Azure PostgreSQL connection logging is disabled

Enable Azure PostgreSQL connection logs to investigate connection attempts and successful connections.

Description

log_connections records connection attempts and successful client authentication and authorization. Disabling it reduces information available to investigate user and application connection history.

Potential impact

Suspicious connection patterns and application connectivity problems can become harder to trace. Connection logs alone do not audit every query or data change.

Remediation

Set log_connections to on on current Flexible Server. Verify delivery to the log collection system, and define retention and access permissions. Configure disconnection logging and query auditing separately as needed.

Examples

The initial excerpt is historical configuration for the retired Single Server service. In the revised excerpt, MyDBServer1 refers to a separately prepared Flexible Server. Parent declarations and data migration are outside these excerpts.

Before

bicep
resource MyDBServer1_log_connections 'Microsoft.DBforPostgreSQL/servers/configurations@2017-12-01' = {
  parent: MyDBServer1
  name: 'log_connections'
  properties: {
    value: 'off'
  }
}

Detailed logging of connection attempts and successful connections is disabled.

After

bicep
resource MyDBServer1_log_connections 'Microsoft.DBforPostgreSQL/flexibleServers/configurations@2024-08-01' = {
  parent: MyDBServer1
  name: 'log_connections'
  properties: {
    source: 'user-override'
    value: 'on'
  }
}

Connection logging is enabled. Confirm that required connections work and their records reach the log collection system.

References