Description
Neptune audit logs help investigate database requests. Enable audit log generation on the cluster as well as CloudWatch export.
Potential impact
Without the required audit records, investigating abnormal access and database activity is harder.
Remediation
Include audit in enable_cloudwatch_logs_exports and set neptune_enable_audit_log to 1 in the cluster parameter group. After applying the settings, verify log collection in CloudWatch.
Examples
The examples show log export settings. Apply the audit-generation parameter separately.
Before
hcl
resource "aws_neptune_cluster" "example" {
cluster_identifier = "neptune-cluster"
engine = "neptune"
backup_retention_period = 5
preferred_backup_window = "10:10-11:11"
skip_final_snapshot = true
iam_database_authentication_enabled = true
apply_immediately = true
}
After
hcl
resource "aws_neptune_cluster" "example" {
cluster_identifier = "neptune-cluster1"
engine = "neptune"
backup_retention_period = 5
preferred_backup_window = "10:10-11:11"
skip_final_snapshot = true
iam_database_authentication_enabled = true
apply_immediately = true
enable_cloudwatch_logs_exports = ["audit"]
}