How can I get an alert if a VMWare VM on an ESXi host is reverted to a snapshot?

Article ID: 408
Category: Network Services
Applies to: 3.5 and latter
Updated: 2022-10-11

In a production environment it can be important to know if and when a VM is reverted to a snapshot. If the VMWare ESXi host is configured to send Syslog messages to a log host like EventSentry, then it will send a message similar to the one shown below when a VM is reverted to a snapshot:

2019-03-15T16:35:47.071Z vmhost14.networkxyz.local Hostd: [220C4B70 info "Vimsvc.TaskManager" opID=F463AA88-00000183 user=root] Task Completed : haTask-47-vim.VirtualMachine.revertToCurrentSnapshot-100007363 Status success

In order to receive an email alert, first follow KB 399 and specify the following filter both in step 2 and step 3 (content filter):

*Vimsvc.TaskManager*Task Completed*VirtualMachine.revertToCurrentSnapshot*Status success*