When configuring outbound syslog forwarding from VMware Aria Operations for Logs, there may be uncertainty about whether syslog traffic originates from the Virtual IP (VIP) or the individual node IP addresses within the cluster.
This can lead to incorrect firewall or routing configurations, particularly because the Send Test Message option in the user interface indicates that the test message is sent through the VIP, while actual syslog traffic may originate from node IP addresses.
Incorrect firewall or reverse routing configurations can result in failed log forwarding.
VMware Aria Operations for Logs 8.x
To ensure successful outbound syslog forwarding, apply the following configuration guidelines: