NSX-T Distributed Firewall Logging in Cloud Director is not working
search cancel

NSX-T Distributed Firewall Logging in Cloud Director is not working

book

Article ID: 434298

calendar_today

Updated On:

Products

VMware Cloud Director

Issue/Introduction

In Cloud Director logs are not showing for the Distribute Firewall Rules. If we check Log Management for the relevant logs we are able to find them from the ESXi host dfwpklog files.

All setup has been completed according to Unable to see logs from Distributed Firewall in Cloud Director UI.

Environment

VMware Cloud Director 10.6.x
Log Management (formerly Aria Operations For Logs) 18.8.x
NSX-T Content Pack 4.0.2 for Log Management

Cause

The older version of the content pack, 4.0.2, in Log Management is not tagging the log entries correctly.

Cloud Director is relying on API calls to Log Management to retrieve relevant distributed firewall logs specific to the Organization VDC. The API calls are succeeding, but returning null.

Resolution

Upgrade to the latest NSX-T Content Pack in Log Management.