Relay1 is unable to send logs to another Relay2. TLS Connection drops. Logs are queuing.
说明
Whenever there's an attempt from Relay1 to connect to Relay2 through TLS connection, the connection seems to be established but will eventually be dropped leading Relay1 to be unable to send logs to Relay2. Logs are queuing.
解决办法
Look out for error messages like the following:
1. curl: error sending HTTP request; url='https://SplunkServerDefaultCert:3333/services/collector/event', error='SSL peer certificate or SSH remote key was not OK', worker_index='0', driver='d_splunk_test#0', location='/opt/syslog-ng/share/syslog-ng/include/scl/splunk/plugin.conf:8:3' 2. Target server down, but no alternative server available. Falling back to retrying after time-reopen(); url='https://SplunkServerDefaultCert:3333/services/collector/event', worker_index='0', driver='d_splunk_test#0', location='/opt/syslog-ng/share/syslog-ng/include/scl/splunk/plugin.conf:8:3' 3. Server disconnected while preparing messages for sending, trying again; driver='d_splunk_test#0', location='/opt/syslog-ng/share/syslog-ng/include/scl/splunk/plugin.conf:8:3', worker_index='0', time_reopen='10', batch_size='1'
The above errors indicate that a token has expired.