Managed Object Browser Guide: Essential ESXi and vCenter Management via VIM API
Virtualization administrators navigating the modern software-defined data center require deep visibility into the hypervisor runtime. While user-friendly graphical dashboards provide convenient high-level abstractions, the Managed Object Browser (MOB) serves as the canonical reference manual and diagnostic console for VMware ESXi and vCenter Server.
Whether you are seeking to understand how VMware manages object-oriented state, inspecting raw hardware sensors, diagnosing distributed virtual switch port bindings, modifying hidden advanced configuration parameters, or tuning vSAN and storage DRS clusters, this Managed Object Browser Guide provides the definitive, comprehensive walkthrough.
In this guide, we explore the core principles of the vSphere Web Services API (VIM API), guide you through complete inventory hierarchy traversal, detail essential property inspectors, explain how to invoke methods safely, examine storage DRS integration, and review developer utilities that streamline configuration analysis.
Architectural Overview: How the Managed Object Browser Works
The Managed Object Browser is a server-side web interface integrated directly into the hostd daemon on ESXi hypervisors and the vpxd service on vCenter Server. It provides an authenticated, HTML-based representation of the in-memory object graph managed by the hypervisor kernel:
+---------------------------------------------------------------------------------+
| ServiceInstance |
+---------------------------------------------------------------------------------+
|
v
+---------------------------------------------------------------------------------+
| ServiceContent |
+---------------------------------------------------------------------------------+
| | | |
v v v v
+--------------+ +--------------+ +--------------+ +--------------+
| rootFolder | | OptionManager| | CustomFields | | LicenseMgr |
| (group-d1) | | (Settings) | | (Attributes) | | (Entitlement)|
+--------------+ +--------------+ +--------------+ +--------------+Key Subsystems Exposed by the Managed Object Browser:
- Inventory Tree (
rootFolder): The structural hierarchy organizing Datacenters, Clusters, Resource Pools, Hosts, and Virtual Machines. - Configuration Settings (
OptionManager): Global advanced options governing hypervisor behavior, DRS thresholds, and logging verbosity. - Storage Topology (
Datastore&StorageResourceManager): Physical LUNs, VMFS volumes, vSAN datastores, and NFS mount paths. - Network Topology (
Network&DistributedVirtualSwitch): Port groups, VLAN tags, teaming policies, and distributed virtual filters.
When formatting configuration files or inspecting API response payloads, our JSON Formatter and XML Formatter allow developers to format and analyze complex nested data structures seamlessly.
Essential MoRef Hierarchy Navigation: From Root to Leaf
To effectively explore the MOB, an administrator must understand how to traverse parent-child relationships across the inventory:
ServiceInstance (Root)
└── content (ServiceContent)
└── rootFolder (group-d1 / Datacenters)
└── childEntity (datacenter-2)
├── hostFolder (group-h4)
│ └── childEntity -> ComputeResource / HostSystem (host-10)
│ ├── hardware (HostHardwareInfo: CPU, Memory, BIOS)
│ ├── runtime (HostRuntimeInfo: Health, State)
│ └── config (HostConfigInfo: Storage, Network)
├── vmFolder (group-v3)
│ └── childEntity -> VirtualMachine (vm-102)
│ ├── config (VirtualMachineConfigInfo)
│ ├── runtime (VirtualMachineRuntimeInfo)
│ └── summary (VirtualMachineSummary)
├── datastoreFolder (group-s5)
│ └── childEntity -> Datastore (datastore-11)
└── networkFolder (group-n6)
└── childEntity -> DistributedVirtualSwitch (dvs-22)1. Inspecting Host Hardware Details (HostHardwareInfo)
When diagnosing hardware compatibility or firmware discrepancies, navigate to https://<esxi-or-vcenter-fqdn>/mob/?moid=host-10 and click on hardware:
cpuInfo: Exact CPU model, clock speed, socket count, and thread distribution.systemInfo: Server vendor, model name (e.g.,PowerEdge R750orProLiant DL380), serial number, and hardware UUID.biosInfo: BIOS firmware release date and version string.
2. Inspecting VM Configuration Options (extraConfig)
Virtual machines often contain low-level VMX parameters that do not appear in the standard UI. To view these:
- Open the target VM view (e.g.,
https://<vcenter-fqdn>/mob/?moid=vm-102). - Click on
config(VirtualMachineConfigInfo). - Scroll to
extraConfig(OptionValue[]array). - Inspect specialized keys such as
isolation.tools.copy.disable,disk.EnableUUID, orsched.mem.pin.
Practical Method Invocations in the Managed Object Browser
Every Managed Object in the MOB provides callable methods located at the bottom of its property view:
+---------------------------------------------------------------------------------+
| Managed Object: VirtualMachine (vm-102) |
+---------------------------------------------------------------------------------+
| Methods: |
| - PowerOnVM_Task(host: HostSystem) |
| - PowerOffVM_Task() |
| - ResetVM_Task() |
| - SuspendVM_Task() |
| - ReconfigVM_Task(spec: VirtualMachineConfigSpec) |
| - CreateSnapshot_Task(name, description, memory, quiesce) |
| - Destroy_Task() |
| - UnregisterVM() |
| - Reload() |
+---------------------------------------------------------------------------------+Example 1: Reloading a Virtual Machine Configuration (Reload)
If you have manually edited a .vmx file on an ESXi datastore via SSH and need the hypervisor to re-read the configuration without unregistering the VM:
- Navigate to the VM object in the MOB (
https://<esxi-ip>/mob/?moid=vm-102). - Scroll to the Methods section.
- Click
Reload. - In the parameter dialog, click Invoke Method.
- The hypervisor reloads the
.vmxconfiguration file into memory immediately.
Example 2: Creating a Snapshot with Custom Parameters
- In the VM view, click
CreateSnapshot_Task. - Fill in the parameters:
name:Pre-Patching-Snapshotdescription:Automated snapshot prior to OS kernel updatememory:false(skips memory dump for faster execution)quiesce:true(quiesces guest filesystem via VMware Tools)
- Click Invoke Method. The task initiates and returns a
TaskMoRef link.
Storage DRS & Datastore Cluster Traversal Internals
Modern enterprise storage utilizes Datastore Clusters managed by Storage DRS (StoragePod MoRefs). Navigating to a StoragePod in the MOB reveals:
podStorageDrsEntry: Dynamic IO metric aggregates and latency profiles.summary.capacityvssummary.freeSpace: Real-time allocation metrics across member datastores.- Method
RecommendDatastores: Evaluates placement recommendation algorithms for thin-provisioned virtual disks.
Advanced Virtual Storage & vVols Storage Container Inspection
Virtual Volumes (vVols) abstract SAN/NAS storage into software-defined containers mapped directly to VMDKs via Protocol Endpoints (PEs). In the MOB, navigating to the VVolDatastore Managed Object exposes:
storageArray: VASA Provider registration endpoint and TLS certificate fingerprints.vvolBinding: Active bindings between Protocol Endpoints and virtual machine disk IDs.- Method
QueryVirtualVolume: Returns storage capability profiles (such as RAID tiering, encryption status, and snapshot deduplication).
DRS Affinity Rules Debugging via ClusterComputeResource
When a critical database VM fails to start with the error Could not find a suitable host according to DRS rules, inspecting the cluster's configurationEx.rule array in the MOB identifies the culprit:
- Navigate to
https://<vcenter-fqdn>/mob/?moid=domain-c15(your compute cluster MoRef). - Click on
configurationEx(ClusterConfigInfoEx). - Scroll to
rule(ClusterRuleInfo[]). - Inspect
ClusterAntiAffinityRuleInfoobjects to locate conflicting VM-to-VM separation policies.
Deep Dive: OptionManager and Kernel Boot Parameters Configuration
The OptionManager Managed Object exposes both standard hypervisor configurations and undocumented kernel parameters (VMkernel.Boot.*).
Key OptionManager Diagnostic Paths:
Mem.ShareForceSalting: Configures inter-VM transparent page sharing (TPS) security boundaries.Disk.QFullSampleSize&Disk.QFullThreshold: Tunes adaptive queue depth throttling for busy SAN LUNs.Net.DVFilterBindIpAddress: Controls third-party network packet inspection firewall filters.
Administrators can invoke the QueryView method on OptionManager by providing a string filter prefix (such as Config.HostAgent) to extract specific property subsets without querying the entire settings table.
Storage Multipathing & PSP / SATP Diagnostics via HostStorageSystem
Storage multipathing issues (such as path thrashing or asymmetric active/optimized latency) can be diagnosed by inspecting the HostStorageSystem Managed Object (storageSystem):
storageDeviceInfo.multipathInfo: Lists all Path Selection Plugins (PSP) such asVMW_PSP_RR(Round Robin) orVMW_PSP_FIXED.storageDeviceInfo.scsiTopology: Maps physical host bus adapters (HBAs), Fibre Channel targets, and LUN IDs.- Method
SetMultipathLunPolicy: Reconfigures storage path selection rules dynamically without requiring an ESXi host reboot.
Virtual Machine Snapshots & Tree Navigation Internals (VirtualMachineSnapshotTree)
Snapshot chains are represented as recursive Data Objects nested within the snapshot property of a VirtualMachine:
currentSnapshot: The activeManagedObjectReference(VirtualMachineSnapshot) representing the delta leaf where guest OS writes currently land.rootSnapshotList: An array ofVirtualMachineSnapshotTreeobjects containingname,description,createTime,state(poweredOn,quiesced), andchildSnapshotList.
When automated backup agents fail to delete temporary consolidation snapshots, inspecting snapshot.rootSnapshotList in the MOB reveals whether hidden CID (Content ID) mismatches or orphaned delta VMDK disks exist in the hierarchy.
Host Diagnostic Log Bundle Generation (DiagnosticManager)
When opening a critical support ticket with VMware / Broadcom engineering, extracting hypervisor log bundles directly via the MOB's DiagnosticManager (diagMgr) avoids CLI timeouts:
- Navigate to
https://<vcenter-fqdn>/mob/?moid=DiagnosticManager. - Inspect
entries: Catalog of available system logs (hostd.log,vmkernel.log,vpxd.log,syslog). - Invoke
GenerateLogBundles_TaskwithincludeDefault = trueto trigger asynchronous archive compilation on the ESXi scratch partition.
ESXi Host Firewall & Service Control via HostFirewallSystem
Administrators troubleshooting blocked syslog, SNMP, or backup agent ports can inspect and modify hypervisor firewall rulesets in real time via the HostFirewallSystem (firewallSystem) Managed Object:
firewallInfo.ruleset: Returns an array ofHostFirewallRulesetobjects containing rule keys (such assyslog,ntpClient,vncServer), enabled status, and permitted IP subnet ranges.- Method
EnableRuleset: Turns specific firewall rulesets on or off immediately. - Method
SetRuleset: Configures IP subnet filtering rules (such as restricting SSH access to management jump hosts).
Developer Scripting: Querying MOB Data via Python pyVmomi
For automated infrastructure audits, Python scripts using the pyVmomi library can mirror MOB navigation programmatically:
#!/usr/bin/env python3
# Script querying ESXi / vCenter MOB hierarchy via pyVmomi
import ssl
from pyVim.connect import SmartConnectNoSSL, Disconnect
from pyVmomi import vim
def query_vcenter_inventory(server, username, password):
context = ssl._create_unverified_context()
si = SmartConnectNoSSL(host=server, user=username, pwd=password, sslContext=context)
try:
content = si.RetrieveContent()
print(f"Connected to: {content.about.fullName}")
for dc in content.rootFolder.childEntity:
print(f"
[Datacenter] {dc.name} (MoRef: {dc._moId})")
host_folder = dc.hostFolder
for cluster_or_host in host_folder.childEntity:
if isinstance(cluster_or_host, vim.ClusterComputeResource):
print(f" [Cluster] {cluster_or_host.name} (MoRef: {cluster_or_host._moId})")
for host in cluster_or_host.host:
print(f" [Host] {host.name:<25} | State: {host.runtime.connectionState}")
finally:
Disconnect(si)
if __name__ == "__main__":
query_vcenter_inventory("vcenter.corp.local", "administrator@vsphere.local", "AdminPassword2026!")Analyzing and diffing script outputs using our Diff Checker or validating HTTP API interactions with the cURL Command Generator ensures robust infrastructure automation.
Operational Comparison: Management Modalities in vSphere
| Feature / Capability | Managed Object Browser (MOB) | vSphere HTML5 Client | PowerCLI / SDK |
| :--- | :--- | :--- | :--- |
| Interface Type | Raw Web / DOM Inspector | Modern Rich Web App | Command-Line / Scripting |
| Execution Directness | Raw Direct VIM API Call | Abstracted UI Layer | Programmatic VIM / REST |
| Object Visibility | 100% (Includes hidden keys) | Standard filtered inventory | 100% (Programmatic) |
| Safety Guardrails | None (Executes directly) | Built-in warnings & checks | Script-dependent |
| Default Availability | Disabled (Security hardened) | Enabled | Available via port 443 |
Frequently Asked Questions (FAQs)
1. What is the primary purpose of the VMware Managed Object Browser?
The Managed Object Browser provides a direct, low-level web interface to view, inspect, and manipulate the vSphere Web Services API (VIM API) object model on ESXi hypervisors and vCenter Server without requiring external client software.
2. Is the Managed Object Browser available in all vSphere versions?
Yes. The MOB has been an integral architectural feature of VMware ESX/ESXi and vCenter Server since early VirtualCenter releases and remains fully supported through vSphere 7.x and vSphere 8.x.
3. How do I find the BIOS UUID of a physical host using the MOB?
Navigate to ServiceContent -> rootFolder -> Datacenter -> hostFolder -> Host (HostSystem). Click on hardware (HostHardwareInfo) -> systemInfo to view the uuid property.
4. Can I use the MOB to modify virtual machine memory or CPU allocations?
Yes. You can invoke the ReconfigVM_Task method on the VirtualMachine Managed Object by passing a VirtualMachineConfigSpec containing the desired memoryMB and numCPUs values.
5. Why should administrators disable the MOB after completing maintenance?
Leaving the MOB enabled exposes an attack surface where users with administrative credentials can execute destructive operations without UI auditing. Industry standards such as CIS Benchmarks mandate keeping MOB disabled in production.
Frequently Asked Questions
Q1. What is the primary purpose of the VMware Managed Object Browser?
The Managed Object Browser provides a direct, low-level web interface to view, inspect, and manipulate the vSphere Web Services API (VIM API) object model on ESXi hypervisors and vCenter Server without requiring external client software.
Q2. Is the Managed Object Browser available in all vSphere versions?
Yes. The MOB has been an integral architectural feature of VMware ESX/ESXi and vCenter Server since early VirtualCenter releases and remains fully supported through vSphere 7.x and vSphere 8.x.
Q3. How do I find the BIOS UUID of a physical host using the MOB?
Navigate to ServiceContent -> rootFolder -> Datacenter -> hostFolder -> Host (HostSystem). Click on hardware (HostHardwareInfo) -> systemInfo to view the uuid property.
Q4. Can I use the MOB to modify virtual machine memory or CPU allocations?
Yes. You can invoke the ReconfigVM_Task method on the VirtualMachine Managed Object by passing a VirtualMachineConfigSpec containing the desired memoryMB and numCPUs values.
Q5. Why should administrators disable the MOB after completing maintenance?
Leaving the MOB enabled exposes an attack surface where users with administrative credentials can execute destructive operations without UI auditing. Industry standards such as CIS Benchmarks mandate keeping MOB disabled in production.