Description
DocumentDB audit and profiler logs help investigate access activity and slow operations. Configure both log generation and CloudWatch export.
Potential impact
Without the required logs, investigating abnormal access and performance problems is harder.
Remediation
Include audit and profiler in enabled_cloudwatch_logs_exports. Also enable auditing and profiling in the cluster parameter group and configure the required events and thresholds.
Examples
The examples compare export settings only. Configure the parameter group separately, and do not use the example password in production.
Before
hcl
resource "aws_docdb_cluster" "example" {
cluster_identifier = "my-docdb-cluster"
engine = "docdb"
master_username = "foo"
master_password = "mustbeeightchars"
backup_retention_period = 5
preferred_backup_window = "07:00-09:00"
skip_final_snapshot = true
}
After
hcl
resource "aws_docdb_cluster" "example" {
cluster_identifier = "my-docdb-cluster"
engine = "docdb"
master_username = "foo"
master_password = "mustbeeightchars"
backup_retention_period = 5
preferred_backup_window = "07:00-09:00"
skip_final_snapshot = true
enabled_cloudwatch_logs_exports = ["profiler", "audit"]
}