[
https://issues.apache.org/jira/browse/RANGER-3265?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17337425#comment-17337425
]
Abhishek Shukla commented on RANGER-3265:
-----------------------------------------
It looks like some of the operations are happening before the policy sync and
it is falling back to hadoop-acl which is not having an audit filter yet that's
why *getfileinfo* access type logs are getting generated at the
beginning(cluster creation) only and not after that once policy synced.
Closing this as information provided.
> [Ranger Audit Filters] getfileinfo is not filtered out in hdfs ranger audits
> ----------------------------------------------------------------------------
>
> Key: RANGER-3265
> URL: https://issues.apache.org/jira/browse/RANGER-3265
> Project: Ranger
> Issue Type: Bug
> Components: audit
> Affects Versions: 2.2.0
> Reporter: Abhishek Shukla
> Assignee: Ramesh Mani
> Priority: Major
> Attachments: hdfs audits with getfileinfo actions.png, hdfs default
> audit filters with getfileinfo.png
>
>
> We have default audit filters in hdfs to filter out audits with getfileinfo
> action, but still observing audits with getfileinfo action.
> Attached screenshots.
> Is it something related to access enforcer as hadoop-acl? As in all of these
> audits, the access enforcer is hadoop-acl
>
> cc [~rmani]
--
This message was sent by Atlassian Jira
(v8.3.4#803005)