VMware Cloud Community
danbarr
Enthusiast
Enthusiast

Custom query for ESXi host AD auth issues

Thought I'd share a quick success story:

After about 10 minutes of having Log Insight installed, it already helped me identify one host out of about 35 that had an issue with its Active Directory configuration. Something must have gotten out of sync with the host and its computer account in AD, and the host was no longer able to authenticate AD users. Of course, normally I would not have found out about this until I actually tried to log into the host directly (probably in a pinch to solve a problem, when it would have been super inconvenient). Anyway, the log entry that pointed this out was:

2013-06-18T13:24:01Z host1.domain.com nssquery: Group lookup failed for 'DOMAIN\ESX Admins'

(actual hostname & domain name redacted)

This event was repeating every minute. A quick query to find more of these (luckily we had none) is priority=warning and appname=nssquery. I will probably set up an alert for this as well. I exported the custom query to a content pack (file attached) if anyone is interested.

Reply
0 Kudos
1 Reply
sflanders
Commander
Commander

Great story, thanks for sharing!

Hope this helps! === If you find this information useful, please award points for "correct" or "helpful". ===
Reply
0 Kudos