How to Recover VMware ESXi 6.7 Virtual Machine Data from VMFS 5 and VMFS 6 Storage

Loss of access to virtual machines in VMware ESXi 6.7 may be caused by datastore corruption, accidental file deletion, drive failures, or hypervisor configuration errors. If the virtual machines were stored on VMFS 5 or VMFS 6 datastores, information recovery requires consideration of the structure of these file systems and the location of virtual disk files. In this article, we will examine how to access lost data, recover virtual machine files, and restore important information even in cases where standard VMware ESXi tools no longer provide access to the datastore.

How to Recover VMware ESXi 6.7 Virtual Machine Data from VMFS 5 and VMFS 6 Storage

In this article, we will analyze real-world data loss cases regularly encountered by both IT professionals and home server owners. These may include locating and recovering accidentally deleted files directly from within guest operating systems, or restoring data after critical infrastructure failures, such as server hardware failure or RAID controller failure.

Our methods will also be useful after ESXi hypervisor failures or loss of configuration files when the server does not boot. In addition, we will consider cases of logical corruption of the datastore structure, when the datastore stops mounting, is no longer recognized by the system, and the hypervisor completely loses access to the virtual machines.

We will show how to connect server drives directly to a computer and successfully extract .vmdk virtual disk files, configurations, and snapshots using specialized software. You will get a universal solution that enables direct access to lost data and effective work in the environment of your choice — Windows, Linux, or macOS.

Go to view
How to Recover VMware ESXi 6.7 Virtual Machine Data from VMFS 5, VMFS 6

How to Recover VMware ESXi 6.7 Virtual Machine Data from VMFS 5, VMFS 6

VMware and VMFS Architecture

ESXi is a type 1 hypervisor. It is installed directly on the server hardware without intermediary operating systems. This provides virtual machines with maximum performance and direct access to resources.

VMware ESXi: connected storage devices

Virtual machines are stored on datastores with the cluster file system VMFS. It is designed specifically for virtualization and optimized for working with large files: vmdk virtual disks, configurations, and snapshots.

VMware ESXi: creating a new datastore

The most common versions are VMFS 5 and the newer VMFS 6, which additionally supports automatic block reclamation and performs better with large-capacity arrays.

The downside of this reliability is the complexity of recovery after failures. VMFS has a closed architecture that standard operating systems cannot understand. If you connect a server drive to a Windows computer, the system will detect an unknown structure and prompt you to format the drive, which will permanently destroy your data. Therefore, specialized software is required for safe reading of VMFS arrays.

VMware ESXi: creating a VMFS 6 datastore

Our Hetman Partition Recovery software handles this task effectively, allowing successful recovery of virtual machine data for versions 5.5, 6.5, and 6.7.

The all-purpose choice for recovering files from deleted, formatted, damaged, or inaccessible storage devices.

How to Connect Server Drives to a Computer

Before starting the recovery process, you need to remove the problematic drive from the server and connect it to a working computer.

The most reliable method is direct connection via the SATA interface to the motherboard. This ensures the highest data read speed and stable operation during deep analysis.

If your server is equipped with enterprise drives using the SAS interface, recognition on a standard PC will require installing a compatible HBA controller into an available PCIe slot.

Using external USB enclosures or docking stations is acceptable as an alternative if direct connection is not possible.

Keep in mind that USB interface bandwidth is usually the bottleneck, so the scan speed of the array will be noticeably lower, which will increase the overall recovery time.

Connection method Requirements Advantages Disadvantages and notes
SATA directly to the motherboard An available SATA port and appropriate power High data transfer speed, stable connection, convenient for long scans Suitable only for drives with a compatible SATA interface
SAS via HBA controller A compatible SAS HBA controller, a PCIe slot, and the appropriate cables Allows connection of server SAS drives and supports stable operation during extended analysis Controller, cable, and drive compatibility must be verified
External USB enclosure An enclosure with support for the drive interface Simple connection, no need to install internal PC components Speed depends on USB version and controller; access to certain drive commands may be limited
USB docking station A docking station with a compatible connector for HDD or SSD Convenient connection and quick drive installation Possible limitations in speed, compatibility, and stability during long scans

What to Do If the Drives Cannot Be Connected to a Computer

In situations where it is technically impossible to connect all required drives to a computer at the same time (for example, due to a shortage of available motherboard ports), you can use the sector-by-sector image creation function. This is also a standard safety measure when working with drives suspected of having hardware issues. An image is an exact byte-for-byte copy of a physical drive, stored as a regular file on another storage device with sufficient capacity.

You can connect server drives to the system one by one, create images of them, and then load all the resulting files directly into Hetman Partition Recovery. Our utility will work with mounted images in exactly the same way as with real hardware, allowing full analysis of the VMFS structure.

To create an image, launch the program, select the required drive from the list, and click the Save disk button on the top panel.

Hetman Partition Recovery: creating a disk image

Specify the location for saving the file.

Note: the size of the completed image will be equal to the full capacity of the source drive, regardless of how many gigabytes are actually used. Therefore, make sure in advance that the target disk has enough free space.

Hetman Partition Recovery: disk image settings

When the saving process is complete, go to the main menu and select Mount disk.

Hetman Partition Recovery: mounting a disk image

In the list of types, select Raw disk images and load the created file.

Hetman Partition Recovery: mounting a RAW disk image

It will immediately appear in the general list of devices. If there are multiple problematic drives, simply repeat this procedure for each of them. After the images are mounted, the program will be ready for a deep analysis of the datastore.

Hetman Partition Recovery: mounted datastore image

How to Recover Virtual Machine Data

METHOD 1. Recovering a Virtual Machine from VMFS

Most often, loss of access to virtual machines is associated not with errors inside the system, but with hardware or structural failures. These may include server hardware failure, RAID controller failure, ESXi boot media failure, a critical hypervisor kernel error known as the Purple Screen of Death, or a logical failure of the VMware platform, when the datastore is corrupted and stops mounting. In such situations, the server becomes unavailable or no longer sees the arrays, but the information on the drives usually remains physically intact.

As is known, the ESXi hypervisor stores virtual machines as a set of files in special directories on the datastore. The most important for us are the main configuration file vmx, which stores all machine parameters, and the virtual hard disk files. It is worth noting that such a disk usually consists of two parts: a small text descriptor vmdk and the main flat file, which contains all the data of your guest system.

ESXi hypervisor: datastore browser

This basic set often includes the nvram file, which stores the settings of the virtual BIOS or UEFI. And if snapshots were created for the machine, delta files — delta or sesparse — will also appear in the directory, where all new changes are written instead of the main disk, as well as a special vmsd file that describes the snapshot chain structure.

Since normal access to the datastore is not possible, we use a computer and our developed Hetman Partition Recovery software for direct block-level reading of this data.

The all-purpose choice for recovering files from deleted, formatted, damaged, or inaccessible storage devices.

After launch, the program automatically analyzes the connected physical drives or mounted images and recognizes partitions with VMware file systems on them. In our test environment, datastores of different versions were created — VMFS 5 and VMFS 6.

Hetman Partition Recovery: mounted VMFS 5 image

To find the lost data, select the required datastore in the device list and start Fast scan mode. This quick scan is ideal for reading a file structure that has not been heavily overwritten.

Hetman Partition Recovery: fast scan of VMFS 5 image

After the analysis is complete, open the found file system. The program will correctly display the entire datastore hierarchy. Here you can easily find the folders of your virtual machines on any of the storages — both on VMFS 5 and on the newer VMFS 6 versions. Open the directory of the required machine, which contains the configuration files and the main vmdk virtual disks.

Hetman Partition Recovery: VMFS 5 image contents

To recover them, select the required items and click the Recovery button on the toolbar. The program will ask you to specify a save location. Be sure to choose a separate hard drive on your computer with sufficient free space to store the large virtual drive files.

Hetman Partition Recovery: saving VMFS 5 contents

After the operation is complete, you will receive the machine files on your PC for further use or analysis.

Ready virtual machine files saved on the PC

METHOD 2. Recovering Files from Guest Systems

There are situations when the datastore is functioning normally, but important information was accidentally deleted directly from within the guest operating system. To recover this data, you do not necessarily need to deploy the found vmdk file on a new server or attach it to another virtual machine.

Hetman Partition Recovery allows you to mount the virtual disk directly in its interface and work with it as with a regular physical drive.

Hetman Partition Recovery: mounting a guest operating system image

Let us look at the recovery process using our test virtual machine from the VMFS 6 datastore as an example. First, we will analyze the 20-gigabyte system disk on which guest Windows 10 was running.

Hetman Partition Recovery: mounted guest operating system image

Click the mounted partition and start Fast scan mode. This quick scan is ideal for finding recently deleted objects.

Hetman Partition Recovery: analyzing a guest operating system image

After the analysis is complete, go to the found file system and open the directory where your data disappeared from.

There is one important technical nuance to consider here: since this is a system disk, a small portion of recently deleted files may have been overwritten immediately by background processes and Windows updates. However, the vast majority of information is recovered correctly.

Select the required files and click the Recovery button on the toolbar. During the saving stage, be sure to specify a path on a separate physical drive with sufficient free space.

Hetman Partition Recovery: recovering data from a guest operating system image

Now let us move to the additional 3-gigabyte virtual drive that was attached to the same machine solely for storing user files. Return to the main menu, select this drive, and also start Fast scan.

Hetman Partition Recovery: mounted 3 GB image

Open the contents and find the deleted test files. Since this drive did not host the operating system itself and there was no background writing of system data, the program successfully finds and recovers all deleted files in their original form.

Hetman Partition Recovery: contents of the mounted 3 GB image

As you can see, the utility allows isolated work with each logical volume of the virtual machine, which ensures the most accurate and convenient restoration of lost information.

METHOD 3. Recovery via Snapshots

Let us move on to one of the most powerful data protection mechanisms — working with snapshots, or system state snapshots.

Snapshots in VMware ESXi work somewhat differently from regular backups. When a snapshot is created, the hypervisor does not copy the entire disk. It freezes the current base vmdk disk and creates a new so-called delta disk. All subsequent changes and new files are written to this delta, while the base disk remains untouched. If several such snapshots are created, an entire chain of dependent files is formed.

Snapshots in VMware ESXi

This architecture opens unique possibilities for data recovery. Imagine that after creating a snapshot, you accidentally deleted important documents inside the guest operating system. From the perspective of the current Windows installation, these files are gone, but their original blocks are safely preserved inside the frozen snapshot files.

Hetman Partition Recovery can read such delta disks directly, allowing data extraction without needing to start the server or perform a complex rollback of the entire machine through the VMware console.

Hetman Partition Recovery: mounting a delta disk

To begin recovery, we go to the mounted folder of our virtual machine in the program interface.

Hetman Partition Recovery: mounting snapshot files

Among the regular configurations, we look for snapshot files — they usually have specific extensions and numbering, for example *-000001.vmdk or *-000002.vmdk. As with regular virtual disks, the utility allows you to mount the required delta disk directly in the program.

In our scenario, after creating the first test environment, we made snapshot 1, then added new files, made snapshot 2, and then deleted part of the data.

We find the required snapshot of the additional disk, mount it, and start Fast scan mode.

Hetman Partition Recovery: mounted snapshot files

The program instantly analyzes the file system of this specific snapshot. As a result, we get full access to the information exactly in the state it was in at the time the snapshot was created, even if we later deleted these files.

Hetman Partition Recovery: mounted snapshot file contents

Next, everything is standard: we select the found files, click the Recovery button, and specify a safe save path on the computer’s hard drive.

Hetman Partition Recovery: recovering data from a mounted snapshot file

Direct reading of snapshots significantly speeds up the information recovery process, since you do not need to restore the entire virtual machine just to retrieve a single accidentally deleted document.

Conclusion

Recovering data from VMware ESXi 6.7 virtual machines stored on VMFS 5 and VMFS 6 requires consideration of the file system organization, virtual disk structure, and the condition of the physical drives. Even if the hypervisor no longer recognizes the datastore, the virtual machine does not start, or its files were accidentally deleted, some or all of the data may still be available for recovery.

To increase the chances of successful data restoration, it is important to stop writing to the problematic drive, connect it correctly to a working computer, and, if possible, create a sector-by-sector copy for further analysis. This is especially relevant in cases of datastore corruption, drive malfunction, or loss of access to virtual machines.

With specialized data recovery software, you can analyze VMFS datastores, find virtual machine configuration files, virtual disks, and other important data, and then recover the available information. This approach makes it possible to work with data even when standard VMware ESXi tools no longer provide access to it.

Therefore, if access to VMware ESXi 6.7 virtual machines is lost, do not rush to format the datastore or recreate the volumes. First, assess the condition of the drive, preserve the existing data, and analyze VMFS 5 or VMFS 6. Timely and careful actions will help reduce the risk of irreversible data loss and increase the likelihood of successful recovery.

Vladimir Artiukh

Author: , Technical Writer

Vladimir Artiukh is a technical writer for Hetman Software, as well as the voice and face of their English-speaking YouTube channel, Hetman Software: Data Recovery for Windows. He handles tutorials, how-tos, and detailed reviews on how the company’s tools work with all kinds of data storage devices.

Oleg Afonin

Editor: , Technical Writer

Oleg Afonin is an expert in mobile forensics, data recovery and computer systems. He often attends large data security conferences, and writes several blogs for such resources as xaker.ru, Elcomsoft and Habr. In addition to his online activities, Oleg’s articles are also published in professional magazines. Also, Oleg Afonin is the co-author of a well-known book, Mobile Forensics - Advanced Investigative Strategies.

Recommended For You