DocumentDB 로그 내보내기 설정 점검

감사와 성능 분석에 필요한 DocumentDB 로그를 생성하고 수집하세요.

설명

DocumentDB의 감사 로그와 profiler 로그는 접근 이벤트와 성능 문제를 조사하는 데 도움이 됩니다. CloudWatch 내보내기뿐 아니라 클러스터 매개변수에서 해당 로그 생성도 활성화해야 합니다.

잠재적 영향

  • 필요한 접근 이벤트나 느린 작업의 기록이 없어 이상 징후를 조사하기 어려울 수 있습니다.
  • 장애 원인과 영향 범위를 파악하는 데 시간이 더 걸릴 수 있습니다.

해결 방법

enabledCloudwatchLogsExports에 필요한 audit 또는 profiler 유형을 지정하세요. 클러스터 매개변수의 audit_logs와 profiler 설정을 목적에 맞게 구성하고 실제 수집, CloudWatch 보존 기간과 접근 권한을 확인하세요.

예시

로그 내보내기를 비교하는 발췌입니다. docdbPassword는 Pulumi 비밀 입력으로 준비하고 네트워크와 매개변수 그룹은 별도로 구성하세요. skipFinalSnapshot은 별도의 삭제·복구 설정이므로 운영 요구에 맞게 검토하세요.

변경 전

yaml
resources:
  aws:docdb/cluster:
    type: aws:docdb:Cluster
    properties:
      clusterIdentifier: my-docdb-cluster
      engine: docdb
      masterUsername: foo
      masterPassword: ${docdbPassword}
      skipFinalSnapshot: true

변경 후

yaml
resources:
  aws:docdb/cluster:
    type: aws:docdb:Cluster
    properties:
      clusterIdentifier: my-docdb-cluster
      engine: docdb
      masterUsername: foo
      masterPassword: ${docdbPassword}
      skipFinalSnapshot: true
      enabledCloudwatchLogsExports:
        - audit
        - profiler

변경 후는 audit와 profiler 로그를 CloudWatch로 내보냅니다. 내보내기 목록만으로 로그 생성이 켜지지는 않으며 기록되는 범위는 매개변수와 지원되는 이벤트에 따라 달라집니다.

참조