get_events
Retrieve recent vCenter/ESXi events filtered by severity, newest first, up to 5000 per window. Use for an inventory-wide event sweep.
Instructions
[READ] Get recent vCenter/ESXi events filtered by severity.
Returns the list envelope, newest first. Up to 5000 events in the window are
read; when more matched, read_truncated is true and read_note says how
far back the read got — the oldest events were not examined, so narrow
hours before concluding nothing happened earlier in the window.
Severity is this skill's own ranking where it has one, and otherwise
vCenter's published event catalogue. An event neither can rank comes back
with severity "unknown" (it is returned, not filtered out) and is counted in
the envelope's unclassified, with classification_note explaining. An
empty items alongside a non-zero unclassified does NOT mean the
window was quiet — read the note before reporting all-clear.
Use this for an inventory-wide event sweep. When you already know the object, prefer vm_investigation_bundle / host_investigation_bundle instead: they return the same events correlated with that object's state in one call. ESXi syslog lines are not events — use host_log_scan for those.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| end | No | Window end, ISO 8601; defaults to now. | |
| hours | No | How many hours back to query (default 24). Ignored when both start and end are given; with end alone, how far back from end. | |
| start | No | Window start, ISO 8601 (e.g. "2026-09-03T12:00:00Z"; no zone = UTC). Use it to ask about a specific day rather than the last N hours. | |
| target | No | vCenter/ESXi target from config (default if omitted). | |
| severity | No | Minimum severity: "critical", "warning", or "info". | warning |
| include_routine | No | List routine login/logout session events too. By default they are folded and counted in ``routine_folded`` — one local agent's logins can outnumber everything else in a window. |