The vRealize Log Insight Server rejects the connection with the Log Insight Agents when you try to send non-encrypted traffic.

When you attempt to use cfapi to send nonencrypted traffic, the vRealize Log Insight Server rejects your connection. The following error message appears in the Log Insight Agent log.

403 Forbidden.

vRealize Log Insight is configured to accept only SSL connections, but the Log Insight Agents are configured to use non-SSL connection.

You can configure vRealize Log Insight Server to accept non-SSL connections or configure the Log Insight Agents to send data through SSL cfapi protocol connection.

1

Configure vRealize Log Insight Server to accept non-SSL connection.

a

Click the configuration drop-down menu icon and select Administration.

b

Under Configuration, click SSL.

c

Under the API Server SSL header, deselect the Require SSL Connection check box.

d

Click Save.

2

Configure the Log Insight Agents to send data through SSL Cfapi protocol connection.

a

Navigate to the folder containing the liagent.ini file.

Operating system

Path

Linux

/var/lib/loginsight-agent/

Windows

%ProgramData%\VMware\Log Insight Agent

b

Open the liagent.ini file in any text editor.

c

Change the ssl key in the [server] section of the liagent.ini file to yes and the protocol to cfapi.

proto=cfapi
ssl=yes
d

Save and close the liagent.ini file.