Quantcast
Channel: VMware Communities : All Content - vRealize Log Insight
Viewing all 1504 articles
Browse latest View live

Administration View of agents is showing no agent but yet, I am getting data

$
0
0

I have two Windows boxes sending event log data to Log Insight.  I am using the new agents.  I am seeing data in LI interactive from them.  However the agents are not see in the Administrative / Agent area.  Has anyone got to see the agents in the Agents area?

 

I am using the old fashion syslog to send the data.  I will try using the new API method.

 

Michael


Minor bug: Log Insight 2.0 doesn't report correct IP address when sending out notification emails

$
0
0

This alert is about your Log Insight installation on <servername>

 

 

Oldest Data Will be Unsearchable Soon (Host = 0.0.0.0) triggered at 2014-03-27T17:17:32.349Z

 

 

This notification was generated from Log Insight node (Host = 0.0.0.0, Node Identifier = 01f2fb77-c62d-4a1a-8862-1e2e58e4f879).

 

 

Data will start rotating in about 5 days 12 hours at the current ingestion rate. This is normal and expected behavior and you will only receive this alert once after each restart of the Log Insight service.

 

 

Assuming log ingestion rates do not significantly change, this will provide you with approximately 5 days 13 hours of searchable log data. Data that has been rotated out will be archived if you have configured archiving, or deleted if you have not. If you would like to retain searchable log data for a longer period of time, you will need to either decrease the quantity of log data being sent to Log Insight, or add additional storage to the Log Insight virtual appliance. See the Online Help for instructions on how to increase storage of the appliance.

 

 

Total allocated space: 233.6 GB, free space: 224.7 GB

vclog windows agent

$
0
0

Hello,

 

I was very pleased to see that in version 2.0 (beta) there is a windows agent for vclog insight:

I got a couple of questions:

 

1) is the traffic between the agent and the vclog server encrypted]

2) if i have an esx server with 40 running windows servers on it. How many licenses do i need then?

 

Regards

 

Hans

Using Windows agent to send log files

$
0
0

Hi there,

 

I really need to figure out the sending of log files using the Windows agent.  I have seeen your doc on it and it is sort of easy.  Then the event_marker is complicated.  The example shows a bunch of control characters and curly brackets.    I need to understand the event_marker parameters.  What in a text file would suggest what needs to be in event_marker?

 

Thanks in advance,

 

Michael

In Agents section of Admin, IP address is used instead of FQDN for sender

$
0
0

Hello,

 

Currently you have an IP Address section to the list of agents in the Admin section.  I would like to see the name of he machine where the agent is installed. It is more useful to me than the IP address.  Can you add an additional column for name, or use FQDN instead of IP?

 

Thanks

 

Michael

In Agents section of Admin, Stats as of appears to be not updating

$
0
0

Hello all,

 

I am using two agents to send logs to LI.    The Stats as of for the agents is days ago.  But last seen is less than a minute ago.  Confusing.  See attached screenshot.

 

Michael

vSphere Integration, View Details, Configured shows no when in fact ESXi hosts are configured

$
0
0

Hello,

In the vSphere Integration part of admin, and View Details, you see a list of my hosts.  They are seen as not configured.  This is not correct.  The rest of the details are correct - name, build, etc.  While I have not used this script to configure the hosts, they are already configured by me and should be shown as such.  See the screenshot.

 

I think it is saying no since the script or LI has not been used but that is not a good way to do it.  If the hosts have a syslog setting that points at LI than it should show yes.

 

Michael

Log Insight 2.0 Beta AD Auth issue

$
0
0

I just updated my lab instance to 2.0 Beta and AD auth has stopped working.

I validated that it was working before the upgrade


Cisco-UCS Content Pack configuration

$
0
0

Hi,

 

I downloaded the latest available Cisco-UCS Content Pack, listed as version 1.5.  I was able to import the Content Pack successfully and see the properties of the Dashboard, Queries, Alerts, and Extracted Fields.  I am also able to select the Cisco-UCS Content Pack from a drop down menu under the Dashboards section of the site (there is no data displayed).

 

However, I cannot find anyway to configure the Content Pack to my Cisco-UCS Fabric Interconnect, etc! 

 

Am I missing something?

Log Insight's own error notifications - where do they go?

$
0
0

There are some SMTP configuration issues in one of our loginsight instance, it is nicely presented to admin as red icon with errors count. However, after you click on it and close after reading the messages completely disappear... there is no way to find them again. I suggest to keep them under Administration somewhere.

thanks,

ildus

This is cool - SMART errors seen

$
0
0

This is cool - I did a search on host and saw these SMART errors.  Didn't know about this.  See attached for what I saw.  BTW, this might make a good item for a widget in the updated and new vSphere dashboard.

 

Michael

Why do I see different when I look in an ESXi log and in Log Insight?

$
0
0

This is a little odd.  But I have screenshots to help.

 

I use the command grep -r error /var/log/vmkernel.log and see what is shown in grepbiddlerror.  Abut 9 or 12 lines of couldn't read volume header errors.  But, when I go look in Log Insight, using that host name where I ran the grep and a search term of error I see different things.  I do see where I ran the grep, including the first time when I misspelled it.  See greperrorli for what I see.

 

I would have though there would have be similarity between the two?

 

Any thoughts or comments welcome.

 

Michael

How to determine licences compliance

$
0
0

Is there an easy way to tell how many event sources Log Insight is seeing? I'd like a way to tell how many sources are going into Log Insight and what those sources are.

vSphere 5.5 and excessive logging

$
0
0

I installed Log Insight (version 1.5.0-1435442) several weeks ago and connected it to vCenter.  At that time we were running vCenter 5.5 and ESXi 5.1 U2.  Log Insight was picking up some stuff from vCenter that I was going to start looking at and appeared to be working fine.  I upgraded to vCenter 5.5 U1 and ESXi 5.5 U1 last Wednesday and the amount of data coming from that environment has increased exponentially.  The Log Insight appliance indicates that it's dropping 500 million events a day.  I don't really know where to begin with identifying what the issue is.  The vCenter and ESXi servers appear to be operating appropriately.  There seems to be an excessive amount of logging occurring.  The average ingestion rate is 2,847 per second and we only have 16 ESXi servers and vCenter, a couple of UCS pods, and vCOPS configured to send info to Log Insight.  From what I can tell there is barely anything coming from vCOPS and UCS.

Loginsight 2.0 beta - High CPU Usage - 3 node cluster

$
0
0

I've deployed the loginsight 2.0 beta as a 3 node cluster and i've noticed that it's consuming much more cpu than it should be. I'm using either the large or extra large configuration (16 cores) and barely sending any traffic to it. It was a fresh install, not an upgrade, and each of the 3 nodes shows 50% cpu usage (8 cores at 100%) all the time. I can create a support bundle and provide additional information, where can I send it?

   --jordan


Heartbleed OpenSSL

$
0
0

VMware is aware of Heartbleed, a serious vulnerability in OpenSSL version 1.0.1a-f. This VMware vCenter Log Insight Beta is not using the OpenSSL effected versions.

How to post a bug?

Is automatic page refresh possible?

$
0
0

I keep a LogInsight page open all day long and am wondering if there is a way to have it automatically refresh

instead of having to click on the refresh button?

 

LogInsight_Refresh.jpg

Configuring Alerts

$
0
0

I have created a query and used "Add Alert for current query" to save it and run it daily (to send me a report).

Two questions:

1) I want the query to run only ONCE in 24 hours period. However, there is no way to change "The query will run every 60 minutes".

2) I want the query to run AT the time I want. we need an option to specify the query run time.

thank you,

ildus

Brocade SAN Content Pack initial setup

$
0
0

I imported the Brocade SAN content pack into our 1.5 log insight appliance. The SAN admin set up syslog forwarding on the network advisor server for the switches via IP address and port 514.

After more than 24 hours no data is shown in log insight under the Brocade SAN dashboards.

Is there another step I'm missing? Documentation is sparse on this product.

I thought to restart the log insight appliance, but a warning comes up about hosts not being able to continue logging after losing connection with the appliance, so I only wanted to do that if absolutely necessary.

Thanks

Viewing all 1504 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>