Apply the correct product account privileges required to allow Log Assist to collect support bundles.

Specific user account privileges are required by Log Assist to collect support bundles from supported products. Ensure that the user account used to add the product to the Skyline Collector has the required privileges to allow support bundle collection.

Important:

Log Assist does not support the collection of support bundles from vRealize Operations Manager, or SDDC Manager.

Note:

Log Assist supports the collection of support bundles from the following:

vSphere

  • vCenter Server

  • ESXi

NSX-V (NSX Data Center for vSphere)

  • NSX Manager

  • NSX Controller

  • NSX Edge

NSX-T (NSX-T Data Center)

  • NSX Manager

  • NSX Edge

  • NSX Edge Cluster

Horizon

  • Horizon Connection Server

Support bundles needed to assist with troubleshooting vSAN are collected within the ESXi support bundle.

vCenter Server User Account Permissions

The following permissions are required for the account used to add the vCenter Server to the Skyline Collector. These permissions are sufficient for both collecting product usage data, and transferring support bundles with Log Assist.

  • vCenter Server Read-Only role

  • Global.Diagnostics

  • Global.Health

  • Global.Licenses

  • Global.Settings

  • Host profile.View

For detailed instructions for how to create a user account with the given permissions, see Knowledge Base Article 59661.

Important:

If you have enabled ESXi Host Encyrption, or vSAN Encryption, the Cryptographic operations > Direct Access permission is required to allow the successful transfer of encrypted support bundles. This permission is only required for this reason, and is not needed unless you have enabled ESXi Host Encryption, or vSAN Encryption. This permission does not apply to Virtual Machine Encryption.

NSX-V (NSX Data Center for vSphere) User Account Permissions

For NSX-V version 6.4.5 and below, the NSX Auditor role does not have sufficient privileges to generate and collect support bundles from NSX-V objects. In order to generate and collect support bundles from NSX-V objects, a user account with the NSX Administrator role is required. Therfore, you have two options for adding NSX-V version 6.4.5 to a Skyline Collector.

For the collection of product usage data only:

  • NSX Auditor

Important:

If an account with the NSX Auditor role is used to add NSX-V, the following is displayed within Skyline Advisor:

  • On the Collector Details page, the Status of NSX-V is: Insufficient Privileges.

  • On the Initiate Log Transfer page, the Privileges check for NSX-V, and all NSX-V components fail.

If using an account with the NSX Auditor role, you cannot transfer support bundles to VMware GSS using Skyline Log Assist.

For the collection of both product usage data, and transferring support bundles with Log Assist:

  • NSX Administrator

Important:

You must assign the required role/privileges to a user account. Assigning the required role/privileges to a group, and using a user account within that group to add NSX-V to the Skyline Collector will fail privileges check within Skyline Advisor.

For NSX-V version 6.4.6, and above:

The NSX Auditor role in NSX-V version 6.4.6 supports the ability to transfer NSX Edge support bundles. This capability was not available in NSX-V versions previous to 6.4.6. Therefore, a user account assigned the NSX Auditor role can be used for product usage data collection, and for the transferring of support bundles using Log Assist.

For the collection of both product usage data, and transferring support bundles with Log Assist:

  • NSX Administrator

NSX-T (NSX-T Data Center) User Account Permissions

For NSX-T, the NSX Auditor role does not have sufficient privileges to generate and collect support bundles from NSX-T objects. In order to generate and collect support bundles from NSX-T objects, a user account with the NSX Administrator role is required. Therfore, you have two options for adding NSX-T to a Skyline Collector.

For the collection of product usage data only:

  • NSX Auditor

Important:

If an account with the NSX Auditor role is used to add NSX-T, the following is displayed within Skyline Advisor:

  • On the Collector Details page, the Status of NSX-T is: Insufficient Privileges.

  • On the Initiate Log Transfer page, the Privileges check for NSX-T, and all NSX-T components fail.

If using an account with the NSX Auditor role, you cannot transfer support bundles to VMware GSS using Skyline Log Assist.

For the collection of both product usage data, and transferring support bundles with Log Assist:

  • NSX Administrator

Important:

You must assign the required role/privileges to a user account. Assigning the required role/privileges to a group, and using a user account within that group to add NSX-T to the Skyline Collector will fail privileges check within Skyline Advisor.

Horizon 7 Connection Server User Account Permissions

The following role/privileges are required for the account used to add the Horizon Connection Server to the Skyline Collector. These role/privileges are sufficient for both collecting product usage data, and transferring support bundles with Log Assist.

  • Administrator (read-only) Role

  • Collect Operation Logs

Important:

If you are using Skyline Collector version 2.3, or below, you must create a new role for Horizon View with the Collect Operations Logs privilege. The role must be named LogCollector.

For Skyline Collector version 2.4 and above, there is no requirement to name the role LogCollector.