Description
Exporting RDS logs to CloudWatch allows centralized analysis across databases. An absent export setting does not mean that the database has no logs of its own.
Potential impact
Without centralized collection, analyzing errors and comparing activity across instances can be harder.
Remediation
Specify the required log types supported by the engine in enabled_cloudwatch_logs_exports. Check the engine parameters needed to generate those logs and configure CloudWatch retention.
Examples
The examples export only PostgreSQL upgrade logs. Consider postgresql logs for general database activity as well. Supply a valid password through the variable.
Before
hcl
resource "aws_db_instance" "example" {
allocated_storage = 20
engine = "postgres"
instance_class = "db.t3.small"
password = var.db_password
username = "admin"
}
After
hcl
resource "aws_db_instance" "example" {
allocated_storage = 20
engine = "postgres"
instance_class = "db.t3.small"
password = var.db_password
username = "admin"
enabled_cloudwatch_logs_exports = ["upgrade"]
}