Description
Without externally retained Redshift audit logs, connection and user activity records needed for longer investigations may be unavailable. LoggingProperties can send logs to S3 or CloudWatch Logs; this is separate from database system-table records.
User activity logging also requires the cluster parameter enable_user_activity_logging. Configuring export alone does not record every SQL activity.
Potential impact
- Incident investigations may be delayed by missing access or activity records for the required period.
- Poor access and retention controls for logs containing sensitive query text may expose information.
Remediation
Configure the required destination and log coverage in LoggingProperties, and enable the user activity parameter when those logs are needed. Set delivery permissions, access restrictions and retention at the destination, then verify collection.
Examples
These excerpts compare S3 log export. Supply the subnet group, a RedshiftNodeType supported by the Region and cluster configuration, and LoggingBucketName. Provide RedshiftMasterPassword through a NoEcho input without a default or an approved secret-management method. PubliclyAccessible: true is not required for logging; review network exposure separately.
Before
Resources:
RedshiftCluster:
Type: AWS::Redshift::Cluster
Properties:
ClusterSubnetGroupName: !Ref RedshiftClusterSubnetGroup
DBName: analytics
MasterUsername: admin
MasterUserPassword: !Ref RedshiftMasterPassword
PubliclyAccessible: true
NodeType: !Ref RedshiftNodeType
Port: 5439
External log export is not configured. This does not mean that database system-table records are absent.
After
Resources:
RedshiftCluster:
Type: AWS::Redshift::Cluster
Properties:
ClusterSubnetGroupName: !Ref RedshiftClusterSubnetGroup
DBName: analytics
MasterUsername: admin
MasterUserPassword: !Ref RedshiftMasterPassword
PubliclyAccessible: true
NodeType: !Ref RedshiftNodeType
Port: 5439
LoggingProperties:
BucketName: !Ref LoggingBucketName
An S3 log destination is specified. Check bucket delivery permissions and the user activity logging parameter separately.