能否通过CloudFormation为Amazon Redshift开启CloudWatch审计日志?
Great question—this is a common point of confusion since the CloudFormation docs don’t explicitly cover it. Let’s break this down clearly:
Current CloudFormation Limitation
Right now, the AWS::Redshift::Cluster resource in CloudFormation (and its LoggingProperties sub-property) doesn’t support enabling audit log delivery to CloudWatch Logs directly. As you noticed, LoggingProperties only configures sending logs to an S3 bucket—there’s no native CloudFormation parameter for CloudWatch log destinations.
So, How Do You Enable CloudWatch Audit Logs?
You’re spot-on that for now, you have to use one of these methods:
- AWS Console: Navigate to your Redshift cluster, go to the "Logs" tab, and enable CloudWatch logging there.
- AWS CLI: Run the
aws redshift enable-loggingcommand with the--log-destination-type cloudwatch-logsflag, plus your cluster ID and target CloudWatch log group. - AWS API/SDK: Call the
EnableLoggingAPI action with the same parameters as the CLI (specifyingcloudwatch-logsas the destination type).
Automating This with CloudFormation (Workaround)
If you want to tie this into your CloudFormation stack automation, you can use a Lambda-backed custom resource to trigger the API call after your cluster is created. Here’s a quick breakdown of the setup:
- Deploy your Redshift cluster normally via CloudFormation.
- Add a Lambda function to your stack that uses the Redshift SDK to enable CloudWatch logging.
- Create a CloudFormation custom resource that runs this Lambda function once the cluster reaches the "available" state.
Here’s a simplified Python example of the Lambda function logic:
import boto3 import cfnresponse def lambda_handler(event, context): try: redshift_client = boto3.client('redshift') cluster_name = event['ResourceProperties']['ClusterName'] log_group_name = event['ResourceProperties']['LogGroupName'] # Enable CloudWatch audit logs redshift_client.enable_logging( ClusterIdentifier=cluster_name, LogDestinationType='cloudwatch-logs', LogGroupName=log_group_name, LogExports=['connectionlog', 'useractivitylog', 'userlog'] ) cfnresponse.send(event, context, cfnresponse.SUCCESS, {}, cluster_name) except Exception as e: cfnresponse.send(event, context, cfnresponse.FAILED, {'Error': str(e)})
Important Tips for the Workaround
- Ensure your Lambda execution role has permissions like
redshift:EnableLogging,logs:CreateLogGroup, andlogs:PutLogEvents(adjust based on your specific needs). - The
LogExportsparameter lets you choose which audit logs to send—pick fromconnectionlog,useractivitylog, oruserlog(or all three).
内容的提问来源于stack exchange,提问作者CharlesMoore

