PostgreSQL disconnection logging is disabled

PostgreSQL disconnection logs help investigate when sessions end and how long they last.

Description

log_disconnections records PostgreSQL session terminations and session duration. Without this information, correlating connection and termination records is harder. A disconnection record alone does not explain every abnormal termination or show the SQL executed.

Potential impact

  • Determining when a session ended and how long it lasted may be harder.
  • Investigations of repeated reconnects or unexpected session lengths may lack evidence.

Remediation

  • Set log_disconnections to on in the current service.
  • Collect it alongside connection and error logs so related sessions can be compared.
  • Verify delivery and retention, and limit access to the logs.

Examples

The first example uses Single Server, which retired on March 28, 2025. The second targets an existing Flexible Server using a module available in azure.azcollection 3.18.0 and later.

Before

yaml
- name: PostgreSQL 설정 변경
  azure.azcollection.azure_rm_postgresqlconfiguration:
    resource_group: myResourceGroup
    server_name: myServer
    name: log_disconnections
    value: "off"

Session termination logging is disabled, so this setting does not produce termination times and session durations.

After

yaml
- name: PostgreSQL 설정 변경
  azure.azcollection.azure_rm_postgresqlflexibleconfiguration:
    resource_group: myResourceGroup
    server_name: myServer
    name: log_disconnections
    value: "on"

Session termination logging is enabled. Correlating these records with connection and error logs supports session investigations.

References