Intermittent Audit logs are being added to the in-memory queue alert on StorageGRID
Applies to
- NetApp StorageGRID
- VMware Storage nodes
- External load balancer configured as syslog host
Issue
- StorageGRID UI intermittently reports
Audit logs being added to the in-memory queue erroron all storage nodes. - Additional alert may persist as a symptom of the audit logs not forwarding:
Logs being added to the on-disk memory queue.

- Frequent Broken connection alerts recorded in
/var/local/log/bycast.logbetween nodes:
| NOTICE 0780 a5367af1fa16b373 RCON: Connection to Node 112XXX has been inactive for 304 seconds. Closing.| WARNING 0393 7ae175e61e5d5a4c IP4F: Connection 1759XXXXX, Flow 17598XXX: 10.XX.XXX.13:38XXX <-> 10.XXX.XXX.10:15XX: Destroyed with bytes pending: unwritten 0, queue DEQ[++++:1|38(1/inf|131472/inf|262144)]ENQ[+++B:0|0(1/inf|131472/inf|262144)], ENDT| NOTICE 0558 a5367af1fa16b373 RCON: peer 112XXX destroyed network result ENDT rcon type ndcd:DISCONNECTED reason dbrk:DISCONNECTED_BROKEN| NOTICE 0686 RRTR: Connection to ADC, NID 112XXX was lost because "Neighbour connection was broken".
- In GRID logs via
os/var/local/log/messages.latestshow frequent connection issues to the external syslog server, from admin and storage nodes:
<node1> rsyslogd: omfwd: TCPSendBuf error -1, destruct TCP Connection to <Syslog_hostname:Port><node1> rsyslogd: cannot connect to <Syslog_hostname:Port>: Connection refused<node2> rsyslogd: omfwd: remote server at <Syslog_hostname:Port> seems to have closed connection. This often happens when the remote peer (or an interim system like a load balancer or firewall) shuts down or aborts a connection. Rsyslog will re-open the connection if configured to do so (we saw a generic IO Error, which usually goes along with that behaviour).
/os/var/local/log/messages.latestalso reports instances of Certificate file is not set:
rsyslogd: Warning: Certificate file is not setrsyslogd: Warning: Key file is not set rsyslogd: nsd_ossl: TLS Connection initiated with remote syslog server.rsyslogd: nsd_ossl: No shared curve between syslog client and server. rsyslogd: nsd_ossl: TLS session terminated with remote syslog server: rsyslogd: action-13-builtin:omfwd queue[DA]: queue files exist on disk, re-starting with 8400 messages. This will keep the disk queue file openrsyslogd: action-14-builtin:omfwd queue[DA]: queue files exist on disk, re-starting with 8396 messages. This will keep the disk queue file openrsyslogd: action-15-builtin:omfwd queue[DA]: queue files exist on disk, re-starting with 3436099 messages. This will keep the disk queue file open
