如何通过CloudFormation在创建RDS MySQL实例时开启审计日志?
Enable RDS MySQL Audit Logs via CloudFormation During Creation
Great question! Yes, you can enable MySQL audit logs and forward them straight to CloudWatch Logs during the RDS instance creation process using CloudFormation—no need for post-launch modifications. Here's exactly how to configure it:
Key Components to Include
You'll need two core parts in your CloudFormation template:
- A custom DB parameter group with the audit log setting enabled
- The RDS instance configuration that links to this parameter group and enables CloudWatch Logs exports
Example CloudFormation Template Snippet
Resources: # Custom DB Parameter Group to enable audit logging MyAuditEnabledDBParamGroup: Type: AWS::RDS::DBParameterGroup Properties: Family: mysql8.0 # Match this to your MySQL engine version (e.g., mysql5.7 for 5.7.x) Description: Custom parameter group enabling MySQL audit logs Parameters: audit_log_enabled: 1 # Enables the audit log feature in MySQL # Optional: Add filtering parameters if needed # audit_log_include_users: 'admin' # Only log actions from specific users # audit_log_exclude_users: 'readonly' # Exclude actions from specific users # RDS Instance with audit logs forwarded to CloudWatch MyRDSMySQLInstance: Type: AWS::RDS::DBInstance Properties: DBInstanceClass: db.t3.micro Engine: mysql EngineVersion: 8.0 # Must match the parameter group's family MasterUsername: dbadmin MasterUserPassword: YourStrongPassword123 # Use AWS Secrets Manager in production! EnableCloudWatchLogsExports: - audit # Tells RDS to send audit logs to CloudWatch DBParameterGroupName: !Ref MyAuditEnabledDBParamGroup # Add other required properties like VPC security groups, storage, etc.
Critical Notes
- Engine Version Compatibility: MySQL audit logs are supported in RDS MySQL 5.6.23+, 5.7.x, and 8.0.x. Make sure your engine version falls in this range.
- Default Parameter Groups Won't Work: You can't modify parameters like
audit_log_enabledin default parameter groups—always use a custom parameter group for such configurations. - IAM Permissions: Ensure your RDS instance has the necessary permissions to send logs to CloudWatch. The default RDS service role typically includes these, but if you're using a custom IAM role, verify it allows
logs:CreateLogStreamandlogs:PutLogEventsactions on the relevant CloudWatch Log groups. - Log Group Naming: RDS will automatically create a CloudWatch Log group named
aws/rds/instance/<your-instance-name>/auditonce the instance is up.
内容的提问来源于stack exchange,提问作者Angelo
相关产品推荐
相关产品推荐

