Uploaded image for project: 'Ranger'
  1. Ranger
  2. RANGER-3532

Delete Archived Spooled Audit Logs Based on TTL

    XMLWordPrintableJSON

Details

    • Improvement
    • Status: Open
    • Major
    • Resolution: Unresolved
    • None
    • None
    • audit
    • None

    Description

      As I understand it,...

      When an audit destination (HDFS/SOLR) is offline, Ranger plugin can spool audit messages to the local disk.  Once the destination comes back online, the Ranger plugin will resume transmitting audit messages.  Once all audit messages are transmitted, the log file containing the message is sent to the audit 'archive' directory.  From there, if there are more than (configurable) 100 archived audit log files, then some number of files are deleted to bring that number down to 100.

       

      This can be problematic if the number of audits is very large (and therefore spooled audit log files are very large) and they can sit in the archive directory for very long periods of time.  As I understand it, the only way for them to be deleted is if another outage event occurs and more files are created, always keeping the total number of files at 100.

       

      Please add an additional criteria for deleting files: TTL

       

      Delete archived audit files which are older than (configurable) a week.

      Attachments

        Issue Links

          Activity

            People

              Unassigned Unassigned
              belugabehr David Mollitor
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

              Dates

                Created:
                Updated: