Description
Connection logs help establish who connected and when through connection attempts and successful authentication and authorization records. Without them, unexpected connection increases or unusual access patterns can be harder to trace. Connection logs do not replace a complete query audit trail.
Potential impact
- Unusual connection patterns may be discovered late.
- Tracing which account connected and when can be harder after an incident.
Remediation
Use the log_connections setting supported by your PostgreSQL version to record required connection events. Verify effective settings, collection and retention on Flexible Server, and restrict access to sensitive logs. Configure detailed query auditing separately when needed.
Examples
The before example uses retired Single Server. The after example targets an existing Flexible Server version that supports the Boolean on setting for log_connections.
Before
resource "azurerm_postgresql_configuration" "example" {
name = "log_connections"
resource_group_name = data.azurerm_resource_group.example.name
server_name = azurerm_postgresql_server.example.name
value = "OFF"
}
After
resource "azurerm_postgresql_flexible_server_configuration" "example" {
name = "log_connections"
server_id = azurerm_postgresql_flexible_server.example.id
value = "on"
}
The after example enables connection logging. It does not block access, so maintain authentication and permission controls separately.