Lab: Deploy VCF Operations for Logs and Configure Syslog Forwarding
Objectives
- Deploy VCF Operations for Logs standalone appliance
- Configure ESXi hosts to forward syslog to Operations for Logs
- Configure vCenter syslog forwarding
- Search and filter log events using Explore Logs interface
- Differentiate between metrics, properties, and logs (exam objective 4.3)
Prerequisites
Holodeck pod with VVF management domain deployed. VCF Operations running (Lab 07 completed).
Prior labs: vvf-admin-07
Required skills:
- ESXi shell commands (esxcli)
- Syslog concepts
- vCenter UI navigation
Lab Environment
Holodeck VVF pod — 3 nested ESXi hosts, vCenter 9.0, vSAN cluster, VCF Operations deployed.
IP Addressing
| Network | Purpose | VLAN |
|---|---|---|
192.168.10.0/24 | Management | 10 |
192.168.10.81 | VCF Operations for Logs node | 10 |
Credentials
| System | Username | Password |
|---|---|---|
| vCenter | administrator@vsphere.local | Set during VCSA deployment |
| VCF Operations for Logs | admin | Set during OVA deployment |
Tasks
Task 1 Deploy VCF Operations for Logs OVA
manageabilityCentralized logging is essential for troubleshooting and compliance. Deploying Operations for Logs alongside VCF Operations provides complete observability.
Download VCF Operations for Logs 8.18 OVA from Broadcom Support Portal. File: VMware-vRealize-Log-Insight-8.18.x.ova (~1.8GB).
In vCenter: Right-click management cluster → Deploy OVF Template → Select downloaded OVA.
Configure: Name='vcf-logs-01', compute=management cluster, storage=vSAN datastore, size='Small' (4 vCPU, 8GB RAM, 530GB disk).
Network: Management port group, IP=192.168.10.81, subnet=255.255.255.0, gateway=192.168.10.1, DNS, NTP.
Power on VM. Wait 5-8 minutes for initialization. Access https://192.168.10.81 → complete initial setup (admin password, EULA).
Validation Gate
Check: Browse to https://192.168.10.81 and login
Expected: Operations for Logs dashboard loads with 'Getting Started' page
Task 2 Configure ESXi Syslog Forwarding
manageabilityESXi hosts generate critical logs (vmkernel, hostd, vpxa). Forwarding them centrally enables fleet-wide search and correlation — a core exam skill.
SSH to first ESXi host (esxi-01.lab.local). Run:
esxcli system syslog config set --loghost=udp://192.168.10.81:514
Reload syslog service:
esxcli system syslog reload
Verify configuration:
esxcli system syslog config get
Repeat steps 1-3 for esxi-02 and esxi-03.
Generate a test log entry on esxi-01:
logger -t TEST 'Syslog forwarding test from esxi-01'
In Operations for Logs UI: Navigate to Explore Logs → search for 'Syslog forwarding test' → verify the test message appears.
Validation Gate
Check: Explore Logs → filter source=esxi-* → verify all 3 hosts sending logs
Expected: Log entries from esxi-01, esxi-02, esxi-03 visible in last 15 minutes
Common Errors
Task 3 Configure vCenter Syslog and Explore Log Analysis
manageabilityvCenter (VCSA) logs contain critical events — task completions, permission changes, alarm triggers. Combined with ESXi logs, this enables cross-component root cause analysis.
SSH to VCSA (vcsa-01.lab.local). Access shell:
shell
Configure syslog forwarding:
/usr/lib/vmware-vmon/vmon-cli --update vpxd --starttype AUTOMATIC
vi /etc/vmware-syslog/syslog.conf
Add line: . @192.168.10.81:514
Restart syslog service on VCSA:
service rsyslog restart
In Operations for Logs: Explore Logs → search 'vpxd' → verify vCenter events appear.
Practice log analysis: Search for 'error OR warning' with source=esxi-* and time range=last 1 hour. Use Group By → source to see error distribution across hosts.
Save this search as a named query: Click 'Save' → name='ESXi Errors and Warnings' → Save.
Validation Gate
Check: Explore Logs → verify both ESXi and vCenter log sources appear in source filter dropdown
Expected: Sources include: esxi-01, esxi-02, esxi-03, vcsa-01. Saved query 'ESXi Errors and Warnings' appears in saved queries list.
Final Validation
VCF Operations for Logs deployed and receiving syslog from all ESXi hosts and vCenter.
✓ Operations for Logs UI accessible at https://192.168.10.81 → Login succeeds, dashboard loads
✓ Explore Logs shows entries from 3 ESXi hosts + vCenter → All 4 sources visible in source filter
✓ Saved query 'ESXi Errors and Warnings' executes successfully → Returns grouped results by source host
Cleanup / Restore
Snapshot: post-vcf-logs-deployed
• Take snapshot 'post-vcf-logs-deployed' for next lab (Custom Dashboard and Alerts)
Design Reflection (VCDX)
A panelist might ask: Why separate VCF Operations (metrics) from Operations for Logs (logs)? What's the correlation workflow between a metric spike and corresponding log entries?
Requirements
- Centralized log collection from all VVF infrastructure
- Full-text search capability for troubleshooting
- Log retention for compliance audit (30+ days)
Constraints
- Single-node deployment limits ingestion to ~5,000 events/sec
- UDP syslog is fire-and-forget — no delivery guarantee
- Disk capacity determines retention period
Assumptions
- Management network has sufficient bandwidth for syslog traffic
- DNS resolution works for all log sources
- ESXi firewall allows outbound syslog
Risks
- Single-node SPOF — logs lost if node fails
- UDP packet loss under network congestion
- Disk full stops log ingestion silently
Self-Assessment Discussion Prompts
- When would you choose a 3-node cluster over standalone deployment for Operations for Logs?
- How do you correlate a vSAN latency spike (metric in VCF Ops) with the root cause (log in Ops for Logs)?
- What log retention policy would you recommend for a customer with PCI-DSS compliance requirements?
References
- VCF Operations for Logs Deployment GuideTier 1 — Official
- ESXi Syslog ConfigurationTier 1 — Official