Academy/VVS/Intelligent Logging & Analytics
This solution targets VCF 5.2

Intelligent Logging and Analytics for VMware Cloud Foundation

VCF 5.2architectvcdxadminautomationPages 237-337

Provides centralized logging for VCF management and VI workload domains using VMware Aria Operations for Logs (formerly vRealize Log Insight) 8.18.0. Deploys a 3-node medium-sized Aria Operations for Logs cluster per VCF instance with Integrated Load Balancer (ILB) behind a VIP; syslog and agent-based log collection for ESXi, vCenter, NSX Manager, NSX Edge, SDDC Manager, Workspace ONE Access, VMware Aria Suite Lifecycle; content pack management; retention and archiving; event forwarding for multi-VCF deployments; AD-based RBAC.

Key Components: NSX, Aria Operations, Aria Automation, SDDC Manager, vCenter, ESXi, Workspace ONE

External dependencies: VMware Aria Operations for Logs 8.18.0 (deployed per VCF instance)

Design Decisions
Implementation
Operations
VCDX Defense
Quiz (15)
Flashcards (15)

35 design decisions

DD-IDDecisionQuality
ILA-VAOL-NET-001JustificationImplicationManageability

Decision: JustificationImplication

Rationale: See source document for rationale

Implication: ILA-VAOL-NET-002Allocate statically a

Component: VAOL

ILA-VAOL-NET-002JustificationImplicationManageability

Decision: JustificationImplication

Rationale: See source document for rationale

Implication: ILA-VAOL-NET-004Configure forward+reverse DNS for all cluster nodes + ILB VIP.FQDN-based access.Must provide DNS records.

Component: VAOL

ILA-VAOL-NET-003JustificationImplicationManageability

Decision: JustificationImplication

Rationale: See source document for rationale

Implication: ILA-VAOL-NET-004Configure forward+reverse DNS for all cluster nodes + ILB VIP.FQDN-based access.Must provide DNS records.

Component: VAOL

ILA-VAOL-NET-004JustificationImplicationManageability

Decision: JustificationImplication

Rationale: See source document for rationale

Implication: ILA-VAOL-NET-005Enable Aria Ops for Logs Integrated Load Balancer (ILB).Balances ingestion across nodes, provides HA.Must provide extra IP and FQDN for ILB.

Component: VAOL

ILA-VAOL-NET-005JustificationImplicationManageability

Decision: JustificationImplication

Rationale: See source document for rationale

Implication: ILA-VAOL-NET-006Configure NTP on each cluster node.Aria Ops for Logs depends on time sync.None.

Component: VAOL

ILA-VAOL-CFG-001Deploy a 3-node (1 primary + 2 workers) Aria Ops for Logs cluster.AvailabilityManageability

Decision: Deploy a 3-node (1 primary + 2 workers) Aria Ops for Logs cluster.

Rationale: Provides high availability and 200 syslog connections support.

Implication: Must deploy 3 VMs; ILB VIP FQDN + IP required.

Component: VAOL

ILA-VAOL-CFG-002Deploy Aria Ops for Logs via Aria Suite Lifecycle.AvailabilityManageability

Decision: Deploy Aria Ops for Logs via Aria Suite Lifecycle.

Rationale: Standard LCM workflow.

Implication: Must deploy Aria Suite Lifecycle first (via SDDC Manager).

Component: VAOL

ILA-VAOL-CFG-003Protect all Aria Ops for Logs VMs with vSphere HA.Availability

Decision: Protect all Aria Ops for Logs VMs with vSphere HA.

Rationale: Supports availability objective.

Implication: None.

Component: VAOL

ILA-VAOL-CFG-004Apply vSphere Distributed Resource Scheduler anti-affinity to cluster nodes.Manageability

Decision: Apply vSphere Distributed Resource Scheduler anti-affinity to cluster nodes.

Rationale: Ensure nodes run on separate hosts for fault tolerance.

Implication: Must configure DRS rules.

Component: VAOL

ILA-VAOL-CFG-005Place Aria Ops for Logs VMs in designated VM folder.Manageability

Decision: Place Aria Ops for Logs VMs in designated VM folder.

Rationale: Inventory organization.

Implication: Must create folder.

Component: VAOL

ILA-VAOL-CFG-006With 2 AZs, bind Aria Ops for Logs cluster to first AZ hosts group.Manageability

Decision: With 2 AZs, bind Aria Ops for Logs cluster to first AZ hosts group.

Rationale: Cluster runs in first AZ; fails over to second AZ on AZ failure.

Implication: VM group update after second AZ deployed.

Component: VAOL

ILA-VAOL-CFG-007In multi-VCF, deploy a separate Aria Ops for Logs cluster per VCF instance.Manageability

Decision: In multi-VCF, deploy a separate Aria Ops for Logs cluster per VCF instance.

Rationale: Provides local Aria Ops for Logs per instance.

Implication: Must deploy Aria Ops for Logs per VCF instance.

Component: VAOL

ILA-VAOL-CFG-008IDILA-VAOL-CFG-009Manageability

Decision: IDILA-VAOL-CFG-009

Rationale: See source document for rationale

Implication: No significant trade-offs identified for this decision.

Component: VAOL

ILA-VAOL-CFG-009Deploy each node sized Medium.Manageability

Decision: Deploy each node sized Medium.

Rationale: See source document for rationale

Implication: Must scale up for additional load.

Component: VAOL

ILA-VAOL-SEC-001Activate integration with identity source via AD over LDAP.ManageabilitySecurity

Decision: Activate integration with identity source via AD over LDAP.

Rationale: Authentication via identity source; role-based authorization for enterprise users/groups.

Implication: None.

Component: VAOL

ILA-VAOL-SEC-002Create security group in directory services for admins; assign Super Admin role.ManageabilitySecurity

Decision: Create security group in directory services for admins; assign Super Admin role.

Rationale: Streamlines role mgmt; managed admin access; accountability.

Implication: Create and maintain AD group outside SDDC stack.

Component: VAOL

ILA-VAOL-SEC-003Create security group for users; assign User role.Streamlines role mgmt.Create and maintain AD groupManageabilitySecurity

Decision: Create security group for users; assign User role.Streamlines role mgmt.Create and maintain AD group.

Rationale: ILA-VAOL-SEC-004Create security group for viewers; assign View Only Admin role.Streamlines role mgmt.Create and maintain AD group.

Implication: Password Management

Component: VAOL

ILA-VAOL-SEC-005Configure password expiration policy for each Aria Ops for Logs appliance.Manageability

Decision: Configure password expiration policy for each Aria Ops for Logs appliance.

Rationale: Compliance alignment.

Implication: Manage via appliance console or SSH.

Component: VAOL

ILA-VAOL-SEC-006Configure password complexity policy.Manageability

Decision: Configure password complexity policy.

Rationale: Compliance alignment.

Implication: Manage via appliance console or SSH.

Component: VAOL

ILA-VAOL-SEC-007Configure account lockout policy.Manageability

Decision: Configure account lockout policy.

Rationale: Compliance alignment.

Implication: Manage via appliance console or SSH.

Component: VAOL

ILA-VAOL-SEC-008Change the root password on recurring schedule via SDDC Manager UI/API.Default password expires everManageabilitySecurity

Decision: Change the root password on recurring schedule via SDDC Manager UI/API.Default password expires every 365 days; root managed from SDDC Manager UI/API (NOT Aria Suite Lifecycle) when deployed in VCF vi

Rationale: ILA-VAOL-SEC-009Change admin account password on recurring schedule via SDDC Manager UI/API.Admin password managed from SDDC Manager UI/API, NOT Aria Suite Lifecycle.Routine password change via SDDC M

Implication: Certificate Management

Component: VAOL

ILA-VAOL-CFG-010Configure retention for medium appliance = 7 days default.Availability

Decision: Configure retention for medium appliance = 7 days default.

Rationale: Balances storage capacity and forensic availability.

Implication: Adjust per compliance needs.

Component: VAOL

ILA-VAOL-CFG-011Configure archive policy = 90 days.Manageability

Decision: Configure archive policy = 90 days.

Rationale: Longer-term audit requirements.

Implication: Requires 400 GB shared NFS storage.

Component: VAOL

ILA-VAOL-CFG-012Configure 400 GB NFS shared storage for log archival.Supports 90-day archive.NFS mount must have enoManageability

Decision: Configure 400 GB NFS shared storage for log archival.Supports 90-day archive.NFS mount must have enough free space; enforce archive policy directly on shared storage; in multi-AZ, NFS share available

Rationale: Alert Notifications Design

Implication: Alert Types

Component: VAOL

ILA-VAOL-CFG-013Configure alert notifications.Manageability

Decision: Configure alert notifications.

Rationale: See source document for rationale

Implication: Must configure SMTP for email notifications.

Component: VAOL

ILA-VAOL-LCM-001Use VMware Aria Suite Lifecycle to perform LCM of Aria Ops for Logs in each VCF instance.ManageabilityPerformance

Decision: Use VMware Aria Suite Lifecycle to perform LCM of Aria Ops for Logs in each VCF instance.

Rationale: See source document for rationale

Implication: Suite Lifecycle must be deployed via SDDC Manager; handles patches/updates/hotfixes.

Component: VAOL

ILA-VAOL-CFG-014Install Linux-Systemd, VMware-NSX, VMware-Aria-Suite-Lifecycle-8.12+, VMware Workspace ONE Access coManageability

Decision: Install Linux-Systemd, VMware-NSX, VMware-Aria-Suite-Lifecycle-8.12+, VMware Workspace ONE Access content packs.

Rationale: Granular monitoring; W1A content pack requires manual install.

Implication: Manual install of the Workspace ONE Access content pack is required; the remaining content packs are installed from the in-product marketplace.

Component: VAOL

ILA-VAOL-CFG-015JustificationImplicationManageability

Decision: JustificationImplication

Rationale: See source document for rationale

Implication: ILA-VAOL-CFG-016Connect VCF VI workload domains to Aria Ops for Logs via SDDC Manager.SDDC Manager auto-adds VI workload domain vCenter + ESXi hosts to Aria Ops for Logs.Non

Component: VAOL

ILA-VAOL-CFG-016Connect VCF VI workload domains to Aria Ops for Logs via SDDC Manager.Manageability

Decision: Connect VCF VI workload domains to Aria Ops for Logs via SDDC Manager.

Rationale: SDDC Manager auto-adds VI workload domain vCenter + ESXi hosts to Aria Ops for Logs.

Implication: None.

Component: VAOL

ILA-VAOL-CFG-017Install and configure Aria Ops for Logs agent on clustered Workspace ONE Access nodes.Manageability

Decision: Install and configure Aria Ops for Logs agent on clustered Workspace ONE Access nodes.

Rationale: Standardized agent config per W1A node for log collection.

Implication: None.

Component: VAOL

ILA-VAOL-CFG-018Configure the W1A agent group.Manageability

Decision: Configure the W1A agent group.

Rationale: Parse W1A-specific logs per file/format.

Implication: None.

Component: VAOL

ILA-VAOL-CFG-019JustificationImplicationManageability

Decision: JustificationImplication

Rationale: See source document for rationale

Implication: ILA-VAOL-CFG-026In multi-VCF, forward logs to other instance(s) vi

Component: VAOL

ILA-VAOL-CFG-020JustificationImplicationManageability

Decision: JustificationImplication

Rationale: See source document for rationale

Implication: ILA-VAOL-CFG-026In multi-VCF, forward logs to other instance(s) via Ingestion API (TCP).Supports structured/unstructured data with client-side compression; log throttl

Component: VAOL

ILA-VAOL-CFG-026In multi-VCF, forward logs to other instance(s) via Ingestion API (TCP).Manageability

Decision: In multi-VCF, forward logs to other instance(s) via Ingestion API (TCP).

Rationale: Supports structured/unstructured data with client-side compression; log throttling across clusters; preserves cross-instance log.

Implication: Requires firewall rules and network reachability between instances on the Ingestion API (TCP) port, and forwarded volume must be sized into the receiving cluster.

Component: VAOL

ILA-VAOL-CFG-027Configure log forwarding to use SSL on port 9543.Security

Decision: Configure log forwarding to use SSL on port 9543.

Rationale: Secure log forwarding.

Implication: Must set up a custom CA-signed SSL certificate; event forwarding with SSL does not work with the self-signed certificate.

Component: VAOL

Prerequisites

  • VCF version in Support Matrix (5.1.0-5.2.1)
  • Environment configured per Before You Apply This Guidance
  • Intelligent Logging and Analytics tab in VCF Planning and Preparation Workbook
  • VCF instance healthy and fully operational
  • DNS forward/reverse records for 3 nodes + ILB VIP
  • Active Directory with DCs, service accounts, security groups
  • Microsoft Certificate Authority available
  • Aria Suite Lifecycle deployed via SDDC Manager
  • 400 GB NFS shared storage for archival (if using 90-day archive)
  • IAM validated solution implemented (AD over LDAP in vCenter)
  • Optional: Workspace ONE Access (for vIDM auth) — this guidance uses AD over LDAP natively
  • PowerShell Automation
  • Workflow

Implementation Procedure

Implementation

Install PowerShell modules (PowerCLI 13.2.1+, vSphere.SsoAdmin 1.3.9+, ImportExcel 7.8.5+, PowerVCF 2.4.0+, PowerValidatedSolutions 2.11.0+)

Start-ValidatedSolutionMenu

Main menu 12. (ILA) Intelligent Logging and Analytics

  1. Generate JSON Specification File
  2. Verify Prerequisites
  3. Generate Signed Certificate from Microsoft Certificate Authority
  4. Replace the Certificate of Aria Suite Lifecycle Instance (import CA-signed)
  5. End-to-End Deployment (deploys Aria Ops for Logs cluster + configures content packs, agent groups, identity sources, role assignments, archival, alert SMTP, ILB, ping adapter, and — if multi-VCF — event forwarding)

UI Implementation Steps

  • Deploy Aria Suite Lifecycle from SDDC Manager (pre-req per LCM design)
  • In Aria Suite Lifecycle, download Aria Ops for Logs 8.18 product bundle
  • Create environment in Aria Suite Lifecycle; import OVA
  • Deploy 3-node cluster with ILB: specify primary/workers/ILB FQDNs and static IPs
  • Configure DNS records (A/PTR) for 3 nodes + ILB VIP
  • Configure NTP, DNS, time zone
  • Install CA-signed certificate via Suite Lifecycle locker
  • Configure AD over LDAP identity source (ILA-VAOL-SEC-001)
  • Assign AD groups to roles: Super Admin, User, View Only Admin (SEC-002/003/004)

Install content packs: VMware - NSX, VMware-Aria-Suite-Lifecycle-8.12+, Linux-Systemd, Workspace ONE Access (manual)

Configure agent groups: VMware Aria Suite Lifecycle, Photon OS, Workspace ONE Access

Add VI workload domains to Aria Ops for Logs via SDDC Manager (CFG-016)

Install and configure Aria Ops for Logs agent on clustered W1A nodes (CFG-017)

Configure log retention + archiving: 7 days retention, 90 days archive on 400 GB NFS share

Configure SMTP in Aria Ops for Logs for alert notifications (CFG-013)

Configure ping adapter for cluster health (CFG-019)

Multi-VCF: configure log forwarding between clusters via Ingestion API over SSL port 9543 (CFG-026/027)

Verify operational state (see Operations section)

External Services / Integration Points

Active Directory (AD)

Day-2 Operations Tasks

Operations

As needed

Personas

As needed

Persona: Log Admin

As needed

PersonaLog Admin

As needed

ResponsibilityFull Aria Ops for Logs admin

As needed

Mapping

As needed

Aria Ops For LogsSuper Admin

As needed

Persona: Log User

As needed

PersonaLog User

As needed

ResponsibilityUse dashboards and Explore Logs

As needed

Monitoring Points

  • Verify 3-node cluster status in Aria Ops for Logs UI (Admin > Cluster)
  • Verify ILB VIP resolves via DNS; UI accessible via VIP FQDN
  • Verify AD authentication: log in with AD user from Super Admin/User/View Only Admin groups
  • Verify ingestion from each source (ESXi/vCenter/NSX/Edge syslog; SDDC Manager/W1A/Aria Suite Lifecycle agent)
  • Verify content packs installed and dashboards populate
  • Verify retention: oldest logs trimmed at 7 days; archive building up on NFS
  • Verify SMTP alert delivery (trigger test alert)
  • Verify ping adapter health dashboard populates
  • Multi-VCF: verify logs from remote instance appear in local cluster via Explore Logs filter
  • Verify with browser: no cert warning on VIP FQDN

Likely Panelist Questions

Q: Why did you choose this architecture?

See design decisions for rationale

Failure Scenarios

3-node cluster with ILB vs standalone — justified: HA, 200 syslog conn support, N+1 node failures tolerated
Impact:
Mitigation:
One cluster per VCF instance (multi-VCF) — ensures local collection during cross-instance outages; trade-off: more mgmt overhead
Impact:
Mitigation:
Not configuring NFS archival storage — retention silently caps ingestion when archive fails
Impact:
Mitigation:
Using self-signed certificate for event forwarding — SSL forwarding fails silently
Impact:
Mitigation:
vSphere HA restarts nodes on host failure
Impact:
Mitigation:

Trade-off Analysis

Trade-Offs Analysis

Chosen:

Justification:

Using Aria Suite Lifecycle to change root/admin password — use SDDC Manager UI/API instead

Chosen:

Justification:

Quiz — Intelligent Logging & Analytics

0/15
Q1
How many nodes does the default Aria Ops for Logs cluster deployment contain?
  • 1
  • 2
  • 3 (1 primary + 2 workers)
  • 5
ILA-VAOL-CFG-001: 3-node cluster with 1 primary + 2 workers behind ILB.
Q2
Which component performs lifecycle management of Aria Ops for Logs in this solution?
  • SDDC Manager
  • VMware Aria Suite Lifecycle
  • Aria Ops for Logs self-LCM
  • kubectl
ILA-VAOL-LCM-001: Aria Suite Lifecycle manages binaries and upgrades.
Q3
Default retention period for a medium-size appliance?
  • 7 days
  • 30 days
  • 90 days
  • 365 days
7 days retention for medium appliance; 90 days archive on 400 GB NFS.
Q4
How is the ILB (Integrated Load Balancer) accessed by clients?
  • Directly on primary node
  • Via VIP FQDN + dedicated IP
  • Via NSX Tier-1 Gateway
  • Via vCenter VIP
ILA-VAOL-NET-005: ILB requires extra IP + FQDN; all ingestion/UI traffic routes via ILB VIP.
Q5
Which protocol/port is used for multi-VCF event forwarding in this design?
  • Syslog UDP/514
  • Syslog TCP/1514
  • Ingestion API over SSL port 9543
  • RELP TCP/20514
ILA-VAOL-CFG-026/027: Ingestion API over SSL port 9543 with custom CA-signed cert (not default self-signed).
Q6
Which content pack requires MANUAL installation (not auto-installed by default or by SDDC Manager)?
  • VMware - vSphere
  • VMware - NSX
  • Linux - Systemd
  • VMware Workspace ONE Access
ILA-VAOL-CFG-014: Workspace ONE Access content pack requires manual installation.
Q7
How is the root password of the Aria Ops for Logs appliance managed when deployed via VCF?
  • Aria Suite Lifecycle
  • SDDC Manager UI/API
  • vCenter SSO
  • Active Directory
ILA-VAOL-SEC-008: root password managed from SDDC Manager UI/API, NOT Aria Suite Lifecycle.
Q8
Which role gives a user full visibility into admin info but user-only actions?
  • Super Admin
  • User
  • View Only Admin
  • Dashboard User
View Only Admin = view admin info + full User access; user cannot modify admin settings.
Q9
In multi-AZ mgmt domain, which group is the Aria Ops for Logs cluster bound to?
  • Second AZ
  • First AZ host group
  • All AZs equally
  • Witness host
ILA-VAOL-CFG-006: cluster runs in first AZ; fails over to second AZ on AZ failure.
Q10
What happens when the NFS archive share is unavailable beyond the retention period?
  • Logs continue normally
  • Aria Ops for Logs stops ingesting new data until space/availability restored
  • Logs auto-migrate to vSAN
  • Cluster reboots
ILA-VAOL-CFG-010-012 implications: ingestion stops until NFS available with free space, or archiving is deactivated.
Q11
Which ingestion type is used for ESXi host logs?
  • Agent
  • Syslog
  • Ingestion API
  • SNMP trap
ESXi logs via syslog; vCenter/NSX/NSX Edge also via syslog. SDDC Manager/W1A/Aria Suite Lifecycle via agent.
Q12
Authentication transition from Workspace ONE Access to AD over LDAP — first step?
  • Remove W1A integration
  • Remove AD group assignments
  • Delete AD service account
  • Reboot cluster
Step 1: remove AD group assignments (added via W1A auth) before configuring AD over LDAP.
Q13
What is the minimum shared NFS storage recommended for a 90-day archive on a medium appliance?
  • 100 GB
  • 200 GB
  • 400 GB
  • 1 TB
Solution recommends 400 GB shared storage for log archival.
Q14
PowerValidatedSolutions menu option for ILA?
  • 04
  • 05
  • 11
  • 12
Main menu 12. (ILA) Intelligent Logging and Analytics.
Q15
Which alert type is deactivated by default in Aria Ops for Logs?
  • System alerts
  • Content pack alerts
  • User-defined alerts
  • All alerts
Content pack alerts deactivated by default; System alerts active for own health; User-defined active when created.

Flashcards — Intelligent Logging & Analytics

Card 1 of 15
Aria Ops for Logs cluster design
3-node: 1 primary + 2 workers behind Integrated Load Balancer (ILB); medium-sized appliances; deployed on management vSphere cluster.

Labs

Lab 1: Deploy 3-Node Aria Ops for Logs Cluster via Aria Suite Lifecycle

Deploy the 3-node medium-sized Aria Ops for Logs cluster with ILB in the management domain via Aria Suite Lifecycle.

Starting State: VCF 5.2 with Aria Suite Lifecycle deployed via SDDC Manager; DNS records for 3 nodes + ILB VIP; static IPs on local-instance NSX segment; NTP configured; CA-signed certificate available in Suite Lifecycle Locker.

Lab 2: Configure Content Packs, Agent Groups, and AD RBAC

Install content packs, configure agent groups for VCF components, and assign AD groups to Aria Ops for Logs roles.

Starting State: Cluster from Lab 1 online; AD security groups gg-vrli-admins, gg-vrli-users, gg-vrli-viewers created; vCenter has AD over LDAP IdP configured (from IAM solution); Workspace ONE Access deployed and AD-integrated.

Lab 3: Configure Multi-VCF Event Forwarding with SSL on Port 9543

In a two-VCF-instance Holodeck deployment, configure event forwarding between Aria Ops for Logs clusters with CA-signed SSL.

Starting State: Two VCF instances (sfo and lax); 3-node Aria Ops for Logs cluster per instance; CA-signed SSL certs installed on each cluster; identical medium sizing; inclusion/exclusion tags defined (for VCF instance differentiation).

Was this page useful?
Type to search. ↑ ↓ to move, Enter to open, Esc to close.