Academy/vSphere Foundation 9.0 Administrator (2V0-16.25)/Lab: Deploy VCF Operations for Logs and Configure Syslog Forwarding
This lab targets VCF 9.0

Lab: Deploy VCF Operations for Logs and Configure Syslog Forwarding

VCF 9.0Intermediateadmincloud-opssupport⏱ 75 min

VCF Operations for Logs 8.18+ (formerly Aria Operations for Logs / vRealize Log Insight)

Objectives

  • Deploy VCF Operations for Logs standalone appliance
  • Configure ESXi hosts to forward syslog to Operations for Logs
  • Configure vCenter syslog forwarding
  • Search and filter log events using Explore Logs interface
  • Differentiate between metrics, properties, and logs (exam objective 4.3)

Prerequisites

Holodeck pod with VVF management domain deployed. VCF Operations running (Lab 07 completed).

Prior labs: vvf-admin-07

Required skills:

  • ESXi shell commands (esxcli)
  • Syslog concepts
  • vCenter UI navigation

Lab Environment

Holodeck VVF pod — 3 nested ESXi hosts, vCenter 9.0, vSAN cluster, VCF Operations deployed.

IP Addressing

NetworkPurposeVLAN
192.168.10.0/24Management10
192.168.10.81VCF Operations for Logs node10

Credentials

SystemUsernamePassword
vCenteradministrator@vsphere.localSet during VCSA deployment
VCF Operations for LogsadminSet during OVA deployment

Tasks

Task 1 Deploy VCF Operations for Logs OVA

manageability

Centralized logging is essential for troubleshooting and compliance. Deploying Operations for Logs alongside VCF Operations provides complete observability.

Step 1

Download VCF Operations for Logs 8.18 OVA from Broadcom Support Portal. File: VMware-vRealize-Log-Insight-8.18.x.ova (~1.8GB).

Step 2
In vCenter: Right-click management cluster → Deploy OVF Template → Select downloaded OVA.
Step 3

Configure: Name='vcf-logs-01', compute=management cluster, storage=vSAN datastore, size='Small' (4 vCPU, 8GB RAM, 530GB disk).

Step 4

Network: Management port group, IP=192.168.10.81, subnet=255.255.255.0, gateway=192.168.10.1, DNS, NTP.

Ensure no IP conflict with VCF Operations node (192.168.10.80).
Step 5
Power on VM. Wait 5-8 minutes for initialization. Access https://192.168.10.81 → complete initial setup (admin password, EULA).

Validation Gate

Check: Browse to https://192.168.10.81 and login

Expected: Operations for Logs dashboard loads with 'Getting Started' page

Task 2 Configure ESXi Syslog Forwarding

manageability

ESXi hosts generate critical logs (vmkernel, hostd, vpxa). Forwarding them centrally enables fleet-wide search and correlation — a core exam skill.

Step 1

SSH to first ESXi host (esxi-01.lab.local). Run:
esxcli system syslog config set --loghost=udp://192.168.10.81:514

Command completes with no output (success).
Step 2

Reload syslog service:
esxcli system syslog reload

No output (success).
Step 3

Verify configuration:
esxcli system syslog config get

Remote Host: udp://192.168.10.81:514
Step 4

Repeat steps 1-3 for esxi-02 and esxi-03.

Alternative: Use Host Profile to configure syslog for all hosts simultaneously. Attach profile → Remediate cluster.
Step 5

Generate a test log entry on esxi-01:
logger -t TEST 'Syslog forwarding test from esxi-01'

Step 6
In Operations for Logs UI: Navigate to Explore Logs → search for 'Syslog forwarding test' → verify the test message appears.
Log entry visible with source=esxi-01, text containing 'Syslog forwarding test'.

Validation Gate

Check: Explore Logs → filter source=esxi-* → verify all 3 hosts sending logs

Expected: Log entries from esxi-01, esxi-02, esxi-03 visible in last 15 minutes

Common Errors

No logs from ESXi hosts after 5 minutes
Cause: Firewall rule on ESXi blocking outbound UDP 514
Fix: Run: esxcli network firewall ruleset set -e true -r syslog. Then: esxcli system syslog reload.
Logs appear but source shows IP instead of hostname
Cause: DNS PTR record missing for ESXi host IPs
Fix: Add PTR records in DNS server or configure hostname in syslog: esxcli system hostname set --host=esxi-01

Task 3 Configure vCenter Syslog and Explore Log Analysis

manageability

vCenter (VCSA) logs contain critical events — task completions, permission changes, alarm triggers. Combined with ESXi logs, this enables cross-component root cause analysis.

Step 1

SSH to VCSA (vcsa-01.lab.local). Access shell:
shell

Configure syslog forwarding:
/usr/lib/vmware-vmon/vmon-cli --update vpxd --starttype AUTOMATIC
vi /etc/vmware-syslog/syslog.conf

Add line: . @192.168.10.81:514

Alternative method: VCSA Management UI (https://vcsa-01.lab.local:5480) → Syslog Configuration → Add remote syslog server.
Step 2

Restart syslog service on VCSA:
service rsyslog restart

Step 3
In Operations for Logs: Explore Logs → search 'vpxd' → verify vCenter events appear.
vpxd.log entries visible — task completions, session events, inventory changes.
Step 4
Practice log analysis: Search for 'error OR warning' with source=esxi-* and time range=last 1 hour. Use Group By → source to see error distribution across hosts.
Results grouped by source host showing count of error/warning events per host.
Step 5
Save this search as a named query: Click 'Save' → name='ESXi Errors and Warnings' → Save.
Saved queries are reusable for daily operations monitoring and can be pinned to dashboards.

Validation Gate

Check: Explore Logs → verify both ESXi and vCenter log sources appear in source filter dropdown

Expected: Sources include: esxi-01, esxi-02, esxi-03, vcsa-01. Saved query 'ESXi Errors and Warnings' appears in saved queries list.

Final Validation

VCF Operations for Logs deployed and receiving syslog from all ESXi hosts and vCenter.

✓ Operations for Logs UI accessible at https://192.168.10.81 → Login succeeds, dashboard loads

✓ Explore Logs shows entries from 3 ESXi hosts + vCenter → All 4 sources visible in source filter

✓ Saved query 'ESXi Errors and Warnings' executes successfully → Returns grouped results by source host

Cleanup / Restore

Snapshot: post-vcf-logs-deployed

• Take snapshot 'post-vcf-logs-deployed' for next lab (Custom Dashboard and Alerts)

Design Reflection (VCDX)

A panelist might ask: Why separate VCF Operations (metrics) from Operations for Logs (logs)? What's the correlation workflow between a metric spike and corresponding log entries?

Requirements

  • Centralized log collection from all VVF infrastructure
  • Full-text search capability for troubleshooting
  • Log retention for compliance audit (30+ days)

Constraints

  • Single-node deployment limits ingestion to ~5,000 events/sec
  • UDP syslog is fire-and-forget — no delivery guarantee
  • Disk capacity determines retention period

Assumptions

  • Management network has sufficient bandwidth for syslog traffic
  • DNS resolution works for all log sources
  • ESXi firewall allows outbound syslog

Risks

  • Single-node SPOF — logs lost if node fails
  • UDP packet loss under network congestion
  • Disk full stops log ingestion silently

Self-Assessment Discussion Prompts

  1. When would you choose a 3-node cluster over standalone deployment for Operations for Logs?
  2. How do you correlate a vSAN latency spike (metric in VCF Ops) with the root cause (log in Ops for Logs)?
  3. What log retention policy would you recommend for a customer with PCI-DSS compliance requirements?

References

Was this page useful?
Type to search. ↑ ↓ to move, Enter to open, Esc to close.