Description
Without generated and retained Neptune audit logs, database requests and access patterns are harder to investigate afterward. Export to CloudWatch Logs helps centralize storage and analysis of the generated audit logs.
Audit log generation and export are separate settings. Set the cluster parameter neptune_enable_audit_log to 1 and reboot the DB instances to generate audit logs.
Potential impact
- Records needed to investigate suspicious requests and access may be missing.
- Evidence needed for incident investigation or an audit may be unavailable.
Remediation
Enable audit logging in the cluster parameters and plan the required reboot. Include audit in EnableCloudwatchLogsExports, then verify actual log generation and delivery. Manage log access and retention, and review encryption at rest separately.
Examples
These are partial cluster settings. Configure the actual identifier, instances, network and audit-log parameter group separately. The retained StorageEncrypted: false setting is not a production recommendation; configure encryption at rest separately.
Before
{
"AWSTemplateFormatVersion": "2010-09-09",
"Resources": {
"Prod": {
"Type": "AWS::Neptune::DBCluster",
"Properties": {
"DBClusterIdentifier": "String",
"Port": 10000,
"StorageEncrypted": false
}
}
}
}
Audit logs are not exported to CloudWatch Logs. This setting alone does not establish whether the cluster generates audit logs internally.
After
{
"AWSTemplateFormatVersion": "2010-09-09",
"Resources": {
"Prod": {
"Type": "AWS::Neptune::DBCluster",
"Properties": {
"DBClusterIdentifier": "String",
"EnableCloudwatchLogsExports": ["audit"],
"Port": 10000,
"StorageEncrypted": false
}
}
}
}
Audit log export is configured. Generating the logs also requires the parameter setting and reboot.