Azure PostgreSQL disconnection logging is disabled

Use disconnection logs to investigate when PostgreSQL sessions end and how long they last.

Description

log_disconnections records session termination, including session duration. Combined with connection logs, it helps investigate session activity. These records alone do not explain every reason for a disconnection.

Potential impact

  • It can be harder to trace when sessions ended.
  • Evidence for investigating connection failures or unusual session activity may be missing.

Remediation

Set log_disconnections to on on Flexible Server and configure any required connection logging. Verify that actual session termination creates a stored log, then apply suitable retention and access permissions.

Examples

The before example uses a retired Single Server parameter. The after excerpt enables disconnection logging on an existing Flexible Server.

Before

hcl
resource "azurerm_postgresql_configuration" "example" {
  name                = "log_disconnections"
  resource_group_name = data.azurerm_resource_group.example.name
  server_name         = azurerm_postgresql_server.example.name
  value               = "OFF"
}

After

hcl
resource "azurerm_postgresql_flexible_server_configuration" "example" {
  name      = "log_disconnections"
  server_id = azurerm_postgresql_flexible_server.example.id
  value     = "on"
}

The after example records session termination. Analyze these records with other evidence, such as error logs, to investigate the cause.

References