Along with identification, authentication and authorization functions for users and services, it is with Audit log capabilities that the security ecosystem is complete.
A fundamental component of Hadoop clusters and security models is Accounting. Along with identification, authentication and authorization functions for users and services, it is with Audit log capabilities that the security ecosystem is complete. Hadoop components handle accounting differently depending on the purpose of the component. Components such as HDFS and HBase are data repositories whereas MapReduce, Hive, Impala are query engines and processing frameworks. So, the auditable events are unique for different elements.
HDFS Audit Logs
HDFS provides 2 different audit logs – hdfs-audit.log is used audit general user activity. SecurityAuth-hdfs.audit is used to audit service-level authorization activity. The setup for these logfiles involves hooking into log4j.category.Securitylogger and log4j.additivity.org.apache.hadoop.hdfs.server.namenode.FSNamesystem.audit.
Auditable events show various actions performed e.g. listStatus, create, setPermission, rename etc. Also, the logs demonstrate who the user is that the event was for, timestamp, IP address and various other bits of information. Also, all unsuccessful access attempts will be recorded.
MapReduce Audit Logs
MapReduce follows a similar approach, it contains 2 audit log files – mapred-audit.log and SecurityAuth-mapred.audit.
Let’s take an example –
- User Alice is identified by Kerberos principal [email protected] and she has successfully used kinit to receive a valid TGT
- MapReduce service-level authorization is not being used
- Alice submits a MapReduce job
- Alice kills the MapReduce job before it finishes
Example 1 (mapred-audit.log)
Example 1 shows Alice performed the operation SUBMIT_JOB which results in MapReduce job id - job_201403112320_0001 along with date time and IP. Example 2 shows Alice authentication to job tracker, authorization and when Alice kills the running job.
YARN Audit Logs
YARN audit log events are scattered among the daemon logfiles. But they are easily identifiable because the class name is logged in the event. For the resource manager, it is org.apache.hadoop.yarn.server.resourcemanager.RMAuditLogger; and for the name manager it is org.apache.hadoop.yarn.server.nodemanager.NMAuditLogger. These class names can be used to parse out audit events from normal application logs. For YARN to log audit events, the log4j properties need to be set and the hook to set this up is the log4j.category.SecurityLogger.
HIVE Audit Logs
Hive auditing is like YARN in that it does not have a dedicated audit logfile. Audit events occur inside the actual Hive metastore service log so it can be a bit of a challenge. However, the audit logger class names can be used to identify audit events. Other Hive components, such as Hive-Server 2, do not have explicit auditing, but Audit like information can still be gleaned from the service logs.