Specific permissions are required for each account used to add products to the Skyline Collector.

There are two types of data collection with Skyline.

  1. Product Usage Data - Used to notify you of potential issues, security vulnerabilities, impacts to usability, and configuration recommendations. This information is presented to you as Findings within Skyline.

  2. Diagnostic Data - Used to assist in troubleshooting a VMware Support Request. This type of data is usually referred to as support bundles, or log bundles.

The following provides details for the minimum required privileges for each product to collect product usage data, and support bundles.

Important:

For some products, the required privileges to collect product usage data, and support bundles, may be different.

vCenter Server Account Permissions

The following role/privileges are required for the account used to add the vCenter Server to the Skyline Collector. These role/privileges are sufficient for both collecting product usage data, and transferring support bundles with Log Assist.

  • vCenter Server Read-Only role

  • Global.Diagnostics

  • Global.Health

  • Global.Licenses

  • Global.Settings

  • Host profile.View

For detailed instructions for how to create a user account with the given permissions, see Knowledge Base Article 59661.

NSX-V (NSX Data Center for vSphere) Account Permissions

For NSX-V version 6.4.5 and below, the NSX Auditor role does not have sufficient privileges to generate and collect support bundles from NSX-V objects. To generate and collect support bundles from NSX-V objects, a user account with the NSX Administrator role is required. Therfore, you have two options for adding NSX-V version 6.4.5 to a Skyline Collector.

For the collection of product usage data only:

  • NSX Auditor

Important:

If an account with the NSX Auditor role is used to add NSX-V, the following is displayed within Skyline Advisor:

  • On the Collector Details page, the Status of NSX-V is: Insufficient Privileges.

  • On the Initiate Log Transfer page, the Privileges check for NSX-V, and all NSX-V components fail.

If using an account with the NSX Auditor role, you cannot transfer support bundles to VMware GSS using Skyline Log Assist.

For the collection of both product usage data, and transferring support bundles with Log Assist:

  • NSX Administrator

For NSX-V version 6.4.6, and above:

The NSX Auditor role in NSX-V version 6.4.6 supports the ability to transfer NSX Edge support bundles. This capability was not available in NSX-V versions previous to 6.4.6. Therefore, a user account assigned the NSX Auditor role can be used for product usage data collection, and for the transferring of support bundles using Log Assist.

For the collection of both product usage data, and transferring support bundles with Log Assist:

  • NSX Administrator

Important:

You must assign the required role/privileges to a user account. Assigning the required role/privileges to a group, and using a user account within that group to add NSX-V to the Skyline Collector will fail the privileges check within Skyline Advisor.

NSX-T (NSX-T Data Center) Account Permissions

For NSX-T, the NSX Auditor role does not have sufficient privileges to generate and collect support bundles from NSX-T objects. In order to generate and collect support bundles from NSX-T objects, a user account with the NSX Administrator role is required. Therfore, you have two options for adding NSX-T to a Skyline Collector.

For the collection of product usage data only:

  • NSX Auditor

Important:

If an account with the NSX Auditor role is used to add NSX-T, the following is displayed within Skyline Advisor:

  • On the Collector Details page, the Status of NSX-T is: Insufficient Privileges.

  • On the Initiate Log Transfer page, the Privileges check for NSX-T, and all NSX-T components fail.

If using an account with the NSX Auditor role, you cannot transfer support bundles to VMware GSS using Skyline Log Assist.

For the collection of both product usage data, and transferring support bundles with Log Assist:

  • NSX Enterprise Administrator

Important:

You must assign the required role/privileges to a user account. Assigning the required role/privileges to a group, and using a user account within that group to add NSX-T to the Skyline Collector will fail privileges check within Skyline Advisor.

Horizon View Account Permissions

The following role/privileges are required for the account used to add the Horizon Connection Server to the Skyline Collector. These role/privileges are sufficient for both collecting product usage data, and transferring support bundles with Log Assist.

  • Administrator (read-only) Role

  • Collect Operation Logs

Important:

If you are using Skyline Collector version 2.3, or below, you must create a new role for Horizon View with the Collect Operations Logs privilege. The role must be named LogCollector.

For Skyline Collector version 2.4, there is no requirement to name the role LogCollector.

Important:

Horizon version 7.10, or above, is required to transfer support bundles to VMware, using Skyline Log Assist.

vRealize Operations Account Permissions

Important:

Skyline Log Assist does not support the transferring of support bundles to VMware GSS. Any vRealize Operations Manager instances added to a Skyline Collector will not appear within Log Assist page of Skyline Advisor.

The following role/privileges are required for the account used to add the vRealize Operations Manager to the Skyline Collector. These role/privileges are sufficient for collecting product usage data.

  • vRealize Operations Read-Only Role

Important:

You must assign the required role/privileges to the user account. Assigning the required role/privileges to a group, and using a user account within that group to add vRealize Operations Manager to the Skyline Collector will fail the privileges check within Skyline Advisor.