WilliamLam.com

  • About
    • About
    • Privacy
  • VMware Cloud Foundation
  • VKS
  • Homelab
    • Resources
    • Nested Virtualization
  • VMware Nostalgia
  • Apple
You are here: Home / Required vSphere Privilege for Read-Only RESXTOP View

Required vSphere Privilege for Read-Only RESXTOP View

06.25.2013 by William Lam // 1 Comment

Yesterday I received a question about the specific vSphere privilege that is required to view RESXTOP data on an ESXi host. The reason for this request was to create a restricted role for a group of users who only needed to have access to RESXTOP performance data. I did not know the answer off the top of my head, but it was a pretty easy to narrow down the specific privilege with a quick test in my lab.

Through the process of elimination, it turns out you just need the Global.Service managers privilege to view only RESXTOP data. It may not seem intuitive, but the Service Manager is responsible for providing vSphere API access to both RESXTOP as well as vScsiStats interfaces which I have written about here.

In my lab, I created a new role called resxtop and then associated the role with the user(s) within the vSphere inventory. You can centrally manage this using vCenter Server or you can do this directly on an ESXi host, but you will need to ensure the role is create on each and every single ESXi host along with it's user association.

More from my site

  • Retrieving ESXTOP Performance Data Using the vSphere 5.1 API
  • Exploring the new vSphere Privilege Recorder in vSphere 8.0 Update 1
  • ESXTOP and VMware Cloud on AWS
  • Using the vSphere API in vCenter Server to collect ESXTOP & vscsiStats metrics
  • How to Run VMware's New Fling VisualEsxtop on Mac OS X

Categories // Uncategorized Tags // esxtop, permission, privilege, resxtop, service manager

Trackbacks

  1. ESXTOP access with read-only account - Provirtualzone says:
    03/15/2017 at 12:44 pm

    […] found a good article from William Lam regarding this esxtop and user […]

    Reply

Leave a Reply to ESXTOP access with read-only account - ProvirtualzoneCancel reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Search

Thank Author

Author

William is Distinguished Platform Engineering Architect in the VMware Cloud Foundation (VCF) Division at Broadcom. His primary focus is helping customers and partners build, run and operate a modern Private Cloud using the VMware Cloud Foundation (VCF) platform.

Connect

  • Bluesky
  • Email
  • GitHub
  • LinkedIn
  • Mastodon
  • Reddit
  • RSS
  • Twitter
  • Vimeo

Recent

  • Programmatically accessing the Broadcom Compatibility Guide (BCG) 05/06/2025
  • Quick Tip - Validating Broadcom Download Token  05/01/2025
  • Supported chipsets for the USB Network Native Driver for ESXi Fling 04/23/2025
  • vCenter Identity Federation with Authelia 04/16/2025
  • vCenter Server Identity Federation with Kanidm 04/10/2025

Advertisment

Privacy & Cookies: This site uses cookies. By continuing to use this website, you agree to their use.
To find out more, including how to control cookies, see here: Cookie Policy

Copyright WilliamLam.com © 2025