Review Neptune audit log exports

Enable Neptune audit logging and export the logs to CloudWatch.

Description

Neptune audit logs help investigate database requests. Enable audit log generation on the cluster as well as CloudWatch export.

Potential impact

Without the required audit records, investigating abnormal access and database activity is harder.

Remediation

Include audit in enable_cloudwatch_logs_exports and set neptune_enable_audit_log to 1 in the cluster parameter group. After applying the settings, verify log collection in CloudWatch.

Examples

The examples show log export settings. Apply the audit-generation parameter separately.

Before

hcl
resource "aws_neptune_cluster" "example" {
  cluster_identifier                  = "neptune-cluster"
  engine                              = "neptune"
  backup_retention_period             = 5
  preferred_backup_window             = "10:10-11:11"
  skip_final_snapshot                 = true
  iam_database_authentication_enabled = true
  apply_immediately                   = true
}

After

hcl
resource "aws_neptune_cluster" "example" {
  cluster_identifier                  = "neptune-cluster1"
  engine                              = "neptune"
  backup_retention_period             = 5
  preferred_backup_window             = "10:10-11:11"
  skip_final_snapshot                 = true
  iam_database_authentication_enabled = true
  apply_immediately                   = true
  enable_cloudwatch_logs_exports      = ["audit"]
}

References