Medium
RedshiftServerless
Regional
Redshift Serverless namespaces should export logs to CloudWatch Logs
Description
Flags Amazon Redshift Serverless namespaces that do not export user, connection, and user-activity logs to CloudWatch. Without these exports, detection of suspicious access patterns (failed logins, long-running statements) is impossible.
Remediation
Enable export of userlog, connectionlog, and useractivitylog to CloudWatch Logs.
Steps
- Open the Amazon Redshift Serverless console and select the namespace.
- Choose Edit, then under Database name and password choose Logging.
- Enable Audit log export for User log, Connection log, and User activity log.
- Save the changes.