Description
When log_connections is disabled in RDS PostgreSQL, less information may be available to investigate connection attempts and successful connections. Connection logs help investigate account misuse and unusual access patterns; they do not block access by themselves.
Potential impact
- Missing connection history makes unusual logins and repeated attempts harder to investigate.
- Determining the scope of account misuse or external access can take longer.
Remediation
Check parameter support for the PostgreSQL version and set log_connections to ON in parameters. Verify the effective value and log collection, and set the required retention and access permissions. For other engines, use their corresponding connection-auditing features.
Examples
These excerpts show RDS PostgreSQL connection logging. Choose version, instance type and storage inputs supported in the target region, and configure network and other creation settings separately.
Before
resource "alicloud_db_instance" "default" {
engine = "PostgreSQL"
engine_version = var.postgresql_version
instance_type = var.db_instance_type
instance_storage = var.db_instance_storage
}
After
resource "alicloud_db_instance" "default" {
engine = "PostgreSQL"
engine_version = var.postgresql_version
instance_type = var.db_instance_type
instance_storage = var.db_instance_storage
parameters {
name = "log_connections"
value = "ON"
}
}
The before example does not specify the logging value, so check its effective parameter value. The after example sets log_connections to ON; verify that connection attempts produce the expected logs.