Implementation of intelligent logging and analytics includes connecting vCenter Server, NSX-T Data Center, and Workspace ONE Access to a vRealize Log Insight cluster that you deploy using vRealize Suite Lifecycle Manager.
During the deployment, SDDC Manager connects vRealize Log Insight to some of the management components in the management domain. You complete the integration with the SDDC management stack by manually configuring the integration with the NSX Edge nodes and the clustered Workspace ONE Access instance.
For information on the intelligent logging and analytics design, see
Detailed Design of Intelligent Logging and Analytics for VMware Cloud Foundation.
If you want to use the PowerShell procedures for portions of the implementation, verify that your system fulfills the following prerequisites.
Verify that your system has Microsoft PowerShell 5.1 installed. See
PowerValidatedSolutions PowerShell module together with the supporting modules from the PowerShell Gallery by running the following commands. Install-Module -Name VMware.PowerCLI -MinimumVersion 12.4.1
Install-Module -Name VMware.vSphere.SsoAdmin -MinimumVersion 1.3.7
Install-Module -Name ImportExcel -MinimumVersion 7.1.1
Install-Module -Name PowerVCF -MinimumVersion 2.2.0
Install-Module -Name PowerValidatedSolutions -MinimumVersion 1.9.0
PowerValidatedSolutions and the PowerCLI PowerShell modules by running the following commands. Import-Module -Name VMware.PowerCLI -MinimumVersion 12.4.1
Import-Module -Name PowerValidatedSolutions -MinimumVersion 1.9.0
Deployment of vRealize Log Insight Deploy vRealize Log Insight in a cluster configuration of three nodes. This configuration is set up with an integrated load balancer and uses one primary and two worker nodes.
Connect a VI Workload Domain to vRealize Log Insight SDDC Manager automatically integrates vRealize Log Insight to the management components in the management domain. To collect logs from the management components in a VI workload domain, connect vRealize Log Insight to the VI workload domain by using the SDDC Manager UI.
Configure the NSX Edge Nodes to Forward Log Events to vRealize Log Insight To configure the NSX Edge nodes to send audit logs and system events to vRealize Log Insight, you use the NSX Manager UI to retrieve the NSX Edge node ID, then send an HTTP post request to the NSX Edge request URL with the necessary configuration.
Configure Log Forwarding for the Clustered Workspace ONE Access Instance To collect log data from the clustered Workspace ONE Access instance, you install and configure the vRealize Log Insight agent on the Workspace ONE Access nodes and configure the vRealize Log Insight agent group.
Create a vRealize Log Insight Photon OS Agent Group for the Management Nodes SDDC Manager installs the Linux - Systemd content pack that is designed for Photon OS. You create and configure an agent group to apply common settings to the agents on the appliances in the VMware Cloud Foundation instance.
Create Alerts in vRealize Log Insight To activate alerts for each component, use the built-in problem and alert signatures in vRealize Log Insight. For each alert, you create one instance for the management domain and one instance per VI workload domain. If vRealize Operations Manager is integrated into your environment, you map these alerts to the vRealize Operations Manager inventory.
Configure Event Forwarding Between VMware Cloud Foundation Instances To retain log collection in a VMware Cloud Foundation environment with two or more instances in case of a disaster, you configure log event forwarding in vRealize Log Insight.