Review DocumentDB audit and profiler logging

Configure required log generation together with CloudWatch export.

Description

Insufficient DocumentDB audit records make authentication and database operations harder to investigate. Profiler logs help analyze slow operations; they do not replace audit logs of access events.

To use the logs in CloudWatch, enable the relevant feature in the cluster parameter group as well as the audit or profiler export. Specifying an export list alone does not generate logs.

Potential impact

  • Missing audit records can hinder investigation of unusual access or data changes.
  • Insufficient profiling information can delay investigation of latency.

Remediation

Select required audit events with audit_logs in a custom cluster parameter group. If profiling is needed, configure profiler, its threshold and sampling. Specify the required audit and profiler types in EnableCloudwatchLogsExports and verify delivery. Restrict log access and retention, and review cost and collection overhead.

Examples

These excerpts compare cluster log exports. Credentials, networking and parameter group settings are omitted.

Before

yaml
Resources:
  MyDocDBCluster:
    Type: AWS::DocDB::DBCluster
    Properties:
      DBClusterIdentifier: my-docdb-cluster
      StorageEncrypted: true

This does not specify log exports. Storage encryption does not replace audit or performance records.

After

yaml
Resources:
  MyDocDBCluster:
    Type: AWS::DocDB::DBCluster
    Properties:
      DBClusterIdentifier: my-docdb-cluster
      StorageEncrypted: true
      EnableCloudwatchLogsExports:
        - audit
        - profiler

This specifies audit and profiler exports. Enable the corresponding log generation in the parameter group and verify actual collection.

References