- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
1.) It depends on how you configure the agent. By default it is over Log Insight's new ingestion API which is TCP 9000 and not encrypted. The agent also supports sending events over the syslog protocol in which case you can choose port 1514 which does support encryption. For more information see this link: VMware vCenter Log Insight 2.0 Documentation Center
2.) Log Insight is licensed on an operating system instance (OSI) basis. If you are collecting logs from ESX then each ESX = 1 OSI. If you collecting logs from 40 windows VMs then you need 40 OSI. If you are collecting from both ESX and VMs then you would need 41 OSI. If you want to collect form vCenter Server as well then you are up to 42. The easiest way to think about it is per originator of a syslog message (e.g. unique IP address).