Description
When server log retention is shorter than the investigation window, error or unusual-access records can disappear before analysis. The required period depends on operational and audit needs; no single duration suits every environment. Flexible Server retains downloadable server logs for 1–7 days, with a default of 3 days.
Potential impact
- Evidence for root-cause analysis may be missing when problems are discovered late.
- Historical records needed for audits or incident response may no longer be available.
Remediation
To use downloadable logs on Flexible Server, set logfiles.download_enable to on and choose logfiles.retention_days within the supported range for operational needs. Collect logs in separate storage with suitable retention and access policies when longer history is required. Verify actual log generation and the period available for retrieval.
Examples
The before example configures retention on retired Single Server. The after example enables downloadable log collection on an existing Flexible Server and retains logs for 5 days. Server and external storage configuration are omitted.
Before
resource "azurerm_postgresql_configuration" "example" {
name = "log_retention_days"
resource_group_name = azurerm_resource_group.example.name
server_name = azurerm_postgresql_server.example.name
value = 2
}
After
resource "azurerm_postgresql_flexible_server_configuration" "download_logs" {
name = "logfiles.download_enable"
server_id = azurerm_postgresql_flexible_server.example.id
value = "on"
}
resource "azurerm_postgresql_flexible_server_configuration" "example" {
name = "logfiles.retention_days"
server_id = azurerm_postgresql_flexible_server.example.id
value = "5"
}
The 5-day value meets an illustrative requirement, not a universal security threshold. Downloadable server logs are disabled by default, so verify actual collection rather than setting retention alone.