Description
Without error logs for an Elasticsearch or OpenSearch domain, query processing, indexing or snapshot problems can be harder to investigate. ES_APPLICATION_LOGS publishes domain error and warning information; it is not a record of every request or application action.
Audit logs and slow search or indexing logs are separate features. Enabling error log publishing does not automatically configure those logs or alarms.
Potential impact
- Missing error information can delay diagnosis and recovery.
- Unprotected logs may expose queries or other sensitive information.
Remediation
Set the actual CloudWatch Logs group ARN and Enabled: true under ES_APPLICATION_LOGS. Prepare a resource policy allowing service log delivery, and verify actual records, retention and access settings. Configure audit logs, slow logs and alarms separately for their intended purposes.
Examples
These excerpts retain the AWS::Elasticsearch::Domain resource type. Prepare an engine that supports error logs, the actual log group and delivery permissions separately.
Before
Resources:
ElasticsearchDomain:
Type: AWS::Elasticsearch::Domain
Properties:
DomainName: my-domain
LogPublishingOptions:
ES_APPLICATION_LOGS:
CloudWatchLogsLogGroupArn: arn:aws:logs:us-east-1:123456789012:log-group:/aws/aes/domains/app
Enabled: false
This turns off CloudWatch publishing of error logs.
After
Resources:
ElasticsearchDomain:
Type: AWS::Elasticsearch::Domain
Properties:
DomainName: my-domain
LogPublishingOptions:
ES_APPLICATION_LOGS:
CloudWatchLogsLogGroupArn: arn:aws:logs:us-east-1:123456789012:log-group:/aws/aes/domains/app
Enabled: true
This configures error log publishing to the specified log group. Replace its ARN with the actual value and verify delivery.