Summary
In this chapter we looked at the general approach for identifying security incidents and events in a secured Hadoop cluster. The SIEM systems consists of a collection agent that gathers the events from the cluster and publishes them to the monitoring server. The monitoring server is configured with rules and policies that are applied on the collected events to generate security alerts and reports. We also looked at how we configure the audit and security logs for the various components in a secured Hadoop cluster.