<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: How to enable audit logging without Navigator in Archives of Support Questions (Read Only)</title>
    <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/How-to-enable-audit-logging-without-Navigator/m-p/285015#M67379</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/71975"&gt;@uv&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You may want to check this public doc about Navigator Audit Filter:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.cloudera.com/documentation/enterprise/latest/topics/cn_admcfg_audit_filters.html" target="_blank"&gt;https://docs.cloudera.com/documentation/enterprise/latest/topics/cn_admcfg_audit_filters.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Li&lt;/P&gt;</description>
    <pubDate>Fri, 06 Dec 2019 22:28:34 GMT</pubDate>
    <dc:creator>lwang</dc:creator>
    <dc:date>2019-12-06T22:28:34Z</dc:date>
    <item>
      <title>How to enable audit logging without Navigator</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/How-to-enable-audit-logging-without-Navigator/m-p/59329#M67375</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;&lt;P&gt;we have 5.11 cluster installed for testing, 2 master nodes, 4 slave nodes, and 1 management node.&lt;/P&gt;&lt;P&gt;now we want to enable the audit logging without using Navigator.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have some questions here&lt;/P&gt;&lt;P&gt;1. we have CM installed, can I use log4j.properties to enable the audit logging?&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; I read some posts like this:&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;A href="https://community.cloudera.com/t5/Cloudera-Manager-Installation/What-is-the-Path-of-hdfs-site-xml-core-xml/m-p/15210#M1787" target="_blank"&gt;https://community.cloudera.com/t5/Cloudera-Manager-Installation/What-is-the-Path-of-hdfs-site-xml-core-xml/m-p/15210#M1787&lt;/A&gt; &amp;nbsp;it said that the actual configuration has non-standard location. So my understanding is no matter what I changed on the configruation location(e.g. /etc/hadoop/conf/.....), it won't work. And I should use the snippet to do the configuration.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2. and I read another posts here:&lt;/P&gt;&lt;P&gt;&lt;A href="http://community.cloudera.com/t5/Cloudera-Manager-Installation/Audit-trail-for-HDFS-data-use/m-p/50428/highlight/true#M9405" target="_blank"&gt;http://community.cloudera.com/t5/Cloudera-Manager-Installation/Audit-trail-for-HDFS-data-use/m-p/50428/highlight/true#M9405&lt;/A&gt; looks like I can use log4j.properties to do the audit logging.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am a little bit confused, how can I enable audit logging without Nav?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Aug 2017 18:51:58 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/How-to-enable-audit-logging-without-Navigator/m-p/59329#M67375</guid>
      <dc:creator>aerin</dc:creator>
      <dc:date>2017-08-28T18:51:58Z</dc:date>
    </item>
    <item>
      <title>Re: How to enable audit logging without Navigator</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/How-to-enable-audit-logging-without-Navigator/m-p/59434#M67376</link>
      <description>&lt;P&gt;Hi There,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for reaching out on the community. I'm Josh, and I'll help address this for you.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;log4j.properties:&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;CM is&amp;nbsp;the central point of configuration for services, so the short answer is that you should adjust log4j settings using safety valves. Below is an engineering blog post with a good description of how CM works.&lt;BR /&gt;&lt;A href="http://blog.cloudera.com/blog/2013/07/how-does-cloudera-manager-work/" target="_blank"&gt;http://blog.cloudera.com/blog/2013/07/how-does-cloudera-manager-work/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;When a CM agent for a host heart beats to Cloudera Manager, Cloudera Manager sends back processes that should be running, and the related config files, one of which is the log4j.properties, for that service and role. From here, the CM agent makes a run time directory for these config files and references those. For instance, the agent will make a directory like the one bellow for a namenode role:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;/&lt;/SPAN&gt;&lt;SPAN&gt;var&lt;/SPAN&gt;&lt;SPAN&gt;/&lt;/SPAN&gt;&lt;SPAN&gt;run&lt;/SPAN&gt;&lt;SPAN&gt;/&lt;/SPAN&gt;&lt;SPAN&gt;cloudera&lt;/SPAN&gt;&lt;SPAN&gt;-&lt;/SPAN&gt;&lt;SPAN&gt;scm&lt;/SPAN&gt;&lt;SPAN&gt;-&lt;/SPAN&gt;&lt;SPAN&gt;agent&lt;/SPAN&gt;&lt;SPAN&gt;/&lt;/SPAN&gt;&lt;SPAN&gt;process&lt;/SPAN&gt;&lt;SPAN&gt;/&lt;/SPAN&gt;&lt;SPAN&gt;879&lt;/SPAN&gt;&lt;SPAN&gt;-&lt;/SPAN&gt;&lt;SPAN&gt;hdfs&lt;/SPAN&gt;&lt;SPAN&gt;-&lt;/SPAN&gt;&lt;SPAN&gt;NAMENODE/&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;this is why editing config files in on the OS has&amp;nbsp;no effect, and is not recommended.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Enabling audit logging:&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;To enable audit logging for a service without navigator, you would want to set the appropriate log4j settings in the appropriate safety valve for that service. Let's use HDFS as an example. Cloudera Manager has a configuration property for HDFS labeled "NameNode Logging Advanced Configuration Snippet (Safety Valve)". This is the one you want to put your log4j settings in. Once you've put your settings in, it will insert those into the log4j.properties it sends over to the agent in heartbeats. The specifics for enabling vanilla hadoop HDFS audit logging can be found bellow:&lt;/P&gt;&lt;P&gt;&lt;A href="http://apprize.info/security/hadoop/7.html" target="_blank"&gt;http://apprize.info/security/hadoop/7.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Considering all of this info, bear in mind that Navigator takes care of all of this for you, as well as adding additional features. For instance, HDFS audit logs can be very bulky and cumbersome by themselves and include many operations that aren't very helpful from an auditing standpoint. Navigator is able to apply event filters to an audit log, store relevant audits, and index them for further searching. Therefore, I highly recommend enabling navigator when doing so becomes feasible.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please let me know if you have any other questions.&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Aug 2017 14:03:13 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/How-to-enable-audit-logging-without-Navigator/m-p/59434#M67376</guid>
      <dc:creator>jmartin1938</dc:creator>
      <dc:date>2017-08-30T14:03:13Z</dc:date>
    </item>
    <item>
      <title>Re: How to enable audit logging without Navigator</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/How-to-enable-audit-logging-without-Navigator/m-p/59489#M67377</link>
      <description>&lt;P&gt;Thank you so much Josh.It's really helpful!&lt;/P&gt;</description>
      <pubDate>Fri, 01 Sep 2017 02:03:51 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/How-to-enable-audit-logging-without-Navigator/m-p/59489#M67377</guid>
      <dc:creator>aerin</dc:creator>
      <dc:date>2017-09-01T02:03:51Z</dc:date>
    </item>
    <item>
      <title>Re: How to enable audit logging without Navigator</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/How-to-enable-audit-logging-without-Navigator/m-p/284933#M67378</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/18996"&gt;@jmartin1938&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You'e recommended using Navigator as it applies event filters and stores relevant audits.&lt;/P&gt;&lt;P&gt;But, we've noticed it capturing operations which aren't executed by the users but are internally triggered due to some other operation.&lt;/P&gt;&lt;P&gt;For example, a single ListStatus (ls) operation results in two records listStatus and getfileinfo&lt;/P&gt;&lt;P&gt;Also, some of the operations captured are not really useful for auditing purposes. (Example :&amp;nbsp;getEZForPath)&lt;/P&gt;&lt;P&gt;Is there a way to customize the event filters? If yes, could you help us with the relevant documentation?&lt;/P&gt;</description>
      <pubDate>Fri, 06 Dec 2019 07:15:33 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/How-to-enable-audit-logging-without-Navigator/m-p/284933#M67378</guid>
      <dc:creator>uv</dc:creator>
      <dc:date>2019-12-06T07:15:33Z</dc:date>
    </item>
    <item>
      <title>Re: How to enable audit logging without Navigator</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/How-to-enable-audit-logging-without-Navigator/m-p/285015#M67379</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/71975"&gt;@uv&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You may want to check this public doc about Navigator Audit Filter:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.cloudera.com/documentation/enterprise/latest/topics/cn_admcfg_audit_filters.html" target="_blank"&gt;https://docs.cloudera.com/documentation/enterprise/latest/topics/cn_admcfg_audit_filters.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Li&lt;/P&gt;</description>
      <pubDate>Fri, 06 Dec 2019 22:28:34 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/How-to-enable-audit-logging-without-Navigator/m-p/285015#M67379</guid>
      <dc:creator>lwang</dc:creator>
      <dc:date>2019-12-06T22:28:34Z</dc:date>
    </item>
  </channel>
</rss>

