Search icon
Arrow left icon
All Products
Best Sellers
New Releases
Books
Videos
Audiobooks
Learning Hub
Newsletters
Free Learning
Arrow right icon
Securing Hadoop

You're reading from  Securing Hadoop

Product type Book
Published in Nov 2013
Publisher Packt
ISBN-13 9781783285259
Pages 116 pages
Edition 1st Edition
Languages
Author (1):
Sudheesh Narayan Sudheesh Narayan
Profile icon Sudheesh Narayan

Security Incident and Event Monitoring in a Hadoop Cluster


A Security Incident and Event Monitoring (SIEM) system is responsible for collecting, monitoring, analyzing, and generating various security alerts for any suspicious activity in the cluster. SIEM systems usually collect the various system logs, network logs, and application logs to identify these security incidents and events. Hadoop itself can be used to perform the analysis and correlation of these security events in a batch mode.

The first step in any SIEM system is to collect the various system logs and identify corresponding events. The following are the events that need to be monitored in a Hadoop cluster to detect any security incidents:

  • User login and authorization events: User login events in a secured Hadoop cluster are generated when the end users or service principals authenticate themselves within the KDC or EIM system. krb5kdc.log for the KDC in the local Hadoop realm will contain the service login events. The central...

lock icon The rest of the chapter is locked
Register for a free Packt account to unlock a world of extra content!
A free Packt account unlocks extra newsletters, articles, discounted offers, and much more. Start advancing your knowledge today.
Unlock this book and the full library FREE for 7 days
Get unlimited access to 7000+ expert-authored eBooks and videos courses covering every tech area you can think of
Renews at $15.99/month. Cancel anytime}