Add runbook references and auto-ticket integration.
Step 5
Tune for false-positive rate <5%.
Validation Gate
Check: Verify lab completion
Expected: Lab exercise completed successfully
Common Errors
Log Intelligence ingesting all logs without filtering
Fix: Ingesting all ESXi, vCenter, NSX, and vSAN logs generates terabytes of data with high noise-to-signal ratio. Configure log filters: ingest warning/error/critical levels for most components, info level only for specific troubleshooting scenarios. This reduces storage cost and improves query performance.
Log alerts without correlation to infrastructure events
Fix: A standalone log alert ('error detected in vpxd.log') without infrastructure context is incomplete. Correlate log alerts with VCF Operations metrics: if vpxd errors spike simultaneously with ESXi host disconnection, the root cause is host failure, not vpxd. Configure VCF Operations to correlate log and metric alerts.
Not configuring log retention policies
Fix: Default log retention may be too short (7 days) for compliance requirements or too long (365 days) for storage cost. HIPAA requires 6-year audit log retention. PCI-DSS requires 1 year online + archive. Configure retention per log source based on regulatory requirements.
Final Validation
Lab completed successfully
✓ All steps completed → No errors observed
Cleanup / Restore
• Revert to snapshot if needed
Design Reflection (VCDX)
Log intelligence architecture demonstrates operational monitoring depth. VCDX designs should include log ingestion strategy, alert engineering, and retention policies aligned with compliance requirements.
⚠ Known Pitfalls (from Community KB)
Ingesting all logs at all levels — creates storage cost explosion and makes finding real issues harder.
Not aligning log retention with compliance requirements — potential audit finding.
Was this page useful?Thanks — noted.
Type to search. ↑↓ to move,
Enter to open, Esc to close.