Redshift audit log export needs review

Check Redshift audit log coverage, external destinations and retention.

Description

Without externally retained Redshift audit logs, connection and user activity records needed for longer investigations may be unavailable. LoggingProperties can send logs to S3 or CloudWatch Logs; this is separate from database system-table records.

User activity logging also requires the cluster parameter enable_user_activity_logging. Configuring export alone does not record every SQL activity.

Potential impact

  • Incident investigations may be delayed by missing access or activity records for the required period.
  • Poor access and retention controls for logs containing sensitive query text may expose information.

Remediation

Configure the required destination and log coverage in LoggingProperties, and enable the user activity parameter when those logs are needed. Set delivery permissions, access restrictions and retention at the destination, then verify collection.

Examples

These excerpts compare S3 log export. Supply the subnet group, a RedshiftNodeType supported by the Region and cluster configuration, and LoggingBucketName. Provide RedshiftMasterPassword through a NoEcho input without a default or an approved secret-management method. PubliclyAccessible: true is not required for logging; review network exposure separately.

Before

yaml
Resources:
  RedshiftCluster:
    Type: AWS::Redshift::Cluster
    Properties:
      ClusterSubnetGroupName: !Ref RedshiftClusterSubnetGroup
      DBName: analytics
      MasterUsername: admin
      MasterUserPassword: !Ref RedshiftMasterPassword
      PubliclyAccessible: true
      NodeType: !Ref RedshiftNodeType
      Port: 5439

External log export is not configured. This does not mean that database system-table records are absent.

After

yaml
Resources:
  RedshiftCluster:
    Type: AWS::Redshift::Cluster
    Properties:
      ClusterSubnetGroupName: !Ref RedshiftClusterSubnetGroup
      DBName: analytics
      MasterUsername: admin
      MasterUserPassword: !Ref RedshiftMasterPassword
      PubliclyAccessible: true
      NodeType: !Ref RedshiftNodeType
      Port: 5439
      LoggingProperties:
        BucketName: !Ref LoggingBucketName

An S3 log destination is specified. Check bucket delivery permissions and the user activity logging parameter separately.

References