Forward GCVE SDDC logs to On-Premise vRealize Log Insight / Aria Operations for Logs

Disclaimer: This is not officially supported by VMware yet. This should be considered as a stop-gap / work-around solution for time being. 
PAGE CONTENTS
What is Google Cloud VMware Engine? (GCVE)
Assumption
Goal
Pre-Requisites
Step-by-Step Guide

What is Google Cloud VMware Engine? (GCVE)

Google Cloud VMware Engine is a fully managed service that lets you run the VMware platform in Google Cloud. VMware Engine includes vSphere, vCenter, vSAN, NSX-T, HCX, and corresponding tools, so it’s fully compatible with your existing VMware tools, processes, and skills training. For more details visit the official documentation page here

Assumption: You have VMware Aria Operations for Logs On-Premise (vRealize Log Insight on-premise) and SDDC deployed in Google Cloud VMware Engine. 

Goal

  1. How to forward GCVE SDDC logs to vRealize Log Insight On-Premise Instance / VMware Aria Operations for Logs. 
  2. Forward SDDC GCVE Logs from On-Premise vRealize Log Insight to vRealize Log Insight Cloud by using On-Premise Collectors. 

Pre-Requisites for On-Premise Aria Operations for Logs (vRealize Log Insight On-Premise) 

  1. Deploy vRealize Suite Life Cycle Manager : Official Documentation Here.
  2. Deploy vRealize Log Insight by Using vRealize Suite Lifecycle Manager: Official Documentation.
  3. Using solution user accounts in GCVE SDDC
    1. VMware Engine also creates user accounts with administrative privileges that you can use for the third-party tools and products
    2. Prepare a Solution User Account in vSphere SDDC GCVE: Refer to Official Documentation

Step-by-Step Guide

  1. Login into vRealize Log Insight On-Premise Instance. 
  2. Click on Integration > vSphere 
  3. Click on + ADD VCENTER SERVER                                                                                                                
  4. Fill and Choose as shown above. Ensure that you are using “solution-user-01@gve.local” account (or any solution user accounts that you have prepared). Click SAVE button                                       
  5. You may note that the connection is successful. vCenter & ESXi hosts have been configured successfully to send logs from SDDC GCVE to vRealize Log Insight On-Premise Instance.                 
  6. You may see in the above screenshot that the vSphere Integration is Successful for GCVE SDDC. Validate further by clicking on ESXi hosts configured (View Details).                                                       
  7. Forwarding logs from GCVE SDDC to vRealize Log Insight On-Premise Instance is completed.    

Forward SDDC GCVE Logs from On-Premise vRealize Log Insight to vRealize Log Insight Cloud by using On-Premise Collectors. 

  1. Login to VMware Cloud Service Console. https://console.cloud.vmware.com 
  2. Launch Service : vRealize Log Insight Cloud. 
  3. Click on Configuration > API Keys. Click  NEW API KEY  . Provide a Unique Name & click Create       
  4. Copy the Url, Key to a secure place. 
  5. Now go to vRealize Log Insight On-Premise Instance. Click on Log Management > Cloud Forwarding > click on + NEW CHANNEL                                                                                                           
  6. Fill above as displayed. Read Official Documentation on On-Premise Collector for vRealize Log Insight Cloud. This has information on Ready Only, Worker Count, etc. Click SAVE button.
  7. Give it a couple of minutes and then again go back to Log Management > Cloud Forwarding           
  8. You may note in the above image, we have now successfully configured On-Premise Collector in vRealize Log Insight On-Premise Instance. You can observe above :
    1. 10,607 events have been forwarded to Log Insight Cloud
    2. On average 63.52 events per second have been forwarded. 
  9. Let us validate the On-Premise Collector on VMware Cloud Service Console > Log Insight Cloud
  10. Click on Cloud Proxies > On-Premise Collectors.                                                                                   
  11. Note in the above image, that the On-Premise Collector that we configured in Cloud Forwarding in On-Premise Log Insight is reflected here in Log Insight Cloud. The configuration is successful.