Collectors stop of log forwarding to syslog until collectors are restarted in RHOCP 4

Solution Verified - Updated -

Issue

  • Log Forwarder in OpenShift Container Platform fails to send log data to an external syslog receiver until the collector pods are restarted
  • The receiver is operational, as logs from other senders are still being processed, but not to the syslog server
  • No error messages or connection issues are logged by the pods.
  • Logs are not forwarded and the collectors does not show any error
  • os error 104 errors observed in the collector logs

    2025-08-04T10:25:28.062157Z ERROR sink{component_kind="sink" component_id=output_syslog component_type=socket}: vector::internal_events::socket: Error sending data. error=Connection reset by peer (os error 104) error_code="socket_send" error_type="writer_failed" stage="sending" mode=tcp internal_log_rate_limit=true
    2025-08-04T10:25:28.062197Z ERROR sink{component_kind="sink" component_id=output_syslog component_type=socket}: vector_common::internal_event::component_events_dropped: Events dropped intentional=false count=1 reason="Error sending data." internal_log_rate_limit=true
    

Environment

  • Red Hat OpenShift Container Platform (RHOCP)
    • 4
  • Red Hat OpenShift Logging (RHOL)
    • 5
    • 6
  • Vector
  • syslog

Subscriber exclusive content

A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.

Current Customers and Partners

Log in for full access

Log In

New to Red Hat?

Learn more about Red Hat subscriptions

Using a Red Hat product through a public cloud?

How to access this content