Skip to main content
Glama
vmware-skills

VMware-Monitor

get_events

Read-onlyIdempotent

Retrieve recent vCenter/ESXi events filtered by severity, newest first, up to 5000 per window. Use for an inventory-wide event sweep.

Instructions

[READ] Get recent vCenter/ESXi events filtered by severity.

Returns the list envelope, newest first. Up to 5000 events in the window are read; when more matched, read_truncated is true and read_note says how far back the read got — the oldest events were not examined, so narrow hours before concluding nothing happened earlier in the window.

Severity is this skill's own ranking where it has one, and otherwise vCenter's published event catalogue. An event neither can rank comes back with severity "unknown" (it is returned, not filtered out) and is counted in the envelope's unclassified, with classification_note explaining. An empty items alongside a non-zero unclassified does NOT mean the window was quiet — read the note before reporting all-clear.

Use this for an inventory-wide event sweep. When you already know the object, prefer vm_investigation_bundle / host_investigation_bundle instead: they return the same events correlated with that object's state in one call. ESXi syslog lines are not events — use host_log_scan for those.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
endNoWindow end, ISO 8601; defaults to now.
hoursNoHow many hours back to query (default 24). Ignored when both start and end are given; with end alone, how far back from end.
startNoWindow start, ISO 8601 (e.g. "2026-09-03T12:00:00Z"; no zone = UTC). Use it to ask about a specific day rather than the last N hours.
targetNovCenter/ESXi target from config (default if omitted).
severityNoMinimum severity: "critical", "warning", or "info".warning
include_routineNoList routine login/logout session events too. By default they are folded and counted in ``routine_folded`` — one local agent's logins can outnumber everything else in a window.

Schema Changelog

Changes observed during successful MCP inspections.

  1. Changed4 schema fields changedv1.14.0
    • addedInput schema / properties / end
      Added value: +{
      +  "anyOf": [
      +    {
      +      "type": "string"
      +    },
      +    {
      +      "type": "null"
      +    }
      +  ],
      +  "default": null,
      +  "description": "Window end, ISO 8601; defaults to now.",
      +  "title": "End"
      +}
    • changedInput schema / properties / hours / description
      Previous value: -"How many hours back to query (default 24)."New value: +"How many hours back to query (default 24). Ignored when both start and end are given; with end alone, how far back from end."
    • addedInput schema / properties / include_routine
      Added value: +{
      +  "default": false,
      +  "description": "List routine login/logout session events too. By default they are folded and counted in ``routine_folded`` — one local agent's logins can outnumber everything else in a window.",
      +  "title": "Include Routine",
      +  "type": "boolean"
      +}
    • addedInput schema / properties / start
      Added value: +{
      +  "anyOf": [
      +    {
      +      "type": "string"
      +    },
      +    {
      +      "type": "null"
      +    }
      +  ],
      +  "default": null,
      +  "description": "Window start, ISO 8601 (e.g. \"2026-09-03T12:00:00Z\"; no zone = UTC). Use it to ask about a specific day rather than the last N hours.",
      +  "title": "Start"
      +}
  2. Changed6 schema fields changedv1.9.2
    • addedInput schema / additionalProperties
      Added value: +false
    • addedInput schema / properties / hours / description
      Added value: +"How many hours back to query (default 24)."
    • addedInput schema / properties / severity / description
      Added value: +"Minimum severity: \"critical\", \"warning\", or \"info\"."
    • addedInput schema / properties / severity / enum
      Added value: +[
      +  "critical",
      +  "warning",
      +  "info"
      +]
    • addedInput schema / properties / target / description
      Added value: +"vCenter/ESXi target from config (default if omitted)."
    • changedOutput schema / (root)
      Previous value: -{
      -  "properties": {
      -    "result": {
      -      "items": {
      -        "additionalProperties": true,
      -        "type": "object"
      -      },
      -      "title": "Result",
      -      "type": "array"
      -    }
      -  },
      -  "required": [
      -    "result"
      -  ],
      -  "title": "get_eventsOutput",
      -  "type": "object"
      -}New value: +null
  3. First observedv0.1.2

TDQS

A4.9/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

The description goes well beyond the annotations (readOnlyHint, idempotentHint, destructiveHint) by disclosing truncation behavior (up to 5000 events, read_truncated, read_note), severity classification rules (own ranking vs vCenter catalogue, 'unknown' severity returned not filtered), and the crucial caveat that an empty items list with non-zero unclassified does not mean silence. This is exactly the kind of behavioral context agents need and is fully consistent with the annotations.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Although the description is long, every sentence earns its place: it front-loads the one-line purpose with the [READ] tag, then covers truncation, severity semantics, all-clear caveats, and alternative tools in a logical order. The density is justified by the tool's complexity and the need to prevent misinterpretation, with no filler.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

With no output schema, the description must explain the return envelope, and it does: newest-first ordering, truncation flags, severity classification, and unclassified counts. Combined with the annotations and 100% parameter schema coverage, the definition equips an agent with everything needed to call the tool correctly, interpret results, and decide when to switch to a sibling.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

With 100% schema coverage, the baseline is 3, and the description adds meaningful parameter-related guidance: it explains how 'hours' interacts with truncation (narrow it before concluding nothing happened earlier) and clarifies the semantics of severity as a minimum threshold with potential 'unknown' outcomes. This goes beyond the schema's simple descriptions, earning a 4.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description states the specific verb (get), resource (vCenter/ESXi events), and filter (by severity), and immediately distinguishes itself from siblings by naming vm_investigation_bundle / host_investigation_bundle and host_log_scan as alternatives for different use cases. An agent can tell exactly what this tool does and what it does not do without inspecting other schemas.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description explicitly states when to use this tool ('inventory-wide event sweep') and when to prefer alternatives ('when you already know the object, prefer vm_investigation_bundle / host_investigation_bundle'), and it warns that ESXi syslog lines are not events, pointing to host_log_scan. It also gives practical guidance on interpreting truncation and unclassified results, leaving no ambiguity about selection.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.