Community Articles
Find and share helpful community-sourced technical articles
Announcements
Alert: Welcome to the Unified Cloudera Community. Former HCC members be sure to read and learn how to activate your account here.
Labels (1)
Contributor

Since Ranger 0.5 there has been the ability to summarize audit events that differ only by timestamp to reduce the amount of events logged in a busy system. When enabled, if a Ranger plugin logs consecutive audit events that differ only by timestamp it will coalesce all such events in to a single event and set 'event_count' to the number of events logged and 'event_dur_ms' to the time difference in milliseconds between the first and last event.

To enable this feature you must set the following properties in the Ranger plugin's configuration:

Configuration nameNotes
xasecure.audit.provider.summary.enabled
  1. To enable summarization set this property to true. This would cause audit messages to be summarized before they are sent to various sinks.
  2. By default it is set to false i.e. audit summarization is disabled.
xasecure.audit.provider.queue.size
  1. If unspecified this value defaults to 1048576, i.e. the queue is sized to store 1M (1024 * 1024) messages.
  2. Note the difference in property name that controls the size of summary queue.
xasecure.audit.provider.summary.interval.ms
  1. The max time interval at which messages would be summarized.
  2. If unspecified it defaults to 5000, i.e. 5 seconds.
Summarization Batch size
  1. Note that regardless of this time interval while summarizing at most 100k messages at a time are considered for aggregation. Thus, if more than 100k messages are logged during this interval then similar messages could show up as multiple summarized audit messages even though they are logged within the configured time interval.
  2. Currently, this value of 100k is not user configurable. It is mentioned here for better understanding of Summarization logic.

More details can be found here: Ranger 0.5 Audit log summarization

869 Views
Don't have an account?
Coming from Hortonworks? Activate your account here
Version history
Revision #:
1 of 1
Last update:
‎09-27-2017 08:47 AM
Updated by:
 
Contributors
Top Kudoed Authors