Review Redshift audit logging

Export Redshift audit logs to an appropriate destination.

Description

Redshift audit logs help investigate connections and user activity. Without external log collection, records needed for long-term retention and centralized analysis may be insufficient.

Potential impact

Records needed to investigate administrative activity or abnormal access may be harder to obtain.

Remediation

Use aws_redshift_logging to deliver audit logs to S3 or CloudWatch Logs. If user activity logs are required, also enable the cluster parameter enable_user_activity_logging.

Examples

The examples add S3 delivery using the current standalone logging resource. Supply mutually compatible, supported node and cluster types through the variables, and prepare the bucket and log-delivery policy separately. The password is illustrative.

Before

hcl
resource "aws_redshift_cluster" "example" {
  cluster_identifier = "tf-redshift-cluster"
  database_name      = "mydb"
  master_username    = "foo"
  master_password    = "Mustbe8characters"
  node_type          = var.redshift_node_type
  cluster_type       = var.redshift_cluster_type
}

After

hcl
resource "aws_redshift_cluster" "example" {
  cluster_identifier = "tf-redshift-cluster"
  database_name      = "mydb"
  master_username    = "foo"
  master_password    = "Mustbe8characters"
  node_type          = var.redshift_node_type
  cluster_type       = var.redshift_cluster_type
}

resource "aws_redshift_logging" "example" {
  cluster_identifier   = aws_redshift_cluster.example.id
  log_destination_type = "s3"
  bucket_name          = aws_s3_bucket.logs.id
}

References