Intelligent Logging and Analytics for VMware Cloud Foundation
Provides centralized logging for VCF management and VI workload domains using VMware Aria Operations for Logs (formerly vRealize Log Insight) 8.18.0. Deploys a 3-node medium-sized Aria Operations for Logs cluster per VCF instance with Integrated Load Balancer (ILB) behind a VIP; syslog and agent-based log collection for ESXi, vCenter, NSX Manager, NSX Edge, SDDC Manager, Workspace ONE Access, VMware Aria Suite Lifecycle; content pack management; retention and archiving; event forwarding for multi-VCF deployments; AD-based RBAC.
Key Components: NSX, Aria Operations, Aria Automation, SDDC Manager, vCenter, ESXi, Workspace ONE
External dependencies: VMware Aria Operations for Logs 8.18.0 (deployed per VCF instance)
35 design decisions
| DD-ID | Decision | Quality |
|---|---|---|
| ILA-VAOL-NET-001 | JustificationImplication | Manageability |
Decision: JustificationImplication Rationale: See source document for rationale Implication: ILA-VAOL-NET-002Allocate statically a Component: VAOL | ||
| ILA-VAOL-NET-002 | JustificationImplication | Manageability |
Decision: JustificationImplication Rationale: See source document for rationale Implication: ILA-VAOL-NET-004Configure forward+reverse DNS for all cluster nodes + ILB VIP.FQDN-based access.Must provide DNS records. Component: VAOL | ||
| ILA-VAOL-NET-003 | JustificationImplication | Manageability |
Decision: JustificationImplication Rationale: See source document for rationale Implication: ILA-VAOL-NET-004Configure forward+reverse DNS for all cluster nodes + ILB VIP.FQDN-based access.Must provide DNS records. Component: VAOL | ||
| ILA-VAOL-NET-004 | JustificationImplication | Manageability |
Decision: JustificationImplication Rationale: See source document for rationale Implication: ILA-VAOL-NET-005Enable Aria Ops for Logs Integrated Load Balancer (ILB).Balances ingestion across nodes, provides HA.Must provide extra IP and FQDN for ILB. Component: VAOL | ||
| ILA-VAOL-NET-005 | JustificationImplication | Manageability |
Decision: JustificationImplication Rationale: See source document for rationale Implication: ILA-VAOL-NET-006Configure NTP on each cluster node.Aria Ops for Logs depends on time sync.None. Component: VAOL | ||
| ILA-VAOL-CFG-001 | Deploy a 3-node (1 primary + 2 workers) Aria Ops for Logs cluster. | AvailabilityManageability |
Decision: Deploy a 3-node (1 primary + 2 workers) Aria Ops for Logs cluster. Rationale: Provides high availability and 200 syslog connections support. Implication: Must deploy 3 VMs; ILB VIP FQDN + IP required. Component: VAOL | ||
| ILA-VAOL-CFG-002 | Deploy Aria Ops for Logs via Aria Suite Lifecycle. | AvailabilityManageability |
Decision: Deploy Aria Ops for Logs via Aria Suite Lifecycle. Rationale: Standard LCM workflow. Implication: Must deploy Aria Suite Lifecycle first (via SDDC Manager). Component: VAOL | ||
| ILA-VAOL-CFG-003 | Protect all Aria Ops for Logs VMs with vSphere HA. | Availability |
Decision: Protect all Aria Ops for Logs VMs with vSphere HA. Rationale: Supports availability objective. Implication: None. Component: VAOL | ||
| ILA-VAOL-CFG-004 | Apply vSphere Distributed Resource Scheduler anti-affinity to cluster nodes. | Manageability |
Decision: Apply vSphere Distributed Resource Scheduler anti-affinity to cluster nodes. Rationale: Ensure nodes run on separate hosts for fault tolerance. Implication: Must configure DRS rules. Component: VAOL | ||
| ILA-VAOL-CFG-005 | Place Aria Ops for Logs VMs in designated VM folder. | Manageability |
Decision: Place Aria Ops for Logs VMs in designated VM folder. Rationale: Inventory organization. Implication: Must create folder. Component: VAOL | ||
| ILA-VAOL-CFG-006 | With 2 AZs, bind Aria Ops for Logs cluster to first AZ hosts group. | Manageability |
Decision: With 2 AZs, bind Aria Ops for Logs cluster to first AZ hosts group. Rationale: Cluster runs in first AZ; fails over to second AZ on AZ failure. Implication: VM group update after second AZ deployed. Component: VAOL | ||
| ILA-VAOL-CFG-007 | In multi-VCF, deploy a separate Aria Ops for Logs cluster per VCF instance. | Manageability |
Decision: In multi-VCF, deploy a separate Aria Ops for Logs cluster per VCF instance. Rationale: Provides local Aria Ops for Logs per instance. Implication: Must deploy Aria Ops for Logs per VCF instance. Component: VAOL | ||
| ILA-VAOL-CFG-008 | IDILA-VAOL-CFG-009 | Manageability |
Decision: IDILA-VAOL-CFG-009 Rationale: See source document for rationale Implication: No significant trade-offs identified for this decision. Component: VAOL | ||
| ILA-VAOL-CFG-009 | Deploy each node sized Medium. | Manageability |
Decision: Deploy each node sized Medium. Rationale: See source document for rationale Implication: Must scale up for additional load. Component: VAOL | ||
| ILA-VAOL-SEC-001 | Activate integration with identity source via AD over LDAP. | ManageabilitySecurity |
Decision: Activate integration with identity source via AD over LDAP. Rationale: Authentication via identity source; role-based authorization for enterprise users/groups. Implication: None. Component: VAOL | ||
| ILA-VAOL-SEC-002 | Create security group in directory services for admins; assign Super Admin role. | ManageabilitySecurity |
Decision: Create security group in directory services for admins; assign Super Admin role. Rationale: Streamlines role mgmt; managed admin access; accountability. Implication: Create and maintain AD group outside SDDC stack. Component: VAOL | ||
| ILA-VAOL-SEC-003 | Create security group for users; assign User role.Streamlines role mgmt.Create and maintain AD group | ManageabilitySecurity |
Decision: Create security group for users; assign User role.Streamlines role mgmt.Create and maintain AD group. Rationale: ILA-VAOL-SEC-004Create security group for viewers; assign View Only Admin role.Streamlines role mgmt.Create and maintain AD group. Implication: Password Management Component: VAOL | ||
| ILA-VAOL-SEC-005 | Configure password expiration policy for each Aria Ops for Logs appliance. | Manageability |
Decision: Configure password expiration policy for each Aria Ops for Logs appliance. Rationale: Compliance alignment. Implication: Manage via appliance console or SSH. Component: VAOL | ||
| ILA-VAOL-SEC-006 | Configure password complexity policy. | Manageability |
Decision: Configure password complexity policy. Rationale: Compliance alignment. Implication: Manage via appliance console or SSH. Component: VAOL | ||
| ILA-VAOL-SEC-007 | Configure account lockout policy. | Manageability |
Decision: Configure account lockout policy. Rationale: Compliance alignment. Implication: Manage via appliance console or SSH. Component: VAOL | ||
| ILA-VAOL-SEC-008 | Change the root password on recurring schedule via SDDC Manager UI/API.Default password expires ever | ManageabilitySecurity |
Decision: Change the root password on recurring schedule via SDDC Manager UI/API.Default password expires every 365 days; root managed from SDDC Manager UI/API (NOT Aria Suite Lifecycle) when deployed in VCF vi Rationale: ILA-VAOL-SEC-009Change admin account password on recurring schedule via SDDC Manager UI/API.Admin password managed from SDDC Manager UI/API, NOT Aria Suite Lifecycle.Routine password change via SDDC M Implication: Certificate Management Component: VAOL | ||
| ILA-VAOL-CFG-010 | Configure retention for medium appliance = 7 days default. | Availability |
Decision: Configure retention for medium appliance = 7 days default. Rationale: Balances storage capacity and forensic availability. Implication: Adjust per compliance needs. Component: VAOL | ||
| ILA-VAOL-CFG-011 | Configure archive policy = 90 days. | Manageability |
Decision: Configure archive policy = 90 days. Rationale: Longer-term audit requirements. Implication: Requires 400 GB shared NFS storage. Component: VAOL | ||
| ILA-VAOL-CFG-012 | Configure 400 GB NFS shared storage for log archival.Supports 90-day archive.NFS mount must have eno | Manageability |
Decision: Configure 400 GB NFS shared storage for log archival.Supports 90-day archive.NFS mount must have enough free space; enforce archive policy directly on shared storage; in multi-AZ, NFS share available Rationale: Alert Notifications Design Implication: Alert Types Component: VAOL | ||
| ILA-VAOL-CFG-013 | Configure alert notifications. | Manageability |
Decision: Configure alert notifications. Rationale: See source document for rationale Implication: Must configure SMTP for email notifications. Component: VAOL | ||
| ILA-VAOL-LCM-001 | Use VMware Aria Suite Lifecycle to perform LCM of Aria Ops for Logs in each VCF instance. | ManageabilityPerformance |
Decision: Use VMware Aria Suite Lifecycle to perform LCM of Aria Ops for Logs in each VCF instance. Rationale: See source document for rationale Implication: Suite Lifecycle must be deployed via SDDC Manager; handles patches/updates/hotfixes. Component: VAOL | ||
| ILA-VAOL-CFG-014 | Install Linux-Systemd, VMware-NSX, VMware-Aria-Suite-Lifecycle-8.12+, VMware Workspace ONE Access co | Manageability |
Decision: Install Linux-Systemd, VMware-NSX, VMware-Aria-Suite-Lifecycle-8.12+, VMware Workspace ONE Access content packs. Rationale: Granular monitoring; W1A content pack requires manual install. Implication: Manual install of the Workspace ONE Access content pack is required; the remaining content packs are installed from the in-product marketplace. Component: VAOL | ||
| ILA-VAOL-CFG-015 | JustificationImplication | Manageability |
Decision: JustificationImplication Rationale: See source document for rationale Implication: ILA-VAOL-CFG-016Connect VCF VI workload domains to Aria Ops for Logs via SDDC Manager.SDDC Manager auto-adds VI workload domain vCenter + ESXi hosts to Aria Ops for Logs.Non Component: VAOL | ||
| ILA-VAOL-CFG-016 | Connect VCF VI workload domains to Aria Ops for Logs via SDDC Manager. | Manageability |
Decision: Connect VCF VI workload domains to Aria Ops for Logs via SDDC Manager. Rationale: SDDC Manager auto-adds VI workload domain vCenter + ESXi hosts to Aria Ops for Logs. Implication: None. Component: VAOL | ||
| ILA-VAOL-CFG-017 | Install and configure Aria Ops for Logs agent on clustered Workspace ONE Access nodes. | Manageability |
Decision: Install and configure Aria Ops for Logs agent on clustered Workspace ONE Access nodes. Rationale: Standardized agent config per W1A node for log collection. Implication: None. Component: VAOL | ||
| ILA-VAOL-CFG-018 | Configure the W1A agent group. | Manageability |
Decision: Configure the W1A agent group. Rationale: Parse W1A-specific logs per file/format. Implication: None. Component: VAOL | ||
| ILA-VAOL-CFG-019 | JustificationImplication | Manageability |
Decision: JustificationImplication Rationale: See source document for rationale Implication: ILA-VAOL-CFG-026In multi-VCF, forward logs to other instance(s) vi Component: VAOL | ||
| ILA-VAOL-CFG-020 | JustificationImplication | Manageability |
Decision: JustificationImplication Rationale: See source document for rationale Implication: ILA-VAOL-CFG-026In multi-VCF, forward logs to other instance(s) via Ingestion API (TCP).Supports structured/unstructured data with client-side compression; log throttl Component: VAOL | ||
| ILA-VAOL-CFG-026 | In multi-VCF, forward logs to other instance(s) via Ingestion API (TCP). | Manageability |
Decision: In multi-VCF, forward logs to other instance(s) via Ingestion API (TCP). Rationale: Supports structured/unstructured data with client-side compression; log throttling across clusters; preserves cross-instance log. Implication: Requires firewall rules and network reachability between instances on the Ingestion API (TCP) port, and forwarded volume must be sized into the receiving cluster. Component: VAOL | ||
| ILA-VAOL-CFG-027 | Configure log forwarding to use SSL on port 9543. | Security |
Decision: Configure log forwarding to use SSL on port 9543. Rationale: Secure log forwarding. Implication: Must set up a custom CA-signed SSL certificate; event forwarding with SSL does not work with the self-signed certificate. Component: VAOL | ||
Prerequisites
- VCF version in Support Matrix (5.1.0-5.2.1)
- Environment configured per Before You Apply This Guidance
- Intelligent Logging and Analytics tab in VCF Planning and Preparation Workbook
- VCF instance healthy and fully operational
- DNS forward/reverse records for 3 nodes + ILB VIP
- Active Directory with DCs, service accounts, security groups
- Microsoft Certificate Authority available
- Aria Suite Lifecycle deployed via SDDC Manager
- 400 GB NFS shared storage for archival (if using 90-day archive)
- IAM validated solution implemented (AD over LDAP in vCenter)
- Optional: Workspace ONE Access (for vIDM auth) — this guidance uses AD over LDAP natively
- PowerShell Automation
- Workflow
Implementation Procedure
Implementation
Install PowerShell modules (PowerCLI 13.2.1+, vSphere.SsoAdmin 1.3.9+, ImportExcel 7.8.5+, PowerVCF 2.4.0+, PowerValidatedSolutions 2.11.0+)
Start-ValidatedSolutionMenu
Main menu 12. (ILA) Intelligent Logging and Analytics
- Generate JSON Specification File
- Verify Prerequisites
- Generate Signed Certificate from Microsoft Certificate Authority
- Replace the Certificate of Aria Suite Lifecycle Instance (import CA-signed)
- End-to-End Deployment (deploys Aria Ops for Logs cluster + configures content packs, agent groups, identity sources, role assignments, archival, alert SMTP, ILB, ping adapter, and — if multi-VCF — event forwarding)
UI Implementation Steps
- Deploy Aria Suite Lifecycle from SDDC Manager (pre-req per LCM design)
- In Aria Suite Lifecycle, download Aria Ops for Logs 8.18 product bundle
- Create environment in Aria Suite Lifecycle; import OVA
- Deploy 3-node cluster with ILB: specify primary/workers/ILB FQDNs and static IPs
- Configure DNS records (A/PTR) for 3 nodes + ILB VIP
- Configure NTP, DNS, time zone
- Install CA-signed certificate via Suite Lifecycle locker
- Configure AD over LDAP identity source (ILA-VAOL-SEC-001)
- Assign AD groups to roles: Super Admin, User, View Only Admin (SEC-002/003/004)
Install content packs: VMware - NSX, VMware-Aria-Suite-Lifecycle-8.12+, Linux-Systemd, Workspace ONE Access (manual)
Configure agent groups: VMware Aria Suite Lifecycle, Photon OS, Workspace ONE Access
Add VI workload domains to Aria Ops for Logs via SDDC Manager (CFG-016)
Install and configure Aria Ops for Logs agent on clustered W1A nodes (CFG-017)
Configure log retention + archiving: 7 days retention, 90 days archive on 400 GB NFS share
Configure SMTP in Aria Ops for Logs for alert notifications (CFG-013)
Configure ping adapter for cluster health (CFG-019)
Multi-VCF: configure log forwarding between clusters via Ingestion API over SSL port 9543 (CFG-026/027)
Verify operational state (see Operations section)
External Services / Integration Points
Active Directory (AD)
Day-2 Operations Tasks
Operations
As neededPersonas
As neededPersona: Log Admin
As neededPersonaLog Admin
As neededResponsibilityFull Aria Ops for Logs admin
As neededMapping
As neededAria Ops For LogsSuper Admin
As neededPersona: Log User
As neededPersonaLog User
As neededResponsibilityUse dashboards and Explore Logs
As neededMonitoring Points
- Verify 3-node cluster status in Aria Ops for Logs UI (Admin > Cluster)
- Verify ILB VIP resolves via DNS; UI accessible via VIP FQDN
- Verify AD authentication: log in with AD user from Super Admin/User/View Only Admin groups
- Verify ingestion from each source (ESXi/vCenter/NSX/Edge syslog; SDDC Manager/W1A/Aria Suite Lifecycle agent)
- Verify content packs installed and dashboards populate
- Verify retention: oldest logs trimmed at 7 days; archive building up on NFS
- Verify SMTP alert delivery (trigger test alert)
- Verify ping adapter health dashboard populates
- Multi-VCF: verify logs from remote instance appear in local cluster via Explore Logs filter
- Verify with browser: no cert warning on VIP FQDN
Likely Panelist Questions
Q: Why did you choose this architecture?
See design decisions for rationale
Failure Scenarios
Trade-off Analysis
Trade-Offs Analysis
Chosen:
Justification:
Using Aria Suite Lifecycle to change root/admin password — use SDDC Manager UI/API instead
Chosen:
Justification:
Quiz — Intelligent Logging & Analytics
- 1
- 2
- 3 (1 primary + 2 workers)
- 5
- SDDC Manager
- VMware Aria Suite Lifecycle
- Aria Ops for Logs self-LCM
- kubectl
- 7 days
- 30 days
- 90 days
- 365 days
- Directly on primary node
- Via VIP FQDN + dedicated IP
- Via NSX Tier-1 Gateway
- Via vCenter VIP
- Syslog UDP/514
- Syslog TCP/1514
- Ingestion API over SSL port 9543
- RELP TCP/20514
- VMware - vSphere
- VMware - NSX
- Linux - Systemd
- VMware Workspace ONE Access
- Aria Suite Lifecycle
- SDDC Manager UI/API
- vCenter SSO
- Active Directory
- Super Admin
- User
- View Only Admin
- Dashboard User
- Second AZ
- First AZ host group
- All AZs equally
- Witness host
- Logs continue normally
- Aria Ops for Logs stops ingesting new data until space/availability restored
- Logs auto-migrate to vSAN
- Cluster reboots
- Agent
- Syslog
- Ingestion API
- SNMP trap
- Remove W1A integration
- Remove AD group assignments
- Delete AD service account
- Reboot cluster
- 100 GB
- 200 GB
- 400 GB
- 1 TB
- 04
- 05
- 11
- 12
- System alerts
- Content pack alerts
- User-defined alerts
- All alerts
Flashcards — Intelligent Logging & Analytics
Labs
Lab 1: Deploy 3-Node Aria Ops for Logs Cluster via Aria Suite Lifecycle
Deploy the 3-node medium-sized Aria Ops for Logs cluster with ILB in the management domain via Aria Suite Lifecycle.
Starting State: VCF 5.2 with Aria Suite Lifecycle deployed via SDDC Manager; DNS records for 3 nodes + ILB VIP; static IPs on local-instance NSX segment; NTP configured; CA-signed certificate available in Suite Lifecycle Locker.
Lab 2: Configure Content Packs, Agent Groups, and AD RBAC
Install content packs, configure agent groups for VCF components, and assign AD groups to Aria Ops for Logs roles.
Starting State: Cluster from Lab 1 online; AD security groups gg-vrli-admins, gg-vrli-users, gg-vrli-viewers created; vCenter has AD over LDAP IdP configured (from IAM solution); Workspace ONE Access deployed and AD-integrated.
Lab 3: Configure Multi-VCF Event Forwarding with SSL on Port 9543
In a two-VCF-instance Holodeck deployment, configure event forwarding between Aria Ops for Logs clusters with CA-signed SSL.
Starting State: Two VCF instances (sfo and lax); 3-node Aria Ops for Logs cluster per instance; CA-signed SSL certs installed on each cluster; identical medium sizing; inclusion/exclusion tags defined (for VCF instance differentiation).