dhivya created RANGER-2820:
------------------------------
Summary: Difference between audit log spool directory and the
archive directory under spool in Ranger
Key: RANGER-2820
URL: https://issues.apache.org/jira/browse/RANGER-2820
Project: Ranger
Issue Type: Bug
Components: Ranger
Affects Versions: 1.2.0
Reporter: dhivya
Fix For: Ranger
>From the Ranger documentation i understand that in case of destination sink
>down then spool directory can hold the the unsent messages to disk files to
>prevent or minimize the loss of audit messages Once memory buffer fills up
For example i could see some logs files are created under
/var/log/hadoop/yarn/audit/solr/spool with the name format spool_yarn_*.log
Inside the spool directory i could see one more folder called "archive",What is
the use of this archive folder? and why the spool directories are not getting
cleaned up once the destination sink is up ? this is bumping up the utilization
on those directory.
Cn someone clarify this
[https://cwiki.apache.org/confluence/display/RANGER/Ranger+0.5+Audit+Configuration]
--
This message was sent by Atlassian Jira
(v8.3.4#803005)