Unable to search few fields under Log forwarding configuration in Aria Operations for Logs
search cancel

Unable to search few fields under Log forwarding configuration in Aria Operations for Logs

book

Article ID: 448937

calendar_today

Updated On:

Products

VCF Operations/Automation (formerly VMware Aria Suite)

Issue/Introduction

Under Log Management -> Log forwarding, the 'New Destination' wizard cannot search a filter with an expected field:

Searching for this field in 'Explore Logs' does not display any events either

Environment

Aria Operations for Logs 8.18

Cause

This happens when the source of this field is not configured in Aria Operations for Logs Agents.

For example, 'product' field is being inherited from the events as below in 'Explore Logs':

Checking the 'source' of these events, they are being initiated by VMware Aria Automation configured under 'Agents'

 

Resolution

Configure the appropriate log agents (e.g., for Aria Automation) to capture missing fields.

Follow the Broadcom Log Agent Configuration Guide to set up agents based on your log source.

Additional Information

These fields will only be populated if a configured agent advertises them.

Aria Operations for Logs can only forward logs that it actually receives. If the event source (eg. Aria Automation) is not yet configured, these fields will not populate until its agent is configured.