Description
PostgreSQL log_connections records connection attempts and successful authentication and authorization. Missing required connection history can make suspicious access or operational failures harder to investigate.
This differs from SQL statement auditing, and off does not mean every authentication failure or error log disappears.
Potential impact
- Evidence of connection identities and timing may be insufficient.
- Investigating access failures or unusual activity can take longer.
Remediation
- Enable required connection records using the
log_connectionsformat supported by your PostgreSQL version. The PostgreSQL 15 examples use on. - Verify log receipt and configure appropriate retention and access permissions. Review volume and sensitive content, and configure SQL auditing separately if needed.
Examples
These examples show part of the instance settings. Choose a supported engine version and machine type, and provide omitted required configuration.
Before
hcl
resource "google_sql_database_instance" "db" {
name = "postgres-instance"
database_version = "POSTGRES_15"
region = "us-central1"
settings {
database_flags {
name = "log_connections"
value = "off"
}
}
}
After
hcl
resource "google_sql_database_instance" "db" {
name = "postgres-instance"
database_version = "POSTGRES_15"
region = "us-central1"
settings {
tier = "db-f1-micro"
database_flags {
name = "log_connections"
value = "on"
}
}
}
Explanation:
- Before: Connection logging is disabled. This does not disable every other error log.
- After: PostgreSQL 15 connection logging is enabled. Verify actual delivery and usability.