After completing a successful upgrade from VCF Operations for Logs 9.0.x to VCF Operations Log Management 9.1, two separate appliances remain active in the environment.
The original 9.0.x appliance continues to collect logs and handle log forwarding, while the new 9.1 appliance is fully deployed. You need to remove the old 9.0.x appliance and transition entirely to the 9.1 appliance without experiencing any data loss.
VCF Operations for Logs 9.x
This article provides the necessary post-upgrade decommissioning and migration steps to safely transition log collection to the new VCF Operations Log Management 9.1 instance and retire the legacy 9.0.x appliance.
To safely decommission the legacy 9.0.x appliance without losing any data or custom configurations, you must complete the post-upgrade migration process. This transition consists of four main phases: reviewing the migration status, manual migration of custom content packs, redirecting your log sources, and transferring historical data.
During the upgrade process, a migration report is generated that details the status of log forwardings, maskings, filterings, and other configuration settings.
Review this report to verify that all standard configurations and processing rules from the 9.0.x environment have successfully mapped to the 9.1 appliance.
For details on validating your post-upgrade state, refer to the Broadcom TechDocs: Validating the Post-Upgrade State.
Important: Custom content (such as custom dashboards, alerts, queries, and content packs) is not automatically transferred to version 9.1 during the upgrade process. You must manually migrate and convert this content.
Review any custom content packs created or modified in your 9.0.x environment.
Convert and import these custom content packs into Management Packs compatible with the 9.1 architecture.
Follow the detailed conversion steps outlined in the Broadcom TechDocs: Converting Content Packs to Management Packs.
The legacy 9.0.x appliance will continue to collect data until your agents, forwarders, and log-emitting infrastructure are reconfigured to target the new appliance.
Leaverage/Reconfigure Agents: Update your log management agents to point directly to the FQDN/IP of the new 9.1 appliance. Refer to: Configuring Log Management Agents.
Reconfigure Log Sources: Ensure syslogs, API integrations, and environmental log sources are actively sending data to the new 9.1 instance. Refer to: Configuring Log Sources for Log Management.
Once live log sources are successfully streaming data to the 9.1 appliance, you must migrate the historical log data residing on the 9.0.x appliance to retain compliance and historical visibility.
Initiate the historical log data transfer from the 9.0.x appliance to the 9.1 appliance.
Follow the detailed steps outlined in the Broadcom TechDocs: Log Data Transfer Instructions.
Warning: Do not turn off the legacy appliance until you have verified that the historical data transfer is 100% complete and new log ingestion on the 9.1 appliance is stable.
Monitor the 9.1 appliance for 24 - 48 hours to ensure log retention, dashboards, custom alerts, and incoming metrics are performing as expected.
Power off the legacy 9.0.x appliance.
Keep the powered-off VM as a backup for a designated retention period according to your internal IT policies before permanently deleting it from your infrastructure.