Review DocumentDB log exports

Export DocumentDB audit and profiler logs to CloudWatch.

Description

DocumentDB audit and profiler logs help investigate access activity and slow operations. Configure both log generation and CloudWatch export.

Potential impact

Without the required logs, investigating abnormal access and performance problems is harder.

Remediation

Include audit and profiler in enabled_cloudwatch_logs_exports. Also enable auditing and profiling in the cluster parameter group and configure the required events and thresholds.

Examples

The examples compare export settings only. Configure the parameter group separately, and do not use the example password in production.

Before

hcl
resource "aws_docdb_cluster" "example" {
  cluster_identifier      = "my-docdb-cluster"
  engine                  = "docdb"
  master_username         = "foo"
  master_password         = "mustbeeightchars"
  backup_retention_period = 5
  preferred_backup_window = "07:00-09:00"
  skip_final_snapshot     = true
}

After

hcl
resource "aws_docdb_cluster" "example" {
  cluster_identifier      = "my-docdb-cluster"
  engine                  = "docdb"
  master_username         = "foo"
  master_password         = "mustbeeightchars"
  backup_retention_period = 5
  preferred_backup_window = "07:00-09:00"
  skip_final_snapshot     = true

  enabled_cloudwatch_logs_exports = ["profiler", "audit"]
}

References