<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/"><channel><title>Log Management on Cosmin.us</title><link>https://cosmin.us/tags/log-management/</link><description>Recent content in Log Management on Cosmin.us</description><generator>Hugo</generator><language>en-US</language><dc:creator>Cosmin Trif</dc:creator><lastBuildDate>Tue, 08 Sep 2026 16:30:00 +0000</lastBuildDate><atom:link href="https://cosmin.us/tags/log-management/index.xml" rel="self" type="application/rss+xml"/><item><title>Upgrading VCF Log Management to 9.1.1 Step by Step</title><link>https://cosmin.us/upgrading-vcf-log-management-to-9-1-1-step-by-step/</link><pubDate>Tue, 08 Sep 2026 16:30:00 +0000</pubDate><dc:creator>Cosmin Trif</dc:creator><guid>https://cosmin.us/upgrading-vcf-log-management-to-9-1-1-step-by-step/</guid><description>&lt;p&gt;With VCF 9.1.1 released on September 3, 2026, I wanted to continue patching the management services in my lab. This post is a follow-up to my &lt;a href="https://cosmin.us/upgrading-vcf-9-1-management-services-to-9-1-0-0400-step-by-step/"&gt;VCF 9.1 management services upgrade walkthrough&lt;/a&gt; and focuses on &lt;strong&gt;Log Management&lt;/strong&gt; through VCF Operations.&lt;/p&gt;
&lt;p&gt;VCF 9.1.1 is a maintenance release focused mostly on supportability improvements. The main &lt;a href="https://techdocs.broadcom.com/us/en/vmware-cis/vcf/vcf-9-0-and-later/9-1/release-notes/vmware-cloud-foundation-9-1-1-0-release-notes.html"&gt;VCF 9.1.1 release notes&lt;/a&gt; and the &lt;a href="https://techdocs.broadcom.com/us/en/vmware-cis/vcf/vcf-9-0-and-later/9-1/release-notes/vmware-cloud-foundation-9-1-1-0-release-notes/vcfoperations-9-1-1-0-release-notes.html"&gt;VCF Operations 9.1.1 release notes&lt;/a&gt; are the references I used for this upgrade.&lt;/p&gt;
&lt;p&gt;In VCF 9.1, Log Management is a VCF management service hosted on the VCF services runtime. The supported lifecycle workflow is therefore in VCF Operations under &lt;strong&gt;Build -&amp;gt; Lifecycle -&amp;gt; VCF Management -&amp;gt; Upgrade&lt;/strong&gt;. This walkthrough covers a 9.1.0.x maintenance upgrade; an environment coming from an older VCF or Aria release should follow the matching &lt;a href="https://techdocs.broadcom.com/us/en/vmware-cis/vcf/vcf-9-0-and-later/9-1/deployment/upgrading-cloud-foundation/upgrade-vcf-operations-for-logs.html"&gt;Log Management upgrade procedure&lt;/a&gt; first.&lt;/p&gt;</description><content:encoded>&lt;p&gt;With VCF 9.1.1 released on September 3, 2026, I wanted to continue patching the management services in my lab. This post is a follow-up to my &lt;a href="https://cosmin.us/upgrading-vcf-9-1-management-services-to-9-1-0-0400-step-by-step/"&gt;VCF 9.1 management services upgrade walkthrough&lt;/a&gt; and focuses on &lt;strong&gt;Log Management&lt;/strong&gt; through VCF Operations.&lt;/p&gt;
&lt;p&gt;VCF 9.1.1 is a maintenance release focused mostly on supportability improvements. The main &lt;a href="https://techdocs.broadcom.com/us/en/vmware-cis/vcf/vcf-9-0-and-later/9-1/release-notes/vmware-cloud-foundation-9-1-1-0-release-notes.html"&gt;VCF 9.1.1 release notes&lt;/a&gt; and the &lt;a href="https://techdocs.broadcom.com/us/en/vmware-cis/vcf/vcf-9-0-and-later/9-1/release-notes/vmware-cloud-foundation-9-1-1-0-release-notes/vcfoperations-9-1-1-0-release-notes.html"&gt;VCF Operations 9.1.1 release notes&lt;/a&gt; are the references I used for this upgrade.&lt;/p&gt;
&lt;p&gt;In VCF 9.1, Log Management is a VCF management service hosted on the VCF services runtime. The supported lifecycle workflow is therefore in VCF Operations under &lt;strong&gt;Build -&amp;gt; Lifecycle -&amp;gt; VCF Management -&amp;gt; Upgrade&lt;/strong&gt;. This walkthrough covers a 9.1.0.x maintenance upgrade; an environment coming from an older VCF or Aria release should follow the matching &lt;a href="https://techdocs.broadcom.com/us/en/vmware-cis/vcf/vcf-9-0-and-later/9-1/deployment/upgrading-cloud-foundation/upgrade-vcf-operations-for-logs.html"&gt;Log Management upgrade procedure&lt;/a&gt; first.&lt;/p&gt;
&lt;h2 id="versions-in-this-upgrade"&gt;Versions in This Upgrade&lt;/h2&gt;
&lt;p&gt;These are the versions reported by the VCF Operations UI in my lab:&lt;/p&gt;
&lt;table&gt;
	&lt;thead&gt;
			&lt;tr&gt;
					&lt;th&gt;Component&lt;/th&gt;
					&lt;th&gt;Current Version&lt;/th&gt;
					&lt;th&gt;Target Version&lt;/th&gt;
			&lt;/tr&gt;
	&lt;/thead&gt;
	&lt;tbody&gt;
			&lt;tr&gt;
					&lt;td&gt;Log Management&lt;/td&gt;
					&lt;td&gt;9.1.0.0400.25544947&lt;/td&gt;
					&lt;td&gt;9.1.1.0.25679624&lt;/td&gt;
			&lt;/tr&gt;
	&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;The target build is also listed in the VCF Operations 9.1.1 release notes.&lt;/p&gt;
&lt;h2 id="before-you-begin"&gt;Before You Begin&lt;/h2&gt;
&lt;p&gt;For an existing &lt;strong&gt;9.1.0.x&lt;/strong&gt; environment, patch &lt;strong&gt;Fleet Lifecycle to 9.1.1.0 before any other VCF component&lt;/strong&gt;. After Fleet Lifecycle is updated, the release notes allow the remaining components to be patched according to the documented dependencies. I ran this Log Management operation by itself so that the task and validation were easy to follow.&lt;/p&gt;
&lt;p&gt;Before starting:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Verify that the external SFTP backup location is configured and reachable under &lt;strong&gt;Build -&amp;gt; Lifecycle -&amp;gt; VCF Management -&amp;gt; Backup &amp;amp; Restore&lt;/strong&gt;. Keep the backup encryption passphrase available for a restore.&lt;/li&gt;
&lt;li&gt;Take an &lt;a href="https://techdocs.broadcom.com/us/en/vmware-cis/vcf/vcf-9-0-and-later/9-1/fleet-management/backup-and-restore-of-cloud-foundation.html"&gt;on-demand component backup&lt;/a&gt; and verify that it completed successfully before patching Log Management.&lt;/li&gt;
&lt;li&gt;Confirm that the lifecycle metadata is current and that the required 9.1.1 binaries are available in the configured software depot. If the depot is offline, prepare the binaries with the &lt;a href="https://techdocs.broadcom.com/us/en/vmware-cis/vcf/vcf-9-0-and-later/9-1/lifecycle-management/binary-management-for-vmware-cloud-foundation.html"&gt;VCF Download Tool&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Make sure no other upgrade or patch operation is running. The &lt;a href="https://techdocs.broadcom.com/us/en/vmware-cis/vcf/vcf-9-0-and-later/9-1/lifecycle-management/using-the-depot-configuration-tab/upgrade-a-vcf-management-component.html"&gt;individual-component procedure&lt;/a&gt; says another component cannot be upgraded or patched while an operation is in progress.&lt;/li&gt;
&lt;li&gt;Plan a maintenance window and record the Log Management integrations and log sources you need to test afterward.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;There is also a 9.1.1 known issue when &lt;strong&gt;Log Management&lt;/strong&gt; and &lt;strong&gt;VCF Operations for networks&lt;/strong&gt; are installed in parallel: the platform can be disrupted, causing Real-time Metrics to fail and the Operations for networks task to remain stuck for more than three hours. Install those components sequentially instead.&lt;/p&gt;
&lt;h2 id="selecting-log-management"&gt;Selecting Log Management&lt;/h2&gt;
&lt;p&gt;Log in to VCF Operations with an Administrator account and go to &lt;strong&gt;Build -&amp;gt; Lifecycle -&amp;gt; VCF Management -&amp;gt; Upgrade&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;The target in my lab is already &lt;code&gt;9.1.1.*&lt;/code&gt;. If the target is still on an older release, click &lt;strong&gt;Select Version&lt;/strong&gt;, choose &lt;code&gt;9.1.1.*&lt;/code&gt;, and apply the target before selecting the component. If the page shows a warning that VCF Operations must be patched independently, finish that patch and wait for it to succeed before continuing with the other management components.&lt;/p&gt;
&lt;p&gt;Filter the component list for &lt;strong&gt;log&lt;/strong&gt;, select &lt;strong&gt;Log management&lt;/strong&gt;, and make sure the intended instance is selected. In my lab the instance is &lt;strong&gt;instance-a&lt;/strong&gt;. Expand &lt;strong&gt;Check Required Binaries&lt;/strong&gt; and resolve any missing binary before continuing.&lt;/p&gt;
&lt;p&gt;The upgrade path should read &lt;strong&gt;9.1.0.0400.25544947 -&amp;gt; 9.1.1.0.25679624&lt;/strong&gt;. The screenshot below shows the target version, the selected Log Management instance, and the &lt;strong&gt;Ready for upgrade&lt;/strong&gt; state.&lt;/p&gt;
&lt;p&gt;&lt;img src="https://cosmin.us/images/2026/09/vcf-log-management-9-1-1-upgrade/001-capture-001.webp" alt="VCF Operations VCF Management Upgrade page showing Log Management instance-a ready to upgrade from 9.1.0.0400.25544947 to 9.1.1.0.25679624." width="1666" height="665" loading="lazy" decoding="async"&gt;
&lt;/p&gt;
&lt;h2 id="running-the-prechecks"&gt;Running the Prechecks&lt;/h2&gt;
&lt;p&gt;With only Log Management selected, click &lt;strong&gt;Run Prechecks (1)&lt;/strong&gt;. Follow the task by opening &lt;strong&gt;Precheck details&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;&lt;img src="https://cosmin.us/images/2026/09/vcf-log-management-9-1-1-upgrade/003-capture-003.webp" alt="Log Management precheck workflow showing the component package being staged in VCF services runtime." width="1128" height="621" loading="lazy" decoding="async"&gt;
&lt;/p&gt;
&lt;p&gt;The precheck workflow in my lab completed successfully in about 14 minutes. It passed the package staging, vCenter, database upgrade, and single-component backup checks.&lt;/p&gt;
&lt;p&gt;&lt;img src="https://cosmin.us/images/2026/09/vcf-log-management-9-1-1-upgrade/004-capture-004.webp" alt="Completed Log Management precheck workflow with an overall Passed result and six checks passed." width="1126" height="510" loading="lazy" decoding="async"&gt;
&lt;/p&gt;
&lt;p&gt;Do not start the upgrade until the precheck status is &lt;strong&gt;Passed&lt;/strong&gt;. If a check fails, open its details, remediate the reported issue, and run the precheck again.&lt;/p&gt;
&lt;h2 id="starting-the-upgrade"&gt;Starting the Upgrade&lt;/h2&gt;
&lt;p&gt;Return to the component list and click &lt;strong&gt;Upgrade&lt;/strong&gt; on the Log Management row. The row changes to &lt;strong&gt;Upgrade in progress&lt;/strong&gt;. Click &lt;strong&gt;Upgrade details&lt;/strong&gt; to follow the workflow.&lt;/p&gt;
&lt;p&gt;The workflow runs through these subtasks:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Set Log Management upgrade context for the workflow.&lt;/li&gt;
&lt;li&gt;Stage the Log Management plugin in VCF services runtime.&lt;/li&gt;
&lt;li&gt;Run the Log Management prechecks.&lt;/li&gt;
&lt;li&gt;Stage the Log Management package in VCF services runtime.&lt;/li&gt;
&lt;li&gt;Prepare Log Management for upgrade.&lt;/li&gt;
&lt;li&gt;Perform the Log Management upgrade.&lt;/li&gt;
&lt;li&gt;Run the post-upgrade inventory sync.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;img src="https://cosmin.us/images/2026/09/vcf-log-management-9-1-1-upgrade/007-capture-007.webp" alt="Log Management upgrade workflow in progress while the component upgrade is being performed." width="1122" height="637" loading="lazy" decoding="async"&gt;
&lt;/p&gt;
&lt;p&gt;The workflow started at &lt;strong&gt;10:53 AM&lt;/strong&gt; in my lab. The task took about &lt;strong&gt;1 hour and 11 minutes&lt;/strong&gt;, completing at &lt;strong&gt;12:04 PM&lt;/strong&gt;. That is the total workflow time shown in my task, not a promise about service downtime in another environment. Wait for the final inventory sync and confirm that the overall task is &lt;strong&gt;Completed&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;&lt;img src="https://cosmin.us/images/2026/09/vcf-log-management-9-1-1-upgrade/008-capture-008.webp" alt="Completed Log Management upgrade workflow with all seven subtasks completed." width="1128" height="480" loading="lazy" decoding="async"&gt;
&lt;/p&gt;
&lt;h2 id="verifying-the-new-version"&gt;Verifying the New Version&lt;/h2&gt;
&lt;p&gt;Go to &lt;strong&gt;Build -&amp;gt; Lifecycle -&amp;gt; VCF Management -&amp;gt; Components&lt;/strong&gt; and open the &lt;strong&gt;Log Management&lt;/strong&gt; component for the instance you upgraded.&lt;/p&gt;
&lt;p&gt;Under &lt;strong&gt;Summary&lt;/strong&gt;, verify that the status is &lt;strong&gt;Running&lt;/strong&gt;, the version is &lt;strong&gt;9.1.1.0.25679624&lt;/strong&gt;, and the component is managed by the expected VCF services runtime. In my lab the deployment size is &lt;strong&gt;Small&lt;/strong&gt; with one replica.&lt;/p&gt;
&lt;p&gt;&lt;img src="https://cosmin.us/images/2026/09/vcf-log-management-9-1-1-upgrade/009-capture-009.webp" alt="Log Management component summary showing Running status and version 9.1.1.0.25679624." width="419" height="376" loading="lazy" decoding="async"&gt;
&lt;/p&gt;
&lt;p&gt;After the component reports Running, validate the parts of the service that matter in your environment:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Open &lt;strong&gt;Operate -&amp;gt; Logs&lt;/strong&gt; and run a known query.&lt;/li&gt;
&lt;li&gt;Confirm that new events are arriving from representative vSphere, ESXi, and application sources.&lt;/li&gt;
&lt;li&gt;Check dashboards, alerts, notification targets, and any custom integrations.&lt;/li&gt;
&lt;li&gt;Verify that any custom log forwarding configuration still points to the correct Log Management instance.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="911-changes-to-keep-in-mind"&gt;9.1.1 Changes to Keep in Mind&lt;/h2&gt;
&lt;p&gt;The release notes call out a few Log Management changes that are easy to miss during validation:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;The &lt;strong&gt;Additional Storage Required&lt;/strong&gt; metric and its related symptoms, alerts, and dashboards were removed because the old value could report a misleading storage shortfall when no retention period was defined.&lt;/li&gt;
&lt;li&gt;The &lt;strong&gt;Server Side Encryption&lt;/strong&gt; field was removed from the &lt;strong&gt;Add New Storage&lt;/strong&gt; screen. AWS S3 uses its default AES-256 behavior; for non-AWS S3-compatible storage, configure bucket-level encryption on the storage server itself.&lt;/li&gt;
&lt;li&gt;If a Log Management Disaster Recovery restore leaves the Log Analysis page showing &lt;strong&gt;Unable to access logs due to user permissions&lt;/strong&gt;, the documented workaround is to restart the Log Management service through Fleet Lifecycle using the component &lt;strong&gt;Stop / Start&lt;/strong&gt; action.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Once the component and log sources have been validated, keep or expire the backup artifacts according to your retention policy. I also recommend clearing the browser cache before using the updated VCF Operations interface.&lt;/p&gt;
&lt;p&gt;Log Management in my lab is now on &lt;strong&gt;9.1.1&lt;/strong&gt;. If this is part of a larger VCF 9.1.1 maintenance run, continue with the remaining components in the order and dependency boundaries documented in the &lt;a href="https://techdocs.broadcom.com/us/en/vmware-cis/vcf/vcf-9-0-and-later/9-1/release-notes/vmware-cloud-foundation-9-1-1-0-release-notes.html"&gt;VCF 9.1.1 release notes&lt;/a&gt;.&lt;/p&gt;
&lt;!-- Editorial review, 2026-09-08:
Broadcom's VCF 9.1.1 release notes and the current individual-component lifecycle
procedure were reviewed on September 8, 2026. The supplied session contains nine
captures; 002, 005, and 006 are cropped state-transition views that repeat the
fuller workflow evidence, so the six higher-value captures are used here. The
included images are lossless WebP conversions with no visual edits. The captures
establish the source and target builds, precheck result, workflow subtasks, task
duration, and final Running state. They do not establish backup completion or
service downtime, so those are written as prerequisites and validation guidance.
The release-note guidance permits parallel work after Fleet Lifecycle where
component dependencies allow it; this walkthrough intentionally runs one
component at a time and follows the individual-component procedure.
--&gt;</content:encoded></item></channel></rss>