VMware
runZero Platform syncs your VMware vCenter and ESXi virtual machine inventories.
Setting up VMware credentials
Unlike other API integrations, VMware synchronization runs as part of your regular runZero Explorer scans. Start by creating a set of VMware credentials.
On the Scanning with credentials page, click Add Credential, choose the VMware vCenter/ESXi Username and Password credential type, and enter the username and password. In most cases the username takes the form user@domain.com. The VMware account needs at least read-only access.
The CIDR allow list field limits which addresses receive the credentials, so the runZero Explorer doesn’t hand them to unexpected VMware systems it encounters on the network.
If runZero has already found VMware API endpoints, the optional VMware thumbprints field lists their IP addresses and TLS fingerprints. Remove any system you don’t want to trust with your VMware credentials. If you’d rather not limit authentication to a fixed list of IP addresses and TLS certificates, set VMware insecure to Yes to allow authentication with untrusted endpoints.
Set organization access for the credentials as you would for any other stored credential; see Scanning with credentials.
Performing VMware synchronization
With the credentials defined, enable VMware synchronization in a scan task. Any task that scans the VMware host systems can synchronize VMware VM data.
The Probes tab of the scan setup has a section for enabling and disabling the VMware probe. Synchronization needs the probe enabled, which it is by default.
On the Credentials tab, use the toggle to enable the right set of VMware vCenter/ESXi credentials.
When the scan runs, the Explorer authenticates with every VMware ESXi or vCenter host it finds that the credentials are configured to trust. runZero imports data about the VMware VMs automatically and merges it with what scanning found.
Troubleshooting
If you’re having trouble with the integration, start with these questions and answers.
Why is the VMware integration unable to connect?
- Check whether the VMware integration is returning any data.
- Query the inventory rather than the task details to review all the data available from this integration.
- In some cases, an integration’s configuration limits how much data reaches the runZero console.
- Some integrations require specific actions that are easy to overlook. If you miss a step during setup, the integration may not work correctly. Review this page and follow the steps exactly.
- If the VMware integration can’t connect, check the task log for errors. Common errors include:
- 500: server error, unable to connect to the endpoint
- 404: hitting an unknown endpoint on the server
- 403: not authorized, likely a credential issue
- If VMware is on-premises, verify that the integration task runs from an Explorer with access to the VMware host.