Is there a log insight query I can use to see who shut down a VM? I don't use Log Insight a lot. We have a VM that keeps shutting down.
Not a defined query as such, but yes you could use the filters to choose Virtual machines and then search for 'shutdown' keyword to look for the logs with shutdown message.
Here's the link to few search query examples.
If you don't absolutely have to use Log Insight to find this information, couldn't you easily just check the Tasks of the VM that is being shutdown and look for the "Initiate guest OS shutdown" task and what account is listed for it in the Initiator column?