[ 
https://issues.apache.org/jira/browse/RANGER-3265?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17337425#comment-17337425
 ] 

Abhishek Shukla commented on RANGER-3265:
-----------------------------------------

 It looks like some of the operations are happening before the policy sync and 
it is falling back to hadoop-acl which is not having an audit filter yet that's 
why *getfileinfo* access type logs are getting generated at the 
beginning(cluster creation) only and not after that once policy synced.

 

Closing this as information provided.

> [Ranger Audit Filters] getfileinfo is not filtered out in hdfs ranger audits
> ----------------------------------------------------------------------------
>
>                 Key: RANGER-3265
>                 URL: https://issues.apache.org/jira/browse/RANGER-3265
>             Project: Ranger
>          Issue Type: Bug
>          Components: audit
>    Affects Versions: 2.2.0
>            Reporter: Abhishek Shukla
>            Assignee: Ramesh Mani
>            Priority: Major
>         Attachments: hdfs audits with getfileinfo actions.png, hdfs default 
> audit filters with getfileinfo.png
>
>
> We have default audit filters in hdfs to filter out audits with getfileinfo 
> action, but still observing audits with getfileinfo action.
> Attached screenshots.
> Is it something related to access enforcer as hadoop-acl? As in all of these 
> audits, the access enforcer is hadoop-acl
>  
> cc [~rmani]



--
This message was sent by Atlassian Jira
(v8.3.4#803005)

Reply via email to