Missing email alerts in Aria Operations for Logs
search cancel

Missing email alerts in Aria Operations for Logs

book

Article ID: 450751

calendar_today

Updated On:

Products

VCF Operations/Automation (formerly VMware Aria Suite)

Issue/Introduction

  • Configured email alarms do not trigger even when events matching the alarm criteria are present in the logs.
  • Test emails sent from the System Notification settings are successful.
  • Log ingestion rates (Events Per Second - EPS) (under Management -> System Monitor -> Statistics)  are near or exceeding the cluster's configuration limits.

Environment

Aria Operations for Logs 8.18.x

Cause

When an Aria Operations for Logs cluster is undersized or hitting ingestion limits (EPS), resources (CPU/Memory) are prioritized for ingestion and indexing to prevent data loss. This resource contention can cause the alerting engine to lag or fail to process triggers in real-time, resulting in missed email notifications.

Resolution

This is an expected behavior when cluster resources are exhausted. To resolve this issue, scale the cluster to match the actual ingestion requirements and Optimize Retention and Filters.

  1. Log in to the Aria Operations for Logs UI.
  2. Navigate to Management → System Monitor.
  3. Select Statistics and review the Events ingestion rate (per second).
  4. Compare this value against the supported limits for the node size (e.g., Medium nodes support ~5,000 EPS; Large nodes support ~15,000 EPS).
    See: Sizing the vRealize Log Insight Virtual Appliance
  5. Scale the Cluster based on the current ingestion rate: 

    If the ingestion rate exceeds the cluster capacity, perform one of the following options:

    Scale Out: Add additional worker nodes to the cluster to distribute the ingestion load. Use the Aria Operations for Logs Sizing Calculator to determine the required node count.

    Scale Up: Increase the vCPU and Memory for all existing nodes. 

  6. Optimize Retention and Filters:
    Review and adjust retention settings to ensure the /storage/core partition is not nearing 100% utilization.
    See: How to calculate Retention Days in Aria Operations for Logs