Review Alibaba Cloud RDS PostgreSQL disconnection logging

Keep logs for investigating session end times and durations.

Description

When log_disconnections is disabled in RDS PostgreSQL, information about session end times and durations may be missing. Reviewing connection and disconnection logs together helps investigate long sessions and unusual usage patterns.

Potential impact

  • Correlating session starts and ends becomes harder.
  • Investigating long connections or operational problems can take longer.

Remediation

Set log_disconnections to ON where supported by the PostgreSQL parameter set. Verify actual session-end log collection alongside log_connections, and manage retention and access permissions. Use the corresponding session-auditing features for other engines.

Examples

These excerpts compare PostgreSQL disconnection logging. Supply a supported PostgreSQL version and instance specifications, and configure the remaining creation settings separately.

Before

hcl
resource "alicloud_db_instance" "default" {
  engine              = "PostgreSQL"
  engine_version      = var.postgresql_version
  instance_type       = var.db_instance_type
  instance_storage    = var.db_instance_storage

  parameters {
    name  = "log_disconnections"
    value = "OFF"
  }
}

After

hcl
resource "alicloud_db_instance" "default" {
  engine              = "PostgreSQL"
  engine_version      = var.postgresql_version
  instance_type       = var.db_instance_type
  instance_storage    = var.db_instance_storage

  parameters {
    name  = "log_disconnections"
    value = "ON"
  }
}

The after example sets log_disconnections to ON. Verify collection of session-end records and session durations.

References