説明
Redshiftの監査ログは、接続やユーザーの活動の調査に役立ちます。外部へのログ収集を設定していないと、長期保存や集中分析に必要な記録が不足する場合があります。
想定される影響
管理操作や不審なアクセスの調査に必要な記録を、確保しにくくなるおそれがあります。
対処方法
aws_redshift_loggingで監査ログをS3またはCloudWatch Logsへ配信してください。ユーザーアクティビティログが必要な場合は、クラスターのenable_user_activity_loggingパラメーターも有効にしてください。
例
以下は、現在の独立したログ設定リソースでS3への配信を追加する例です。ノードとクラスターのタイプには、互換性のあるサポート対象の値を変数で指定してください。バケットとログ配信ポリシーは別途準備します。パスワードは説明用の例です。
変更前
hcl
resource "aws_redshift_cluster" "example" {
cluster_identifier = "tf-redshift-cluster"
database_name = "mydb"
master_username = "foo"
master_password = "Mustbe8characters"
node_type = var.redshift_node_type
cluster_type = var.redshift_cluster_type
}
変更後
hcl
resource "aws_redshift_cluster" "example" {
cluster_identifier = "tf-redshift-cluster"
database_name = "mydb"
master_username = "foo"
master_password = "Mustbe8characters"
node_type = var.redshift_node_type
cluster_type = var.redshift_cluster_type
}
resource "aws_redshift_logging" "example" {
cluster_identifier = aws_redshift_cluster.example.id
log_destination_type = "s3"
bucket_name = aws_s3_bucket.logs.id
}