Applications Systems

Prevent VMAN From Displaying a vCenter Appliance as a Guest Virtual Machine

When VMAN monitors a vCenter Server Appliance that is hosted on a virtual machine, it may also display that appliance as a guest virtual machine. This is caused by the VMAN VMware credential having access to the VM hosting vCenter. To prevent the duplicate guest display, assign the No access role to the VMAN monitoring account or group on the vCenter appliance VM in the vSphere Client, enable propagation, and allow VMAN to complete a polling cycle.

First published date

8/30/2026 2:45 AM

Last published date

8/30/2026 2:45 AM

Overview

When a VMware vCenter Server Appliance is hosted as a virtual machine, VMAN may identify and display it both as:

  • A monitored vCenter server

  • A guest virtual machine under the vCenter’s virtualization hierarchy

This occurs when VMAN polls the vCenter and can also access the virtual machine hosting that vCenter. In some environments, the behavior may also affect AppStack by displaying the vCenter’s parent entities instead of the environment managed beneath it.

Environment

This issue may occur in:

  • SolarWinds Virtualization Manager (VMAN)

  • SolarWinds Platform deployments using VMAN

  • VMware vCenter Server Appliance environments

  • Nested or cross-vCenter environments where one vCenter is hosted on a VM managed by another vCenter

Symptoms

You may observe one or more of the following symptoms:

  • The vCenter appliance appears as a guest virtual machine in VMAN.

  • The same system appears as both a vCenter and a VM.

  • VMAN or AppStack displays the vCenter’s parent host or cluster instead of the environment beneath the vCenter.

  • The vCenter is added successfully, but the virtualization hierarchy is displayed incorrectly.

  • The vCenter appliance consumes an additional VM or node resource in the SolarWinds Platform.

Product section

Virtualization Manager

Cause

VMAN uses the VMware API to collect inventory and performance data. If the VMAN credential has permission to access the virtual machine hosting vCenter, VMAN can discover that appliance as a guest VM. This creates a conflict because VMAN is simultaneously monitoring the vCenter as a virtualization-management endpoint and the appliance as a child VM.

Resolution

Modify the VMware permissions for the account or group used by VMAN so that it cannot access the virtual machine hosting the vCenter appliance.

Assign the No access role to that account or group on the vCenter appliance VM.

Prerequisites

Before proceeding:

  1. Identify the exact VMAN VMware credential used to monitor the vCenter.

  2. Identify the virtual machine hosting the vCenter Server Appliance.

  3. Confirm that the change will not affect other monitoring or administration tools using the same VMware account.

  4. If the account is shared, coordinate the change with the VMware administrator.

Important: Assigning No access removes the selected account’s ability to view or manage the vCenter appliance VM. Use a dedicated read-only monitoring account whenever possible.

Procedure

  1. Log in to the VMware vSphere Client.

  2. Locate and select the virtual machine hosting the vCenter Server Appliance.

  3. Open the Permissions tab.

  4. Locate the user or group used by VMAN to monitor the vCenter.

  5. Modify the access rule for that user or group.

  6. Set the role to No access.

  7. Select Propagate, if available.

  8. Click OK to save the permission change.

  9. Allow VMAN to complete a polling cycle.

  10. Confirm that the vCenter remains monitored as a vCenter and is no longer displayed as a guest VM.

The recommended workaround is to apply the No access role to the vCenter appliance VM for the VMAN monitoring account and propagate the permission.

Validation

After the next polling cycle, verify the following:

  • The vCenter status is healthy.

  • Datacenters, clusters, ESXi hosts, datastores, and guest VMs under the vCenter are visible.

  • The vCenter appliance is not listed as a guest VM.

  • AppStack displays the expected vCenter hierarchy.

  • No duplicate vCenter or VM objects are present.

VMAN normally monitors the virtualization hierarchy from the vCenter through datacenters, clusters, ESXi hosts, and individual virtual machines.

If the vCenter Is No Longer Polling Correctly

If the vCenter disappears or shows an unknown status after changing permissions:

  1. Verify that the No access permission was applied only to the vCenter appliance VM.

  2. Confirm that the VMAN account still has the required read permissions on the vCenter inventory, hosts, and VMs that must be monitored.

  3. Test access to the vCenter MOB using the same credential:

     https://<vcenter-hostname-or-ip>/mob
  4. Confirm that the credential can navigate to the datacenters and ESXi hosts.

  5. Check the VMAN polling method and confirm that the vCenter is configured for VMAN polling.

  6. Wait approximately 5–10 minutes for polling data to refresh.

  7. If necessary, restart the Orion Module Engine, Collector Service, and Job Engine services during an approved maintenance window.

The VMAN credential requires appropriate permissions for the objects and metrics being monitored. At minimum, VMware data collection generally requires read-only access to the hosts and VMs that VMAN must monitor.

If the Guest Entry Remains

If the vCenter appliance continues to appear as a guest after the permission change:

  1. Go to Settings > All Settings > Virtualization Settings.

  2. Review the VMware configuration and identify duplicate or stale objects.

  3. Go to Settings > Manage Nodes.

  4. Search for the vCenter appliance VM.

  5. Delete only the incorrect duplicate node, if present.

  6. Allow VMAN to complete another polling cycle.

Do not manually modify VMAN database tables unless directed by SolarWinds Support and after creating a verified database backup. Duplicate or stale virtualization objects may require additional investigation.

Alternative Considerations

If the VMAN credential is used for several monitoring functions, create a dedicated VMware monitoring account instead of changing permissions on a shared administrative account. Assign the account read-only permissions for the required vCenter inventory and No access specifically to the vCenter appliance VM.

VMAN automatically adds the child ESXi hosts when a vCenter is added for monitoring, so ensure the monitoring account retains access to those hosts and the virtual objects that should remain visible.