Description
Amazon DocumentDB audit logs help investigate authentication and database operations. Profiler logs support analysis of slow operations according to the configured threshold and sampling rate; they do not replace audit logging of access events.
To use these logs in CloudWatch, select the types in enableCloudwatchLogsExports and enable the corresponding features in the cluster parameter group. Adding export types alone does not generate the logs.
Potential impact
- Missing audit records can make abnormal access and database changes harder to investigate.
- Insufficient performance records can delay analysis of slow operations and failures.
Remediation
- Select required audit events with
audit_logs. If profiling is needed, configureprofiler, its threshold and sampling in a custom parameter group and associate it with the cluster. - Specify the required
auditandprofilertypes inenableCloudwatchLogsExports, then verify that actual events arrive in CloudWatch Logs. - Restrict access to sensitive logs, set retention periods, and review collection costs and profiling overhead.
Examples
These partial examples show only log export settings. Configure the parameter group and remaining cluster settings separately.
Before
apiVersion: docdb.aws.crossplane.io/v1alpha1
kind: DBCluster
spec:
forProvider:
region: us-east-1
engine: docdb
CloudWatch export of audit and profiler logs is not specified. CloudTrail records of management API operations are separate from auditing operations within the database.
After
apiVersion: docdb.aws.crossplane.io/v1alpha1
kind: DBCluster
spec:
forProvider:
region: us-east-1
engine: docdb
enableCloudwatchLogsExports:
- audit
- profiler
Both export types are specified. Enable the corresponding parameters and verify actual log generation and delivery.