Review DocumentDB log exports

Generate and collect DocumentDB logs needed for audit and performance analysis.

Description

DocumentDB audit and profiler logs help investigate access events and performance problems. In addition to CloudWatch export, the corresponding log generation must be enabled in cluster parameters.

Potential impact

  • Missing records of relevant access events or slow operations can hinder investigations.
  • Determining a failure’s cause and scope can take longer.

Remediation

Add the required audit or profiler types to enabledCloudwatchLogsExports. Configure the cluster audit_logs and profiler parameters for the intended purpose, then verify collection, CloudWatch retention and access permissions.

Examples

These excerpts compare log exports. Provide docdbPassword as a Pulumi secret input, and configure networking and the parameter group separately. Review skipFinalSnapshot independently against deletion and recovery requirements.

Before

yaml
resources:
  aws:docdb/cluster:
    type: aws:docdb:Cluster
    properties:
      clusterIdentifier: my-docdb-cluster
      engine: docdb
      masterUsername: foo
      masterPassword: ${docdbPassword}
      skipFinalSnapshot: true

After

yaml
resources:
  aws:docdb/cluster:
    type: aws:docdb:Cluster
    properties:
      clusterIdentifier: my-docdb-cluster
      engine: docdb
      masterUsername: foo
      masterPassword: ${docdbPassword}
      skipFinalSnapshot: true
      enabledCloudwatchLogsExports:
        - audit
        - profiler

The after example exports audit and profiler logs to CloudWatch. The export list does not itself turn on log generation; the recorded scope depends on parameter settings and supported events.

References