You are viewing a plain text version of this content. The canonical link for it is here.
Posted to notifications@logging.apache.org by "Ralph Goers (Jira)" <ji...@apache.org> on 2020/02/22 21:51:00 UTC
[jira] [Closed] (LOG4J2-2775) Migrated the apache spark 2.4.2
source from log4j 1.x to 2.x and found log4j 1.x jar in packaged tgz file.
[ https://issues.apache.org/jira/browse/LOG4J2-2775?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]
Ralph Goers closed LOG4J2-2775.
-------------------------------
Resolution: Information Provided
Closing since this is not a Log4j issue.
> Migrated the apache spark 2.4.2 source from log4j 1.x to 2.x and found log4j 1.x jar in packaged tgz file.
> ------------------------------------------------------------------------------------------------------------
>
> Key: LOG4J2-2775
> URL: https://issues.apache.org/jira/browse/LOG4J2-2775
> Project: Log4j 2
> Issue Type: Question
> Components: Build, Core
> Affects Versions: 2.13.0
> Environment: *Kubernetes*
> Reporter: Srinivas Yarra
> Priority: Major
>
> Hi,
> Recently, we migrated apache spark 2.4.2 source from log4j 1.x to 2.x using below jars where it is used the log4j-1.2.17.jar in the pom.
> {code:java}
> <dependency>
> <groupId>org.apache.logging.log4j</groupId>
> <artifactId>log4j-core</artifactId>
> <version>2.13.0</version>
> </dependency>
> <dependency>
> <groupId>org.apache.logging.log4j</groupId>
> <artifactId>log4j-api</artifactId>
> <version>2.13.0</version>
> </dependency>
> <dependency>
> <groupId>org.apache.logging.log4j</groupId>
> <artifactId>log4j-slf4j-impl</artifactId>
> <version>2.13.0</version>
> </dependency>
> <dependency>
> <groupId>org.apache.logging.log4j</groupId>
> <artifactId>log4j-1.2-api</artifactId>
> <version>2.13.0</version>
> </dependency>
> {code}
> It is using a lot of third-party libraries and some of the thrd-party libraries are using the log4j-1.2.17.jar project. We identified log4j jars with the help of "mvn dependency:tree" CLI command and excluded the log4j-1.2.17 jars as shown below. Please find the excluded log4j 1.x dependencies wherever it is using log4j 1.2.17 as project/module dependency jar.
>
> {code:java}
> <dependency>
> <groupId>org.apache.zookeeper</groupId>
> <artifactId>zookeeper</artifactId>
> <exclusions>
> <exclusion>
> <groupId>log4j</groupId>
> <artifactId>log4j</artifactId>
> </exclusion>
> <exclusion>
> <groupId>org.slf4j</groupId>
> <artifactId>slf4j-log4j12</artifactId>
> </exclusion>
> </exclusions>
> </dependency>
> <dependency>
> <groupId>org.apache.hadoop</groupId>
> <artifactId>hadoop-client</artifactId>
> <exclusions>
> <exclusion>
> <groupId>org.slf4j</groupId>
> <artifactId>slf4j-log4j12</artifactId>
> </exclusion>
> <exclusion>
> <groupId>log4j</groupId>
> <artifactId>log4j</artifactId>
> </exclusion>
> </exclusions>
> </dependency>
> {code}
> After packaging spark project and observed that log4j-1.2.17.jar in jars directory of the spark.tgz file. But we did not find in the project as dependency or sub-dependency.
> Now, my questions:- If we delete the log4j-.1.2.17.jar from the spark -**.tgz then Is it impact any functionality of third party libraries?
> Kindly provide your suggestion.
>
--
This message was sent by Atlassian Jira
(v8.3.4#803005)