Collectors stop of log forwarding to syslog until collectors are restarted in RHOCP 4
Issue
- Log Forwarder in OpenShift Container Platform fails to send log data to an external syslog receiver until the collector pods are restarted
- The receiver is operational, as logs from other senders are still being processed, but not to the syslog server
- No error messages or connection issues are logged by the pods.
- Logs are not forwarded and the collectors does not show any error
-
os error 104
errors observed in the collector logs2025-08-04T10:25:28.062157Z ERROR sink{component_kind="sink" component_id=output_syslog component_type=socket}: vector::internal_events::socket: Error sending data. error=Connection reset by peer (os error 104) error_code="socket_send" error_type="writer_failed" stage="sending" mode=tcp internal_log_rate_limit=true 2025-08-04T10:25:28.062197Z ERROR sink{component_kind="sink" component_id=output_syslog component_type=socket}: vector_common::internal_event::component_events_dropped: Events dropped intentional=false count=1 reason="Error sending data." internal_log_rate_limit=true
Environment
- Red Hat OpenShift Container Platform (RHOCP)
- 4
- Red Hat OpenShift Logging (RHOL)
- 5
- 6
- Vector
- syslog
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.