Error: omfwd/udp: sendto() error: Invalid argument in Aria Operations for Networks
search cancel

Error: omfwd/udp: sendto() error: Invalid argument in Aria Operations for Networks

book

Article ID: 447800

calendar_today

Updated On:

Products

VCF Operations for Networks

Issue/Introduction

  • SIEM stops receiving logs after upgrading to version 6.14.3.
  • /var/log/syslog contains: omfwd/udp: sendto() error: Invalid argument.
  • Running the sudo systemctl status rsyslog command shows the following error:

  • Syslog forwarding appears suspended or retrying repeatedly.

Environment

  • VMware Aria Operations for Networks (vRNI) 6.14.3

Cause

 Manual modification of rsyslog configuration files via the CLI. The appliance does not support direct CLI edits for log forwarding; changes must be managed via the User Interface to ensure correct protocol handling.

Resolution

Remove the manual entries from the /etc/rsyslog.conf files. Configure the syslog server details directly in the AON UI:

  1. Log in to the Platform User Interface.

  2. Navigate to the Settings page, and under Logs, click Syslog Configuration.

  3. Click Add Server and configure the remote server details.

  4. Map all platform logs and events to the two remote syslog servers correctly.

  5. Use the Send Test Log feature to verify connectivity.

 

For more details, refer: Setup Syslog Configuration