Review Azure PostgreSQL log retention

Check collection and actual retention of Azure PostgreSQL server logs.

Description

When PostgreSQL server logs are not retained for the required period, connection problems, query errors and unusual activity become harder to trace. Define what to collect and how long to retain it, then verify that records are actually available.

Azure Database for PostgreSQL Single Server retired on March 28, 2025. On Flexible Server, logfiles.download_enable enables downloadable server logs. logfiles.retention_days supports 1–7 days and defaults to 3 days. Export logs through diagnostic settings to a suitable destination when longer retention is required.

Potential impact

  • Deleted database events can leave gaps in audits and incident investigations.
  • Diagnosing failures or unusual behavior can take longer.

Remediation

  • Check the supported log collection and retention settings for the server type in use.
  • Choose a period that meets investigation and operational needs, including the retention policy at any long-term destination.
  • Verify incoming logs and the oldest available records, and manage log access and storage costs.

Examples

These historical excerpts use azurerm_postgresql_configuration for the retired Single Server service. They show different log_retention values and are not instructions to apply unchanged to Flexible Server.

Before

hcl
resource "azurerm_postgresql_configuration" "example" {
  name                = "log_retention"
  resource_group_name = data.azurerm_resource_group.example.name
  server_name         = azurerm_postgresql_server.example.name
  value               = "OFF"
}

After

hcl
resource "azurerm_postgresql_configuration" "example" {
  name                = "log_retention"
  resource_group_name = data.azurerm_resource_group.example.name
  server_name         = azurerm_postgresql_server.example.name
  value               = "ON"
}

Changing this historical setting alone does not configure long-term retention for the current service. Check settings for the actual server type and retention at the log destination.

References