Medium RedshiftServerless Regional

Redshift Serverless namespaces should export logs to CloudWatch Logs

Description

Flags Amazon Redshift Serverless namespaces that do not export user, connection, and user-activity logs to CloudWatch. Without these exports, detection of suspicious access patterns (failed logins, long-running statements) is impossible.


Remediation

Enable export of userlog, connectionlog, and useractivitylog to CloudWatch Logs.

Steps

  1. Open the Amazon Redshift Serverless console and select the namespace.
  2. Choose Edit, then under Database name and password choose Logging.
  3. Enable Audit log export for User log, Connection log, and User activity log.
  4. Save the changes.