IBM Support

IBM Security Guardium: Hadoop Policy not Excluding Data as Expected for "Skip Commands" Group

Troubleshooting


Problem

The installed Guardium policy is configured with the allow action when the command is in the Hadoop "Skip Commands" group. But commands in this group are being logged in the Collector. You would not expect these to be logged.

Symptom

One command example is the getFileInfo. This will show up in reports but should not be logged.
The GDM_FIELD and GDM_CONSTRUCT_INSTANCE tables are large.

[{"Product":{"code":"SSMPHH","label":"IBM Security Guardium"},"Business Unit":{"code":"BU048","label":"IBM Software"},"Component":"Guardium Appliances","Platform":[{"code":"PF016","label":"Linux"}],"Version":"9.5","Edition":"","Line of Business":{"code":"LOB76","label":"Data Platform"}}]

Log InLog in to view more of this document

This document has the abstract of a technical article that is available to authorized users once you have logged on. Please use Log in button above to access the full document. After log in, if you do not have the right authorization for this document, there will be instructions on what to do next.

Document Information

Modified date:
16 June 2018

UID

swg21990790