Description
Redshift audit logs help investigate connections and user activity. Without external log collection, records needed for long-term retention and centralized analysis may be insufficient.
Potential impact
Records needed to investigate administrative activity or abnormal access may be harder to obtain.
Remediation
Use aws_redshift_logging to deliver audit logs to S3 or CloudWatch Logs. If user activity logs are required, also enable the cluster parameter enable_user_activity_logging.
Examples
The examples add S3 delivery using the current standalone logging resource. Supply mutually compatible, supported node and cluster types through the variables, and prepare the bucket and log-delivery policy separately. The password is illustrative.
Before
resource "aws_redshift_cluster" "example" {
cluster_identifier = "tf-redshift-cluster"
database_name = "mydb"
master_username = "foo"
master_password = "Mustbe8characters"
node_type = var.redshift_node_type
cluster_type = var.redshift_cluster_type
}
After
resource "aws_redshift_cluster" "example" {
cluster_identifier = "tf-redshift-cluster"
database_name = "mydb"
master_username = "foo"
master_password = "Mustbe8characters"
node_type = var.redshift_node_type
cluster_type = var.redshift_cluster_type
}
resource "aws_redshift_logging" "example" {
cluster_identifier = aws_redshift_cluster.example.id
log_destination_type = "s3"
bucket_name = aws_s3_bucket.logs.id
}