VMware Aria Operations for Logs (SaaS) provides built-in system alerts for critical issues that need your immediate attention or activities that you must be aware of. A system alert is triggered when the system wants to notify you about a problem and also when the problem is resolved.

You can view the system alerts when you expand the main menu and select Configuration > System Alerts. If you are an administrator, you can use a toggle to enable or deactivate a system alert in the System Alerts page. You can also configure email and webhook notifications for the enabled alerts in this page:

VMware Aria Operations for Logs (SaaS) provides the following system alerts:

Alert Description Action Required
Cloud Proxy Dropping Logs The Cloud Proxy or Cloud Native Collector configured to send logs to the VMware Aria Operations for Logs (SaaS) service is dropping logs. Logs are dropped because of a latency between the Cloud Proxy or Cloud Native Collector and the service, or because the Cloud Proxy or Cloud Native Collector is under a heavy load. Ensure that:
  • The Cloud Proxy or Cloud Native Collector is resourced correctly.
  • There is no high latency between the Cloud Proxy or Cloud Native Collector and the VMware Aria Operations for Logs (SaaS) service.
Failure to Forward Logs VMware Aria Operations for Logs (SaaS) cannot forward logs to the endpoint because the endpoint is not accessible or under a heavy load. If you are an administrator, verify the following:
  • The log forwarding endpoint configuration is correct.
  • If the destination for the log forwarding configuration is Cloud, ensure that the log forwarding endpoint is accessible across the Internet.
  • If the destination for the log forwarding configuration is On Premise, ensure that the log forwarding endpoint is accessible to the Cloud Proxy configured to forward logs.
Inactive Cloud Proxy The connection between the Cloud Proxy or Cloud Native Collector and the VMware Aria Operations for Logs (SaaS) service is broken. Ensure that:
  • The Cloud Proxy or Cloud Native Collector is resourced correctly.
  • The Cloud Proxy or Cloud Native Collector can connect to the VMware Aria Operations for Logs (SaaS) service.
Inactive VMware Aria Operations for Logs Agent The VMware Aria Operations for Logs Agent cannot communicate with VMware Aria Operations for Logs (SaaS). If you are an administrator, ensure that:
  • The Cloud Proxy or Cloud Native Collector is up and running.
  • The VMware Aria Operations for Logs Agent is running.
  • The VMware Aria Operations for Logs Agent is able to reach the Cloud Proxy or Cloud Native Collector.
Ingestion Delay There is a delay in viewing and querying the data collected by VMware Aria Operations for Logs (SaaS). The delay might be because of indexing taking more time or a planned maintenance window. None.
Ingestion Failures at Cloud Proxy The Cloud Proxy or Cloud Native Collector fails to forward all incoming messages to VMware Aria Operations for Logs (SaaS). Messages are not forwarded because of a latency between the Cloud Proxy or Cloud Native Collector and the service, or because the Cloud Proxy or Cloud Native Collectoris under a heavy load. Ensure that:
  • The Cloud Proxy or Cloud Native Collector is resourced correctly.
  • There is no high latency between the Cloud Proxy or Cloud Native Collector and the VMware Aria Operations for Logs (SaaS) service.
Ingestion Quota Exceeded You have exceeded your ingestion limit for the day and no more logs are ingested for the day. Ingestion will begin again at the start of the next day (PST time zone). None.
Log Forwarding Disabled Temporarily Log forwarding is temporarily deactivated for the next few minutes. Too many log forwarding failures have been detected for the configured endpoint, within the time window of the last three minutes.
Note: This system alert is enabled by default. You cannot deactivate it.
If you are an administrator, verify the following:
  • The log forwarding endpoint configuration is correct.
  • If the destination for the log forwarding configuration is Cloud, ensure that the log forwarding endpoint is accessible across the Internet.
Log Forwarding Disabled Log forwarding is deactivated for the configured endpoint due to the inability to establish a connection.
Note: This system alert is enabled by default. You cannot deactivate it.
If you are an administrator, verify the following:
  • The log forwarding endpoint configuration is correct.
  • If the destination for the log forwarding configuration is Cloud, ensure that the log forwarding endpoint is accessible across the Internet.
Daily Ingestion Alert The daily log ingestion volume has exceeded the configured warning or critical threshold values.
Monthly Ingestion Alert The monthly log ingestion volume has exceeded the configured warning or critical threshold values.
Important:

The Cloud Proxy is deprecated. You can continue to use your existing Cloud Proxy configurations, but there will be no new feature updates to the Cloud Proxy.