<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: In Apache Ranger, Audit logging not working for superuser only in Support Questions</title>
    <link>https://community.cloudera.com/t5/Support-Questions/In-Apache-Ranger-Audit-logging-not-working-for-superuser/m-p/392419#M248122</link>
    <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/114665"&gt;@eddy28&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Have you configured this property properly&lt;BR /&gt;"&lt;SPAN class="token token tag punctuation"&gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class="token token tag"&gt;name&lt;/SPAN&gt;&lt;SPAN class="token token tag punctuation"&gt;&amp;gt;&lt;/SPAN&gt;&lt;SPAN&gt;ranger.plugin.hdfs.service.name&lt;/SPAN&gt;&lt;SPAN class="token token tag punctuation"&gt;&amp;lt;/&lt;/SPAN&gt;&lt;SPAN class="token token tag"&gt;name&lt;/SPAN&gt;&lt;SPAN class="token token tag punctuation"&gt;&amp;gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="token token tag punctuation"&gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class="token token tag"&gt;value&lt;/SPAN&gt;&lt;SPAN class="token token tag punctuation"&gt;&amp;gt;&lt;/SPAN&gt;&lt;SPAN&gt;hadoopdev&lt;/SPAN&gt;&lt;SPAN class="token token tag punctuation"&gt;&amp;lt;/&lt;/SPAN&gt;&lt;SPAN class="token token tag"&gt;value&lt;/SPAN&gt;&lt;SPAN class="token token tag punctuation"&gt;&amp;gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="token token comment"&gt;&amp;lt;!-- Replace with your Ranger service name --&amp;gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;"&lt;BR /&gt;Do you have any exception after configuring the suggested property?&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 23 Aug 2024 08:46:13 GMT</pubDate>
    <dc:creator>vats</dc:creator>
    <dc:date>2024-08-23T08:46:13Z</dc:date>
    <item>
      <title>In Apache Ranger, Audit logging not working for superuser only</title>
      <link>https://community.cloudera.com/t5/Support-Questions/In-Apache-Ranger-Audit-logging-not-working-for-superuser/m-p/392262#M248050</link>
      <description>&lt;P&gt;Hi Everyone,&lt;/P&gt;&lt;P&gt;I’m new to Apache Ranger. I’ve created an HDFS policy and configured it to store audit logs in Solr. When I create or delete directories in HDFS, the audit logs are generated and visible in the Ranger UI. However, when I perform operations as the superuser (hdfs), no audit logs are generated.&lt;BR /&gt;&lt;BR /&gt;As shown in below screenshot, rangertest1 and rangertest2 users audit logs are shown on UI. But any operations performed using hdfs user, those logs not going in Audit DB.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="eddy28_0-1724264132109.png" style="width: 400px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/41488i2C23FF6F65BD1380/image-size/medium?v=v2&amp;amp;px=400" role="button" title="eddy28_0-1724264132109.png" alt="eddy28_0-1724264132109.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does Ranger not support audit logging for superuser actions?&lt;BR /&gt;I have already checked all the configs and there are no exclusions to any user.&lt;/P&gt;&lt;P&gt;Best regards,&lt;BR /&gt;Aditya&lt;/P&gt;</description>
      <pubDate>Wed, 21 Aug 2024 18:17:50 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/In-Apache-Ranger-Audit-logging-not-working-for-superuser/m-p/392262#M248050</guid>
      <dc:creator>eddy28</dc:creator>
      <dc:date>2024-08-21T18:17:50Z</dc:date>
    </item>
    <item>
      <title>Re: In Apache Ranger, Audit logging not working for superuser only</title>
      <link>https://community.cloudera.com/t5/Support-Questions/In-Apache-Ranger-Audit-logging-not-working-for-superuser/m-p/392263#M248051</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/114665"&gt;@eddy28&lt;/a&gt;&amp;nbsp;Welcome to the Cloudera Community!&lt;BR /&gt;&lt;BR /&gt;To help you get the best possible solution, I have tagged our Ranger experts&amp;nbsp;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/77040"&gt;@Atahar&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/72413"&gt;@vamsi_redd&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/93215"&gt;@Puni&lt;/a&gt;&amp;nbsp; who may be able to assist you further.&lt;BR /&gt;&lt;BR /&gt;Please keep us updated on your post, and we hope you find a satisfactory solution to your query.&lt;/P&gt;</description>
      <pubDate>Wed, 21 Aug 2024 18:53:03 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/In-Apache-Ranger-Audit-logging-not-working-for-superuser/m-p/392263#M248051</guid>
      <dc:creator>DianaTorres</dc:creator>
      <dc:date>2024-08-21T18:53:03Z</dc:date>
    </item>
    <item>
      <title>Re: In Apache Ranger, Audit logging not working for superuser only</title>
      <link>https://community.cloudera.com/t5/Support-Questions/In-Apache-Ranger-Audit-logging-not-working-for-superuser/m-p/392274#M248061</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/114665"&gt;@eddy28&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you are performing operations as the superuser (hdfs) and no audit logs are generated, it is likely because the superuser is bypassing the HDFS permissions and Ranger policies. The superuser has administrative privileges and can perform any action in HDFS without being subject to the policies defined in Ranger.&lt;/P&gt;&lt;P&gt;By default, HDFS does not generate audit logs for actions performed by the superuser. If you want to track the activities of the superuser, you can enable audit logging specifically for the superuser.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Aug 2024 20:48:00 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/In-Apache-Ranger-Audit-logging-not-working-for-superuser/m-p/392274#M248061</guid>
      <dc:creator>vats</dc:creator>
      <dc:date>2024-08-21T20:48:00Z</dc:date>
    </item>
    <item>
      <title>Re: In Apache Ranger, Audit logging not working for superuser only</title>
      <link>https://community.cloudera.com/t5/Support-Questions/In-Apache-Ranger-Audit-logging-not-working-for-superuser/m-p/392301#M248067</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/97070"&gt;@vats&lt;/a&gt;&amp;nbsp;,&lt;BR /&gt;&lt;BR /&gt;Thanks for your quick reply.&lt;BR /&gt;&lt;BR /&gt;I have already tried below steps, but still not able to get audit logs for superuser.&lt;BR /&gt;1.) Added Audit filter:-&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="eddy28_2-1724310913441.png" style="width: 400px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/41494i0DCBB27D329C1A37/image-size/medium?v=v2&amp;amp;px=400" role="button" title="eddy28_2-1724310913441.png" alt="eddy28_2-1724310913441.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2.) Gave allow permission in Ranger policy.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="eddy28_1-1724310709117.png" style="width: 400px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/41493iF9CA2C8A27B23845/image-size/medium?v=v2&amp;amp;px=400" role="button" title="eddy28_1-1724310709117.png" alt="eddy28_1-1724310709117.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Is there anything else I need to follow to &lt;SPAN&gt;enable audit logging specifically for the superuser.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Aditya&lt;/P&gt;</description>
      <pubDate>Thu, 22 Aug 2024 07:15:22 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/In-Apache-Ranger-Audit-logging-not-working-for-superuser/m-p/392301#M248067</guid>
      <dc:creator>eddy28</dc:creator>
      <dc:date>2024-08-22T07:15:22Z</dc:date>
    </item>
    <item>
      <title>Re: In Apache Ranger, Audit logging not working for superuser only</title>
      <link>https://community.cloudera.com/t5/Support-Questions/In-Apache-Ranger-Audit-logging-not-working-for-superuser/m-p/392350#M248093</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/114665"&gt;@eddy28&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;To enable audit logging for superuser actions, you need to update the HDFS configuration. Follow these steps:&lt;/P&gt;&lt;P&gt;Open the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;hdfs-site.xml&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;file in the Hadoop configuration directory ($HADOOP_HOME/etc/hadoop).&lt;/P&gt;&lt;P&gt;Add the following properties to enable audit logging for superuser actions:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class="stCodeBlock st-emotion-cache-12r09dv e1ycw9pz1"&gt;&lt;DIV&gt;&lt;SPAN class="token token tag punctuation"&gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class="token token tag"&gt;property&lt;/SPAN&gt;&lt;SPAN class="token token tag punctuation"&gt;&amp;gt;&lt;/SPAN&gt; &lt;SPAN class="token token tag punctuation"&gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class="token token tag"&gt;name&lt;/SPAN&gt;&lt;SPAN class="token token tag punctuation"&gt;&amp;gt;&lt;/SPAN&gt;&lt;SPAN&gt;dfs.namenode.inode.attributes.provider.class&lt;/SPAN&gt;&lt;SPAN class="token token tag punctuation"&gt;&amp;lt;/&lt;/SPAN&gt;&lt;SPAN class="token token tag"&gt;name&lt;/SPAN&gt;&lt;SPAN class="token token tag punctuation"&gt;&amp;gt;&lt;/SPAN&gt; &lt;SPAN class="token token tag punctuation"&gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class="token token tag"&gt;value&lt;/SPAN&gt;&lt;SPAN class="token token tag punctuation"&gt;&amp;gt;&lt;/SPAN&gt;&lt;SPAN&gt;org.apache.ranger.authorization.hadoop.RangerHdfsAuthorizer&lt;/SPAN&gt;&lt;SPAN class="token token tag punctuation"&gt;&amp;lt;/&lt;/SPAN&gt;&lt;SPAN class="token token tag"&gt;value&lt;/SPAN&gt;&lt;SPAN class="token token tag punctuation"&gt;&amp;gt;&lt;/SPAN&gt; &lt;SPAN class="token token tag punctuation"&gt;&amp;lt;/&lt;/SPAN&gt;&lt;SPAN class="token token tag"&gt;property&lt;/SPAN&gt;&lt;SPAN class="token token tag punctuation"&gt;&amp;gt;&lt;/SPAN&gt; &lt;SPAN class="token token tag punctuation"&gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class="token token tag"&gt;property&lt;/SPAN&gt;&lt;SPAN class="token token tag punctuation"&gt;&amp;gt;&lt;/SPAN&gt; &lt;SPAN class="token token tag punctuation"&gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class="token token tag"&gt;name&lt;/SPAN&gt;&lt;SPAN class="token token tag punctuation"&gt;&amp;gt;&lt;/SPAN&gt;&lt;SPAN&gt;ranger.plugin.hdfs.service.name&lt;/SPAN&gt;&lt;SPAN class="token token tag punctuation"&gt;&amp;lt;/&lt;/SPAN&gt;&lt;SPAN class="token token tag"&gt;name&lt;/SPAN&gt;&lt;SPAN class="token token tag punctuation"&gt;&amp;gt;&lt;/SPAN&gt; &lt;SPAN class="token token tag punctuation"&gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class="token token tag"&gt;value&lt;/SPAN&gt;&lt;SPAN class="token token tag punctuation"&gt;&amp;gt;&lt;/SPAN&gt;&lt;SPAN&gt;hadoopdev&lt;/SPAN&gt;&lt;SPAN class="token token tag punctuation"&gt;&amp;lt;/&lt;/SPAN&gt;&lt;SPAN class="token token tag"&gt;value&lt;/SPAN&gt;&lt;SPAN class="token token tag punctuation"&gt;&amp;gt;&lt;/SPAN&gt; &lt;SPAN class="token token comment"&gt;&amp;lt;!-- Replace with your Ranger service name --&amp;gt;&lt;/SPAN&gt; &lt;SPAN class="token token tag punctuation"&gt;&amp;lt;/&lt;/SPAN&gt;&lt;SPAN class="token token tag"&gt;property&lt;/SPAN&gt;&lt;SPAN class="token token tag punctuation"&gt;&amp;gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="st-emotion-cache-chk1w8 e1ycw9pz2"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;P&gt;Save the changes and restart the HDFS service for the new configuration to take effect.&lt;/P&gt;&lt;P&gt;With this configuration, the superuser actions should generate audit logs, which will be visible in the Ranger UI alongside other HDFS actions.&lt;BR /&gt;&lt;BR /&gt;Note-Please test this configuration with you uat cluster&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Aug 2024 11:46:26 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/In-Apache-Ranger-Audit-logging-not-working-for-superuser/m-p/392350#M248093</guid>
      <dc:creator>vats</dc:creator>
      <dc:date>2024-08-22T11:46:26Z</dc:date>
    </item>
    <item>
      <title>Re: In Apache Ranger, Audit logging not working for superuser only</title>
      <link>https://community.cloudera.com/t5/Support-Questions/In-Apache-Ranger-Audit-logging-not-working-for-superuser/m-p/392388#M248108</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/97070"&gt;@vats&lt;/a&gt;&amp;nbsp;,&lt;BR /&gt;I have tried it, but still no luck.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Aditya&lt;/P&gt;</description>
      <pubDate>Thu, 22 Aug 2024 19:50:04 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/In-Apache-Ranger-Audit-logging-not-working-for-superuser/m-p/392388#M248108</guid>
      <dc:creator>eddy28</dc:creator>
      <dc:date>2024-08-22T19:50:04Z</dc:date>
    </item>
    <item>
      <title>Re: In Apache Ranger, Audit logging not working for superuser only</title>
      <link>https://community.cloudera.com/t5/Support-Questions/In-Apache-Ranger-Audit-logging-not-working-for-superuser/m-p/392419#M248122</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/114665"&gt;@eddy28&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Have you configured this property properly&lt;BR /&gt;"&lt;SPAN class="token token tag punctuation"&gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class="token token tag"&gt;name&lt;/SPAN&gt;&lt;SPAN class="token token tag punctuation"&gt;&amp;gt;&lt;/SPAN&gt;&lt;SPAN&gt;ranger.plugin.hdfs.service.name&lt;/SPAN&gt;&lt;SPAN class="token token tag punctuation"&gt;&amp;lt;/&lt;/SPAN&gt;&lt;SPAN class="token token tag"&gt;name&lt;/SPAN&gt;&lt;SPAN class="token token tag punctuation"&gt;&amp;gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="token token tag punctuation"&gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class="token token tag"&gt;value&lt;/SPAN&gt;&lt;SPAN class="token token tag punctuation"&gt;&amp;gt;&lt;/SPAN&gt;&lt;SPAN&gt;hadoopdev&lt;/SPAN&gt;&lt;SPAN class="token token tag punctuation"&gt;&amp;lt;/&lt;/SPAN&gt;&lt;SPAN class="token token tag"&gt;value&lt;/SPAN&gt;&lt;SPAN class="token token tag punctuation"&gt;&amp;gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="token token comment"&gt;&amp;lt;!-- Replace with your Ranger service name --&amp;gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;"&lt;BR /&gt;Do you have any exception after configuring the suggested property?&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Aug 2024 08:46:13 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/In-Apache-Ranger-Audit-logging-not-working-for-superuser/m-p/392419#M248122</guid>
      <dc:creator>vats</dc:creator>
      <dc:date>2024-08-23T08:46:13Z</dc:date>
    </item>
    <item>
      <title>Re: In Apache Ranger, Audit logging not working for superuser only</title>
      <link>https://community.cloudera.com/t5/Support-Questions/In-Apache-Ranger-Audit-logging-not-working-for-superuser/m-p/392428#M248125</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/97070"&gt;@vats&lt;/a&gt;&amp;nbsp;,&lt;BR /&gt;&lt;BR /&gt;Yes I have added configs properly. Kindly see the screenshot below:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="eddy28_0-1724404613256.png" style="width: 400px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/41510i0C7707B967BD1223/image-size/medium?v=v2&amp;amp;px=400" role="button" title="eddy28_0-1724404613256.png" alt="eddy28_0-1724404613256.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;My service name is also hadoopdev&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="eddy28_1-1724404670057.png" style="width: 400px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/41511iB431066CE8D52D7F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="eddy28_1-1724404670057.png" alt="eddy28_1-1724404670057.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Aditya&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Aug 2024 09:50:57 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/In-Apache-Ranger-Audit-logging-not-working-for-superuser/m-p/392428#M248125</guid>
      <dc:creator>eddy28</dc:creator>
      <dc:date>2024-08-23T09:50:57Z</dc:date>
    </item>
  </channel>
</rss>

