BLOG · GUIDE ·

VMware health check: what a review of a vSphere estate with 10 to 60 hosts covers and what you get

Eurokommerz, Vienna, since 2006: Private AI/ML · IT Managed Services · Enterprise Training · AI Hardware & Software

IN BRIEF
  • A VMware health check compares the estate with Broadcom’s documented rules and with its own usage data, then lists each deviation as a finding with evidence, risk, fix and maintenance window
  • For 10 to 60 hosts it covers versions and lifecycle, hardware compatibility, cluster limits, HA and DRS, vSAN health, snapshots, virtual networking, hardening, backup coverage, capacity and licensed cores
  • Broadcom’s KB 319011 gives 4 October 2024 as the end of life of the Skyline Advisor service, whose features are being rolled into VCF Operations and Diagnostics; KB 375104 says Diagnostics works on both VVF and VCF with no licence dependency
  • Diagnostics scans vCenter, ESX, vSAN and NSX properties every four hours and checks the estate against VMware Security Advisories; vSAN adds its own health service with checks from hardware compatibility to capacity
  • Broadcom’s snapshot guidance in KB 318825 supports 32 snapshots in a chain, advises 2 to 3 for performance and no single snapshot older than 72 hours, and says snapshots are not backups

Eurokommerz × Vixen.UNO: VMware Optimisation  Talk to an expert →

What a VMware health check covers

A VMware health check, also called a vSphere health check or VMware assessment, compares the estate with the rules Broadcom documents for it and with the estate’s own usage data, then lists every deviation as a finding ranked by risk. For 10 to 60 hosts, the review covers versions and lifecycle dates, hardware compatibility, cluster limits, HA and DRS settings, vSAN health, storage and snapshots, virtual networking as it affects VMs, security hardening, backup coverage, capacity and the licensed core count. Each finding should name the rule it breaks, the evidence, the risk, the fix and the maintenance window in which the fix can run.

The rules come from Broadcom’s own documents: the Configuration Maximums tool, the Broadcom Compatibility Guide, the vSphere Security Configuration Guide, the vSAN health checks, knowledge base articles such as KB 318825 on snapshots, and the product lifecycle dates. Diagnostics in VCF Operations automates part of the comparison. The rest is reading configuration and performance data that vCenter already holds, and asking the team why a setting is the way it is.

VMware health check checklist: areas and rules

AREAWHAT IS CHECKEDSOURCE OF THE RULE
Versions and lifecycleESXi, vCenter and vSAN builds, end of general supportBroadcom product lifecycle, security advisories
Hardware compatibilityservers, I/O devices, drivers and firmware for the ESXi releaseBroadcom Compatibility Guide
Cluster limitshosts, VMs and objects against tested limitsConfiguration Maximums tool
HA and DRSadmission control policy, reserved failover capacity, DRS rulesvSphere Availability documentation
vSANhealth service results by categoryvSAN health checks, KB 326438
Snapshots and datastoressnapshot count and age, free spaceKB 318825
Virtual networkingVLAN, MTU and teaming against the physical switch portsdistributed switch health check, KB 321305
Security hardeninghost, vCenter and VM settings against the baselinevSphere Security Configuration Guide
Backup coverageevery VM in a job, retention, restore testsyour backup policy
Capacity and licencesdemand against usable capacity, licensed coresVCF Operations, KB 313548

Broadcom TechDocs, vSphere 8.0 (16 September 2026); Broadcom KB 318825, 326438, 321305, 313548 and 375104; configmax.broadcom.com; compatibilityguide.broadcom.com.

In a post addressed to SAP customers on its VCF blog of 1 August 2025, Broadcom states that “General Support for VMware vSphere 7 ends on October 2, 2025.” The same post says vSphere 8 “will be supported until October 2027”, with an optional two-year Extended Support period for purchase. A host still on 7.0 turns the upgrade path into the first line of the plan, and the exact end date for 8.0 is discussed in our guide to vSphere 8 end of general support.

The Configuration Maximums tool states that it provides “the recommended configuration limits for VMware products” and that its limits “are tested, recommended limits, and are fully supported by VMware.” A health check compares host, VM and object counts per cluster with the limits for the release the estate runs and for the release it is moving to.

Data sources: vCenter, VCF Operations and Diagnostics

Broadcom’s Skyline FAQ (KB 319011) states that “The VMware Skyline Advisor service will be reaching end of life on October 4th, 2024” and that its features “are being rolled into VMware Cloud Foundation (VCF) under VCF Operations and Diagnostics.” The same KB says Skyline Health Diagnostics “will continue to be available until further notice.”

Diagnostics for VMware Cloud Foundation runs inside VCF Operations. According to Broadcom’s KB 375104, findings in Aria Operations 8.18 and 9.0 are computed by rules and by scans of collected logs. Checks against property-based signatures run every four hours across vCenter, ESX, NSX, SDDC Manager, VCF Operations, vSAN and VCF Automation. The KB states that Diagnostics validates whether the environment is affected by important VMware Security Advisories, and that “There is no license dependency. This works on both VVF and VCF.” It also says that “VCF Health is only available to VCF customers.” An estate on another vSphere edition should confirm that its subscription includes VCF Operations. The evaluation needs no internet connection, while opening the referenced KBs does. Broadcom’s VCF blog of 28 May 2026 adds that estates on vSphere 8.x and NSX 4.x can install or upgrade to VCF Operations 9.x and that their findings still work.

vCenter supplies the inventory, cluster settings, alarms and performance history. Its default collection intervals keep 5-minute samples for one day, 30-minute samples for a week and 2-hour samples for a month (vSphere 8.0 documentation, 16 September 2026). Usage findings need at least 30 days at 5-minute resolution, kept in VCF Operations or an external collector, as our guide to waste in a vSphere estate explains; a capacity forecast needs 90 days.

The licence data comes from Broadcom’s core count script in KB 313548, a PowerCLI module (PowerCLI 13.3 or later) that connects to vCenter and reports the core licences and vSAN TiB the hosts need.

vSAN health, snapshots and storage

vSAN has its own health service in the vSphere Client. Broadcom’s KB 326438, the index of vSAN health check articles, lists the categories, among them Capacity Utilization, Cluster, Data, Hardware Compatibility, Network, Online Health, Performance Service, Physical Disk, Stretched Cluster and vSAN Build Recommendation. A review records the result of every check for every vSAN cluster, explains each warning that has been silenced, and follows a Hardware Compatibility warning back to the Compatibility Guide row in the table above.

Broadcom’s KB 318825 states that “A maximum of 32 snapshots are supported in a chain. However, for better performance, use only 2 to 3 snapshots.” It also says “Do not retain a single snapshot for more than 72 hours” and “Do not use VMware snapshots as backups.” The health check lists each snapshot with its age, size and datastore, and checks free space on the datastores that hold long chains.

Cluster, HA, DRS and virtual networking

Broadcom’s vSphere Availability documentation states that “vSphere HA uses admission control to ensure that sufficient resources are reserved for virtual machine recovery when a host fails”, and offers three policies: cluster resource percentage, slot policy and dedicated failover hosts. With admission control turned off, the same page says, “you have no assurance that the expected number of virtual machines can be restarted after a failure”, and it advises: “Do not permanently deactivate admission control.” The check reads the policy of each cluster and compares the reserved capacity with the host count today, since hosts may have been added or removed after the policy was set.

DRS rules, manual automation levels and VM overrides are read against the reasons they were set; a rule whose owner has left the company is a finding of its own. Per-VM contention is read as CPU ready per vCPU, with the thresholds our CPU ready guide takes from Broadcom’s KB 438023.

Networking is reviewed as it affects VMs, vMotion and vSAN. Broadcom’s KB 321305 describes the distributed switch health check, which compares VLAN settings with the trunk ports, MTU per VLAN with the physical access switch ports, and the teaming policy with the EtherChannel setting, at a default interval of one minute. The same KB warns that the check generates MAC addresses on the physical switches, with a risk that the switches run out of memory and lose network connectivity. KB 315270, written for false VLAN and MTU alarms on a switch with IP hash teaming, advises disabling the check after confirming that the load balancing policy is set correctly. Given both KBs, turn the check on for the review and off afterwards.

Security hardening and backup coverage

The hardening section compares host, vCenter and VM settings with Broadcom’s vSphere Security Configuration Guide, last updated on 16 September 2026. Each control carries a “Baseline Suggested Value” and PowerCLI commands for assessment and remediation, which makes the comparison scriptable. Broadcom also states that “The security controls do not map directly to regulatory guidelines or frameworks” and that they “are not intended for use as a security checklist”, so a health check reports deviations and their reasons, not a compliance status. Lockdown mode, SSH and execInstalledOnly are covered in our ESXi ransomware hardening guide.

Backup coverage is checked from the backup side. Every production VM should appear in a job with the retention its owner expects, the vCenter appliance and its configuration should be in scope, and the report should show when a restore of each critical system was last tested. Snapshots found in the previous section do not count as coverage, per KB 318825.

Capacity and licensed cores

Capacity is read as demand against usable capacity per cluster, as VCF Operations calculates it: its VCF 9.1 documentation, updated on 8 October 2026, defines usable capacity as the total capacity minus the resources that vSphere HA admission control reserves for failover. Oversized VMs, idle VMs and stale headroom belong to the right-sizing work in our guide to waste, and the three-year forecast to our guide to vSphere capacity planning.

Licence use is checked against the subscription. Broadcom’s KB 313548 states that “You must license a minimum of 16 physical cores for each CPU (physical processor)” and that core licensing “is based on the total number of physical CPU cores across all ESXi hosts you intend to license.” The health check compares the script output with the cores in the current subscription and the renewal quote, and flags hosts with fewer than 16 cores per CPU, since each still counts as 16. Running the script and reading its output is explained in our guide to the Broadcom core count script.

What a VMware health check report should contain

A useful health check report gives each finding the rule it breaks, the evidence, the risk if it stays, the fix and the window in which the fix can run, and sorts the findings so that the first maintenance window removes the largest risk. The example below is illustrative and not taken from a client; it shows the format for a hypothetical estate of 36 hosts in three clusters, one of them on vSAN.

FINDINGEVIDENCERISKFIXWINDOW
Snapshots past 72 hours14 VMs, oldest 9 monthsdatastore runs out of spaceconsolidate after free-space checklow-load hours
HA admission control offcluster settings exportrestarts not assured after a host failurecluster resource percentage for one hostagreed window
vSAN compatibility warningvSAN health resultdriver and firmware outside the guidealign with the Compatibility Guidehost by host
Security advisory findingDiagnostics finding with KBknown vulnerability openpatch vCenter, then hostsagreed window, rollback plan
12-core CPUs in 4 hostsKB 313548 output16 cores per CPU counted, 12 presentreplace at host refreshrenewal plan

Illustrative example with hypothetical values, not a client case; rules from Broadcom KB 318825, vSphere Availability documentation, KB 326438, KB 375104 and KB 313548.

Under VMware optimisation, our engineering partner Vixen.UNO reviews versions, subscriptions, resource usage and the risk profile of the estate and delivers an action plan with dates. Tell us how many hosts and clusters you run, and on which versions.

How a VMware health check runs

  1. Fix the scope in writing: vCenter instances, clusters, the areas from the table above and the questions management wants answered.
  2. Collect the data: vCenter inventory and cluster settings, Diagnostics findings, vSAN health results, KB 313548 output, 30 days of 5-minute performance data and the backup job report.
  3. Interview the team on why rules, exceptions and silenced alarms exist, since many findings have a reason that no export shows.
  4. Compare each area with its rule from the checklist table above and rank the findings by risk.
  5. Turn the findings into a plan, with each fix assigned to a maintenance window and a rollback step, and dated against lifecycle and renewal dates.
  6. Present the results to IT management and agree which findings are accepted risks.

Our infrastructure audit works from the documentation and exports you provide and from interviews with your team, without access to your production systems, and ends with a prioritised risk map and a roadmap. Describe your estate and the areas you want reviewed.

What we do

Eurokommerz holds the contract and supplies hardware and licences, with engineering by our partner Vixen.UNO. Under VMware optimisation, the Vixen.UNO team audits versions, subscriptions, actual resource usage and the risk profile of the estate, matches editions to your workloads and delivers an action plan ahead of renewal and end of support, with dates; if there is nothing to optimise, we say so. Fixes and upgrades run in agreed maintenance windows, step by step, with a rollback plan at every stage, and support under an agreed SLA can follow. Our infrastructure audit covers compute and virtualisation, storage and backup, networks, security and access, and licences from the documentation and exports you provide. The first call is free of charge; the price of the technical assessment is fixed before work begins.

FAQ

What is a VMware health check?
A VMware health check is a review of a vSphere estate against Broadcom’s documented rules, such as configuration maximums, hardware compatibility, the Security Configuration Guide and snapshot guidance, and against the estate’s own usage data. The result is a list of findings, each with evidence, risk, fix and the maintenance window for the fix.
What is on a vSphere health check checklist?
For 10 to 60 hosts it covers versions and lifecycle dates, hardware compatibility, cluster limits, HA admission control and DRS rules, vSAN health, snapshots and datastore space, virtual networking, security hardening, backup coverage, capacity and the licensed core count. Each area is compared with the Broadcom document that sets its rule.
What replaced VMware Skyline for health checks?
Broadcom’s KB 319011 gives 4 October 2024 as the end of life of the Skyline Advisor service and states that its features are being rolled into VCF Operations and Diagnostics. Broadcom’s KB 375104 says Diagnostics has no licence dependency and works on both VVF and VCF, while VCF Health is only available to VCF customers. Skyline Health Diagnostics remains available until further notice, according to KB 319011.
How do I check vSAN health?
Open the vSAN health service for the cluster in the vSphere Client and review every check, including silenced ones. Broadcom’s KB 326438 indexes the checks by category, among them Hardware Compatibility, Network, Physical Disk, Data, Capacity Utilization and vSAN Build Recommendation, each with its own KB.
Does a VMware assessment need access to production systems?
Much of a health check works from exports such as vCenter inventory, cluster settings, vSAN health results, Diagnostics findings and the core count script output. Live checks such as the distributed switch health check need someone with access to turn them on for the review and off afterwards.
How often should a VMware health check be done?
Diagnostics in VCF Operations re-runs its property-based checks every four hours, so routine findings can be watched between reviews. A full review with interviews and a plan fits before a subscription renewal, before a major upgrade and after large changes such as new clusters or a host refresh.

Send us your host and cluster count, your vCenter, ESXi and vSAN versions, your renewal date and the areas that concern you most. We reply within one business day, and in the first call, which is free of charge, we work through your estate and you leave with 2 or 3 possible scenarios.

Talk to an expert
Talk to an expert

We reply within one business day

By sending this form you agree that we process your details to answer your enquiry; see our privacy policy.

request@eurokommerz.at
Jordangasse 7, 1010 Vienna