Description
log_min_duration_statement records the duration and SQL text of PostgreSQL statements that meet a duration threshold. Positive values without units are milliseconds; 0 records every statement, and -1 disables this duration-based logging.
The feature helps diagnose performance, but sensitive values in SQL can also enter logs. Disabling it does not disable every error or SQL log produced by other settings.
Potential impact
- Sensitive SQL values can become visible to people with log access.
- An overly low threshold can increase log volume and overhead, while unnecessary disabling can remove useful diagnostic evidence.
Remediation
- Choose
log_min_duration_statementto match diagnostic and audit needs. Use -1 only when this logging is unnecessary; otherwise choose a suitable threshold. - Restrict log access and retention, and check for sensitive SQL values. Verify log volume, performance impact and required diagnostic information after changes.
Examples
These examples show part of the instance settings. Choose a supported engine version and machine type, and provide omitted required configuration. The engine-version difference is not a prerequisite for changing this flag.
Before
hcl
resource "google_sql_database_instance" "db" {
name = "postgres-instance"
database_version = "POSTGRES_14"
region = "us-central1"
settings {
database_flags {
name = "log_min_duration_statement"
value = "2"
}
}
}
After
hcl
resource "google_sql_database_instance" "db" {
name = "postgres-instance"
database_version = "POSTGRES_15"
region = "us-central1"
settings {
tier = "db-f1-micro"
database_flags {
name = "log_min_duration_statement"
value = "-1"
}
}
}
Explanation:
- Before: 2 logs statements taking at least 2 milliseconds.
- After: -1 disables this duration-based statement logging. It does not disable all PostgreSQL logs.