Skip to main content

Posts

setting up log4j2 for Kafka Provider

Good Afternoon, Am looking to control log4j2 output produced by Kafka...but am having a little difficultly getting this to work as expected. During the kafka producer startup I've added this command: -Dlog4j2.configurationFile=/<whatever>/kafka/producers/log4j2.properties I've created a log4j2.properties file as follows: # Root Logger rootLogger=INFO, STDERR # Direct log messages to stderr appender.console.type = Console appender.console.name = STDERR appender.console.layout.type = PatternLayout appender.console.layout.pattern = [%-5level] %d{yyyy-MM-dd HH:mm:ss.SSS} [%t] %C{1} - %msg%n Yet, when I look at STDERR am not seeing the desired messages. Do I need to configure slf4j instead or in conjunction? Anything I'm possibly doing wrong? Anyone with experience on customizing kafka message logging, will to chime in? Thank You, --Alex

Re: Kafka Streams Abnormal Latency & Lag Spiking Under High Load

Not sure if this is at all helpful, but we also experienced poor performance with Kafka Streams, and it took us quite a while to figure out all the tuning knobs, but we found that in our case we were experiencing extended RocksDB write stalls (overfilling memtables causing RocksDB to stall and eventually pause writes) which led to extended commit periods which led to large application latency gaps... I am not at all sure if you hit the same problem, but I would recommend enabling as many debug metrics as you can handle, turn on RocksDB stats logging, and in our case we ran a Claude Code instance with access to logs, dashboards, JFR dump (incl stack sampling) and it was actually quite good at identifying problematic configuration. You can't trust everything it says, but it can highlight things you didn't even consider... > On Aug 8, 2026, at 6:52 PM, Brebner, Paul via users <users@kafka.apache.org> wrote: > > Hi Tamar, > > Interesting problem...

Re: [ANNOUNCE] New committer: Jiunn-Yang Huang

Congrats! On 8/24/26 12:26 PM, o.g.h.ibrahim@gmail.com wrote: > Congratulations! > > Omnia > Sent from my iPhone > >> On 24 Aug 2026, at 08:27, Sanghyeok An <ojt90902@gmail.com> wrote: >> >> Congratulations! Well-deserved! >> >> Regards, >> Sanghyeok An >> >> 2026년 8월 24일 (월) 오후 4:15, Muralidhar Basani via dev <dev@kafka.apache.org>님이 >> 작성: >> >>> Congratulations! >>> >>> Regards, >>> Murali >>> >>>> On Mon, Aug 24, 2026 at 2:55 AM Luke Chen <showuon@gmail.com> wrote: >>>> >>>> Congratulations! Well deserved! >>>> Please remember to help review PRs and KIPs. :) >>>> >>>> Luke >>>> >>>>> On Mon, Aug 24, 2026 at 9:35 AM jian fu <fujian1115@gmail.com> wrote: >>>> >>>>> Congratulations! ...

Re: Kafka v4.3.0 JLine related vulnerabilities

Hi Vivek, The CVE was fixed in the scope of KAFKA-20815 <https://issues.apache.org/jira/browse/KAFKA-20815> and will be included in the upcoming 4.4 release. You can find my analysis about the CVE in this <https://issues.apache.org/jira/browse/KAFKA-20815?focusedCommentId=18097890&page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel#comment-18097890> comment. Best regards, Gergely On Fri, 21 Aug 2026 at 08:22, Vivek Agarwal B via users < users@kafka.apache.org> wrote: > Hello Apache Kafka Team, > > In our product, kafka v4.3.0 is used. Below 2 Jline related > vulnerabilities are reported on this kafka version - > > CVE-2026-56740 > CVE-2026-56741 > > I see in kafka v4.3.0, jline-3.30.4.jar is present in the libs folder - > libs/jline-3.30.4.jar/META-INF/maven/org.jline/jline-remote-telnet/pom.xml. > > As per github advisory, these vulnerabilities are fixed in Jline v4.2.1 > ver...

Kafka v4.3.0 JLine related vulnerabilities

Hello Apache Kafka Team, In our product, kafka v4.3.0 is used. Below 2 Jline related vulnerabilities are reported on this kafka version - CVE-2026-56740 CVE-2026-56741 I see in kafka v4.3.0, jline-3.30.4.jar is present in the libs folder - libs/jline-3.30.4.jar/META-INF/maven/org.jline/jline-remote-telnet/pom.xml. As per github advisory, these vulnerabilities are fixed in Jline v4.2.1 versions. [1] CVE-2026-56740 Official Advisory - https://github.com/advisories/GHSA-47qp-hqvx-6r3f [2] CVE-2026-56741 Official Advisory - https://github.com/advisories/GHSA-2r2c-cx56-8933 Please confirm what apache kafka upcoming versions will upgrade to Jline v.4.2.1. Regards Vivek

Re: CVE-2026-59949 – Impact on Kafka (lz4-java)

In general, Kafka has a 1-year support window, so currently we are supporting 4.3, 4.2, and 4.1 release: https://kafka.apache.org/community/downloads/#supported-releases With the upcoming 4.4.0 release, 4.1 will drop out of the support window. So it's very unlikely that we would ship another 3.9.x bug-fix release. Given that 3.9 is the last release with ZK support, and upgrading to 4.x requires to migrate to KRaft, there is a possibility that we might maintain 3.9.x for a little longer than usual. However, officially 3.9 is not supported any longer, and the 3.9 and 4.0 release got archived already: https://kafka.apache.org/community/downloads/#archived-releases -Matthias On 8/19/26 7:21 AM, Gergely Harmadás wrote: > Hi James, > > I am not a project maintainer, just an enthusiastic contributor who > happened to have the same problem with lz4 :) There are some discussion > about a possible 3.9 release in this thread, so far no concrete...

Re: CVE-2026-59949 – Impact on Kafka (lz4-java)

Hi James, I am not a project maintainer, just an enthusiastic contributor who happened to have the same problem with lz4 :) There are some discussion about a possible 3.9 release in this thread, so far no concrete plans https://lists.apache.org/thread/bq27on99lf5b24d16zt5g5hnysd30c3w Best regards, Gergely On Mon, 17 Aug 2026 at 13:54, JAMES JOSE <jamejose@in.ibm.com> wrote: > Hello Gergely, > > Any plan for patching 3.9.* release with fixed version of lz4-java ? > > Regards, > James > > -----Original Message----- > From: JAMES JOSE > Sent: 17 August 2026 16:10 > To: 'users@kafka.apache.org' <users@kafka.apache.org> > Subject: RE: [EXTERNAL] Re: CVE-2026-59949 – Impact on Kafka (lz4-java) > > Thanks for the information. > > Regards, > James > > -----Original Message----- > From: Gergely Harmadás <harmadasg@gmail.com> > Sent: 14 August 2026 16:58 > To: users@k...