ESXi hosts experience syslog message loss and trigger frequent HostErrorAlarm alerts in VCF Operations. Log output displays vmsyslog logger lost log messages. This occurs when syslog forwarding is configured to send logs to both the Cloud Proxy IP address and the VCF Logs VIP simultaneously.
VCF Operations 9.0.2
When "Collect logs using the collector/group" is enabled for the vCenter adapter in VCF Operations, the system automatically appends the Cloud Proxy IP address to the Syslog.global.logHost property on the ESXi host. If the environment is also configured to forward logs to a VCF Logs VIP, this creates a duplicate configuration, resulting in syslog message loss and frequent HostErrorAlarm alerts.
Configure log collection to target the Logs cluster directly:
/etc/init.d/vmsyslogd restart
For additional details on syslog troubleshooting, refer to Syslog troubleshooting for VCF Operations.