설명
Neptune 감사 로그는 데이터베이스 요청을 조사하는 데 도움이 됩니다. CloudWatch 내보내기와 함께 클러스터의 감사 로그 생성도 활성화해야 합니다.
잠재적 영향
필요한 감사 기록이 없으면 비정상 접근과 데이터베이스 활동을 조사하기 어려워집니다.
해결 방법
enable_cloudwatch_logs_exports에 audit를 포함하고 클러스터 파라미터 그룹에서 neptune_enable_audit_log를 1로 설정하세요. 설정 적용 후 CloudWatch에서 로그 수집을 확인하세요.
예시
예시는 로그 내보내기 설정을 보여 줍니다. 감사 로그 생성 파라미터는 별도로 적용해야 합니다.
변경 전
hcl
resource "aws_neptune_cluster" "example" {
cluster_identifier = "neptune-cluster"
engine = "neptune"
backup_retention_period = 5
preferred_backup_window = "10:10-11:11"
skip_final_snapshot = true
iam_database_authentication_enabled = true
apply_immediately = true
}
변경 후
hcl
resource "aws_neptune_cluster" "example" {
cluster_identifier = "neptune-cluster1"
engine = "neptune"
backup_retention_period = 5
preferred_backup_window = "10:10-11:11"
skip_final_snapshot = true
iam_database_authentication_enabled = true
apply_immediately = true
enable_cloudwatch_logs_exports = ["audit"]
}