Architecting a vRealize Log Insight Solution : Sample Syslog Design Scenarios : 10.1 Design Scenario A
   
10.1 Design Scenario A
This is a simple single-site deployment in which vRealize Log Insight is located on the same network segment as the source hosts being monitored. Each syslog source is configured to send events directly to a single vRealize Log Insight instance using UDP.
Figure 12. Design Scenario A
 
The following information provides specific comments about this scenario and accompanying solution design.
Design Quality
Architect Notes
Simple Configuration
Dependent only on the syslog agent, local network connectivity and vRealize Log Insight VA. There are no obvious drawbacks. However, this design is clearly limited in scope and would not meet the needs of most service provider level customers.
Syslog transport protocol: UDP
UDP is the most efficient protocol for local network syslog traffic most often used when there is no specific requirement to verify data packet delivery.
Single vRealize Log Insight instance
Sufficient for this design, as the number of source hosts will not go above the ingestion limit of 750. No vRealize Log Insight redundancy is provided other than standard vSphere HA protection, protecting against host failure. Another solution would be to provide a vRealize Log Insight cluster made up of two or more smaller instances. This would have the added advantage of providing an increase in syslog application availability.