After you install the vRealize Log Insight agent on the Site Recovery Manager appliance, to start forwarding log events to vRealize Log Insight, configure the agent with the location of the vRealize Log Insight cluster, set the log ingestion API as the protocol for remote logging, and disable SSL-enabled log collection.

Procedure

  1. Log in to the Site Recovery Manager appliance by using a Secure Shell (SSH) client.
    Setting Value
    FQDN sfo01m01srm01.sfo01.rainpole.local
    User name admin
    Password srm_admin_password
  2. Open the liagent.ini file for editing by using a text editor such as vi.
    sudo vi /var/lib/loginsight-agent/liagent.ini
  3. Locate the [server] section, remove the comment for these parameters, insert the following values, and save the file.
    [server]
    hostname=sfo01vrli01.sfo01.rainpole.local
    
    ; Hostname or IP address of your Log Insight server / cluster load balancer. Default:
    ;hostname=LOGINSIGHT
    
    ; Protocol can be cfapi (Log Insight REST API), syslog, syslog_udp. Default:
    proto=cfapi
    
    ; Log Insight server port to connect to. Default ports for protocols:
    ; syslog and syslog_udp: 514; syslog with ssl: 6514; cfapi: 9000; cfapi with ssl: 9543. Default:
    port=9000
    
    ; SSL usage. Default:
    ssl=no
    ; Example of configuration with trusted CA:
    ;ssl=yes
    ;ssl_ca_path=/etc/pki/tls/certs/ca.pem
    
    ; Time in minutes to force reconnection to the server.
    ; This option mitigates imbalances caused by long-lived TCP connections. Default:
    ;reconnect=30
  4. Restart the vRealize Log Insight agent on the appliance.
    sudo systemctl restart liagentd
  5. Verify that the vRealize Log Insight agent is running on the appliance.
    sudo systemctl status liagentd
  6. Repeat this procedure for the Site Recovery Manager in region B using the following settings.
    Setting Value
    Site Recovery Manager lax01m01srm01.lax01.rainpole.local
    Log Insight lax01vrli01.lax01.rainpole.local