Review Azure PostgreSQL server log retention

Keep server logs for the investigation period you need and collect them externally for longer retention.

Description

When server log retention is shorter than the investigation window, error or unusual-access records can disappear before analysis. The required period depends on operational and audit needs; no single duration suits every environment. Flexible Server retains downloadable server logs for 1–7 days, with a default of 3 days.

Potential impact

  • Evidence for root-cause analysis may be missing when problems are discovered late.
  • Historical records needed for audits or incident response may no longer be available.

Remediation

To use downloadable logs on Flexible Server, set logfiles.download_enable to on and choose logfiles.retention_days within the supported range for operational needs. Collect logs in separate storage with suitable retention and access policies when longer history is required. Verify actual log generation and the period available for retrieval.

Examples

The before example configures retention on retired Single Server. The after example enables downloadable log collection on an existing Flexible Server and retains logs for 5 days. Server and external storage configuration are omitted.

Before

hcl
resource "azurerm_postgresql_configuration" "example" {
  name                = "log_retention_days"
  resource_group_name = azurerm_resource_group.example.name
  server_name         = azurerm_postgresql_server.example.name
  value               = 2
}

After

hcl
resource "azurerm_postgresql_flexible_server_configuration" "download_logs" {
  name      = "logfiles.download_enable"
  server_id = azurerm_postgresql_flexible_server.example.id
  value     = "on"
}

resource "azurerm_postgresql_flexible_server_configuration" "example" {
  name      = "logfiles.retention_days"
  server_id = azurerm_postgresql_flexible_server.example.id
  value     = "5"
}

The 5-day value meets an illustrative requirement, not a universal security threshold. Downloadable server logs are disabled by default, so verify actual collection rather than setting retention alone.

References