Мониторинг дисковой подсистемы VMware через CIM/Zabbix
В 2021 году уже известно, что Zabbix предлагает в качестве средства комплексного мониторинга инфраструктуры VMware набор шаблонов, использующих функционал Low Level Discovery (LLD) и элементы типа Host prototype, в которых создаются стандартные списочные сенсоры из известных vCenter’у. Однако отнюдь не все вендоры оборудования корректно публикуют сенсоры или счетчики своих устройств в доступном для vCenter виде. Здесь рассматривается в подробностях настройка мониторинга для всё ещё поддерживаемых, но не отображающих состояние в vCenter контроллерах дисковой подсистемы Adaptec SmartRAID. Способ получения данных может быть пригоден и для других вендоров.
Итак, задача. Есть несколько хостов ESXi, купленных порознь у разных вендоров, с разным наполнением, и есть охота заиметь под них одинаковый мониторинг. Часть хостов выдает информацию в vSphere web client, но неструктурировано — никаких красивых группировок сенсоров по слову «storage» и близко нет, другая часть вообще ничего не выдает. При этом необходимое ПО установлено! Пример:
] esxcli software vib list
<snip>
scsi-aacraid 6.0.6.2.1.59002-1OEM.600.0.0.2494585 Adaptec_Inc VMwareCertified 2020-08-14
arc-cim-provider 3.07-23850 Adaptec VMwareAccepted 2021-02-15
arcconf 3.07-23850 Adaptec VMwareAccepted 2021-02-15
Как видим, в списке есть и драйвер для контроллера (здесь Adaptec RAID 8805), и утилита управления arcconf, и «родной» провайдер данных для внешних служб (далее «CIM провайдер») arc-cim-provider, все последних версий. Версия VMware на хосте 6.7U3, и сенсоров состояния подсистемы хранения в ней нет. Однако, если есть провайдер, то как-то можно получить от него данные — этим и займемся.
Во-первых, как получать эти данные. В документации на VMware, помимо всего прочего, сказано, что есть сервис sfcb, который запускается при установке стороннего CIM-провайдера, и сервис openwsman, представляющий собой сервер WS-Management, к тому же, умеющий работать с более примитивными запросами CIM или WBEM. А для работы с данными протоколами есть вполне серьезный клиент pywbem, возвращающий данные в любом удобном виде. Для своей реализации мониторинга я взял более привычную мне среду программирования bash и wbemcli в качестве средства обращения к хосту ESXi.
Чтобы получить данные от хоста, необходимо на нем авторизоваться, но локального root, естественно, заббиксу никто давать не будет. Поэтому на каждом хосте, подлежащем отслеживанию, нужно создать пользователя с ограниченным доступом, но в то же время имеющего доступ к подсистеме CIM, которая в VMware ограничена дополнительно. m4ce, создавший свой вариант шаблона для ESXi-хоста, выложил инструкцию, как правильно создать пользователя для Zabbix на ESXi-хосте версий 6.х (для более ранних необходимы слегка другие команды):
Инструкция слегка избыточна, так как, если когда-то мониторинг по CIM/WBEM/WS-Man уже настраивался, роль пользователя, подобная CIM_ReadOnly, может существовать, но на чистой системе подобных ролей не найдено.
Далее самое интересное. Дело в том, что сенсоры, которые собирает VMware vCenter, находятся в пространстве имен WBEM «по умолчанию», оно же «root/cimv2», а так как информации о дисках там нет, либо она в кривом виде, нужно найти правильное пространство имен, где эти данные есть, и правильные имена классов устройств, которые нужно отслеживать. Вторая часть несколько проще — беглым поиском находятся имена классов CIM_DiskDrive, CIM_StorageVolume, CIM_Controller, от которых можно отталкиваться в поисках фактических элементов. А с первой поможет вот этот документ от VMware (PDF), содержащий ссылки на ужасно обрезанную документацию по вендорским провайдерам. Но она есть, и вуаля — для Adaptec CIM Provider найдено пространство имен «root/pmc/arc/smi_15». Из того же документа можно узнать пространства имен и для других вендоров, пусть иногда и не напрямую — например, для Emulex пространство имен «root/emulex».
Если в одной строке появляются несколько символов подчеркивания, визуальный редактор их сжирает, думая, что это элемент форматирования. Как это отрубить?
Теперь у нас есть вся необходимая информация, чтобы начать собирать какие-то данные с хоста. Но данные из wbemcli возвращаются в очень громоздком и нечитаемом виде, мало того, адресуются элементы в командной строке не очень легко, к тому же, в Zabbix нужно суметь передать структуру обнаруженных данных через тот же механизм LLD. Для этого я написал скрипт, который умеет две вещи — отдавать найденные инстансы некоего класса из определенного пространства имен в Zabbix, и отдавать необработанные данные wbemcli при запросе конкретного инстанса. Скрипт представляет собой обертку над вызовами wbemcli ein и wbemcli gi , с форматированием данных в режиме обнаружения в формат, приемлемый для Zabbix’a. Шаблон для его использования находится там же, в нем настроены некоторые основные параметры отслеживаемых физических и логических дисков — для физических это состояние, температура (два варианта — один для сервера с HDD, второй для сервера с SSD, они заполняют разные параметры!), флаг состояния SMART (тоже два), счетчик оставшегося ресурса SSD и счетчики аппаратных ошибок, для логических — только состояние, и некоторые базовые триггеры на их основе. Дополнения и тесты на не-Adaptec системах приветствуются.
Напоследок: Если вы не сумели найти правильное пространство имен, в поисках поможет то, что «пространство имен» — это тоже класс, с именем __namespace , перечисление экземпляров которого можно начать с пространства «root».
Guide Monitoring RAID-Controller VMware ESXi/en
Deutsch
• English
Guide Monitoring RAID-Controller VMware ESXi
Inhaltsverzeichnis
Guide Monitoring RAID-Controller VMware ESXi
General
VMware ESXi uses so-called CIM providers (Common Information Model) for monitoring of hardware. These providers read the hardware state of a device and deliver these data back to the CIM broker. This information in turn can be read by the vSphere Client for instance.
If you have a server with hardware RAID ad VMware support at EUserv you are able to monitor the status of the hardware RAID. In the following guide we will show you how to install the CIM provider for the RAID controller and how to monitor the device status.
Procedure / preparations
In order to install the CIM provider the SSH access has to be enabled on the ESXi host first. This will be done via the vSphere Client. After this the CIM provider for the RAID controller has to be retrieved and installed.
Finally, the ESXi host has to be rebooted. The device information can then be reviewed in the vSphere Client.
For the following steps VMware’s vSphere Client is required. You can find additional hints about installation of the client here: Guide_VMware_ESXi
Enabling SSH access
In order to enable the SSH server on the ESXi host, start the vSphere Client first. Select your host from the upper left side and click Software -> Security Profile in the middle window:
Under the section Services select Properties from the upper right:
Select SSH from the list of available services, then click Options. Select Start and stop with host and click Start. Confirm this dialogue with OK:
Installing the CIM provider
After the SSH server has been started, connect to the server with an SSH client. The CIM provider will be installed using the tool esxcli which is included in ESXi by default. The CIM provider for the LSI MegaRAID controller is already available as *.vib file from the EUserv mirror. dem EUserv-Mirror vor.
The installation can be done with the following command:
You should see the following output:
In order for the changes to become effective you need to reboot the ESXi host. This can either be done using the reboot command or via the vSphere Client.
Verifying the CIM provider
After the reboot log in via SSH again and execute the following command:
You wil now see a list of all installed software and driver packages. The CIM for the LSI MegaRAID controller should be registered as follows:
Reading the device status
After the successful installation of the CIM klick on System Health in the Hardware section. You will now see a listing of the controller status, the connected hard disks and the logical volumes as well as the port status. The Status column displays the current health state (Normal or Alert):
What is a CIM VMware?
C ommon Information Model (CIM) providers allow management functions such as reporting health monitoring information or updating driver firmware.
What is CIM server on VMware ESXi?
The Common Information Model (CIM) is used on ESXi instead of installing the hardware agents in the Service Console. VMware vCenter server is capable of presenting this information through the Hardware Status tab, where it provides all the hardware information.
What is VMware CIM SLP?
https://kb.vmware.com/s/article/76372 Service Location Protocol (SLP) is a standard protocol that provides a framework to allow networking applications to discover the existence, location, and configuration of networked services in networks.
What is the CIM server?
Answer: CIM (Common Information Model) or WBEM (Web-Based Enterprise Management) is a standardized way of monitoring health performance for computer hardware such as servers and storage. The CIM agent (often referred to as CIMOM) is the piece of software that KNM will query for its information, much like an SNMP agent.
What is a CIM agent?
A CIM agent provides a means by which a device can be managed by common building blocks rather than proprietary software. If a device is CIM-compliant, software that is also CIM-compliant can manage the device.
How do I start my own CIM server?
- Log in as root or Administrator.
- Enter the following at the command prompt: smis cimserver restart.
How do I enable CIM on ESXi?
To enable or disable the CIM agent on an ESXi 6.x and ESXi 7.0 host using the vSphere Client
- Login the the vSphere Client.
- Select the ESXi Host.
- Click on Configure — Services.
- Click on “Cim Server” as per the screenshot below.
- Click on Stop and then click on “ok” in the window that pops up – see screen shot below.
What is Slpd service?
The Service Location Protocol (SLP) is a protocol for service discovery. It allows clients to locate servers and other services on the network. This may be the result of a hosts file on the client that has been populated with the IP addresses of the services the client needs.
What is OpenSLP in vmware?
What is OpenSLP? The OpenSLP project is an effort to develop an open-source implementation of the IETF Service Location Protocol suitable for commercial and non-commercial application.
How to enable CIM Server (WBEM service) in ESXi 8
To be able to monitor the underlying hardware of an ESXi server, the most common method is to use the integrated CIM Server. The CIM Server reads the current operational or health status of each hardware element and represents this in the output.
But since ESXi version 6.5 the CIM Server is stopped and disabled by default. This article shows how to correctly enable and start the CIM Server (aka WBEM service) in ESXi 8.
The official documentation lacks information
The official documentation from VMware is Knowledge Base Article #1025757. According to this KB article, it’s enough to start the CIM Server service in the vSphere UI.
However when trying to start the sfcbd-watchdog (CIM Server) service, the status switches back to "Stopped" after a few seconds.

The reason for this is that the service itself is administratively disabled (and unable to be started) by default. This his now shown in the UI though and can only be enabled using the esxcli command, directly on the ESXi server.
Enabling CIM Server on the command line using esxcli
To be able to execute commands directly on the ESXi server(s), we first need to be able to connect to the ESXi server using SSH.
Logged in on the vSphere User Interface (using the browser and the IP address of the ESXi server), click on "Manage" (under the Host entry) in the left-side navigation. On the right side, click on the tab "Services". Scroll down the list of services until you find the "TSM-SSH" service — which is by default stopped.

Select the TSM-SSH service and click on Start above.
Now use your terminal (if you’re on Linux or macOS) or a SSH client, such as PuTTY (if you’re on Windows) to connect to the IP of the ESXi server. Use the "root" user with the known password (same as you’ve used to log in to the UI).
$ ssh 192.168.15.115 -l root
The authenticity of host ‘192.168.15.115 (192.168.15.115)’ can’t be established.
ECDSA key fingerprint is SHA256:FVX5WJiyiTMzXO+2irzSxItA23n9f65jKnZW66V5L9M.
Are you sure you want to continue connecting (yes/no/[fingerprint])? yes
Warning: Permanently added ‘192.168.15.115’ (ECDSA) to the list of known hosts.
Password:
The time and date of this login have been sent to the system logs.
WARNING:
All commands run on the ESXi shell are logged and may be included in
support bundles. Do not provide passwords directly on the command line.
Most tools can prompt for secrets or accept them from standard input.
VMware offers supported, powerful system administration tools. Please
see www.vmware.com/go/sysadmintools for details.
The ESXi Shell can be disabled by an administrative user. See the
vSphere Security documentation for more information.
[root@localhost:
A manual start of the sfcbd-watchdog service confirms the same behaviour as in the UI:
] /etc/init.d/sfcbd-watchdog start
sfcbd-init[134838]: args (‘start’)
sfcbd-init[134838]: Getting Exclusive access, please wait.
sfcbd-init[134838]: Exclusive access granted.
sfcbd-init[134838]: Request to start sfcbd-watchdog, pid 134838
sfcbd-init[134838]: sfcbd not started, administratively disabled.
To definitely enable this service, we first need to enable the "wbem" service using esxcli :
] esxcli system wbem set -e true
To verify the current settings of that service we can show the details:
] esxcli system wbem get
Enabled: true
WS-Management Service: true
Enable HTTPS: true
Authorization Model: password
Port: 5989
HTTP Procs: 2
HTTPS Procs: 4
Provider Procs: 16
Keepalive Timeout: 1
Keepalive Max Requests: 10
Provider Sample Interval: 30
Provider Timeout Interval: 120
HTTP Max Content Length: 1048576
Max Message Length: 40000000
Thread Stack Size: 1048576
Provider Resource Pool Override:
SSL Cipher List: ECDHE+AESGCM:ECDHE+AES
Threadpool Size: 5
Readonly: false
Log Level: warning
Service Location Protocol PID: 0
WS-Management PID: 134939
CIM Object Manager PID: 134967
Enabled SSL Protocols:
Enabled System SSL Protocols: tlsv1.2
Enabled Running SSL Protocols: tlsv1.2
Enabled is now set to true.
Communication with CIM Server
Enabling the "wbem" service should also have auto-started the sfcbd-watchdog service:
] /etc/init.d/sfcbd-watchdog status
sfcbd-init[134989]: args (‘status’)
sfcbd-init[134989]: Getting Exclusive access, please wait.
sfcbd-init[134989]: Exclusive access granted.
sfcbd is running
If the service was not started, you can now either start the service in the vSphere UI or on the command line:

You should now be able to communicate with the CIM server using tcp/5989:
$ telnet 192.168.15.115 5989
Trying 192.168.15.115.
Connected to 192.168.15.115.
Escape character is ‘^]’.
^]
telnet> quit
Connection closed.
This now also allows the check_esxi_hardware monitoring plugin to read the hardware status from the ESXi server.
For security reasons, don’t forget to disable SSH service once the CIM Server was enabled.