Review Amazon MQ broker logging

Collect operational and audit logs appropriate for the broker engine.

Description

Without the required Amazon MQ logs, broker failures or administrative actions can be harder to investigate. General provides operational logs; Audit records management actions through ActiveMQ JMX or its web console. Audit does not apply to RabbitMQ brokers.

Audit logs do not provide a history of every message processed. Message content sent through the web console may appear in logs, so review log sensitivity and access permissions.

Potential impact

  • Insufficient records can hinder investigation of failures or suspicious administrative actions.
  • Message or management information in logs may be exposed to unintended users.

Remediation

Enable Logs.General for the broker engine and operational purpose, and enable Logs.Audit when ActiveMQ management auditing is needed. Prepare permissions for CloudWatch log group creation and delivery, then verify actual records after applying the changes. Restrict log retention and access.

Examples

These historical ActiveMQ examples compare logging settings. Replace the engine version and instance type with a currently supported combination and supply BrokerUsername and BrokerPassword securely. Prepare networking and log delivery permissions separately.

Before

yaml
AWSTemplateFormatVersion: "2010-09-09"
Description: "Create a basic ActiveMQ broker"
Resources:
  BasicBroker:
    Type: "AWS::AmazonMQ::Broker"
    Properties:
      BrokerName: MyBasicBroker
      DeploymentMode: SINGLE_INSTANCE
      EngineType: ActiveMQ
      EngineVersion: "5.15.0"
      HostInstanceType: mq.t2.micro
      PubliclyAccessible: false
      Users:
        - ConsoleAccess: "true"
          Groups:
            - MyGroup
          Password:
            Ref: "BrokerPassword"
          Username:
            Ref: "BrokerUsername"
      Logs:
        General: true

This enables general logs but does not specify management audit logging.

After

yaml
AWSTemplateFormatVersion: "2010-09-09"
Description: "Create a basic ActiveMQ broker"
Resources:
  BasicBroker:
    Type: "AWS::AmazonMQ::Broker"
    Properties:
      AutoMinorVersionUpgrade: "false"
      BrokerName: MyBasicBroker
      DeploymentMode: SINGLE_INSTANCE
      EncryptionOptions:
        UseAwsOwnedKey: true
      EngineType: ActiveMQ
      EngineVersion: "5.15.0"
      HostInstanceType: mq.t2.micro
      PubliclyAccessible: false
      Users:
        - ConsoleAccess: "true"
          Groups:
            - MyGroup
          Password:
            Ref: "BrokerPassword"
          Username:
            Ref: "BrokerUsername"
      Logs:
        General: true
        Audit: true

This enables general and management audit logs. AutoMinorVersionUpgrade: false is not a logging requirement; review it against the current engine’s update policy.

References