You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

能否通过CloudFormation为Amazon Redshift开启CloudWatch审计日志?

Redshift CloudWatch Audit Logs with CloudFormation: What You Need to Know

Great question—this is a common point of confusion since the CloudFormation docs don’t explicitly cover it. Let’s break this down clearly:

Current CloudFormation Limitation

Right now, the AWS::Redshift::Cluster resource in CloudFormation (and its LoggingProperties sub-property) doesn’t support enabling audit log delivery to CloudWatch Logs directly. As you noticed, LoggingProperties only configures sending logs to an S3 bucket—there’s no native CloudFormation parameter for CloudWatch log destinations.

So, How Do You Enable CloudWatch Audit Logs?

You’re spot-on that for now, you have to use one of these methods:

  • AWS Console: Navigate to your Redshift cluster, go to the "Logs" tab, and enable CloudWatch logging there.
  • AWS CLI: Run the aws redshift enable-logging command with the --log-destination-type cloudwatch-logs flag, plus your cluster ID and target CloudWatch log group.
  • AWS API/SDK: Call the EnableLogging API action with the same parameters as the CLI (specifying cloudwatch-logs as the destination type).

Automating This with CloudFormation (Workaround)

If you want to tie this into your CloudFormation stack automation, you can use a Lambda-backed custom resource to trigger the API call after your cluster is created. Here’s a quick breakdown of the setup:

  1. Deploy your Redshift cluster normally via CloudFormation.
  2. Add a Lambda function to your stack that uses the Redshift SDK to enable CloudWatch logging.
  3. Create a CloudFormation custom resource that runs this Lambda function once the cluster reaches the "available" state.

Here’s a simplified Python example of the Lambda function logic:

import boto3
import cfnresponse

def lambda_handler(event, context):
    try:
        redshift_client = boto3.client('redshift')
        cluster_name = event['ResourceProperties']['ClusterName']
        log_group_name = event['ResourceProperties']['LogGroupName']
        
        # Enable CloudWatch audit logs
        redshift_client.enable_logging(
            ClusterIdentifier=cluster_name,
            LogDestinationType='cloudwatch-logs',
            LogGroupName=log_group_name,
            LogExports=['connectionlog', 'useractivitylog', 'userlog']
        )
        
        cfnresponse.send(event, context, cfnresponse.SUCCESS, {}, cluster_name)
    except Exception as e:
        cfnresponse.send(event, context, cfnresponse.FAILED, {'Error': str(e)})

Important Tips for the Workaround

  • Ensure your Lambda execution role has permissions like redshift:EnableLogging, logs:CreateLogGroup, and logs:PutLogEvents (adjust based on your specific needs).
  • The LogExports parameter lets you choose which audit logs to send—pick from connectionlog, useractivitylog, or userlog (or all three).

内容的提问来源于stack exchange,提问作者CharlesMoore

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.27 21:47:34