This document describes Apache Eagle, an open source platform for monitoring Hadoop ecosystems in real time. It can identify access to sensitive data, recognize malicious activities, and block access in real time by integrating with components like Ranger, Sentry, Knox, and Splunk. Eagle turns audit data from HDFS, Hive, and other systems into a common event format, applies user-defined policies using a CEP engine on Storm, and generates alerts when policies are triggered. It is extensible and can integrate with additional data sources and tools for remediation and visualization.