Tools

Kiwi Syslog logs throwing Errors Unable to connect to Service socket on TCP port 3300 & Out of memory | Module Name: Syslogd.frm

This article explains cause and resolution of such Errors reported under Kiwi Syslog when its started throwing such Errors and symptoms

First published date

12/27/2021 9:07 AM

Last published date

2/4/2026 12:30 AM

Overview

Service running, but Service/Manager comm link is not connecting. Unable to connect to Service socket on TCP port 3300
2021-10-23 14:00:49	Service Version =9.7.2.1 | Error Number: 7 | Description: Out of memory | Module Name: Syslogd.frm |
 Procedure Name: ParseMessageQueue | Line Number: 10 | Date and time: 10/23/2021 2:00:49 PM
2021-10-23 14:23:44	*** INTERNAL PROGRAM ERROR - Please contact http://www.kiwisyslog.com/support/ ***
2021-10-23 14:23:44	Service Version =9.7.2.1 | Error Number: -2147024882 | Description: Exception of type
 'System.OutOfMemoryException' was thrown. | Module Name: Syslogd.frm | Procedure Name: ParseMessageQueue | Line Number: 1480 
| Date and time: 10/23/2021 2:23:44 PM
2021-10-23 14:50:54	*** INTERNAL PROGRAM ERROR - Please contact http://www.kiwisyslog.com/support/ ***
2021-10-23 14:50:54	Service Version =9.7.2.1 | Error Number: -2147024882 | Description: Exception of type 'System.OutOfMemoryException' was thrown.
 | Module Name: Syslogd.frm | Procedure Name: ParseMessageQueue | Line Number: 400 | Date and time: 10/23/2021 2:50:54 PM
Next Error :
2021-12-23 18:38:45 Unable to open InterApp listening socket on TCP port 3300
2021-12-20 10:11:42	Service Version =9.7.2.1 | Error Number: -2147024882 | Description: Exception of type 'System.OutOfMemoryException' was thrown. | Module Name: Syslogd.frm | Procedure Name: ParseMessageQueue | Line Number: 400 | Date and time: 12/20/2021 10:11:42 AM
2021-12-23 18:38:45	Unable to open InterApp listening socket on TCP port 3300


- Unable to generate Tech Support File in Kiwi Syslog Service Manager Console.
- Unable to generate Diagnostics in Kiwi Syslog Service Manager Console.
 

Product section

Kiwi Syslog Server

Cause

These are all indication of high influx of syslog messages that broke the Service/Manager communication (i.e.Service running, but Service/Manager comm link is not connecting)

Error_Log:
Description: Exception of type 'System.OutOfMemoryException' was thrown. | Module Name: Syslogd.frm 

Reason for this to happen is exceeding the volume of traffic allowed by Kiwi.
Kiwi Syslog can handle 2 million messages per hour, or 48 million per day when logging to 'flatfiles'. (If logging to a database, including the built-in Kiwi web access database, Kiwi can only handle 360,000 messages per hour, or 8.6 million per day).

This error is also due to the fact that your syslog server is receiving a high influx of syslog messages and confirms it.

Resolution

Additional Information:
This article explains the maximum number of messages that the Kiwi Syslog Daemon can handle.
Maximum number of messages for Kiwi Syslog Daemon:


Support Recommendations: Resolution : 

1. In order to eliminate the halting, try reducing the volume of syslog messages you are sending to the Kiwi Syslog Server.
Maybe you can remove Info and Notice level messages if it not essential.  Here is the KB article that describes how to do that in Kiwi Syslog:


Each incoming message contains a priority value, consisting of a facility and a level. Use the Priority filter to trigger an action when you receive high or low priority messages. For example, you can create a rule that sends an email when you receive a message with a critical or higher priority level.
Filter messages based on priority


2. And if it is essential, you can Load Balance Kiwi Syslog Server to distribute the process into multiple servers. 
More on this can be found here:
This article discusses how to load balance the Kiwi Syslog Server to mitigate any overloading that may occur.
Load balance the Kiwi Syslog Server:

3. If you need more capacity for receiving High Volume of Syslog Messages, our Solarwinds Security Event Manager (SEM) can handle more than 2 million messages per hour.

For more information:

Security Event Manager (SEM) formerly Log and Event Manager (LEM):