Skip to content
English
  • There are no suggestions because the search field is empty.

VM snapshot monitoring

How the VMware MP discovers VM snapshots, alerts on snapshot age and active snapshot count, and how to tune or exclude them.

Applies to: OpsLogix VMware Management Pack (all versions) · SCOM 2019, 2022, 2025 · vCenter 7.0, 8.0, 9.0
Last updated: October 2026 · Reading time: 5 minutes

Old snapshots and long snapshot chains slow down virtual machines and take a long time to consolidate. The VMware Management Pack discovers VM snapshots and alerts you when they get too old or when a VM runs on too many of them. This article explains the default behavior and how to tune it.

Snapshot discovery

The VMware Virtual Machine snapshot discovery creates a VMware Virtual Machine Snapshot object for each snapshot. Each object is hosted by its virtual machine.

PropertyDescription
Snapshot nameThe name of the snapshot in vCenter. This is also the display name.
DescriptionThe snapshot description in vCenter.
Create timeWhen the snapshot was taken.
StateThe power state of the VM when the snapshot was taken, for example poweredOn or poweredOff.

The discovery is enabled by default and runs every 23,000 seconds (about 6.4 hours). A new snapshot can take up to one discovery cycle to appear in SCOM.

The discovery finds the first-level snapshots of each VM, that is, the start of each snapshot chain. Child snapshots in a chain don't get their own object. A child is always newer than the snapshot it's based on, so the age check on the first-level snapshot already covers the oldest snapshot in the chain.

You find the snapshots in the Monitoring workspace, in the VMware folder under VirtualMachines > Virtual Machine Snapshots.

Snapshot age check

The Virtual Machine Snapshot age check. monitor targets each snapshot object. It calculates the age of the snapshot in hours every 5 minutes.

Snapshot ageState
24 hours or lessHealthy
More than 24 and less than 48 hoursWarning
48 hours or moreCritical

The monitor is enabled by default. It raises an alert on Warning and Critical, with a severity that matches the state. The alert shows the snapshot name and the current age in hours. It closes on its own when the snapshot is removed or the state is Healthy again.

Virtual Machine Active SnapShot Count

The Virtual Machine Active SnapShot Count monitor targets each virtual machine. It counts the snapshots in the chain that the VM is running on, up to and including the current snapshot. A VM that isn't running on a snapshot reports 0.

Active snapshot countState
0Healthy
1 or 2Warning
3 or moreCritical

The monitor is enabled by default and runs every 5 minutes. It raises an alert on Warning and Critical, with a severity that matches the state, and closes the alert automatically. The alert shows the VM name and the current count.

With the defaults, a VM with one snapshot already shows Warning. If short-lived snapshots are normal in your environment, raise the Healthy threshold. See the next section.

Both monitors roll up to the Configuration health of the object, not to Availability.

Override parameters

Both monitors use the same parameter names.

ParameterSnapshot age checkActive SnapShot Count
HealthyValueHighest age in hours that is still Healthy. Default 24.Highest count that is still Healthy. Default 0.
CriticalValueAge in hours from which the state is Critical. Default 48.Count from which the state is Critical. Default 3.
IntervalSecondsHow often the monitor runs. Default 300.How often the monitor runs. Default 300.

Values between HealthyValue and CriticalValue give a Warning. Keep HealthyValue lower than CriticalValue.

Example: to warn after 3 days and go Critical after 7 days, set HealthyValue to 72 and CriticalValue to 168 on the age check.

How to change a threshold

  1. In the Operations console, go to Authoring > Management Pack Objects > Monitors.
  2. Search for Virtual Machine Snapshot age check or Virtual Machine Active SnapShot Count.
  3. Right-click the monitor and select Overrides > Override the Monitor.
  4. Select For all objects of class to change it everywhere. Select For a group to change it for a group of VMs only.
  5. Select Override next to HealthyValue and/or CriticalValue, and enter the new value.
  6. Select an unsealed management pack to store the override, or create a new one.
  7. Click OK. The new thresholds apply at the next monitor run.

To turn a monitor off, override Enabled to False in the same dialog.

Exclude snapshots from discovery

Some snapshots are expected, for example snapshots that a backup product creates and removes. You can keep them out of SCOM with an override on the snapshot discovery. The filter matches the snapshot name.

ParameterDefaultMeaning
IncludePropertyValue(.*)Regular expression. Only snapshots whose name matches are discovered.
ExcludePropertyValue^()$Regular expression. Snapshots whose name matches are not discovered.
  1. Go to Authoring > Management Pack Objects > Object Discoveries.
  2. Search for VMware Virtual Machine snapshot discovery.
  3. Right-click it and select Overrides > Override the Object Discovery > For all objects of class: VMware Virtual Machine (or for a group).
  4. Override ExcludePropertyValue with a regular expression for the names to skip. For example, ^(Backup-.*|Temp-.*)$ skips all snapshots whose name starts with "Backup-" or "Temp-".
  5. Save the override in an unsealed management pack.

Excluded snapshots disappear from SCOM after the next discovery cycle, and the age check no longer runs for them. The Active SnapShot Count monitor reads the snapshot chain from the VM itself, so it still counts excluded snapshots.

For more filter options, see How to exclude VMware components from monitoring.

See also