top of page


VMware Aria Suite Updates
Last night VMware dropped several new releases, here they are! Aria Operations 8.14 and Aria Operations SaaS (October 2023) What's New Blog 8.14 Release Notes SaaS October 2023 Release Notes Aria Operations for Logs 8.14 and Aria Operations for Logs SaaS (October 2023) What's New Blog Release Notes Aria Automation 8.14 and Aria Automation SaaS (October 2023) What's New Blog Release Notes Aria Suite Lifecycle 8.14 What's New Blog Release Notes First, let's upgrade Ari

Brock Peterson
Oct 20, 2023


Keeping Logs with VMware Aria Operations for Logs SaaS
VMware Aria Operations for Logs SaaS has been activated, you've deployed an on-prem Cloud Proxy and are now collecting data. As per the...

Brock Peterson
Oct 1, 2023


VMware Aria Operations for Logs Content Pack for Microsoft Active Directory
There are 80+ Aria Operations for Logs Content Packs available on the Marketplace and they are all free! This blog will discuss the...

Brock Peterson
Sep 18, 2023


VMware Aria Operations for Logs as a Syslog Destination
VMware Aria Operations for Logs has been deployed, you've configured your vSphere integration/s, mine look like this. The checkbox for...

Brock Peterson
Aug 17, 2023


Log Filtering with VMware Aria Operations for Logs SaaS
You have logs coming into VMware Aria Operations for Logs SaaS, maybe too many logs, how to filter what you need? Log Processing Rules!...

Brock Peterson
Apr 3, 2023


Capture VM Reboots with VMware Aria Operations
VMs reboot all the time and while most often you won't care, there are times you want to be notified. How can we use VMware Aria...

Brock Peterson
Feb 12, 2023


VMware Aria Operations for Logs Data Sets
VMware Aria Operations for Logs (formerly vRealize Log Insight or vRLI) is a powerful logging platform. It can ingest logs from vCenter, ESXi Hosts, Syslog Sources, and more. But what if I want certain users to see only certain logs? Say for example, I want to give a user access to see only logs for certain VMs? We'll use Data Sets , let's explore! You've deployed VMware Aria Operations for Logs and are sending logs from vCenter, ESXi Hosts, and more. You're seeing all l

Brock Peterson
Feb 5, 2023


VMware Aria Operations for Logs Authentication using Microsoft Active Directory
VMware Aria Operations for Logs (formerly vRealize Log Insight) is up and running and I've been logging in directly with the local admin...

Brock Peterson
Jan 19, 2023


Send VMware Aria Operations for Logs Alerts to Slack
In our previous post we detailed how to send VMware Aria Operations (formerly vRealize Operations) Alerts to Slack . This blog will detail how to send VMware Aria Operations for Logs (formerly vRealize Log Insight) Alerts to Slack. We can use the same Slack Webhook URL we set up previously, so this should be a bit easier. Log into Aria Operations for Logs and go to Alerts - Webhook - NEW WEBHOOK. I've given my new Webhook a name, selected Slack from the Endpoint dropdown (t

Brock Peterson
Dec 19, 2022


VMware Aria Operations SaaS, Aria Operations for Logs SaaS, and their Cloud Proxies
VMware Aria Operations SaaS and VMware Aria Operations for Logs SaaS Services have been activated, you've deployed Cloud Proxies (CP) for...

Brock Peterson
Dec 14, 2022


vROps and vRLI Integrations
vROps has been deployed, vRLI is up and running, let's integrate them! In vROps, to integrate with vRLI, you activate the vRLI...

Brock Peterson
Jul 21, 2022


Send vRLI Alerts to Microsoft Teams
Today we can send vRLI Alerts to vROps, we can generate emails on them, and there are out of the box Webhooks for Slack, Pager Duty, and vRO. What about Microsoft Teams? Well, we can create a custom Webhook for it, so what does that look like. Let's first generate a TEAMs URL to which we will point our Webhook. Go to Teams, select your Team, then go to the three dots top right. Select Connectors. Click Add and then Add which will add the Incoming Webhook to the Channel. W

Brock Peterson
Jun 12, 2022


vRLI Cloud: KB Insights, Live Tail, and Log RCA
VMware vRealize Log Insight Cloud (vRLI Cloud) was introduced back in 2020. Since then VMware has released new versions on a roughly...

Brock Peterson
May 29, 2022


Searching Index Partitions in vRLI 8.8!
VMware vRealize Log Insight (vRLI) 8.1 introduced Index Partitions with customizable retention periods, giving us the ability to put logs in certain partitions and keep them as long as we'd like. vRLI 8.4 gave us the ability to archive individual Index Partitions via NFS, which looks like this. vRLI 8.8 brings us the ability to query Index Partitions! Before digging into this new feature, let's take a step back and look at the larger picture. Index Partitions are general

Brock Peterson
May 28, 2022


Extract Fields with vRealize Log Insight
VMware vRealize Log Insight (vRLI) is a powerful logging tool with all sorts of capabilities, one of them being the ability to extract fields from log entries. Out of the box, each vRLI log entry will contain certain fields like source, event_type, file path, hostname, and more. They are documented here. Beyond those, there are Extracted Fields, which are user defined or Content Pack defined fields extracted from log entries. For example, the VMware vSphere Content Pack c

Brock Peterson
Apr 24, 2022


Send Oracle Database Logs to vRLI
vRLI is up and running, you're getting vCenter Alarms, Events, and Tasks, ESXi Host Logs, but you want more! Specifically, you want your Oracle Database logs. There is a Content Pack available in the Marketplace, but there is some work required and a necessary adjustment to the included Event Marker (REGEX). Let's start by asking the DBA to turn on Oracle Listener logging and Oracle Alert logging. We'll need the path to and the names of these logs, as they are what we will

Brock Peterson
Apr 23, 2022


Capture Certificate Expirations with vRLI
vRLI is up and running, you're collecting vCenter events, tasks and alarms, as well as ESXi Host logs. In addition, vRLI is receiving logs from F5 BIG-IP, Citrix NetScaler, NetApp FAS, and more. Let's use it to capture Certificates that have expired and Certificates that will be expiring. A quick look at my environment shows the following entries, in this case coming from F5 BIG-IP. Remember that the vRLI query language uses the logical "and" operator for phrases, in this c

Brock Peterson
Apr 17, 2022


vRLI and the Cisco UCS Content Pack
I'd like to start bringing Cisco UCS logs into my vRLI environment, here's how I did it. Go to Content Packs - Marketplace and look for Cisco UCS. There are dozens of other Content Packs available here as well. As a note, I'm using vROps 8.6.2, UCSM 4.1(1b), and the 2.0 Version of the Cisco UCS Content Pack in this blog. Select it and click INSTALL. Once installed, you'll be given instructions on how to enable log forwarding via UCS Manager. Clicking the link takes you to

Brock Peterson
Mar 19, 2022


Discover Guest OS Crashes with vRLI and send Alerts to vROps!
We've deployed vRLI, configured our vCenters and ESXi Hosts to send logs to it and now we want to use it to find VMs that have crashed. Let's do it! Go to Interactive Analytics and search for "guest operating system has crashed". I've found five log entries with this string since I started collecting data (notice the All time dropdown top right). As you hover over the Source you'll see the log source. You can also colorize by source by clicking the source link, which is qu

Brock Peterson
Mar 17, 2022


vRLI Cloud, the Cloud Proxy, and the Log Forwarder
If you're using any of the vRealize Suite Cloud offerings, you are running Cloud Proxies (CP) in your Private Cloud. These sit in your on-prem Datacenter and act as the gateway from the Cloud into your environment. Each of the vRealize Suite Cloud offerings (vROps, vRLI, vRA, and vRNI) has its own CP (or Collector VM in the case of vRNI), we will focus on the vRLI CP here, but let's take a step back and consider all of them first. A standard deployment might look something

Brock Peterson
Jan 17, 2022


Capturing Logs with the vRLI Linux Agent
You've designed and deployed your vRLI Cluster, you've configured it to collect logs from your vCenters and ESXi Hosts, but you want more. Specifically, you want to collect logs from your Linux VMs. Well, we can do that with the vRLI Linux Agent. In a previous blog , we discussed the vRLI Windows Agent and how to use that to collect Windows Events. This blog will be the Linux analog to that one. Before getting into the details, let's take a look from above. Your vRLI Clus

Brock Peterson
Oct 27, 2021


vRealize 8.6 Updates via vRSLCM
Beyond vROps, vRLI, and vRA, the vRealize Suite comes packaged with the vRealize Suite Lifecycle Manager (vRSLCM). It's the vRealize...

Brock Peterson
Oct 16, 2021


vRealize Cloud Management Updates
Yesterday was a big day! We released new versions of every product in our vRealize Suite: vROps, vRLI, vRA, vRNI, and vRSLCM. Here are...

Brock Peterson
Oct 13, 2021


Windows Events with VMware vRealize Log Insight
I'd like to know which Windows Servers in my environment have seen EventID 4740 in their Security Log, indicating a user account has been...

Brock Peterson
May 23, 2021
bottom of page



