Why are infrastructure logs not stored in local Elasticsearch when ClusterLogForwarder is defined?
Issue
When a ClusterLogForwarder is configured in RHOCP cluster the infrastructure and/or audit logs are not being stored in local Elasticsearch. Usually the first sign of this behavior is that Kibana stops showing any events.
Environment
- Red Hat OpenShift Container Platform (RHOCP) 4
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.