[
https://issues.apache.org/jira/browse/RANGER-2820?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17194306#comment-17194306
]
Velmurugan Periasamy commented on RANGER-2820:
----------------------------------------------
CC [~mehul] / [~rmani]
> Difference between audit log spool directory and the archive directory under
> spool in Ranger
> --------------------------------------------------------------------------------------------
>
> Key: RANGER-2820
> URL: https://issues.apache.org/jira/browse/RANGER-2820
> Project: Ranger
> Issue Type: Bug
> Components: Ranger
> Affects Versions: 1.2.0
> Reporter: dhivya
> Priority: Minor
>
> From the Ranger documentation i understand that in case of destination sink
> down then spool directory can hold the the unsent messages to disk files to
> prevent or minimize the loss of audit messages Once memory buffer fills up
> For example i could see some logs files are created under
> /var/log/hadoop/yarn/audit/solr/spool with the name format spool_yarn_*.log
> Inside the spool directory i could see one more folder called "archive",What
> is the use of this archive folder? and why the spool directories are not
> getting cleaned up once the destination sink is up ? this is bumping up the
> utilization on those directory.
> Cn someone clarify this
>
> [https://cwiki.apache.org/confluence/display/RANGER/Ranger+0.5+Audit+Configuration]
>
--
This message was sent by Atlassian Jira
(v8.3.4#803005)