You need to forward VCF Operations component logs to an external syslog or SIEM solution for centralized monitoring, compliance, or troubleshooting purposes.
In VCF Operations 9.x, all component logs are collected centrally by VCF Operations for Logs 9.0. appliance or the VCF Operations 9.1 Log Management feature.
VCF Operations 9.0
VCF Operations 9.1
Direct log forwarding from VCF Operations to an external syslog server is not supported in VCF Operations 9.x.
To forward logs from VCF Operations 9.1 to an external syslog server see Configuring Log Forwarding.
To forward logs from VCF Operations 9.0 configure the log forwarding rules directly within the VCF Operations for Logs 9.0 appliance.
Verify that log collection is actively established before configuring the external server:
Log in to the VCF Operations UI.
Navigate to:
Infrastructure Operations > Configurations > Log Collection in VCF 9.0
Operate > Administration > Configurations > Log Collection in VCF 9.1
Ensure that the VCF Operations is successfully configured as a log collector.
Steps to Configure Log Forwarding
Log in directly to the VCF Operations for Logs 9.0 appliance.
Go to Log Management > Log Forwarding in VCF 9.0 or Operate > Administration > Configurations > Log Collection in VCF 9.1 Operations UI.
Enter the required details for your external syslog server (including the protocol, IP address/hostname, port, and format).
Configure Filters: To ensure only VCF Operations logs are forwarded to this destination, add a filter for the hostname (e.g., set the criteria to match the VCF Operations FQDN). You can also add any other filters as required by your organization's logging policies.
Save the configuration.
Once saved, the appliance will automatically route the filtered logs from VCF Operations to your external syslog server.
Find the documentation mentioned below for more information
VCF Operations から外部 Syslog サーバーへログを転送する方法 (451327)