Review the Cloud SQL PostgreSQL server-log threshold

Retain required server messages while reducing unnecessary log volume.

Description

PostgreSQL log_min_messages sets the minimum message level included in server logs. Its default is WARNING, and a more detailed level can be justified for diagnostics. Client messages and SQL statement auditing are separate settings.

Potential impact

  • Unnecessary detail can obscure important errors and increase storage costs.
  • An overly high threshold can omit warnings or errors needed for investigations.

Remediation

  • Use WARNING as a starting point and set log_min_messages to meet operational and diagnostic needs. Review temporary detailed settings when diagnostics end.
  • Check actual log usefulness and volume, and configure required retention and access permissions.

Examples

These excerpts compare part of the instance settings. Use a supported engine version and supply omitted required settings. Changing this flag does not require the engine-version change shown here.

Before

hcl
resource "google_sql_database_instance" "example" {
  name             = "postgres-instance-with-flag"
  database_version = "POSTGRES_14"
  region           = "us-central1"

  settings {
    database_flags {
      name  = "log_min_messages"
      value = "NOTICE"
    }
  }
}

After

hcl
resource "google_sql_database_instance" "example" {
  name             = "postgres-instance-with-flag"
  database_version = "POSTGRES_15"
  region           = "us-central1"

  settings {
    database_flags {
      name  = "log_min_messages"
      value = "WARNING"
    }
  }
}

Explanation:

  • Before: Server messages are logged from NOTICE upward. This can be appropriate when more detailed diagnostics are needed.
  • After: Messages are logged from WARNING upward. Verify that required records remain available.

References