top of page


VMware Aria Suite Updates
Last night VMware dropped several new releases, here they are! Aria Operations 8.14 and Aria Operations SaaS (October 2023) What's New Blog 8.14 Release Notes SaaS October 2023 Release Notes Aria Operations for Logs 8.14 and Aria Operations for Logs SaaS (October 2023) What's New Blog Release Notes Aria Automation 8.14 and Aria Automation SaaS (October 2023) What's New Blog Release Notes Aria Suite Lifecycle 8.14 What's New Blog Release Notes First, let's upgrade Aria Suite

Brock Peterson
Oct 20, 2023


Keeping Logs with VMware Aria Operations for Logs SaaS
VMware Aria Operations for Logs SaaS has been activated, you've deployed an on-prem Cloud Proxy and are now collecting data. As per the terms of service, logs are kept for 30 days, but what if you want to keep them longer than 30 days? We'll use Log Partitions do it, here's how! Aria Operations for Logs SaaS uses two types of storage: Indexed Storage: this is what supports your default partition and where the latest 30 days of logs are kept. It runs on high performance AWS

Brock Peterson
Oct 1, 2023


VMware Aria Operations for Logs Content Pack for Microsoft Active Directory
There are 80+ Aria Operations for Logs Content Packs available on the Marketplace and they are all free! This blog will discuss the Content Pack for Microsoft Active Directory. Find the tile in the Marketplace and install it, once installed it'll show under the Installed Content Packs list. As indicated, we'll be capturing AD logs via the Windows Event Logs, which means we'll be using Agents. There are four configuration times to be done (detailed in the Setup Instructions

Brock Peterson
Sep 18, 2023


VMware Aria Operations for Logs as a Syslog Destination
VMware Aria Operations for Logs has been deployed, you've configured your vSphere integration/s, mine look like this. The checkbox for "Collect vCenter Server events, tasks, and alarms" does just that. The information bubble indicates the following. Part of the vSphere integration also configures the ESXi Hosts Syslog configuration in the target vCenter to forward logs (and optionally tag them). I've tagged my vCenter and ESXi Host logs with "product=vmware", they look like

Brock Peterson
Aug 17, 2023


Log Filtering with VMware Aria Operations for Logs SaaS
You have logs coming into VMware Aria Operations for Logs SaaS, maybe too many logs, how to filter what you need? Log Processing Rules! Log into Aria Operations for Logs SaaS, go to Log Management - Log Processing Rules, and Filter Logs. This is where you can filter out logs that you may not want. To create a new filter click on NEW CONFIGURATION. There are several options here, in order to drop logs with a certain text string, give the filter a name and define the Query, s

Brock Peterson
Apr 3, 2023


Capture VM Reboots with VMware Aria Operations
VMs reboot all the time and while most often you won't care, there are times you want to be notified. How can we use VMware Aria Operations (formerly vRealize Operations or vROps) to capture VM reboots? There are two VM metrics to consider: OS Uptime: Seconds the OS has been up and running. Uptime: Seconds since system startup, ie seconds the virtual hardware has been powered on. VMware Senior Staff Technical Marketing Manager Brandon Gordon explained it best: VM Uptime wo

Brock Peterson
Feb 12, 2023


VMware Aria Operations for Logs Data Sets
VMware Aria Operations for Logs (formerly vRealize Log Insight or vRLI) is a powerful logging platform. It can ingest logs from vCenter, ESXi Hosts, Syslog Sources, and more. But what if I want certain users to see only certain logs? Say for example, I want to give a user access to see only logs for certain VMs? We'll use Data Sets, let's explore! You've deployed VMware Aria Operations for Logs and are sending logs from vCenter, ESXi Hosts, and more. You're seeing all lo

Brock Peterson
Feb 5, 2023


VMware Aria Operations for Logs Authentication using Microsoft Active Directory
VMware Aria Operations for Logs (formerly vRealize Log Insight) is up and running and I've been logging in directly with the local admin account. I'd prefer to use my Microsoft Active Directory (AD) credentials, how do I tell Aria Operations for Logs to use AD? First, log into Aria Operations for Logs, go to Configuration - Authentication - Active Directory and toggle on the Enable Active Directory support button and enter your AD information. There are three Connection Type

Brock Peterson
Jan 19, 2023


Send VMware Aria Operations for Logs Alerts to Slack
In our previous post we detailed how to send VMware Aria Operations (formerly vRealize Operations) Alerts to Slack. This blog will detail how to send VMware Aria Operations for Logs (formerly vRealize Log Insight) Alerts to Slack. We can use the same Slack Webhook URL we set up previously, so this should be a bit easier. Log into Aria Operations for Logs and go to Alerts - Webhook - NEW WEBHOOK. I've given my new Webhook a name, selected Slack from the Endpoint dropdown (th

Brock Peterson
Dec 19, 2022


VMware Aria Operations SaaS, Aria Operations for Logs SaaS, and their Cloud Proxies
VMware Aria Operations SaaS and VMware Aria Operations for Logs SaaS Services have been activated, you've deployed Cloud Proxies (CP) for each, and now want to monitor CP health. There are a few ways to do this and it's different for each Service, we'll explore them here. First, a quick look back at VMware Aria SaaS CPs and their place in your environment. Effectively, CPs act as a gateway, allowing Aria SaaS Services to see your private cloud vSphere vCenters. I blogged p

Brock Peterson
Dec 14, 2022


vROps and vRLI Integrations
vROps has been deployed, vRLI is up and running, let's integrate them! In vROps, to integrate with vRLI, you activate the vRLI Integration. Go to Data Sources - Integrations - Repository. You will first Activate the Integration by finding the vRLI tile and clicking the ACTIVATE button. Once done, you will configure it by clicking ADD ACCOUNT. Give it your vRLI IP address or FQDN. Click VALIDATE CONNECTION to confirm the connection. Notice that you don't provide credential

Brock Peterson
Jul 21, 2022


Send vRLI Alerts to Microsoft Teams
Today we can send vRLI Alerts to vROps, we can generate emails on them, and there are out of the box Webhooks for Slack, Pager Duty, and vRO. What about Microsoft Teams? Well, we can create a custom Webhook for it, so what does that look like. Let's first generate a TEAMs URL to which we will point our Webhook. Go to Teams, select your Team, then go to the three dots top right. Select Connectors. Click Add and then Add which will add the Incoming Webhook to the Channel. W

Brock Peterson
Jun 12, 2022


vRLI Cloud: KB Insights, Live Tail, and Log RCA
VMware vRealize Log Insight Cloud (vRLI Cloud) was introduced back in 2020. Since then VMware has released new versions on a roughly monthly cadence. vRLI Cloud development is done cloud first, so new features are introduced in vRLI Cloud before vRLI. Three of these features are KB Insights, Live Tail, and Log RCA. KB Insights - introduced in May 2021, KB Insights provides KB articles as solutions for problems found in your logs. It uses a combination of a set of process

Brock Peterson
May 29, 2022


Searching Index Partitions in vRLI 8.8!
VMware vRealize Log Insight (vRLI) 8.1 introduced Index Partitions with customizable retention periods, giving us the ability to put logs in certain partitions and keep them as long as we'd like. vRLI 8.4 gave us the ability to archive individual Index Partitions via NFS, which looks like this. vRLI 8.8 brings us the ability to query Index Partitions! Before digging into this new feature, let's take a step back and look at the larger picture. Index Partitions are generally

Brock Peterson
May 28, 2022


Extract Fields with vRealize Log Insight
VMware vRealize Log Insight (vRLI) is a powerful logging tool with all sorts of capabilities, one of them being the ability to extract fields from log entries. Out of the box, each vRLI log entry will contain certain fields like source, event_type, file path, hostname, and more. They are documented here. Beyond those, there are Extracted Fields, which are user defined or Content Pack defined fields extracted from log entries. For example, the VMware vSphere Content Pack c

Brock Peterson
Apr 24, 2022


Send Oracle Database Logs to vRLI
vRLI is up and running, you're getting vCenter Alarms, Events, and Tasks, ESXi Host Logs, but you want more! Specifically, you want your Oracle Database logs. There is a Content Pack available in the Marketplace, but there is some work required and a necessary adjustment to the included Event Marker (REGEX). Let's start by asking the DBA to turn on Oracle Listener logging and Oracle Alert logging. We'll need the path to and the names of these logs, as they are what we will

Brock Peterson
Apr 23, 2022


Capture Certificate Expirations with vRLI
vRLI is up and running, you're collecting vCenter events, tasks and alarms, as well as ESXi Host logs. In addition, vRLI is receiving logs from F5 BIG-IP, Citrix NetScaler, NetApp FAS, and more. Let's use it to capture Certificates that have expired and Certificates that will be expiring. A quick look at my environment shows the following entries, in this case coming from F5 BIG-IP. Remember that the vRLI query language uses the logical "and" operator for phrases, in this c

Brock Peterson
Apr 17, 2022


vRLI and the Cisco UCS Content Pack
I'd like to start bringing Cisco UCS logs into my vRLI environment, here's how I did it. Go to Content Packs - Marketplace and look for Cisco UCS. There are dozens of other Content Packs available here as well. As a note, I'm using vROps 8.6.2, UCSM 4.1(1b), and the 2.0 Version of the Cisco UCS Content Pack in this blog. Select it and click INSTALL. Once installed, you'll be given instructions on how to enable log forwarding via UCS Manager. Clicking the link takes you to

Brock Peterson
Mar 19, 2022


Discover Guest OS Crashes with vRLI and send Alerts to vROps!
We've deployed vRLI, configured our vCenters and ESXi Hosts to send logs to it and now we want to use it to find VMs that have crashed. Let's do it! Go to Interactive Analytics and search for "guest operating system has crashed". I've found five log entries with this string since I started collecting data (notice the All time dropdown top right). As you hover over the Source you'll see the log source. You can also colorize by source by clicking the source link, which is qu

Brock Peterson
Mar 17, 2022


vRLI Cloud, the Cloud Proxy, and the Log Forwarder
If you're using any of the vRealize Suite Cloud offerings, you are running Cloud Proxies (CP) in your Private Cloud. These sit in your on-prem Datacenter and act as the gateway from the Cloud into your environment. Each of the vRealize Suite Cloud offerings (vROps, vRLI, vRA, and vRNI) has its own CP (or Collector VM in the case of vRNI), we will focus on the vRLI CP here, but let's take a step back and consider all of them first. A standard deployment might look something

Brock Peterson
Jan 17, 2022


Capturing Logs with the vRLI Linux Agent
You've designed and deployed your vRLI Cluster, you've configured it to collect logs from your vCenters and ESXi Hosts, but you want more. Specifically, you want to collect logs from your Linux VMs. Well, we can do that with the vRLI Linux Agent. In a previous blog, we discussed the vRLI Windows Agent and how to use that to collect Windows Events. This blog will be the Linux analog to that one. Before getting into the details, let's take a look from above. Your vRLI Clust

Brock Peterson
Oct 27, 2021


vRealize 8.6 Updates via vRSLCM
Beyond vROps, vRLI, and vRA, the vRealize Suite comes packaged with the vRealize Suite Lifecycle Manager (vRSLCM). It's the vRealize counterpart to the vSphere Lifecycle Manager. vRSLCM 8.6 has six main services (vRealize Cloud is a new service): Lifecycle Operations - used to manage environments, datacenter, perform upgrades, monitor requests, and adjust settings. Locker - used to manage certificates, retrieve and add licenses, and support credentials. Identity and Tenant

Brock Peterson
Oct 16, 2021


vRealize Cloud Management Updates
Yesterday was a big day! We released new versions of every product in our vRealize Suite: vROps, vRLI, vRA, vRNI, and vRSLCM. Here are the details, go get them! vROps 8.6 What's New? This release will provide an exciting new user interface for smoother navigation, new public cloud integrations, improved application management, an enhanced integration between vRealize Operations and vRealize Automation and much more that will deliver unified monitoring, visibility, and auto

Brock Peterson
Oct 13, 2021


Windows Events with VMware vRealize Log Insight
I'd like to know which Windows Servers in my environment have seen EventID 4740 in their Security Log, indicating a user account has been locked. How can I efficiently scan the Security Logs on thousands of servers? Well, the short answer is vRealize Log Insight (vRLI), let's do it! We'll need vRLI Agents on the Windows Servers, vRLI supports everything from Windows 7 to Windows 2019, the documented list of supported platforms can be found here: https://docs.vmware.com/en/v

Brock Peterson
May 23, 2021
bottom of page



