host_log_scan
Scan recent ESXi host syslog lines for error/warning patterns, returning grouped findings with severity and sample messages to diagnose host issues when vCenter events are insufficient.
Instructions
[READ] Scan recent ESXi host syslog lines for error/warning patterns.
Reads the last lines entries of the hostd/vmkernel/vpxa logs via the
diagnostic system and returns only the lines matching known trouble patterns
(error, fail, critical, panic, lost access, timeout, …). Severity follows the
level ESXi wrote on the line (Cr/Er/Wa/In…, raw token in log_level); a
critical keyword still wins. By default findings are grouped by pattern —
each item has count, hosts, first_seen/last_seen (log time), severity,
source (host_log:<key>), pattern and one sample; lines_matched is the
ungrouped count. group=false returns one row per line (severity, source,
message, time, entity, log_level, log_time). Returns the list envelope {items,
returned, limit, total, truncated, hint}. total is
null on purpose — this is "errors within the scanned window", not all errors
ever. logs_unavailable lists every host/log that could NOT be read, with
the reason (e.g. the account lacks Global.Diagnostics); empty items means
nothing matched only when logs_unavailable is empty too.
Use this when get_events or host_investigation_bundle show a host in trouble
but not why: vCenter events and ESXi syslog are different sources. Filter
with host_name to keep the scan fast on large clusters; a name that
matches no host returns an error (get the exact name from list_esxi_hosts),
not an empty result. Every call reads the last lines lines afresh.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| group | No | Group repeated lines by pattern (default true). One call on a lab returned 353 lines, 195 of them one statistics-provider message. | |
| lines | No | How many recent lines per log to scan (default 500, at least 1). | |
| target | No | vCenter/ESXi target from config (default if omitted). | |
| host_name | No | Filter to a single host by exact name (None = all hosts). |