Description
log_connections records connection attempts and successful authentication and authorization. Disabling it reduces evidence for investigating account connections and unusual access patterns. Other error logs may still exist, and this setting does not replace access permissions or query auditing.
Potential impact
- Identifying which account connected and when may be harder.
- Account misuse or unusual connection patterns may go unnoticed for longer.
Remediation
- Set
log_connectionstoonthrough your service’s server parameters. - Review connection logs together with authentication failures and network records.
- Verify delivery, retention and log access permissions, and consider collection costs.
Examples
The first excerpt targets Single Server, which retired on March 28, 2025. The second updates an existing Flexible Server using azure.azcollection 3.18.0 or later.
Before
- name: PostgreSQL 설정 변경
azure.azcollection.azure_rm_postgresqlconfiguration:
resource_group: myResourceGroup
server_name: myServer
name: log_connections
value: "off"
Connection logging is disabled. Even if separate error records exist, check whether the available connection history meets your needs.
After
- name: PostgreSQL 설정 변경
azure.azcollection.azure_rm_postgresqlflexibleconfiguration:
resource_group: myResourceGroup
server_name: myServer
name: log_connections
value: "on"
Connection logging is enabled. Verify actual connection events; this setting does not restrict database permissions.