Description
DocumentDB audit and profiler logs help investigate access events and performance problems. In addition to CloudWatch export, the corresponding log generation must be enabled in cluster parameters.
Potential impact
- Missing records of relevant access events or slow operations can hinder investigations.
- Determining a failure’s cause and scope can take longer.
Remediation
Add the required audit or profiler types to enabledCloudwatchLogsExports. Configure the cluster audit_logs and profiler parameters for the intended purpose, then verify collection, CloudWatch retention and access permissions.
Examples
These excerpts compare log exports. Provide docdbPassword as a Pulumi secret input, and configure networking and the parameter group separately. Review skipFinalSnapshot independently against deletion and recovery requirements.
Before
resources:
aws:docdb/cluster:
type: aws:docdb:Cluster
properties:
clusterIdentifier: my-docdb-cluster
engine: docdb
masterUsername: foo
masterPassword: ${docdbPassword}
skipFinalSnapshot: true
After
resources:
aws:docdb/cluster:
type: aws:docdb:Cluster
properties:
clusterIdentifier: my-docdb-cluster
engine: docdb
masterUsername: foo
masterPassword: ${docdbPassword}
skipFinalSnapshot: true
enabledCloudwatchLogsExports:
- audit
- profiler
The after example exports audit and profiler logs to CloudWatch. The export list does not itself turn on log generation; the recorded scope depends on parameter settings and supported events.