The document discusses deploying and configuring VMware Log Insight, integrating it with other VMware products like vSphere and vRealize Operation Manager, using and managing Log Insight features such as machine learning and archiving log data, and using content packs to analyze specific application logs from software like IIS and Cisco UCS. Log Insight provides log management and analytics capabilities through centralized log collection, analysis, and archiving across virtual, cloud, and physical environments.
1. Log management and analytics
by VMware Log Insight
Kiss Tibor vExpert 17/Cloud
@kisstib0r
kisstibor.info
2. Agenda
1 Deploy and configure
2 Integration with other VMware Products
3 Using and Managing vRealize Log Insight
4 Content packs
3. Requirements
Analyze
• Can analyze any unstructured data, configuration etc…
• Automatically identifies structures in the data then uses machine learning to group data
Scale
• Central, scale out store (no-SQL) for all collceted data
• Archiving
SDDC
• Queries, alerts, fields, charts in the vSphere Content Pack
• Ability to search and export Logs entries (even after vCenter has rolled over historical
logs)
Integration
• Root Cause Analysis
4. Deploy and Configure – Sizing
https://docs.vmware.com/en/vRealize-Log-Insight/4.5/com.vmware.log-insight.getting-started.doc/GUID-284FC5F4-B832-47A7-912E-D407A760CAE4.html
• Single deployment: Typical OVF deploy process, nothing special, except one -> For large installations, you must
upgrade the virtual hardware version of the vRealize Log Insight virtual machine.
• Cluster deployment: Use medium configuration, or larger, for the master and worker nodes in a vRealize Log
Insight cluster. The number of events per second increases linearly with the number of nodes. Two nodes cluster
not supported!!!
• Each ESXi host sends up to 10 messages per second with an average message size of 170 bytes/message. This is
roughly equivalent to 150MB/day/host.
• If you want to use the Extra Small version of the appliance on your laptop, but the laptop does not have enough
memory, you can reduce the memory size to 2GB.
http://www.vmware.com/go/loginsight/calculator
5. Deploy and Configure – Examples and advices from real life
1. Install one medium size configurtaion appliance at first
2. Choose different IP address that you want to use for
Cluster (Eg.: 10.10.1.11)
3. Use naming conventions (Eg.: SRV-LogNodeW-01)
4. Master and Worker Node(s) runs on different DS
5. Thick Provision Eager Zeroed for performance
6. DO NOT click Configure vSphere Integration yet!
6. Deploy and Configure – Examples and advices from real life
The sum of Syslog Events and API Events.
1. Go Admin page
2. Jump to Administration / Management / Cluster
3. Create VIP (Eg.: 10.10.1.10)
a) Easy setup (Integrated Load Balancer)
b) You can decide later beside to cluster environment
4. Create „A” DNS record for VIP (Eg.: logs.mydomain.loc)
5. Use VIP FQDN for setups (Eg.: ESXi hosts log settings)
Create new Virtual IP
8. Integration with other VMware Products – vSphere
1. Create new Rule / Permission in vCenter
a) You must configure the permission on the top-level folder
within the vCenter Server inventory, and verify that
the Propagate to children check box is selected
2. Create new dedicated service user for Log Insight
3. Assign rule to dedicated service user (use global
permission)
4. Add vCenter server(s) to VMware Log Insight
5. Test connection
6. Save settings
Level of Integration Required Privileges
Events, tasks, and
alarms collection
System > View
System > View is a system-defined privilege. When you add a custom role and do not
assign any privileges to it, the role is created as a Read Only role with three system-
defined privileges: System > Anonymous, System > View, and System > Read.
Syslog configuration
on ESXi hosts
Host > Configuration > Change settings
Host > Configuration > Network configuration
Host > Configuration > Advanced Settings
Host > Configuration > Security profile and firewall
9. Integration with other VMware Products – vSphere
Check the value of „Syslog.global.logHost” under HOST / Manage / Settings / Advanced System Settings
You can see your VIP FQDN address
10. Integration with other VMware Products – vRealize Operation Manager
1. Create service accont in vROPs (U can use local user)
2. Fill VMware Log Insight Adapter instance in vROPs
3. Test and Save configuration
1. In Log Insight go Administration / Integration / vRealize
Operation
2. Add host name or IP, User and Password
3. Enable alerts integration
1. Log Insight user alerts can optionally be sent to vRealize
Operations Manager
4. Enable launch in context
a) Launch in context allows vRealize Operations Manager to open
Log Insight and query for selected objects
5. Test and Save settings
11. Integration with other VMware Products – vRealize Operation Manager
Now, You can see
your logs in vRops
12. Integration with other VMware Products – vRealize Operation Manager
• Select one VM in vROPs (MS SQL) and click „Logs” tab
• You will see logs from VM
• But not only from VM’s level
• Now You are able to check state of MS SQL Tr. Log backup job in vROPs
Yes! U can do it!
DEMO-VM
DEMO-VM
What?
13. Integration with other VMware Products – vRealize Operation Manager
https://kisstibor.info/2017/10/24/vrealize-log-insight-alert-integrate-with-operation-manager/
Veeam Backup Server
Veeam Log folder
14. Integration with other VMware Products – vRealize Operation Manager
https://kisstibor.info/2017/10/24/vrealize-log-insight-alert-integrate-with-operation-manager/
18. Using and Managing vRealize Log Insight – F5 traffic information
How many connections
from IP addresses
19. Using and Managing vRealize Log Insight – Machine Learning
Intelligent grouping scans incoming unstructured data and quickly groups messages by problem type
20. Using and Managing vRealize Log Insight – Expanding Virtual Machine Resources
2 TB
VMDK
1 TB
VMDK
Add storage
• Power off the vRealize Log Insight virtual machine
• Add virtual disk
• As many disks as needed can be added to the vRealize Log Insight virtual appliance, up to 4 TB
(plus the OS drive) of total addressable storage
• When the vRealize Log Insight virtual appliance is powered on again, the virtual machine discovers
the new virtual disk and automatically adds it to the default data volume
0,5 TB
VMDK
Data Volume
OS
VMDK
=/= 4TB
21. Using and Managing vRealize Log Insight – Archiving Log Data
Data volume
DD2500
NFS share
Log InsightSources
23. Content Packs – IIS
• Agent must be installed on the server
• Change One log file per: Server
• IIS content pack uses logs in W3C format
• Create new IIS specific agent group