Review MQ broker logging

Enable operational and audit logs supported by the Amazon MQ engine.

Description

Amazon MQ general logs help investigate broker problems. ActiveMQ can also audit management actions through JMX or the web console; RabbitMQ does not support this audit-log option.

Potential impact

Without the required logs, tracing broker errors and administrative actions is harder.

Remediation

Set general = true in logs, and also set audit = true for ActiveMQ. Configure CloudWatch Logs delivery permissions and retention.

Examples

The examples compare ActiveMQ logging settings. Supply a supported engine version, a compatible instance type for the Region, and a valid password through variables. Other required settings are omitted from the before example.

Before

hcl
resource "aws_mq_broker" "example" {
  broker_name = "disabled-logging"

  logs {
    general = false
    audit   = true
  }
}

After

hcl
resource "aws_mq_broker" "example" {
  broker_name = "example"

  configuration {
    id       = aws_mq_configuration.test.id
    revision = aws_mq_configuration.test.latest_revision
  }

  engine_type        = "ActiveMQ"
  engine_version     = var.activemq_engine_version
  host_instance_type = var.mq_instance_type
  security_groups    = [aws_security_group.test.id]

  user {
    username = "ExampleUser"
    password = var.broker_password
  }

  logs {
    general = true
    audit   = true
  }
}

References