- Subscribe to RSS Feed
- Mark Question as New
- Mark Question as Read
- Float this Question for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
On-boarding Ranger Audit logs to SIEM
- Labels:
-
Apache Ranger
Created 03-15-2021 11:25 PM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello,
We are in the process of setting up our Cloudera and would like to request you to provide the steps to Integrate Audit logs from Ranger to SIEM (splunk) systems. Request you to let us know if there are any other services needed on the cluster to get this Integration(other than Ranger).
Thanks a lot.
Regards,
Madhuri
Created 03-22-2021 02:27 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Madhuri,
Streaming Ranger audits to third-party services (other than HDFS, Solr) is still not officially supported. I found this article though, can you check if that helps:
https://my.cloudera.com/knowledge/How-to-send-Ranger-audit-logs-to-log4j-appenders?id=276802
Also, there's a Github page to enable streaming Ranger audits to Kafka topics:
https://github.com/Raghav-Guru/kafka-ranger-audit
Here's an Apache document on steps to enable Audits to a component that has log4j appender:
Created 08-02-2022 06:31 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Madhuri, did you get any solution for this .. I am looking for the same audit logs into Splunk.
Created 08-03-2022 04:38 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi All,
You can check the below article for more details on Configuring Apache ranger to send syslog to a SIEM system:
We officially support two destination location for ranger audits i.e. HDFS & SOLR
Audits to log4j is a community feature and not certified by Cloudera Engineering
Other KB reference:
https://my.cloudera.com/knowledge/How-to-send-Ranger-audit-logs-to-log4j-appenders?id=276802
Created 08-08-2022 02:31 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
@ammukana, did any of the replies helped resolve your issue? If so, please mark the appropriate reply as the solution, as it will make it easier for others to find the answer in the future.
Regards,
Vidya Sargur,Community Manager
Was your question answered? Make sure to mark the answer as the accepted solution.
If you find a reply useful, say thanks by clicking on the thumbs up button.
Learn more about the Cloudera Community:
