Description
Amazon MQ general logs help investigate broker problems. ActiveMQ can also audit management actions through JMX or the web console; RabbitMQ does not support this audit-log option.
Potential impact
Without the required logs, tracing broker errors and administrative actions is harder.
Remediation
Set general = true in logs, and also set audit = true for ActiveMQ. Configure CloudWatch Logs delivery permissions and retention.
Examples
The examples compare ActiveMQ logging settings. Supply a supported engine version, a compatible instance type for the Region, and a valid password through variables. Other required settings are omitted from the before example.
Before
hcl
resource "aws_mq_broker" "example" {
broker_name = "disabled-logging"
logs {
general = false
audit = true
}
}
After
hcl
resource "aws_mq_broker" "example" {
broker_name = "example"
configuration {
id = aws_mq_configuration.test.id
revision = aws_mq_configuration.test.latest_revision
}
engine_type = "ActiveMQ"
engine_version = var.activemq_engine_version
host_instance_type = var.mq_instance_type
security_groups = [aws_security_group.test.id]
user {
username = "ExampleUser"
password = var.broker_password
}
logs {
general = true
audit = true
}
}