Skip to main content

VMware Log Insight

Disclaimer: Community-maintained open-source project, not affiliated with, endorsed by, or sponsored by VMware, Inc. or Broadcom Inc. "VMware", "vSphere", and "Aria" are trademarks of Broadcom. Source is publicly auditable under the MIT license.

Read-only log search and aggregation for VMware Aria Operations for Logs (formerly vRealize Log Insight) — the appliance that collects syslog from ESXi hosts, vCenter, and VMs. The centralized-log data source for the VMware skill family. Strictly non-destructive: it queries, it never writes.

Companion Skills

Need Skill Tools
Raw centralized logs + spikes vmware-log-insight (this) 7
vCenter events & alarms vmware-monitor 27
Metrics, anomalies, capacity vmware-aria 28
Incident correlation / root cause vmware-debug — feed it log_search output 2
VM lifecycle / operations vmware-aiops 49

Install

uv tool install vmware-log-insight
mkdir -p ~/.vmware-log-insight
cp config.example.yaml ~/.vmware-log-insight/config.yaml   # edit host/username/provider
echo 'VMWARE_LOG_INSIGHT_PROD_PASSWORD=...' > ~/.vmware-log-insight/.env
chmod 600 ~/.vmware-log-insight/.env
vmware-log-insight doctor

Offline / Air-Gapped Install (from source)

This project uses the modern PEP 517 build system (hatchling), so there is no setup.py by design — that is expected, not a missing file. If you cloned the source and hit ERROR: File "setup.py" or "setup.cfg" not found ... editable mode currently requires a setuptools-based build, your pip is older than 21.3 and cannot do an editable (-e) install with a non-setuptools backend. Editable mode is a developer convenience, not needed to run the tool — do one of:

# From the source tree — a normal (non-editable) install builds a wheel:
pip install .              # NOT  pip install -e .

# ...or upgrade pip first, and editable works too:
pip install --upgrade pip && pip install -e .

For a truly air-gapped host, build the wheels on a connected machine and copy them over — the target then needs no network:

# On a connected machine, collect this package + its dependencies as wheels:
pip wheel . -w dist        # → dist/*.whl   (or: uv build, for just this package)

# Copy dist/ to the air-gapped host, then install offline:
pip install --no-index --find-links dist vmware-log-insight

MCP Tools (7 — all read-only)

Tool What
log_search Search events by time window + text + filters
log_aggregate Count/aggregate over time bins, with z-score spike detection
log_fields List extracted fields usable in filters
log_version Appliance version/build
alert_list / alert_get / alert_history Query defined alerts and their trigger history

Workflows

  • Find errors fastvmware-log-insight search -q error -l 1h.
  • Where did logs burst?vmware-log-insight aggregate -q error -l 6h --bin-ms 300000, read spikes[], then search the spike window.
  • Root cause — pass log_search results (plus vCenter events from vmware-monitor and metrics from vmware-aria) to vmware-debug incident_timeline.

Troubleshooting

  • 401 on /sessions → check username/password/provider and the VMWARE_LOG_INSIGHT_<TARGET>_PASSWORD env var.
  • 503 everywhere → appliance starting up; doctor reports it as a status, not a crash.
  • Empty results → widen --last; default API port is 9543 (set port if different).

Security

Read-only by construction. Credentials in ~/.vmware-log-insight/.env (chmod 600); plaintext passwords auto-obfuscated to grep-safe b64: (obfuscation, not encryption — inject from a secret manager for real secrecy). TLS on by default. See SECURITY.md.

License

MIT.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

vmware_log_insight-1.8.7.tar.gz (186.6 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

vmware_log_insight-1.8.7-py3-none-any.whl (35.2 kB view details)

Uploaded Python 3

File details

Details for the file vmware_log_insight-1.8.7.tar.gz.

File metadata

  • Download URL: vmware_log_insight-1.8.7.tar.gz
  • Upload date:
  • Size: 186.6 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: uv/0.10.0 {"installer":{"name":"uv","version":"0.10.0","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"macOS","version":null,"id":null,"libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":null}

File hashes

Hashes for vmware_log_insight-1.8.7.tar.gz
Algorithm Hash digest
SHA256 b3e3876a3542cf4c505f3e4c61bf7712684ab55ac6cc52972e340f72ec4bcfa2
MD5 3c989a636203096f91c355eca0c50cbe
BLAKE2b-256 ce17fee247f4f81feef4dae2595e67ffbd5c5a46be2bcf03c79a84f9d161a23f

See more details on using hashes here.

File details

Details for the file vmware_log_insight-1.8.7-py3-none-any.whl.

File metadata

  • Download URL: vmware_log_insight-1.8.7-py3-none-any.whl
  • Upload date:
  • Size: 35.2 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: uv/0.10.0 {"installer":{"name":"uv","version":"0.10.0","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"macOS","version":null,"id":null,"libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":null}

File hashes

Hashes for vmware_log_insight-1.8.7-py3-none-any.whl
Algorithm Hash digest
SHA256 db058adb51e0706ae74d0d8146d22818bf015fa15347ca7dd7dcb721a29c474d
MD5 e7319cfa22526f475485ab13cd586331
BLAKE2b-256 7b48da7a35a391f7b897826da9447f82210daa8aaacea83e7a7b1dfbe7a15fb3

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page