vRealize Log Insight collects log events from all management components in both regions of the SDDC.

Logical Design

In a multi-region Software-Defined Data Center (SDDC), deploy a vRealize Log Insight cluster in each region that consists of three nodes. This configuration allows for continued availability and increased log ingestion rates.

Figure 1. Logical Design of vRealize Log Insight


In this validated design, vRealize Log Insight retrieves log information from all management components in the dual-region SDDC. The Log Insight deployment consists of three nodes to accommodate the scale of the deployment.

Sources of Log Data

vRealize Log Insight collects logs as to provide monitoring information about the SDDC from a central location.

vRealize Log Insight collects log events from the following virtual infrastructure and cloud management components.

  • Management pod

    • Platform Services Controller

    • vCenter Server

    • ESXi hosts

  • Shared edge and compute pod

    • Platform Services Controller

    • vCenter Server

    • ESXi hosts

  • NSX for vSphere for the management cluster and for the shared compute and edge cluster

    • NSX Managers

    • NSX Controller instances

    • NSX Edge services gateway instances

    • NSX distributed logical router instances

    • NSX universal distributed logical router instances

    • NSX distributed firewall ESXi kernel module

  • vRealize Automation

    • vRealize Automation Appliance

    • vRealize IaaS Web Server

    • vRealize IaaS Management Server

    • vRealize IaaS DEM

    • vRealize Agent Servers

    • vRealize Orchestrator (embedded in the vRealize Automation Appliance)

    • Microsoft SQL Server

  • vRealize Business

    • vRealize Business server

    • vRealize Business data collectors

  • vRealize Operations Manager

    • Analytics cluster nodes

    • Remote collectors

  • vRealize Log Insight instance in the other region as a result of event forwarding