Configuring and Importing log archives for additional data retention
search cancel

Configuring and Importing log archives for additional data retention

book

Article ID: 449266

calendar_today

Updated On:

Products

VCF Operations

Issue/Introduction

  • Administrators need to understand architecture, configuration, and data recovery for log archiving and custom data retention in VMware Cloud Foundation (VCF) Operations for Logs.
  • This involves managing archive storage via NFSv3 or S3-compatible endpoints, configuring index partitions for extended data retention, and importing historical .blob files via Fleet Manager.
  • How to setup an archive cluster

Environment

VCF Ops / VCF for Logs: 9.1

Resolution

  • What is an archive location?

    • The archive location is an NFS shared storage drive (VCF 9 uses NFSv3 and 9.1 includes the use of an S3 compatible endpoint) 

  • What does an archive location provide?

    • Configuring an archive location allows you to keep a running copy of all logs ingested by VCF for logs while keeping a rotating retention period within VCF for logs itself. 

  • Is the archive location managed by VCF for logs?

    • The archive itself is not managed by VCF for logs and will continue to have log events copied over so long as there is sufficient space to store said log events. See VCF Operations for Logs Detailed Design

  • How do you view logs stored in the archive location?

  • Can older archived log events be imported into newer versions of VCF for logs?

    • The underlying format used to store log events (.blob files) remains unchanged. VCF 9 can read imported log events stored from older versions of Aria for logs|Log Insight. 

  • How do we set up an Index Partitions to increase data retention for specific clusters/hosts?

Additional Information

Configure Archive Log Import