Missing vCenters in VCF Operations for Logs Integrations and License in Evaluation Mode
search cancel

Missing vCenters in VCF Operations for Logs Integrations and License in Evaluation Mode

book

Article ID: 444553

calendar_today

Updated On:

Products

VCF Operations

Issue/Introduction

Administrators may observe that vCenters do not appear in VMware Cloud Foundation (VCF) Operations for Logs under the IntegrationsvSphere section, despite products being configured for logging. Additionally, the VCF Logs UI displays a yellow warning banner stating the license is in evaluation mode. Despite these issues, ESXi hosts and vCenter FQDNs may still be visible under the ManagementHosts section with recent events received, and vCenters appear normally within VCF Operations configurations.

Environment

  • VCF Operations 9.0.x
  • VCF Operations for Logs 9.0.x

Cause

The deployed cloud proxies are sized as "Small," leading to memory resource spikes.  
Log collection is configured to use the "Collect logs using the cloud proxy/group" option, which routes traffic through the resource-constrained proxies, preventing the vSphere integrations and licensing states from updating properly in the UI.

Resolution

To immediately restore visibility and correct the licensing state, perform the following steps:
  1. Navigate to the log collection settings and change the option from "Collect logs using the cloud proxy/group" to "Collect logs directly into Logs cluster". Refer: Configuring Log Sources for Log Management
  2. Restart the loginsight service on all three nodes of the VCF Logs cluster: 
    systemctl restart loginsight
  3. Wait for one collection cycle (approximately 5 minutes). The vCenters will then populate in the VCF Logs UI, the system will recognize the valid license, and the evaluation mode warning will disappear.  

Additional Information

  • During this issue, log ingestion from all endpoints remains active.  
  • Licensing and integrations on the core VCF Operations platform remain intact and healthy during this occurrence.
  • Remove the heapdump file (~10 GB) from the primary node of VCF Logs: Refer: Primary node crashes intermittently.
To prevent this issue from recurring, complete the following long-term corrective actions:
  1. Scale up the cloud proxy nodes to "Standard" size, strictly adhering to the official sizing guide.  
  2. Apply Express Patch 2 (EP2) to VCF Operations for Logs to resolve the known heapdump issue.

Refer: