PostgreSQL connection logging is disabled

Insufficient PostgreSQL connection logs can make database access history harder to investigate.

Description

log_connections records connection attempts and successful authentication and authorization. Disabling it reduces evidence for investigating account connections and unusual access patterns. Other error logs may still exist, and this setting does not replace access permissions or query auditing.

Potential impact

  • Identifying which account connected and when may be harder.
  • Account misuse or unusual connection patterns may go unnoticed for longer.

Remediation

  • Set log_connections to on through your service’s server parameters.
  • Review connection logs together with authentication failures and network records.
  • Verify delivery, retention and log access permissions, and consider collection costs.

Examples

The first excerpt targets Single Server, which retired on March 28, 2025. The second updates an existing Flexible Server using azure.azcollection 3.18.0 or later.

Before

yaml
- name: PostgreSQL 설정 변경
  azure.azcollection.azure_rm_postgresqlconfiguration:
    resource_group: myResourceGroup
    server_name: myServer
    name: log_connections
    value: "off"

Connection logging is disabled. Even if separate error records exist, check whether the available connection history meets your needs.

After

yaml
- name: PostgreSQL 설정 변경
  azure.azcollection.azure_rm_postgresqlflexibleconfiguration:
    resource_group: myResourceGroup
    server_name: myServer
    name: log_connections
    value: "on"

Connection logging is enabled. Verify actual connection events; this setting does not restrict database permissions.

References