Description
If PostgreSQL logs expire before they are needed, evidence of failures and security events may be unavailable. Manage the storage destination, retention period and ability to retrieve logs as well as log generation.
Potential impact
- Relevant records may already be deleted when an incident is discovered.
- Operational audits and root-cause analysis may lack historical evidence.
Remediation
- Check the retention settings supported by your Azure PostgreSQL service. For Flexible Server, review
logfiles.download_enableandlogfiles.retention_days. - For longer retention, export through diagnostic settings and apply the destination’s retention policy.
- Verify log generation, delivery, retrieval and access permissions. A retention period alone does not generate logs.
Examples
The first example uses the module for Single Server, which retired on March 28, 2025. The second configures log collection and retention on an existing Flexible Server and requires azure.azcollection 3.18.0 or later.
Before
- name: PostgreSQL 설정 변경
azure_rm_postgresqlconfiguration:
resource_group: myResourceGroup
server_name: myServer
name: log_retention
value: off
log_retention: off is not Microsoft’s documented retention-period setting. Changing it to on does not configure a retention policy.
After
- name: PostgreSQL 로그 수집 활성화
azure.azcollection.azure_rm_postgresqlflexibleconfiguration:
resource_group: myResourceGroup
server_name: myServer
name: logfiles.download_enable
value: "on"
- name: PostgreSQL 로그 보존 기간 설정
azure.azcollection.azure_rm_postgresqlflexibleconfiguration:
resource_group: myResourceGroup
server_name: myServer
name: logfiles.retention_days
value: "7"
Server log collection for download is enabled with a seven-day retention period. Export logs to an external destination when longer retention is required.