Skip to content
English
  • There are no suggestions because the search field is empty.

The OpsLogix VMware Collector explained

What the OpsLogix VMware Collector service is, what it installs, which ports it uses, how it handles credentials, and how to deploy, update and remove it.

Applies to: OpsLogix VMware Management Pack (all versions) · SCOM 2019, 2022, 2025 · vCenter 7.0, 8.0, 9.0
Last updated: October 2026 · Reading time: 7 minutes

The OpsLogix VMware Collector is a Windows service that the VMware Management Pack installs on every management server and gateway server in the resource pool you use for VMware monitoring. The SCOM workflows of the management pack never talk to vCenter themselves. They ask the local collector, and the collector talks to vCenter or ESXi on their behalf. This article explains what the collector is, what it installs, which network connections it makes and how you deploy, update, remove and monitor it. It is written for SCOM administrators, security reviewers and firewall teams.

What the collector does

  • It receives requests from the VMware MP workflows (discoveries, monitors, performance rules and alarm rules) that run on the same server.
  • It logs on to vCenter or ESXi with the account of the connection, collects the requested data and returns it to the workflow.
  • It keeps its vCenter sessions open in memory and reuses them, so each workflow does not have to log on again. It also caches some data in memory, such as the definitions of performance counters.
  • It only returns data for the ESXi hosts that you assigned a license to in the Assign tab of the VMware Configuration Dashboard.
  • It drops vCenter alarms that match the alarm filter file before they reach SCOM (see Files in the install folder below).

Because each pool member runs its own collector, every member of the VMware resource pool needs the collector, and every member must be able to reach vCenter.

The collector at a glance

ItemValue
Program name (Programs and Features)OpsLogix VMware Collector
Service nameOpsLogix.VMware.Collector.Service
Service display nameOpslogix VMware Collector Service
Startup typeAutomatic
Runs asLocal System (the installer does not set a different account)
Install folderC:\Program Files\Opslogix\OpsLogix VMware Collector
Local endpointhttp://localhost:7000 (local use only)
Event logOperations Manager, source OpsLogix VMware Collector
Registry (install information)HKLM\SOFTWARE\Opslogix\OpsLogix VMware Collector (values Path and Version)
RequirementMicrosoft .NET Framework 4.7.2 or later
VersionThe same build number as the VMware Management Pack it ships with

The installer itself only checks for .NET Framework 4.5. The service is built for .NET Framework 4.7.2, so make sure 4.7.2 or 4.8 is installed on every pool member before you deploy.

Network connections

Inbound: the collector listens on http://localhost:7000. This endpoint is for the SCOM workflows on the same server. You do not need to open port 7000 in any firewall, and you should not. Other servers have no reason to connect to it.

Outbound: the collector connects only to the vCenter servers and ESXi hosts that you added as connections. All traffic uses HTTPS. The collector does not connect to OpsLogix or to the internet; license checks are done locally.

DestinationPortUsed for
vSphere Web Services API (SOAP), path /sdkThe port of the connection (443 by default)Logon, inventory and discovery, monitoring data, performance counters, alarms and events
vCenter REST API, path /api (vCenter 7.0 and later) or /rest (older)The port of the connection (443 by default)vSphere tags, and vCenter Server Appliance health and services (Appliance Monitoring MP)
vSAN health service, path /vsanHealth on vCenter or /vsan on a directly added ESXi host443vSAN discovery, health and performance (vSAN MP)

If you added a connection with a non-default port, note that the vSAN endpoints are always contacted on port 443.

Firewall rule summary: allow TCP 443 (or your custom port, plus 443 for vSAN) from every management server and gateway server in the VMware resource pool to each vCenter server or ESXi host you monitor.

How the vCenter credentials are handled

  • You enter the monitoring account in the VMware Configuration Dashboard (or with the PowerShell module). The password is stored in encrypted form as a property of the vCenter connection object in SCOM.
  • When a workflow runs, SCOM hands the connection properties to the workflow. The workflow passes them to the collector on the same server, over the local endpoint.
  • The collector decrypts the password in memory and logs on to vCenter. It keeps the session in memory only.
  • The collector does not write the vCenter credentials to disk. The only files it writes are the license and license assignment files described below.

Use a dedicated monitoring account. It needs at least the Read-only role and the "Validate session" privilege in vCenter.

Files in the install folder

FileWhat it isCan you change it?
license.licYour OpsLogix license key and management group name. Written by the collector when the license is set. Encrypted.No. If it is out of date, see Clear stale licensing information.
whitelist.wlThe license assignment: which ESXi hosts are licensed per connection. Written when you click Update in the Assign tab. Encrypted. It contains host names, not credentials.No. Change the assignment in the Configuration Dashboard.
inventories.invA file from older collector versions. The installer moves it from the old install folder during an upgrade. Current versions do not use it.No.
AlarmFilter\AlarmFilter.csvA list of vCenter alarms that the collector drops before they reach SCOM. Plain text CSV.Yes. See How to change the SCOM alert generation triggered due to a vCenter alert.
appsettings.json and program files (.exe, .dll)Program files of the service.No. Do not edit them.

To change the collector's logging level, use the registry setting described in How do I enable debug logging for the SCOM VMware monitoring, not appsettings.json.

How the collector is deployed

The installer (OpsLogix.VMware.Collector.Service.Installer.exe) is embedded in the OpsLogix IMP - VMware Collector management pack. SCOM copies it to the pool members, and a task installs it. You can start that task in three ways:

  1. Check Connection in the VMware Configuration Dashboard (Administration > OpsLogix MP Configuration > VMware IMP Configuration Dashboard, tab Add/Remove Connections). Before the connection is tested, the collector is deployed to all members of the selected resource pool.
  2. The task OpsLogix Deploy VMware Collector Task. In the Monitoring workspace, open Discovered Inventory, change the target type to Microsoft.SystemCenter.ManagementService, select the servers and run the task from the Tasks pane.
  3. The PowerShell module: Install-VMwareCollector -ResourcepoolName "<pool name>". Use -OpsMgrSDK to point to a management server other than the local one. Add-SCOMVMwareConnection also deploys the collector before it adds the connection.

Check Connection and Install-VMwareCollector stop with an error if any member of the resource pool is unavailable. Make sure all pool members are healthy before you start.

The deployment writes its progress to the Operations Manager event log on each server, with source Health Service Script, event ID 1000. The messages start with [Opslogix Rest API]. The same text appears in the task output.

Updating the collector

The collector is not updated by importing the new management pack alone. After you upgrade the VMware Management Pack:

  1. Wait until the new management packs have been distributed to the pool members.
  2. Open the VMware Configuration Dashboard, select a connection and click Check Connection. Do this once for each resource pool you use. You can also run the deploy task or Install-VMwareCollector.
  3. The deployment compares the installed version with the version in the management pack. If they differ, it uninstalls the old version and installs the new one. If they match, it does nothing.

Your license.lic and whitelist.wl files are kept. As a precaution, keep a copy of AlarmFilter\AlarmFilter.csv before you upgrade if you changed it.

The Collector MP also contains the rule OpsLogix Deploy VMware Collector rule, which runs the same check every hour. It is disabled by default.

If you add a new server to the VMware resource pool, run Check Connection again so the collector is installed on the new member.

Uninstalling the collector

  1. In the Monitoring workspace, open Discovered Inventory and change the target type to OpsLogix VMware Collector Service.
  2. Select the collector on the server you want to clean up.
  3. Run the task OpsLogix Uninstall VMware Collector Task.

You can also remove OpsLogix VMware Collector from Programs and Features on the server. If the server is still a member of the VMware resource pool, the next Check Connection installs the collector again. Remove the server from the pool first; see How to remove a member from the VMware resource pool.

Monitoring the collector

The OpsLogix IMP - VMware Collector management pack monitors the collector itself:

  • The class OpsLogix VMware Collector Service is discovered on every Windows computer where the service OpsLogix.VMware.Collector.Service exists. The discovery runs every hour.
  • The monitor OpsLogix VMware check if the license is still valid runs once a day on each collector. It raises the alert OpsLogix VMware license is not valid when the license check fails.
  • The views State VMware Collector Service and Active Alerts VMware Collector Service are in the VMware Collector folder.

The Collector MP does not include a monitor for the service state. If you want an alert when the service stops, create a Windows Service monitor for OpsLogix.VMware.Collector.Service with the SCOM Windows Service template, targeted at the servers in the VMware resource pool.

See also