ClusterLogForwarder is not sending full audit logs to external rsyslog
Issue
- Enabled
ClusterLogForwarderto send audit logs to external rsyslog log aggregator, but full audit logs are not appearing. - Checking the OpenShift audit logs on the node using
oc node-logs, full log entries are shown. -
The output send from the
ClusterLogForwarder, only the following is shown:fluentd: type=ANOM_PROMISCUOUS msg=audit(xxxxxxxxxx.989:205): dev=vethxxxxxxxx prom=0 old_prom=256 auid=4xxxxxxx5 uid=800 gid=801 ses=4xxxxxxx 5AUID="unset" UID="openvswitch" GID="xxxxxfs" - The collector is not forwarding the logs to external
rsyslogserver whenRFC5424is used withClusterLogForwardercustom resource. - The
payloadKeysyslog parameter is configured tomessageto capture audit messages.
Environment
- Red Hat OpenShift Container Platform (RHOCP)
- 4
- Red Hat OpenShift Logging (RHOL)
- 5
- 6
- Fluentd
- Vector
ClusterLogForwarder- Syslog protocol
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.