After making changes to the Docker Network in Test Appliance, Qradar is no longer getting syslogs. Production is working fine though.
Release : 4.1.0, 4.1.1, 4.1.2
While modifying the docker networking setting an invalid address was entered in the configuration. Subsequently, this was corrected but several settings in the PAM database were inadvertently modified. This caused 2 of the internal docker containers to fail to restart after rebooting the node.
This needs to be corrected in the PAM database directly by a Broadcom Support engineer over ssh as this will not auto correct.