Hello Everyone, We have Druid 0.22.1 running in pr...
# general
b
Hello Everyone, We have Druid 0.22.1 running in production for last two years. But currently we recieved a security vulnerability from our compliance team that "*EOL/Obsolete Software: Apache Log4j 1.X Detected*". I believe it by default using this version. How can we change this to use Apache Log4j 2.X ? Thanks in advance, as I am beginner to Druid, any help is appreciated on this
n
Hi Bhavok , I am running with druid 25 , as a docker deployment I add log4j2 jar and drop log4j1 jar that bundle with druid .. here part of my docker file ..
you need first do WORKDIR /opt/druid/lib and at end back to WORKDIR /opt/druid
b
@Nir Bar On: Thanks, I will try to do it this way
@Nir Bar On: I tried the way out and it kind of worked and I am able to see logs working without any issue. There are still more Log41.x packages that ships with druid0.22.1 installation as below: 1. druid/extensions/druid-ranger-security/log4j-1.2.17.jar 2. druid/hadoop-dependencies/hadoop-client/2.8.5/log4j-1.2.17.jar 3. druid/root/.m2/repository/log4j/log4j/1.2.17/log4j-1.2.17.jar Can you please suggest the replacements for these? @John Kowtko Hey John, it would be really helpful if you can suggest replacements for these in druid0.22.1 version? many thanks!
n
@Bhavok - I currently working with druid-25 , so I am not sure for 22 version ... it basicly the same jar file on 3 different locations .. , and maybe those are not in use in runtime ..but only for some tools ..- need to verify with durid team .. if all works for you why you want to change those as well ?
b
@Nir Bar On: I have removed all from druid/lib but these are in different directory druid/hadoop-dependencies, druid/extensions etc which is scanned as vulnerability as these are also LOG4j1.x versions. What would be replacement for log4j-1.2.17.jar in druid 0.22.1 and would that work in existing druid or will I have to change anything manually? Can you help me with their alternatives or any guidance would be helpful?
@John Kowtko: Could you please provide any insights on this on how to perform this action,? we need it urgently, thanks