This article addresses persistent alerts in VMware Aria Operations that do not auto-cancel after the underlying I/O condition resolves, as well as redundant notification bursts. This typically occurs in environments integrated with VMware Aria Operations for Logs.
Periodically receiving active alerts in VMware Aria Operations or VMware Aria Automation.
Notification Event details show:
VMware Aria Operations for Logs: Failed-IOs-on-ESXi_Hostname
These alerts remain open indefinitely and do not auto-cancel.
Corresponding events are not active or visible on the underlying vCenter Server instance.
VMware Aria Operations 8.18.x
VMware Aria Operations for Logs (formerly VMware vRealize Log Insight) 8.18.x
Alerts fail to clear due to two primary configuration deficits:
Failed-IOs-on-$(hostname) alert definition.These notification events originate from log queries within VMware Aria Operations for Logs and are forwarded to Aria Operations via integration.
The alert definition Failed-IOs-on-$(hostname) does not automatically clear because the Auto Cancel feature is disabled by default for this specific alert definition in Aria Operations for Logs. Because the alert lacks an auto-cancellation trigger, Aria Operations retains the alert in an active state even after the underlying I/O condition resolves.
1. Enable Auto Cancel
Failed-IOs-on-$(hostname).2. Disable Notification Heartbeat
3. Manual Cleanup Existing active alerts created prior to these changes must be cleared manually: