@dsharma Go to custom ranger-hbase-security section in ambari and add the following. These setting in ranger will help you modify the read and connection timeout. Please try increasing this and see how it goes?
@luis marmolejo Please check the permission of the file /tmp/ranger_hdfs_audit.log. Make sure it has rw permission for all others also. This is working fine.
@bdurai I dont see an internal reference for this. We need to create one. Your are right. we need to do the configuration changes via Amabri for respective components if Ambari is used.
@luis marmolejo You can conifgure Ranger Audit to go to Log4J appender. In this way a copy can be sent to file as you needed. Configure these properties via Ambari for the respective components if you are using Ambari for managing. 1 ) You need to enable auditing to log4j appender by adding the following property to ranger-<component>-audit.xml <property> <name></name> <value>true</value> </property> <property> <name>xasecure.audit.destination.log4j</name> <value>true</value> </property> <property> <name>xasecure.audit.destination.log4j.logger</name> <value>xaaudit</value> </property> 2) Add the appender to the or log4j.xml file for the <component> ranger.logger=INFO,console,RANGERAUDIT log4j.logger.xaaudit=${ranger.logger} log4j.appender.RANGERAUDIT=org.apache.log4j.DailyRollingFileAppender log4j.appender.RANGERAUDIT.File=/tmp/ranger_hdfs_audit.log log4j.appender.RANGERAUDIT.layout=org.apache.log4j.PatternLayout log4j.appender.RANGERAUDIT.layout.ConversionPattern=%d{ISO8601} %p %c{2}: %L %m%n log4j.appender.RANGERAUDIT.DatePattern=.yyyy-MM-dd restart the respective component. A copy of the Ranger Audit will be sent to /tmp/ranger_hdfs_audit.log ( in this case )
You can also check that port 6083 is configured in the port forwarding setting to access http://localhost:6083/solr/ranger_audits. For Audit not being in Ranger UI you need to check what is configured for ranger.audit.source.type in ranger config. It should be solr.
@Gerd Koening. Check in Ranger -> Config > Advanced ranger-admin-site
ranger.audit.source.type = db Do you see any exception in namenode log related to Ranger Auditing? Also check that the policy is having the audit enabled. Also hdfs operation you are doing should be for the resources which are in the Policy.
@Jonas Straub Also please check that conf folder where there ranger config is there in the class path of the solr process. This might be the case for you.
Please check the value for property "" in ranger-solr-security.xml in the solr conf folder. This should have the right value for the ranger admin. You can put the right value and restart solr plugin. Not sure why the enabling of ranger solr plugin didnt update the right value. Did you see any exception in when you enabled solr plugin. May be you can try reinstalling it will be debug on the enable script to see if there are any exceptions and let us know.
Also setting "xasecure.add-hadoop-authorization" = false in ranger-hdfs-security.xml in /etc/hadoop/conf will stop the fall back to HDFS ACL.
In Ambari -> Ranger -> Config -> Advanced -> Advanced ranger-usersync-site -> ranger.usersync.sleeptimeinmillisbetweensynccycle This is where you maintain the time interval If its a manual install this property in ranger-ugsync-site.xml in conf folder of range-usersync
