Review Azure PostgreSQL connection logging

Collect the logs needed to investigate PostgreSQL connection attempts and successful connections.

Description

Connection logs help establish who connected and when through connection attempts and successful authentication and authorization records. Without them, unexpected connection increases or unusual access patterns can be harder to trace. Connection logs do not replace a complete query audit trail.

Potential impact

  • Unusual connection patterns may be discovered late.
  • Tracing which account connected and when can be harder after an incident.

Remediation

Use the log_connections setting supported by your PostgreSQL version to record required connection events. Verify effective settings, collection and retention on Flexible Server, and restrict access to sensitive logs. Configure detailed query auditing separately when needed.

Examples

The before example uses retired Single Server. The after example targets an existing Flexible Server version that supports the Boolean on setting for log_connections.

Before

hcl
resource "azurerm_postgresql_configuration" "example" {
  name                = "log_connections"
  resource_group_name = data.azurerm_resource_group.example.name
  server_name         = azurerm_postgresql_server.example.name
  value               = "OFF"
}

After

hcl
resource "azurerm_postgresql_flexible_server_configuration" "example" {
  name      = "log_connections"
  server_id = azurerm_postgresql_flexible_server.example.id
  value     = "on"
}

The after example enables connection logging. It does not block access, so maintain authentication and permission controls separately.

References