Setup vRealize Log Insight- Deployment & Integration

This article is about setting up vRealize Log Insight and integrating it with vSphere and vRealize Operations Manager.
Log Insight provides powerful real-time log management for VMware Environment with machine learning based intelligent grouping and faster search. This allows for swift troubleshooting and better analytics across physical and Virtual Environments.

It’s only a matter of exploring the options the tool gives for log analysis and you will enjoy using it.

The deployment can be broken down into below steps.

  • Pre-requisites
  • Deploy the Appliance
  • Configuration
  • Integration with vSphere and vROPS

Pre-Requisites

Log Insight accepts data from sources(Virtual/Physical/Cloud) which use syslog protocol, sources that write logs and can run the vRealize log insight Agent and sources that can post data with HTTP/HTTPS through the REST API.

Ports for syslog feeds: 514(UDP), 514(TCP), 1514(TCP) SSL.

log1

The appliance can be deployed in 4 configurations based on the sizing requirements. The configuration decide the amount of compute and storage resources the appliance requires.

log2.jpg

The below link for sizing calculator will help you determine sizing

http://www.vmware.com/go/loginsight/calculator

Deploying the Appliance

Login to the vSphere Web Client once the .OVA is available

Deploy OVF Template from vCenter and select Local file.

Browse and Select the .ova file

Click Next

Name the appliance and select location

Click Next

Select Resource and Review Details

OVF_1

Click Next

OVF_2

Accept the EULA and click Next

OVF_3

Choose the Configuration and Click Next

OVF_4

Select Storage and click Next

OVF_5

Select Network and click Next

OVF_6

OVF_7

Provide Network and Other Properties

OVF_8

Review and Click Finish.

Configuration

The initial configuration is available after the appliance deployment

https://vRealizeLogInsight.hostname

Welcome screen Click Next

Config_1

Click Start New Deployment unless you are deploying this as a second node to an existing Log Insight to make a cluster(HA)

Config_2

Provide email ID and admin password

Config_3

Provide License Key.

Config_4

 

Admin email for Notifications

Config_5

SMTP configurations

Config_6

Finish

Config_7

Integration with vSphere and vRealize Operations Manager

Login to https://vRealizeLogInsight.hostname

Go to Administration.

Click vSphere under Integration

vSphere2

Provide vCenter FQDN and Credentials.

vSphere3

It is recommended to create a Custom User for Integration with below privileges on vCenter root.

  • Configuration.Change settings
  • Configuration.Network configuration
  • Configuration.Advanced settings
  • Configuration.Security profile and firewall

Once configured you will notice the Syslog setting and firewall configuration done on the ESXi hosts.

vSphere4

Go back to the Administration page and click vRealize Operations under Integration.

vrops1

This allows you to access the Log Insight dashboard from the vRealize Operations Manager page.

vrops2

I would also suggest you to go through the below link for a quick go through on Searching and Filtering event. You will need this coz there will lot of events if it’s a big infrastructure and you’ll have to find what you are looking for.

https://docs.vmware.com/en/vRealize-Log-Insight/4.5/com.vmware.log-insight.user.doc/GUID-142258C3-B056-4D82-BD34-8E1A2E7A5093.html

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out /  Change )

Google photo

You are commenting using your Google account. Log Out /  Change )

Twitter picture

You are commenting using your Twitter account. Log Out /  Change )

Facebook photo

You are commenting using your Facebook account. Log Out /  Change )

Connecting to %s