Deploy vRealize Log Insight in a cluster configuration of three nodes. This configuration is set up with an integrated load balancer and uses one primary and two worker nodes.
Procedure
Deploy vRealize Log Insight in Region A Start the deployment of vRealize Log Insight in Region A by deploying the primary and worker nodes and forming the vRealize Log Insight cluster.
Integrate vRealize Log Insight with the Region-Specific Workspace ONE Access in Region A To propagate user roles in vRealize Log Insight that are maintained centrally and are inline with the other solutions in the SDDC, configure vRealize Log Insight to use the region-specific Workspace ONE Access instance as an authentication source.
Connect vRealize Log Insight to the vSphere Environment in Region A Start collecting log information about the ESXi and vCenter Server instances in the SDDC.
Connect vRealize Log Insight to vRealize Operations Manager in Region A Connect vRealize Log Insight to vRealize Operations Manager so that you can use the Launch in Context functionality between the two applications to troubleshoot management nodes and vRealize Operations Manager by using dashboards and alerts in the vRealize Log Insight user interface.
Connect vRealize Log Insight to NSX Data Center for vSphere in Region A Install and configure the vRealize Log Insight content pack for log visualization and alerting of the NSX Data Center for vSphere real-time operation. You can use the NSX-vSphere dashboards to monitor logs about installation and configuration, and about virtual networking services in the management and workload domains.
Connect vRealize Log Insight to NSX-T Data Center in Region A If you deployed NSX-T Data Center in the workload domain, you connect vRealize Log Insight to the NSX-T Data Center components to start collecting log information.
Download the vRealize Log Insight Agent You download the vRealize Log Insight agent, so that later you install this agent on the Workspace ONE Access nodes.
Install and Configure the vRealize Log Insight Agent on the Workspace ONE Access Nodes Install and configure the vRealize Log Insight agent on each Workspace ONE Access node to send audit logs and system events to vRealize Log Insight.
Configure Log Forwarding for vRealize Suite Lifecycle Manager in Region A You configure vRealize Suite Lifecycle Manager to forward logs to vRealize Log Insight.
Validate Log Forwarding for SDDC Manager in Region A The VMware Cloud Foundation 3.10 bring-up process installs and configures the vRealize Log Insight agent in the SDDC Manager appliance. Validate that the vRealize Log Insight аgent in the SDDC Manager appliance is configured to forward logs to the newly deployed vRealize Suite 2019 vRealize Log Insight.
Collect Operating System Logs from the Management Virtual Appliances in vRealize Log Insight in Region A To visualize and analyze operating system logs from the management virtual appliances, you install and configure the vRealize Log Insight content packs for Linux. For the Workspace ONE Access appliance, you install and configure the general content pack for Linux. For the remaining management appliances, you install and configure the content pack that is designed for Photon OS.
Configure Log Retention and Archiving for vRealize Log Insight in Region A Set the retention notification threshold to one week. Enable data archiving, so that you can manually archive logs for 90 days and selectively clean the datastore when free space is required.