The OHS log at <GC_INST>/user_projects/domains/GCDomain/servers/ohs1/logs/ohs1.log shows messages like the following:
[2018-08-07T10:37:08.5618-05:00] [OHS] [ERROR:32] [] [core.c] [client_id: <client ip address>] [host_id: <OMS hostname>] [host_addr: <OMS IP address>] [tid: 140073893857024] [user: oracle] [ecid: 0000MIjGpMU3b6M5mNT4iZ1RHes^00000F] [rid: 0:5701] [VirtualHost: <OMS hostname>:0] client denied by server configuration: <PATH TO $GC_INST>/WebTierIH1/config/OHS/ohs1/htdocs/empbs
Cause
One of the agents was trying to upload data to the EM repository using the unlocked http url, and the EM OMS upload repository is locked.
The agent can be found by using the client IP address in the ohs1.log file, as indicated here: [client_id: <client ip address>]
Solution
Secure that agent on the machine identified by that IP address by running:
emctl secure agent
This will prompt for the registration password. If you or your administrators do not have this password one can be set following this note: Note 1367946.1 – Enterprise Manager Cloud Control Security: How to Create or Edit the Agent Registration Password for Agent to OMS Secure Communication