Redshift監査ログ設定の確認

Redshiftの監査ログを適切な保存先へエクスポートしてください。

説明

Redshiftの監査ログは、接続やユーザーの活動の調査に役立ちます。外部へのログ収集を設定していないと、長期保存や集中分析に必要な記録が不足する場合があります。

想定される影響

管理操作や不審なアクセスの調査に必要な記録を、確保しにくくなるおそれがあります。

対処方法

aws_redshift_loggingで監査ログをS3またはCloudWatch Logsへ配信してください。ユーザーアクティビティログが必要な場合は、クラスターのenable_user_activity_loggingパラメーターも有効にしてください。

例

以下は、現在の独立したログ設定リソースでS3への配信を追加する例です。ノードとクラスターのタイプには、互換性のあるサポート対象の値を変数で指定してください。バケットとログ配信ポリシーは別途準備します。パスワードは説明用の例です。

変更前

hcl
resource "aws_redshift_cluster" "example" {
  cluster_identifier = "tf-redshift-cluster"
  database_name      = "mydb"
  master_username    = "foo"
  master_password    = "Mustbe8characters"
  node_type          = var.redshift_node_type
  cluster_type       = var.redshift_cluster_type
}

変更後

hcl
resource "aws_redshift_cluster" "example" {
  cluster_identifier = "tf-redshift-cluster"
  database_name      = "mydb"
  master_username    = "foo"
  master_password    = "Mustbe8characters"
  node_type          = var.redshift_node_type
  cluster_type       = var.redshift_cluster_type
}

resource "aws_redshift_logging" "example" {
  cluster_identifier   = aws_redshift_cluster.example.id
  log_destination_type = "s3"
  bucket_name          = aws_s3_bucket.logs.id
}

参考資料