[
https://issues.apache.org/jira/browse/RANGER-2820?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17194325#comment-17194325
]
Ramesh Mani commented on RANGER-2820:
-------------------------------------
[~dhivyat] Archive directories are for moving the spool files once they are
picked up and sent to the destination when it is up. Archive directories will
be cleaned periodically when it reaches max of 100 files. It is configurable
and you are refer it at
https://github.com/apache/ranger/blob/master/agents-audit/src/main/java/org/apache/ranger/audit/queue/AuditFileSpool.java#L65
> Difference between audit log spool directory and the archive directory under
> spool in Ranger
> --------------------------------------------------------------------------------------------
>
> Key: RANGER-2820
> URL: https://issues.apache.org/jira/browse/RANGER-2820
> Project: Ranger
> Issue Type: Bug
> Components: Ranger
> Affects Versions: 1.2.0
> Reporter: dhivya
> Priority: Minor
>
> From the Ranger documentation i understand that in case of destination sink
> down then spool directory can hold the the unsent messages to disk files to
> prevent or minimize the loss of audit messages Once memory buffer fills up
> For example i could see some logs files are created under
> /var/log/hadoop/yarn/audit/solr/spool with the name format spool_yarn_*.log
> Inside the spool directory i could see one more folder called "archive",What
> is the use of this archive folder? and why the spool directories are not
> getting cleaned up once the destination sink is up ? this is bumping up the
> utilization on those directory.
> Cn someone clarify this
>
> [https://cwiki.apache.org/confluence/display/RANGER/Ranger+0.5+Audit+Configuration]
>
--
This message was sent by Atlassian Jira
(v8.3.4#803005)