Description
RDS audit, slow-query and performance logs support investigation of database activity and performance problems. Disabled collection or instances outside the collection scope can leave gaps in incident and operational evidence.
Potential impact
- Missing database activity records can hinder access-history investigations.
- Correlating performance and audit logs can become harder, delaying diagnosis.
Remediation
Configure rds_enabled, rds_slow_enabled and rds_perf_enabled in variable_map for collection requirements. Enable required categories with "true" and verify instance support, audit features and collection policies. Confirm delivery to the destination and manage retention, costs and access permissions.
Examples
This excerpt enables audit log collection. Supply the actual account ID through account_id and configure service permissions and instance audit features separately.
Before
resource "alicloud_log_audit" "example" {
display_name = "tf-audit-test"
aliuid = var.account_id
variable_map = {
rds_enabled = "false"
rds_slow_enabled = "true"
rds_perf_enabled = "true"
}
}
After
resource "alicloud_log_audit" "example" {
display_name = "tf-audit-test"
aliuid = var.account_id
variable_map = {
rds_enabled = "true"
rds_slow_enabled = "true"
rds_perf_enabled = "true"
}
}
The after example requests audit, slow-query and performance log collection. These three settings alone do not guarantee collection of every database event; verify actual coverage.