Hostd[20###33]: [Originator@6876 sub=Vimsvc.TaskManager opID=13cb###7-f5-2##d sid=52b###87 user=vpxuser:VSPHERE.LOCAL\Administrator] Task Created : haTask-ha-host-vim.option.OptionManager.updateValues-110###1745
Hostd[2099036]: [Originator@6876 sub=Hostsvc.SyslogConfigProvider opID=13cb###7-f5-2##d sid=52b###87 user=vpxuser:VSPHERE.LOCAL\Administrator] Set called with key 'Syslog.global.logHost', value '"udp://<Destination_IP>:514,udp://<Destination_FQDN>:514"'
Hostd[2099036]: [Originator@6876 sub=Libs opID=13cb###7-f5-2##d sid=52b###87 user=vpxuser:VSPHERE.LOCAL\Administrator] info [ConfigStore:a23###1700] Checking for empty objects and arrays in comp esx grp syslog key global_settings objectA legacy VMware Aria Operations for Logs cluster has the automated vSphere integration enabled. As documented in the product's architecture guidelines, when the vSphere integration is configured with the "Automatically configure all ESXi hosts" option, the appliance continuously executes automated API calls to the vCenter Server. It actively evaluates and overwrites ESXi host configurations to enforce its specific syslog settings, reverting any manual changes.
To resolve this issue, you must halt the automated API calls originating from the legacy log cluster and then re-apply the correct syslog endpoint settings: