VMware Aria Operations for Logs Log Forwarding not function correctly
search cancel

VMware Aria Operations for Logs Log Forwarding not function correctly

book

Article ID: 412557

calendar_today

Updated On:

Products

VCF Operations/Automation (formerly VMware Aria Suite)

Issue/Introduction

  • Adding a forwarding rule to Operations for logs that catch 'FIREWALL-PKTLOGS' and 'DROP' events fails.
  • The rule is configured with he filter 'appname' = 'FIREWALL-PKTLOGS' and 'Text'; != 'PASS'

Environment

  • Aria Operations for Logs 8.18.x

Cause

The 'Log Forwarding' filter does not behave in the same way as the 'Explore Logs' filter. Machine learning is used to optimise results in 'Explore Logs' and is not available for 'Log Forwarding' 

Resolution

To achieve the goal of sending the dropped DFW events to an endpoint, the following filters can be used.

  • 'Text', 'Matches'. '*FIREWALL-PKTLOGS*'
  • 'Text', 'Matches', '*DROP*'

Additional Information

  • When designing filters to catch specific events, the 'Text' and 'Matches' are the most reliable. 
  • Find unique strings within the events that are to be filtered and add wildcards (*) to the start and end of the string.