Post-Upgrade Decommissioning of Legacy VCF Operations for Logs 9.0.x Appliance
search cancel

Post-Upgrade Decommissioning of Legacy VCF Operations for Logs 9.0.x Appliance

book

Article ID: 443492

calendar_today

Updated On:

Products

VCF Operations

Issue/Introduction

After completing a successful upgrade from VCF Operations for Logs 9.0.x to VCF Operations Log Management 9.1, two separate appliances remain active in the environment.

The original 9.0.x appliance continues to collect logs and handle log forwarding, while the new 9.1 appliance is fully deployed. You need to remove the old 9.0.x appliance and transition entirely to the 9.1 appliance without experiencing any data loss.

Environment

VCF Operations for Logs 9.x

Cause

This article provides the necessary post-upgrade decommissioning and migration steps to safely transition log collection to the new VCF Operations Log Management 9.1 instance and retire the legacy 9.0.x appliance.

Resolution

To safely decommission the legacy 9.0.x appliance without losing any data or custom configurations, you must complete the post-upgrade migration process. This transition consists of four main phases: reviewing the migration status, manual migration of custom content packs, redirecting your log sources, and transferring historical data.

Phase 1: Review the Upgrade Migration Report

During the upgrade process, a migration report is generated that details the status of log forwardings, maskings, filterings, and other configuration settings.

  1. Review this report to verify that all standard configurations and processing rules from the 9.0.x environment have successfully mapped to the 9.1 appliance.

  2. For details on validating your post-upgrade state, refer to the Broadcom TechDocs: Validating the Post-Upgrade State.

Phase 2: Convert and Migrate Custom Content Packs (Manual Step)

Important: Custom content (such as custom dashboards, alerts, queries, and content packs) is not automatically transferred to version 9.1 during the upgrade process. You must manually migrate and convert this content.

  1. Review any custom content packs created or modified in your 9.0.x environment.

  2. Convert and import these custom content packs into Management Packs compatible with the 9.1 architecture.

  3. Follow the detailed conversion steps outlined in the Broadcom TechDocs: Converting Content Packs to Management Packs.

Phase 3: Redirect Log Sources and Endpoints

The legacy 9.0.x appliance will continue to collect data until your agents, forwarders, and log-emitting infrastructure are reconfigured to target the new appliance.

  1. Leaverage/Reconfigure Agents: Update your log management agents to point directly to the FQDN/IP of the new 9.1 appliance. Refer to: Configuring Log Management Agents.

  2. Reconfigure Log Sources: Ensure syslogs, API integrations, and environmental log sources are actively sending data to the new 9.1 instance. Refer to: Configuring Log Sources for Log Management.

Phase 4: Transfer Historical Log Data

Once live log sources are successfully streaming data to the 9.1 appliance, you must migrate the historical log data residing on the 9.0.x appliance to retain compliance and historical visibility.

  1. Initiate the historical log data transfer from the 9.0.x appliance to the 9.1 appliance.

  2. Follow the detailed steps outlined in the Broadcom TechDocs: Log Data Transfer Instructions.

Warning: Do not turn off the legacy appliance until you have verified that the historical data transfer is 100% complete and new log ingestion on the 9.1 appliance is stable.

Phase 5: Final Decommissioning

  1. Monitor the 9.1 appliance for 24 - 48 hours to ensure log retention, dashboards, custom alerts, and incoming metrics are performing as expected.

  2. Power off the legacy 9.0.x appliance.

  3. Keep the powered-off VM as a backup for a designated retention period according to your internal IT policies before permanently deleting it from your infrastructure.

Additional Information

Upgrade to Log Management 9.1