Our Community is getting an upgrade! To get everything ready for the relaunch, we’ll be placing the site in read-only mode starting September 21st.
We really appreciate your understanding while we get things set up behind the scenes. Catch up on all the exciting details about the move here.
Need help or have questions? Drop us a line at [email protected]

Community Articles

Find and share helpful community-sourced technical articles.
Announcements
Share your experience with Cloudera on G2 and get a $25 Amazon Gift card.
Hi, I'm CLEO! Something exciting is coming to the Community. Stay Tuned!
Labels (1)
avatar
Expert Contributor

Since Ranger 0.5 there has been the ability to summarize audit events that differ only by timestamp to reduce the amount of events logged in a busy system. When enabled, if a Ranger plugin logs consecutive audit events that differ only by timestamp it will coalesce all such events in to a single event and set 'event_count' to the number of events logged and 'event_dur_ms' to the time difference in milliseconds between the first and last event.

To enable this feature you must set the following properties in the Ranger plugin's configuration:

Configuration nameNotes
xasecure.audit.provider.summary.enabled
  1. To enable summarization set this property to true. This would cause audit messages to be summarized before they are sent to various sinks.
  2. By default it is set to false i.e. audit summarization is disabled.
xasecure.audit.provider.queue.size
  1. If unspecified this value defaults to 1048576, i.e. the queue is sized to store 1M (1024 * 1024) messages.
  2. Note the difference in property name that controls the size of summary queue.
xasecure.audit.provider.summary.interval.ms
  1. The max time interval at which messages would be summarized.
  2. If unspecified it defaults to 5000, i.e. 5 seconds.
Summarization Batch size
  1. Note that regardless of this time interval while summarizing at most 100k messages at a time are considered for aggregation. Thus, if more than 100k messages are logged during this interval then similar messages could show up as multiple summarized audit messages even though they are logged within the configured time interval.
  2. Currently, this value of 100k is not user configurable. It is mentioned here for better understanding of Summarization logic.

More details can be found here: Ranger 0.5 Audit log summarization

4,619 Views
Comments
avatar

I believe that in Ranger 1.2.0 the property xasecure.audit.provider.summary.enabled is called Audit provider summary enabled (checkbox to tick) in Advanced ranger-hdfs-audit in HDFS service in Ambari.

Version history
Last update:
‎09-27-2017 08:47 AM
Updated by:
Contributors