Lab: Create and Execute Orchestrator Workflow for Automated Log Collection
Objectives
- Configure VCF Operations Orchestrator and connect to vCenter
- Browse and run pre-built workflows from the workflow library
- Create a custom workflow for automated log collection across hosts
- Schedule workflow execution for recurring support tasks
- Understand event-based triggers for automated remediation
Prerequisites
VVF lab with VCF Operations Orchestrator deployed (or bundled with VCF Operations). vCenter operational.
Prior labs: vvf-support-12
Required skills:
- VCF Operations UI basics
- Basic scripting concepts
- vCenter administration
Lab Environment
Holodeck VVF pod with VCF Operations Orchestrator running. vCenter connected as endpoint.
Credentials
| System | Username | Password |
|---|---|---|
| Orchestrator | admin | Set during deployment |
| vCenter | administrator@vsphere.local | Holodeck default |
Tasks
Task 1 Configure Orchestrator and Explore Pre-Built Workflows
manageabilityOrchestrator automates repetitive support tasks. Understanding configuration and the pre-built workflow library is foundational for Obj 5.9.
VCF Operations → Orchestrate (or navigate to Orchestrator UI). Verify Orchestrator status: Should show 'Running' with vCenter endpoint connected.
If vCenter endpoint not configured: Orchestrate → Endpoints → Add → vCenter. Enter FQDN, credentials, accept certificate.
Browse workflow library: Orchestrate → Library → browse categories: vSphere, vSAN, Lifecycle Management, Custom. Note the pre-built workflows available.
Run a pre-built workflow: Select 'Create a snapshot for all VMs in a resource pool' → Run. Select target resource pool. Set snapshot name and description.
Review workflow execution history: Orchestrate → Runs → select completed workflow. Review: start time, duration, status (succeeded/failed), input/output parameters.
Validation Gate
Check: Orchestrator configured, pre-built workflow executed successfully
Expected: vCenter endpoint connected. Snapshot workflow completed. Execution history recorded.
Common Errors
Task 2 Create Custom Workflow for Automated Log Collection
manageabilityCustom workflows automate repetitive support tasks. Building a log collection workflow demonstrates Orchestrator's scripting and action chaining capabilities.
Orchestrate → Workflows → New Workflow. Name: 'Automated ESXi Log Collection'. Description: 'Collects support bundles from all ESXi hosts in a cluster and stores in central location.'
Define input parameters: Add parameter 'targetCluster' (type: VC:ClusterComputeResource) — this lets the operator select which cluster to collect logs from.
Add workflow elements in sequence: (1) 'Get hosts in cluster' action — retrieves all ESXi hosts from targetCluster. (2) For-each loop over hosts. (3) Inside loop: 'Run SSH command' action — executes 'esxcli system supportrequest interactive' on each host.
Add error handling: Wrap the SSH command in a try-catch block. On failure, log the error and continue to next host (don't stop the entire workflow for one host failure).
Add final action: 'Send email notification' — sends summary email listing which hosts succeeded and which failed. Configure SMTP settings if not already done.
Validate and save workflow. Click 'Validate' to check for binding errors or missing connections. Fix any validation warnings.
Test run: Execute workflow → select target cluster → monitor execution in Runs tab.
Validation Gate
Check: Custom workflow created, validated, and executed successfully
Expected: Workflow runs against cluster. Log collection completes on all hosts (or gracefully handles failures).
Common Errors
Task 3 Schedule Workflow and Configure Event Triggers
manageabilityScheduling and event-based triggers turn manual workflows into automated operations — key for proactive support and exam Obj 5.9.
Schedule the log collection workflow: Orchestrate → Workflows → select 'Automated ESXi Log Collection' → Schedule. Set: Daily at 02:00 UTC, target cluster pre-selected.
Configure event-based trigger: Orchestrate → Policies → Add Policy. Create trigger: 'When VCF Operations raises Critical alert on ESXi host → run log collection workflow on affected host.'
Review policy configuration: Trigger condition (alert severity = Critical, object type = Host System), Action (run workflow with affected host as input), Notification (email/log).
Test the trigger: Simulate a critical alert in VCF Operations (or wait for one). Verify the workflow auto-triggers and collects logs from the affected host.
Document automation patterns: List 3 common support scenarios that benefit from Orchestrator automation: (1) Proactive log collection on alert, (2) Scheduled compliance checks, (3) Automated VM snapshot cleanup (delete snapshots >7 days old).
Validation Gate
Check: Workflow scheduled, event trigger configured, automation patterns documented
Expected: Scheduled task visible. Policy trigger configured. Three automation use cases documented.
Common Errors
Final Validation
Orchestrator configured, custom workflow created and tested, scheduling and event triggers operational
✓ Orchestrator connected to vCenter → Endpoint shows 'Connected'
✓ Pre-built workflow executed → Snapshot workflow completed successfully
✓ Custom log collection workflow works → Support bundles generated on target hosts
✓ Schedule configured → Daily schedule visible in Scheduled Tasks
✓ Event trigger configured → Policy with critical alert trigger and workflow action
Cleanup / Restore
• Disable scheduled tasks if not needed for ongoing lab use
• Delete test snapshots created by pre-built workflow
• Remove event trigger policies to prevent unintended workflow execution
Design Reflection (VCDX)
Orchestrator transforms reactive support into proactive operations. Architects should design automation runbooks that cover the top-10 support scenarios, reducing human intervention and MTTR.
Requirements
- Automate log collection across all cluster hosts
- Event-driven response to critical alerts
Constraints
- SSH must be enabled on target hosts (security consideration)
- Orchestrator needs sufficient resources for concurrent workflow execution
Assumptions
- vCenter endpoint credentials remain valid
- SMTP configured for email notifications (optional in lab)
Risks
- Overly aggressive event triggers can cause workflow storms — implement cooldown periods
- SSH access to ESXi hosts creates security surface — restrict to Orchestrator service account only
Self-Assessment Discussion Prompts
- What safeguards prevent an event trigger from creating an infinite loop of workflow executions?
- How would you design an Orchestrator workflow for automated host remediation (vLCM patch + reboot)?
- What are the security implications of Orchestrator having SSH access to all ESXi hosts?
Extensions
Create a workflow that generates a weekly vSAN health report and emails it to the ops team
Build an automated snapshot cleanup workflow that deletes snapshots older than 7 days
Integrate Orchestrator with a ticketing system (ServiceNow) to auto-create incidents on critical alerts
Create a multi-step remediation workflow: detect disk failure → evacuate data → create support ticket
⚠ Known Pitfalls (from Community KB)
References
- VCF Operations Orchestrator DocumentationTier 1 — Official
- Orchestrator Workflow Design GuideTier 1 — Official
- VCF Operations Policy and Alert ConfigurationTier 1 — Official