
VMware, Inc. 83
Appendix 14 vShield Endpoint Events and Alarms
VM Alarms
VMalarmsaregeneratedbyeventsaffectingthehealthstatusofthevShieldEndpointmodule.
Events
EventsareusedforloggingandauditingconditionsinsidethevShieldEndpoint‐basedsecuritysystem.
EventscanbedisplayedwithoutacustomvSphereplug‐in.SeethevCenterServerAdministrationGuideon
eventsandalarms.
Eventsarethebasisforalarmsthataregenerated.UponregisteringasavCenterServerextension,the
vShield
Managerdefinestherulesthatcreateandremovealarms.
Defaultbaseargumentsforaneventarethereportedtime andthevShieldManagerevent_id.
Table 14‐6listsvShieldEndpointeventsreportedbytheSVMandthevShieldManager(VSM)inorderbycode
number.Thetableshowstheevencode,
name,theVCarguments,theeventcategory,andadescription.Inthe
EventCategorycolumn,eventsthatgenerateerroralarmsarecoloredred.Eventsthatgeneratewarning
alarmsarecoloredyellow.
Table 14-4. Warnings
Possible Cause Action
TheSVMisoverloaded.Thevirtualmachines
willnotbeprotectedwhilethealarmpersists.
CheckresourcesallocationfortheSVMandallocatemoreresources,
ifnecessary.CheckthevCenterServereventlogfortheESXtheSVM
isattachedto.Aneventcodeof1002canindicateanoverloaded
SVM.
Thethinagentinoneormorevirtualmachinesis
initializedbutnotreportingevents.Thosevirtual
machinesarenotprotectedwhilethiswarning
persists.
Thisisusuallyatransientalarmthatdoesnotrequireattention.Ifit
persistsorturnstored,lookatthevCenterServerev entlogfor
the
protectedVM.Aneventcodeof1000indicatesanon‐functioning
thinagent.
Table 14-5. Errors
Possible Cause Action
Thethinagentversionisnotcompatiblewiththe
vShieldEndpointmodule
Installcompatiblecomponents.LookinthevShieldEndpoint
InstallationGuideforcompatibleversionsforvShieldEndpoint
moduleandSVM.
ThethinagentisnotreportingvShieldEndpoint
events.Thevirtualmachineisnotprotected.
Thethinagentismalfunctioning,or
notinitialized.Lookattheevent
logtoseeifthethinagentwasinitializedsuccessfully.
Thevirtualmachineisstillpoweredon,butthe
thinagentisdisabled.Thevirtualmachineisnot
protected.
Iftheerrorpersists,thisthinagentismalfunctioning.(Avirtual
machinethatisshuttingdown
orintheprocessofavMotionmove
doesnotgeneratearedalarm.)
Table 14-6. vShield Endpoint Events
Code Name
VC
Arguments
Event
Category Description
0001 VSM_FSFD_EVENT_VERSION_MISMATCH timestamp,
SVMversion
ofFSFD
protocol,
FSFDversion
ofFSFD
protocol
error vShieldEndpoint:TheSVMwas
contactedbyanon‐compatibleversion
ofthevShieldEndpointThinAgent.
0003 VSM_FSFD_EVENT_DISK_FULL timestamp warning ThevShieldEndpointThinAgent
encounteredaʺdiskfullʺerrorwhile
attemptingtowritetothelocaldisk.
0004 VSM_FSFD_EVENT_TIMEOUT timestamp warning A
timeoutoccurredinthe
communicationbetweentheSVMand
theThinAgent.
Kommentare zu diesen Handbüchern