dhivya created RANGER-2820:
------------------------------

             Summary: Difference between audit log spool directory and the 
archive directory under spool in Ranger
                 Key: RANGER-2820
                 URL: https://issues.apache.org/jira/browse/RANGER-2820
             Project: Ranger
          Issue Type: Bug
          Components: Ranger
    Affects Versions: 1.2.0
            Reporter: dhivya
             Fix For: Ranger


>From the Ranger documentation i understand that in case of destination sink 
>down then spool directory can hold the the unsent messages to disk files to 
>prevent or minimize the loss of audit messages Once memory buffer fills up 

For example i could see some logs files are created under 
/var/log/hadoop/yarn/audit/solr/spool with the name format spool_yarn_*.log 

Inside the spool directory i could see one more folder called "archive",What is 
the use of this archive folder? and why the spool directories are not getting 
cleaned up once the destination sink is up ? this is bumping up the utilization 
on those directory.

Cn someone clarify this 

 
[https://cwiki.apache.org/confluence/display/RANGER/Ranger+0.5+Audit+Configuration]
 



--
This message was sent by Atlassian Jira
(v8.3.4#803005)

Reply via email to