Review Elasticsearch log publishing

Enable CloudWatch publishing for the Elasticsearch domain logs you need.

Description

Search-domain logs help investigate slow operations and errors. Configure both publishing and actual generation of the required log types.

Potential impact

Without logs, finding the cause of search and indexing performance problems is harder.

Remediation

Specify the log group and log type in log_publishing_options and set enabled = true. For slow logs, also set index thresholds and permit publishing through a CloudWatch Logs resource policy.

Examples

The examples enable only INDEX_SLOW_LOGS publishing. Other required settings, such as the domain name, index thresholds, and logging permissions are omitted.

Before

hcl
resource "aws_elasticsearch_domain" "example" {
  log_publishing_options {
    cloudwatch_log_group_arn = aws_cloudwatch_log_group.example.arn
    log_type                 = "INDEX_SLOW_LOGS"
    enabled                  = false
  }
}

After

hcl
resource "aws_elasticsearch_domain" "example" {
  log_publishing_options {
    cloudwatch_log_group_arn = aws_cloudwatch_log_group.example.arn
    log_type                 = "INDEX_SLOW_LOGS"
    enabled                  = true
  }
}

References