"Host IPMI system event log status" alarm in vCenter Server
search cancel

"Host IPMI system event log status" alarm in vCenter Server

book

Article ID: 316579

calendar_today

Updated On:

Products

VMware vSphere ESXi

Issue/Introduction

When host IPMI system event log status alarm is triggered repeatedly in the Hardware Status tab in vCenter Server 4.x, 5.x or 6.x, clear the IPMI System Event log file located at /var/log/ipmi.

Symptoms:
  • The Host Intelligent Platform Management Interface (IPMI) System Event Log (SEL) status alarm is triggered repeatedly on the ESXi/ESX host.
  • Acknowledging the alarm removes the exclamation on the ESXi/ESX host in the Inventory.
Note: For additional symptoms and log entries, see Additional Information section.


Environment

VMware vSphere 6.5.x
VMware vSphere ESXi 5.1
VMware vSphere ESXi 6.0
VMware vSphere 5.5.x
VMware vSphere ESXi 6.7

Cause

This issue occurs when the IPMI System Event log file is full, which triggers the alarm that monitors the log file.

Resolution

To resolve this issue, ensure that the NTP settings are correct on the ESXi host, clear the IPMI System Event log file, and reset the sensors.
 
To clear the IPMI System Event log file and reset the sensors:
  1. Open vCenter Server using the vSphere Client.
  2. In the vCenter Server Inventory, select the ESXi/ESX host.
  3. Click the Hardware Status tab.
  4. Click System Event log under View.
  5. Click Reset Event Log. The red alert is removed from the System Event log.
  6. Click Reset Sensors to reset the host sensors.
Starting with ESXi 5.5 P01 and later, you can use the localcli command line to clear the IPMI SEL logs.

To clear the IPMI SEL logs in ESXi 5.1 and later:
  1. Connect to the ESXi host through SSH.
  2. Run this command:

    localcli hardware ipmi sel clear

Alternatively, you can consider Restart the management agents as well. 

Note: If the sfcbd-watchdog service is stopped, use the two below commands to start the service:
esxcli system wbem set --enable true
 
/etc/init.d/sfcbd-watchdog restart


Additional Information

To determine why the log has filled up, investigate the hardware.
 
You experience these additional symptoms:
 
  • In the /var/log/vmkernel.log file, you see entries similar to:

    sfcb-vmware_raw[5153]: IpmiIfcSelReadAll: failed call to IpmiIfcSelReadEntry cc = 0xff
    sfcb-vmware_raw[5153]: IpmiIfcSelReadAll: failed call to IpmiIfcSelReadEntry cc = 0xff
    snmpd[19956]: Connection from UDP: [10.16.16.65]:61945
    sfcb-vmware_raw[5153]: IpmiIfcSelReadAll: failed call to IpmiIfcSelReadEntry cc = 0xff
    /usr/lib/vmware/bin/vmware-hostd[19577]: Accepted password for user root from 10.16.16.65
    sfcb-vmware_raw[5153]: IpmiIfcSelReadAll: failed call to IpmiIfcSelReadEntry cc = 0xff
    sfcb-vmware_raw[5153]: IpmiIfcSelReadAll: failed call to IpmiIfcSelReadEntry cc = 0xff
    snmpd[19956]: Connection from UDP: [10.16.16.65]:61945
    sfcb-vmware_raw[5153]: IpmiIfcSelReadAll: failed call to IpmiIfcSelReadEntry cc = 0xff
    sfcb-vmware_raw[5153]: IpmiIfcSelReadAll: failed call to IpmiIfcSelReadEntry cc = 0xff
Note :If you are experiencing Warnings in the Hardware Status tab of an ESXi host fail to clear  refer https://kb.vmware.com/s/article/2061093

Restarting the Management agents in ESXi
Using Tech Support Mode in ESXi 4.1, ESXi 5.x, and ESXi 6.x
Location of vCenter Server log files
Timekeeping best practices for Windows, including NTP
vCenter Server 中出现 “主机 IPMI 系统事件日志状态 (Host IPMI system event log status)” 警报
vCenter Server の「ホスト IPMI のシステム イベント ログの状態」アラーム
Alarma "Host IPMI system event log status" en vCenter Server
O alarme "Status do log de eventos do sistema do IPMI do host" no vCenter Server
Der Ereignisprotokoll-Statusalarm für das Host-IPMI-System wird in VMware vCenter Server 4.x und 5.x wiederholt ausgelöst
Der Ereignisprotokoll-Statusalarm für das Host-IPMI-System wird in VMware vCenter Server 4.x und 5.x wiederholt ausgelöst