Data collection is not available after enabling NSX Intelligence
search cancel

Data collection is not available after enabling NSX Intelligence

book

Article ID: 447178

calendar_today

Updated On:

Products

VMware vDefend Firewall with Advanced Threat Prevention VMware vDefend Firewall

Issue/Introduction

After enabling NSX Intelligence, flow data collection fails to function across ESXi Transport Nodes. Users may observe one or all of the following symptoms:

1. Blank Flow Maps:    The SSP Intelligence console shows completely empty datasets under the data collection host capacity visualization charts.

2. Transport Node CLI Observations :

   We may see flow config and status in ESXI shows below details.

 "nsxcli -c get intelligence flow config" returns Enabled: FALSE. 

 "nsxcli -c get intelligence flow stats ack" reports an explicit error string: "Service is disabled"

 

3. NSX UI Group Status : We may see NSX Intelligence Data collection group failed status : 

Navigating to Inventory > Groups, the system-defined NSX Intelligence Data Collection inventory group shows a permanent Failed status (Red).

 

 

 

 

Environment

Security Services Platform (SSP) 5.x

Cause

 This issue occurs when the pace-host-config-profile configuration fails to push down to the ESXi Transport Nodes.

The underlying root cause chain is as follows:

  1. The Service Config object—responsible for binding the system-created NSX Intelligence Data Collection Group to the pace-host-config-profile—is missing.

  2. Because If the Service Config object is absent, the Central Control Plane (CCP) is never instructed to push the pace-host-config-profile to the ESXi hosts. Without this profile, host-level flow collection cannot initialize.

  3. The Service Config object may  fails to initialize because the NSX Intelligence Data Collection Group enters a Failed realization state due to a stale, leftover group entry from a previous or improperly uninstalled NSX Application Platform (NAPP).

Resolution

To clear the stale enteires and re-initialize the Service Config object, we can perform a clean offboard and re-registration cycle:

Log into the Security Services Platform UI.

  1. Delete Intelligence feature. 
  2. Navigate to System > NSX Manager . Select and trigger the formal Offboard sequence for your platform deployment. This instructs the management plane to clear out active features and drop dependent database handlers.

  3. Once offboarded completely, Re-onboard / Re-register the NSX Manager to the platform platform.

  4. Re-enable the NSX Intelligence feature and verify group realization and flow collection status.