Yeah sure, it's hard to correlate (rsyslog getting into this state is preventing new ssh attempts and such) but, I just got lucky and have an active root session on a box experiencing this. I'm only getting this behaviour on the boxes we installed osquery on, everything is CentOS6, it initially appeared because we started getting unresponsive boxes but from looking into this processes appear to all be up and running. However, all logging has stopped. The only change that seems to correlate was Osquery getting deployed. We have osquery configured to use syslog only as the logger plugin (if that would matter) the last logs from local3 are: