Markus
There are couple of ways to get the logs into syslog: Use log4j Audit Destination in Ranger plugin. You can get from HDFS and stream it to syslog Configure File Destination for Ranger Audit Logs and stream it to syslog. Regarding illegal logins, Ranger doesn’t do authentication. So, you might have look into individual service audit logs. Bosco From: <markus.gier...@fiduciagad.de> Reply-To: <user@ranger.apache.org> Date: Thursday, April 11, 2019 at 12:42 AM To: <user@ranger.apache.org> Subject: export Ranger Audit log and activate logging of unsucessful logins Hi! is it possible to export the Audit log shown in der Admin UI as a file or send it to syslog ? And on the other hand can I activate the audit logging for saving of unsuccessful logins, to ?? Or is there another way to recognize illegal login attempts in hadoop. Best Regards MARKUS Fiducia & GAD IT AG | www.fiduciagad.de AG Frankfurt a. M. HRB 102381 | Sitz der Gesellschaft: Frankfurt a. M. | USt-IdNr. DE 143582320 Vorstand: Klaus-Peter Bruns (Vorsitzender), Jens-Olaf Bartels, Martin Beyer, Birgit Frohnhoff, Carsten Pfläging, Jörg Staff Vorsitzender des Aufsichtsrats: Jürgen Brinkmann