Use the vRealize Log Insight known event signature engine to monitor key events. You can use a set of alerts to send to vRealize Operations Manager and through SMTP for operations team notification.
With the integration between vRealize Log Insight and vRealize Operations Manager you can implement the following cross-product event tracking:
Send alerts from vRealize Log Insight to vRealize Operations Manager, which maps them to the target objects.
Launch in context from a vRealize Operations Manager object to the objects logs in vRealize Log Insight.
Launch in context from a vRealize Log Insight event to the objects in vRealize Operations Manager.
For applications that are failed over between regions, such as vRealize Automation and vRealize Operations Manager, configure alerting in both regions to avoid missing any alerts when applications move between regions.
Procedure
View the Full List of Alerts for a Management Product Explore alerts and queries that are available in vRealize Log Insight for the management products in the SDDC such as vSphere, NSX for vSphere, vRealize Automation, and so on. Content packs for these products handle the alerts and queries.
Enable the Alerts for vSphere Resources Use the built-in problem and alert signatures in vRealize Log Insight for an ESXi host and a vCenter Server to enable alerts for these components and map these alerts to the vRealize Operations Manager inventory. For each alert, you create one instance for the management data center and one instance for the shared edge and compute data center in each region.
Enable the Alerts for vSphere Networking Use the in-built problem and alert signatures in vRealize Log Insight and create alerts for network-related events and map them to the vRealize Operations Manager inventory. For each alert, you create one instance for the management data center and one instance for the shared edge and compute data center in each region.
Enable the Alerts for Storage Resources Use the built-in problem and alert signatures in vRealize Log Insight to create alerts about storage and map these alerts to the vRealize Operations Manager inventory. For each alert, you create one instance for the management data center and one instance for the shared edge and compute data center in each region.
Enable the Alerts for vSAN Use the built-in problem and alert signatures in vRealize Log Insight to create alerts for vSAN monitoring and map them to the vRealize Operations Manager inventory. For each alert, you create one instance for the management data center in each region. This validated design uses vSAN only for the SDDC management components. If you use vSAN also for your tenant workloads, configure alerts accordingly.
Enable the Alerts for NSX for vSphere Create alerts using the in-built problem and alert signatures in vRealize Log Insight for NSX for vSphere and direct them to the vRealize Operations Manager inventory. For each alert, you create one instance for the NSX Manager for the management cluster and one instance for the NSX Manager for the shared edge and compute cluster in the region.
Enable the Alerts for vRealize Operations Manager Use the built-in problem and alert signatures in vRealize Log Insight for vRealize Operations Manager. You create one instance of each alert in Region A and in Region B because the vRealize Operations Manager instance works in the context of both management and compute resources in each region. The SDDC also contains one analytics cluster that is failed over to Region B and you receive alerts only about it.
Enable the Alerts for vRealize Automation Use the in-built problem and alert signatures in vRealize Log Insight for vRealize Automation. You create one instance of each alert in Region A and in Region B because the vRealize Automation instance in the SDDC works in the context of the compute resources in each region. The environment also contains one vRealize Automation deployment that is failed over to Region B and you receive alerts only about it.
Enable the Alerts for Microsoft SQL Server for vRealize Automation Use the built-in problem and alert signatures in vRealize Log Insight for the Microsoft SQL Server for vRealize Automation. For each alert, you create one instance for each region so that alerts are still available if the Microsoft SQL Server instance is failed over to Region B.