You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过CloudFormation在创建RDS MySQL实例时开启审计日志?

Enable RDS MySQL Audit Logs via CloudFormation During Creation

Great question! Yes, you can enable MySQL audit logs and forward them straight to CloudWatch Logs during the RDS instance creation process using CloudFormation—no need for post-launch modifications. Here's exactly how to configure it:

Key Components to Include

You'll need two core parts in your CloudFormation template:

  1. A custom DB parameter group with the audit log setting enabled
  2. The RDS instance configuration that links to this parameter group and enables CloudWatch Logs exports

Example CloudFormation Template Snippet

Resources:
  # Custom DB Parameter Group to enable audit logging
  MyAuditEnabledDBParamGroup:
    Type: AWS::RDS::DBParameterGroup
    Properties:
      Family: mysql8.0  # Match this to your MySQL engine version (e.g., mysql5.7 for 5.7.x)
      Description: Custom parameter group enabling MySQL audit logs
      Parameters:
        audit_log_enabled: 1  # Enables the audit log feature in MySQL
        # Optional: Add filtering parameters if needed
        # audit_log_include_users: 'admin'  # Only log actions from specific users
        # audit_log_exclude_users: 'readonly'  # Exclude actions from specific users

  # RDS Instance with audit logs forwarded to CloudWatch
  MyRDSMySQLInstance:
    Type: AWS::RDS::DBInstance
    Properties:
      DBInstanceClass: db.t3.micro
      Engine: mysql
      EngineVersion: 8.0  # Must match the parameter group's family
      MasterUsername: dbadmin
      MasterUserPassword: YourStrongPassword123  # Use AWS Secrets Manager in production!
      EnableCloudWatchLogsExports:
        - audit  # Tells RDS to send audit logs to CloudWatch
      DBParameterGroupName: !Ref MyAuditEnabledDBParamGroup
      # Add other required properties like VPC security groups, storage, etc.

Critical Notes

  • Engine Version Compatibility: MySQL audit logs are supported in RDS MySQL 5.6.23+, 5.7.x, and 8.0.x. Make sure your engine version falls in this range.
  • Default Parameter Groups Won't Work: You can't modify parameters like audit_log_enabled in default parameter groups—always use a custom parameter group for such configurations.
  • IAM Permissions: Ensure your RDS instance has the necessary permissions to send logs to CloudWatch. The default RDS service role typically includes these, but if you're using a custom IAM role, verify it allows logs:CreateLogStream and logs:PutLogEvents actions on the relevant CloudWatch Log groups.
  • Log Group Naming: RDS will automatically create a CloudWatch Log group named aws/rds/instance/<your-instance-name>/audit once the instance is up.

内容的提问来源于stack exchange,提问作者Angelo

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.19 09:33:54