
|   |                                                                                     |
|   +-- vmkernel.log    : Core hypervisor events, device drivers, SCSI commands, NICs     |
|   +-- vmkwarning.log  : Filtered warnings and errors extracted from vmkernel.log        |
|   +-- hostd.log       : Local host management daemon (VM power, local tasks, UI)        |
|   +-- vpxa.log        : vCenter Server agent daemon (vpxd communication & heartbeats)   |
|   +-- syslog.log      : System initialization, management scripts, NTP daemon           |
|   +-- auth.log        : Authentication, SSH sessions, PAM, DCUI logins                  |
|   +-- shell.log       : Command-line audit log of commands typed in ESXi Shell          |
|   +-- vobd.log        : VMkernel Observation Daemon (broadcasts VOB events to vCenter)  |
+-----------------------------------------------------------------------------------------+

Core ESXi Log Files and Diagnostic Functions

  1. vmkernel.log: The foundational hypervisor log file. It records low-level operations from the core VMkernel operating system, including:
    • Physical hardware device detection, PCI initialization, and device driver loads.
    • Network uplink link-state changes (link down/link up, speed negotiation, duplex mismatches).
    • Storage commands, LUN discovery, path transitions, SCSI aborts, and SCSI sense codes.
    • Memory allocation alerts and NUMA node placement messages.
  2. vmkwarning.log: A filtered, high-signal subset of vmkernel.log. It captures exclusively messages tagged with WARNING or ALERT severities. When beginning a hardware or storage triage session, reviewing vmkwarning.log allows administrators to bypass informational kernel noise.
  3. hostd.log: The log for the local host management daemon (hostd). It records:
    • Local virtual machine registration, power transitions, snapshot workflows, and configuration changes.
    • ESXi Host Client (web UI) session activities.
    • Internal host tasks, scheduled maintenance, and direct CIM provider interactions.
  4. vpxa.log: The log for the vCenter Server Agent (vpxa). It records:
    • Communication exchanges between vCenter's vpxd daemon and the host.
    • Task instructions issued from vCenter (e.g., vMotion migrations, distributed switch port reconfigurations).
    • UDP heartbeat transmissions (port 902) confirming host liveness.
  5. auth.log: Security and authentication log recording:
    • User login attempts via SSH, DCUI, and ESXi Host Client.
    • Pluggable Authentication Module (PAM) successes and failures.
    • Privilege escalation and invalid credential lockouts.
  6. shell.log: Audit logging for administrative compliance. Records every command entered into the ESXi Shell or SSH sessions, including timestamps and the originating user account.
  7. vobd.log: The VMkernel Observation Daemon log. VOB captures critical system events (e.g., storage path failures, network link drops, PSOD crash events) and broadcasts formatted event notifications to vCenter Server to trigger alarms.

Virtual Machine & vCenter Server Logging

Diagnostic telemetry extends beyond the ESXi hypervisor to individual virtual machines and the vCenter Server Appliance (vCSA).

Virtual Machine Directory Logs (vmware.log)

Every virtual machine maintains its own operational log named vmware.log. Crucially, this log does not reside in /var/log/ on the ESXi host. Instead, it is located inside the virtual machine's dedicated folder on the datastore, directly alongside the .vmx configuration file and .vmdk disk descriptors.

  • Historical Archiving: When a virtual machine undergoes a power cycle (power off and power on), the active vmware.log is closed and renamed sequentially to vmware-1.log, vmware-2.log, etc., and a fresh vmware.log is initialized. By default, ESXi preserves up to 6 historical log files.
  • Diagnostic Content: vmware.log records:
    • Virtual hardware initialization (virtual CPU count, virtual NVMe/LSI Logic controllers, E1000e/VMXNET3 adapters).
    • Guest operating system BSOD (Windows Blue Screen) or kernel panic stack traces.
    • Virtual Machine monitor (VMM) panics and crash dumps.
    • Snapshot creation, delta disk opening, and disk consolidation timings.
    • vMotion migration handoffs and stun times (the brief sub-second freeze during final memory copy).

vCenter Server Appliance (vCSA) Log Hierarchy

Within the vCenter Server Appliance (based on VMware Photon OS), log files reside under /var/log/vmware/ organized by microservice:

Log File PathService / ComponentDiagnostic Focus
/var/log/vmware/vpxd/vpxd.logvCenter Server Daemon (vpxd)Core vCenter operations, database connection issues, DRS/HA calculations, task scheduling, host connection status.
/var/log/vmware/vpxd/vpxd-alert.logvpxd Alert SubsystemHigh-priority warnings and error alerts triggered within vCenter.
/var/log/vmware/sso/Single Sign-On (SSO / STS)Identity provider federation, Active Directory/LDAP authentication, SAML token generation.
/var/log/vmware/eam/eam.logESX Agent ManagerLifecycle management of host solution agents (NSX vibs, storage appliances).
/var/log/vmware/vmware-vmon/vmon.logvCenter Service Lifecycle ManagerService health monitoring, startup sequences, automated restarts of failed daemons.
/var/log/vmware/applmgmt/Appliance Management (VAMI)vCSA backups, patches, network configuration, port 5480 web console.
Loading diagram...
ESXi and vCenter Telemetry and Logging Pipeline

SCSI Sense Code Diagnostics & Support Bundles

When storage errors occur, the VMkernel logs raw SCSI sense codes in vmkernel.log returned from the storage array. Deciphering these codes allows administrators to distinguish between transient fabric timeouts and catastrophic hardware failures.

Decoding SCSI Sense Codes

SCSI error lines in vmkernel.log typically appear in the following standard notation: ScsiDeviceIO: 4056: Cmd(0x43a600) 0x28, CmdSN 0x80 from world 1024 to dev "naa.6005..." failed H:0x0 D:0x2 P:0x0 Valid sense data: 0x5 0x25 0x00

  • Host Status (H:): Status from the local HBA driver. 0x0 indicates Host OK; 0x1 indicates No Connect; 0x5 indicates Command Aborted.
  • Device Status (D:): Status returned by the target array. 0x0 indicates Good; 0x2 indicates Check Condition (sense data follows).
  • Sense Key / ASC / ASCQ (0xS 0xASC 0xASCQ): The three critical hex values defining the exact failure reason:
    1. Sense Key (0xS): General category of error (e.g., 0x2 = Not Ready, 0x5 = Illegal Request, 0x6 = Unit Attention).
    2. Additional Sense Code (0xASC): Specific error description.
    3. Additional Sense Code Qualifier (0xASCQ): Granular sub-code detailing the error condition.

Critical SCSI Sense Code Diagnostic Matrix

SCSI Sense CodeSense Key NameAdditional Sense DescriptionDiagnostic Meaning & VMkernel Action
0x5 0x25 0x00ILLEGAL REQUESTLOGICAL UNIT NOT SUPPORTEDPermanent Device Loss (PDL). The LUN has been unmapped or destroyed on the array. ESXi ceases I/O immediately.
0x2 0x04 0x01NOT READYLOGICAL UNIT IN PROCESS OF BECOMING READYThe storage controller is initializing or spinning up. Hypervisor retries the command.
0x2 0x04 0x03NOT READYMANUAL INTERVENTION REQUIREDArray hardware failure; human operator required to restore storage.
0x6 0x29 0x00UNIT ATTENTIONPOWER ON, RESET, OR BUS DEVICE RESETStorage array controller rebooted or SAN path was reset. Normal during controller firmware failover.
0x3 0x0C 0x00MEDIUM ERRORWRITE ERRORUnderlying physical disk surface failure or flash cell write failure.
0x5 0x20 0x00ILLEGAL REQUESTINVALID COMMAND OPERATION CODEArray does not support the issued SCSI opcode (common with unsupported VAAI primitives).

Diagnostic Data Collection: Support Bundles

When escalating issues to VMware Support or conducting deep root-cause audits, administrators must generate comprehensive diagnostic bundles containing logs, configuration files, and state dumps:

  1. ESXi Host Diagnostic Bundle (vm-support):
    • Executed via ESXi Shell / SSH: vm-support
    • Best Practice Execution: Direct output to a shared datastore to avoid filling host ramdisk memory:
      vm-support -w /vmfs/volumes/SAN-Datastore-01/support_bundles/
      
    • Performance Snapshot Mode: Captures high-frequency performance counters over time:
      vm-support -p -d 30 -i 5
      
      (Captures performance data every 5 seconds for 30 seconds duration).
  2. vCenter Server Diagnostic Bundle (vc-support):
    • Executed from the appliance Bash shell: vc-support
    • Packages /var/log/vmware/, PostgreSQL configuration dumps, and SSO identity states into a compressed .tar.gz archive.
  3. vSphere Client GUI Export:
    • In the vSphere Client, right-click any ESXi host, cluster, or vCenter object -> select Export System Logs -> select specific log components -> download bundle directly through the web browser.

Centralized Syslog Forwarding & VMware Skyline

Because local host logs are subject to rotation and can be lost if system storage fails, enterprise vSphere deployments enforce centralized remote logging conforming to RFC 5424:

  • Configuring Remote Syslog via esxcli:
    # Configure remote syslog target (IP/FQDN, protocol, and port)
    esxcli system syslog config set --loghost='tcp://syslog.corp.local:514'
    
    # Reload the syslog daemon to apply configuration
    esxcli system syslog reload
    
    # Open the outgoing syslog port through the ESXi host firewall
    esxcli network firewall ruleset set --ruleset-id=syslog --enabled=true
    
  • VMware Skyline (Objective 5.11): Skyline used a Skyline Collector virtual appliance in the customer environment to send product usage data to VMware. The Skyline Advisor portal turned that data into proactive findings (known issues, VMSA security advisories, best-practice gaps) with remediation guidance, and Log Assist could upload support bundles to a support request. Status: Broadcom ended the Skyline Advisor service on October 4, 2024. Its findings are moving into VMware Cloud Foundation operations tooling (for example, Aria Operations 8.18 and VCF 5.2 surface critical findings), while vSphere and vSAN keep their in-product Skyline Health checks in the vSphere Client.
Test Your Knowledge

A storage array path experiences an unrecoverable failure. Which log file on the ESXi host should an administrator inspect to find the raw SCSI sense codes, HBA driver errors, and VMFS volume unmount warnings?

A

The /var/log/vpxa.log file

B

The /var/log/hostd.log file

C

The /var/log/vmkernel.log file

D

The /var/log/auth.log file

Test Your Knowledge

An administrator examines /var/log/vmkernel.log on an ESXi 8.0 host and discovers the following entry: 'ScsiDeviceIO: ... failed H:0x0 D:0x2 P:0x0 Valid sense data: 0x5 0x25 0x00'. How does the ESXi hypervisor interpret this specific SCSI sense code?

A

As an All Paths Down (APD) condition indicating a transient Fibre Channel switch zoning failure

B

As a Permanent Device Loss (PDL) condition indicating Logical Unit Not Supported

C

As a Unit Attention condition indicating that the storage array controller has rebooted

D

As a Not Ready condition indicating that the LUN is spinning up and becoming ready

Test Your Knowledge

An administrator needs to collect an ESXi diagnostic support bundle from the command line while ensuring that the resulting archive does not consume space on the local host ramdisk. Which command should be executed?

A

esxcli system support bundle generate --output=/tmp

B

tar -czvf /scratch/log/bundle.tar.gz /var/log/*

C

vc-support -l --dest=/vmfs/volumes/Datastore01/bundles/

D

vm-support -w /vmfs/volumes/Datastore01/bundles/

Sections you finish are checked off in the contents.