Description
Without the required Amazon MQ logs, broker failures or administrative actions can be harder to investigate. General provides operational logs; Audit records management actions through ActiveMQ JMX or its web console. Audit does not apply to RabbitMQ brokers.
Audit logs do not provide a history of every message processed. Message content sent through the web console may appear in logs, so review log sensitivity and access permissions.
Potential impact
- Insufficient records can hinder investigation of failures or suspicious administrative actions.
- Message or management information in logs may be exposed to unintended users.
Remediation
Enable Logs.General for the broker engine and operational purpose, and enable Logs.Audit when ActiveMQ management auditing is needed. Prepare permissions for CloudWatch log group creation and delivery, then verify actual records after applying the changes. Restrict log retention and access.
Examples
These historical ActiveMQ examples compare logging settings. Replace the engine version and instance type with a currently supported combination and supply BrokerUsername and BrokerPassword securely. Prepare networking and log delivery permissions separately.
Before
AWSTemplateFormatVersion: "2010-09-09"
Description: "Create a basic ActiveMQ broker"
Resources:
BasicBroker:
Type: "AWS::AmazonMQ::Broker"
Properties:
BrokerName: MyBasicBroker
DeploymentMode: SINGLE_INSTANCE
EngineType: ActiveMQ
EngineVersion: "5.15.0"
HostInstanceType: mq.t2.micro
PubliclyAccessible: false
Users:
- ConsoleAccess: "true"
Groups:
- MyGroup
Password:
Ref: "BrokerPassword"
Username:
Ref: "BrokerUsername"
Logs:
General: true
This enables general logs but does not specify management audit logging.
After
AWSTemplateFormatVersion: "2010-09-09"
Description: "Create a basic ActiveMQ broker"
Resources:
BasicBroker:
Type: "AWS::AmazonMQ::Broker"
Properties:
AutoMinorVersionUpgrade: "false"
BrokerName: MyBasicBroker
DeploymentMode: SINGLE_INSTANCE
EncryptionOptions:
UseAwsOwnedKey: true
EngineType: ActiveMQ
EngineVersion: "5.15.0"
HostInstanceType: mq.t2.micro
PubliclyAccessible: false
Users:
- ConsoleAccess: "true"
Groups:
- MyGroup
Password:
Ref: "BrokerPassword"
Username:
Ref: "BrokerUsername"
Logs:
General: true
Audit: true
This enables general and management audit logs. AutoMinorVersionUpgrade: false is not a logging requirement; review it against the current engine’s update policy.