Description
Elasticsearch or OpenSearch domain logs help investigate slow queries, errors and security events. Without generating and publishing the required logs, records needed to investigate failures and unusual activity may be missing.
Potential impact
- Investigating slow queries and operational errors can become harder.
- Missing audit records can delay security-event investigations.
Remediation
Set the required log types and CloudWatch log group in logPublishingOptions, with enabled set to true. Configure log-group write permissions and retention, enable the relevant slow-log thresholds or audit prerequisites, and verify actual collection.
Examples
These excerpts show domain configuration and log-publishing options separately. Add the after options to the remaining settings of the same domain, and prepare the referenced log group and permissions separately.
Before
resources:
exampleDomain:
type: aws:elasticsearch:Domain
properties:
elasticsearchVersion: "7.10"
clusterConfig:
instanceType: t2.small.elasticsearch
instanceCount: 1
After
resources:
exampleDomain:
type: aws:elasticsearch:Domain
properties:
logPublishingOptions:
- cloudwatchLogGroupArn: ${exampleLogGroup.arn}
logType: INDEX_SLOW_LOGS
enabled: true
INDEX_SLOW_LOGS configures publishing of indexing slow logs. It does not enable all search slow logs, application errors or audit logs; configure the index slow-log thresholds as well.