Community Articles
Find and share helpful community-sourced technical articles.
Cloudera Employee


As some of you already know, Solr through knox on HDP platform isn't fully supported yet, however, it is possible to achieve that using an IBM IOP distribution.

Here are some steps:

Problems like that are usually related with kerberos issues.

Pre-reqs: You should have already configured your knox with the desired authentication mode:

OBS: In order to use this flag "", the jdk 1.8 or above must be used.


Root cause:

a) You may have not configured your browser for authentication ( SPNEGO ),

b) You haven't included your users into the SolR Plugin on Ranger.

c) You are hitting a known issue related with this parameter "", which is better described in this forum

1) Add the following parameters into your Hadoop core-site.xml:

hadoop.proxyuser.knox.groups = *

hadoop.proxyuser.knox.hosts = *

OBS: You can change the impersonation requirements accordingly with your environment.

2) According to the "known" issue aforementioned, you will have to add this parameter "" on Ambari > SolR > solr.env >

The configuration needs to be configured like that:

SOLR_OPTS="-Dsolr.directoryFactory=HdfsDirectoryFactory -Dsolr.lock.type=hdfs -Dsolr.hdfs.confdir=/etc/hadoop/conf -Dsolr.hdfs.home={{fs_root}}{{solr_hdfs_home_dir}}{{security_enabled}}{{solr_kerberos_keytab}}{{solr_kerberos_principal}} -Dsolr.log4j.dir={{solr_log_dir}}"

3) Go to the "Quick Links > Ranger > Ranger Admin UI > Solr" and add the user "knox"


After these steps, your SolR UI should work fine through Knox.


0 Kudos
Take a Tour of the Community
Don't have an account?
Your experience may be limited. Sign in to explore more.
Version history
Last update:
‎08-17-2019 07:44 AM
Updated by:
Top Kudoed Authors
; ;