Specific permissions are required for each account used to add products to the Skyline Collector.

There are two types of data collection with Skyline.

  1. Product Usage Data - Used to notify you of potential issues, security vulnerabilities, impacts to usability, and configuration recommendations. This information is presented to you as Findings within Skyline.

  2. Diagnostic Data - Used to assist in troubleshooting a VMware Support Request. This type of data is usually referred to as support bundles, or log bundles.

The following provides details for the minimum required privileges for each product to collect product usage data, and support bundles.

Important:

For some products, the required privileges to collect product usage data, and support bundles, may be different.

vCenter Server Account Permissions

The following role/privileges are required for the account used to add the vCenter Server to the Skyline Collector. These role/privileges are sufficient for both collecting product usage data, and transferring support bundles with Log Assist.

  • vCenter Server Read-Only role

  • Global.Diagnostics

  • Global.Health

  • Global.Licenses

  • Global.Settings

  • Host profile.View

For detailed instructions for how to create a user account with the given permissions, see Knowledge Base Article 59661.

NSX Manager Account Permissions

NSX for vSphere has two options for assigning role/privileges for the account used to add NSX Manager to the Skyline Collector.

For the collection of product usage data only:

  • NSX Auditor

Important:

If an account with the NSX Auditor role is used to add NSX Manager, the following is displayed within Skyline Advisor:

  • On the Collector Details page, the Status of the NSX Manager is: Insufficient Privileges.

  • On the Initiate Log Transfer page, the Privileges check for NSX Manager, and all NSX components fail.

If using an account with the NSX Auditor role, you cannot transfer support bundles to VMware GSS using Skyline Log Assist.

For the collection of both product usage data, and transferring support bundles with Log Assist:

  • NSX Administrator

Horizon View Account Permissions

The following role/privileges are required for the account used to add the Horizon Connection Server to the Skyline Collector. These role/privileges are sufficient for both collecting product usage data, and transferring support bundles with Log Assist.

  • Administrator (read-only) Role

  • Collect Operation Logs

Important:

If you are using Skyline Collector version 2.3, or below, you must create a new role for Horizon View with the Collect Operations Logs privilege. The role must be named LogCollector.

For Skyline Collector version 2.4, there is no requirement to name the role LogCollector.

vRealize Operations Account Permissions

Note:

Skyline, and vRealize Operations, do not support the transferring of support bundles to VMware GSS using Skyline Log Assist.

The following role/privileges are required for the account used to add the vRealize Operations Manager to the Skyline Collector. These role/privileges are sufficient for collecting product usage data.

  • vRealize Operations Read-Only Role