<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: LogSearch audit-logs empty in Support Questions</title>
    <link>https://community.cloudera.com/t5/Support-Questions/LogSearch-audit-logs-empty/m-p/198936#M160984</link>
    <description>&lt;P&gt;hi &lt;A rel="user" href="https://community.cloudera.com/users/12470/theyaamatti.html" nodeid="12470"&gt;@Theyaa Matti&lt;/A&gt;,&lt;/P&gt;&lt;P&gt;I think you hit that issue: &lt;A href="https://issues.apache.org/jira/browse/AMBARI-18372" target="_blank"&gt;https://issues.apache.org/jira/browse/AMBARI-18372&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 18 Apr 2017 21:36:36 GMT</pubDate>
    <dc:creator>oszabo</dc:creator>
    <dc:date>2017-04-18T21:36:36Z</dc:date>
    <item>
      <title>LogSearch audit-logs empty</title>
      <link>https://community.cloudera.com/t5/Support-Questions/LogSearch-audit-logs-empty/m-p/198932#M160980</link>
      <description>&lt;P&gt;I am trying to use logsearch and I have already hadoop logs showing up in the ui. But I can never get the audit-logs to show up. Are those logs related to specific actions on the cluster so I can trigger them?&lt;/P&gt;</description>
      <pubDate>Fri, 14 Apr 2017 00:11:57 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/LogSearch-audit-logs-empty/m-p/198932#M160980</guid>
      <dc:creator>theyaa</dc:creator>
      <dc:date>2017-04-14T00:11:57Z</dc:date>
    </item>
    <item>
      <title>Re: LogSearch audit-logs empty</title>
      <link>https://community.cloudera.com/t5/Support-Questions/LogSearch-audit-logs-empty/m-p/198933#M160981</link>
      <description>&lt;P&gt;Hi &lt;A rel="user" href="https://community.cloudera.com/users/12470/theyaamatti.html" nodeid="12470"&gt;@Theyaa Matti&lt;/A&gt;, &lt;/P&gt;&lt;P&gt;Depending upon the services you have deployed in your cluster, the audit logs will generally be written to for service-specific actions that occur (HDFS write, HDFS read, Ambari REST calls, etc).&lt;/P&gt;&lt;P&gt;Are you looking for a specific service's audit logs?  Please note that not all services write audit logs. &lt;/P&gt;&lt;P&gt;What version of Ambari are you using? &lt;/P&gt;&lt;P&gt;Hope this helps,&lt;/P&gt;&lt;P&gt;Bob&lt;/P&gt;</description>
      <pubDate>Fri, 14 Apr 2017 01:35:46 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/LogSearch-audit-logs-empty/m-p/198933#M160981</guid>
      <dc:creator>rnettleton</dc:creator>
      <dc:date>2017-04-14T01:35:46Z</dc:date>
    </item>
    <item>
      <title>Re: LogSearch audit-logs empty</title>
      <link>https://community.cloudera.com/t5/Support-Questions/LogSearch-audit-logs-empty/m-p/198934#M160982</link>
      <description>&lt;P&gt;Hi &lt;A rel="user" href="https://community.cloudera.com/users/12470/theyaamatti.html" nodeid="12470"&gt;@Theyaa Matti&lt;/A&gt;!&lt;/P&gt;&lt;P&gt;It processes ambari-audit or hdfs-audit log file as well, but its possible the parsing is not working properly because the grok patters that are used are not matching. (that can happen because of the date pattern, as that can change based on system language settings as well)&lt;/P&gt;&lt;P&gt;Which version of ambari/logsearch are you using? (if 2.5, those patterns can be changed: &lt;A href="https://issues.apache.org/jira/browse/AMBARI-18548" target="_blank"&gt;https://issues.apache.org/jira/browse/AMBARI-18548&lt;/A&gt; , if 2.4, then maybe you will need to check log4j settings for those services)&lt;/P&gt;&lt;P&gt;some pointers: for logfeeder generated input patterns and common grok patters located at /etc/ambari-logsearch-logfeeder/conf. You can try out the patterns with lines here: &lt;A href="https://grokdebug.herokuapp.com/" target="_blank"&gt;https://grokdebug.herokuapp.com/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Apr 2017 01:49:38 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/LogSearch-audit-logs-empty/m-p/198934#M160982</guid>
      <dc:creator>oszabo</dc:creator>
      <dc:date>2017-04-14T01:49:38Z</dc:date>
    </item>
    <item>
      <title>Re: LogSearch audit-logs empty</title>
      <link>https://community.cloudera.com/t5/Support-Questions/LogSearch-audit-logs-empty/m-p/198935#M160983</link>
      <description>&lt;P&gt;Hi &lt;A rel="user" href="https://community.cloudera.com/users/375/oszabo.html" nodeid="375"&gt;@oszabo&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Thank you for your info. I tried the gork debugger and compared it with the logs I have and I found out the issue was that I had to include the INFO logging in logsearch in order to capture the audit logs for hdfs access and hive access.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Apr 2017 20:56:05 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/LogSearch-audit-logs-empty/m-p/198935#M160983</guid>
      <dc:creator>theyaa</dc:creator>
      <dc:date>2017-04-18T20:56:05Z</dc:date>
    </item>
    <item>
      <title>Re: LogSearch audit-logs empty</title>
      <link>https://community.cloudera.com/t5/Support-Questions/LogSearch-audit-logs-empty/m-p/198936#M160984</link>
      <description>&lt;P&gt;hi &lt;A rel="user" href="https://community.cloudera.com/users/12470/theyaamatti.html" nodeid="12470"&gt;@Theyaa Matti&lt;/A&gt;,&lt;/P&gt;&lt;P&gt;I think you hit that issue: &lt;A href="https://issues.apache.org/jira/browse/AMBARI-18372" target="_blank"&gt;https://issues.apache.org/jira/browse/AMBARI-18372&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Apr 2017 21:36:36 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/LogSearch-audit-logs-empty/m-p/198936#M160984</guid>
      <dc:creator>oszabo</dc:creator>
      <dc:date>2017-04-18T21:36:36Z</dc:date>
    </item>
  </channel>
</rss>

