ranger-dev mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "Velmurugan Periasamy (Jira)" <j...@apache.org>
Subject [jira] [Commented] (RANGER-2820) Difference between audit log spool directory and the archive directory under spool in Ranger
Date Fri, 11 Sep 2020 14:50:00 GMT

    [ https://issues.apache.org/jira/browse/RANGER-2820?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17194306#comment-17194306
] 

Velmurugan Periasamy commented on RANGER-2820:
----------------------------------------------

CC [~mehul] / [~rmani]

> Difference between audit log spool directory and the archive directory under spool in
Ranger
> --------------------------------------------------------------------------------------------
>
>                 Key: RANGER-2820
>                 URL: https://issues.apache.org/jira/browse/RANGER-2820
>             Project: Ranger
>          Issue Type: Bug
>          Components: Ranger
>    Affects Versions: 1.2.0
>            Reporter: dhivya
>            Priority: Minor
>
> From the Ranger documentation i understand that in case of destination sink down then
spool directory can hold the the unsent messages to disk files to prevent or minimize the
loss of audit messages Once memory buffer fills up 
> For example i could see some logs files are created under /var/log/hadoop/yarn/audit/solr/spool
with the name format spool_yarn_*.log 
> Inside the spool directory i could see one more folder called "archive",What is the use
of this archive folder? and why the spool directories are not getting cleaned up once the
destination sink is up ? this is bumping up the utilization on those directory.
> Cn someone clarify this 
>  [https://cwiki.apache.org/confluence/display/RANGER/Ranger+0.5+Audit+Configuration] 



--
This message was sent by Atlassian Jira
(v8.3.4#803005)

Mime
View raw message