Review Elasticsearch and OpenSearch error logging

Deliver the logs needed to investigate domain errors to CloudWatch.

Description

Without error logs for an Elasticsearch or OpenSearch domain, query processing, indexing or snapshot problems can be harder to investigate. ES_APPLICATION_LOGS publishes domain error and warning information; it is not a record of every request or application action.

Audit logs and slow search or indexing logs are separate features. Enabling error log publishing does not automatically configure those logs or alarms.

Potential impact

  • Missing error information can delay diagnosis and recovery.
  • Unprotected logs may expose queries or other sensitive information.

Remediation

Set the actual CloudWatch Logs group ARN and Enabled: true under ES_APPLICATION_LOGS. Prepare a resource policy allowing service log delivery, and verify actual records, retention and access settings. Configure audit logs, slow logs and alarms separately for their intended purposes.

Examples

These excerpts retain the AWS::Elasticsearch::Domain resource type. Prepare an engine that supports error logs, the actual log group and delivery permissions separately.

Before

yaml
Resources:
  ElasticsearchDomain:
    Type: AWS::Elasticsearch::Domain
    Properties:
      DomainName: my-domain
      LogPublishingOptions:
        ES_APPLICATION_LOGS:
          CloudWatchLogsLogGroupArn: arn:aws:logs:us-east-1:123456789012:log-group:/aws/aes/domains/app
          Enabled: false

This turns off CloudWatch publishing of error logs.

After

yaml
Resources:
  ElasticsearchDomain:
    Type: AWS::Elasticsearch::Domain
    Properties:
      DomainName: my-domain
      LogPublishingOptions:
        ES_APPLICATION_LOGS:
          CloudWatchLogsLogGroupArn: arn:aws:logs:us-east-1:123456789012:log-group:/aws/aes/domains/app
          Enabled: true

This configures error log publishing to the specified log group. Replace its ARN with the actual value and verify delivery.

References