All Products
Search
Document Center

Cloud Config:rds-instance-enabled-auditing

Last Updated:Jan 04, 2026

Checks whether the SQL explorer and audit feature is enabled. If so, the evaluation result is Compliant.

Scenarios

This rule applies when need to record the operations that are performed by executing all Data Query Language (DQL) statements, Data Manipulation Language (DML) statements, and Data Definition Language (DDL) statements. This way, you can perform security auditing and performance diagnostics on databases.

Risk level

Default risk level: medium.

When you apply this rule, you can change the risk level based on your business requirements.

Compliance evaluation logic

  • If the SQL explorer and audit feature is enabled for each ApsaraDB RDS instance, the evaluation result is Compliant.
  • If the SQL explorer and audit feature is disabled for an ApsaraDB RDS instance, the evaluation result is Incompliant.

Rule details

ItemDescription
Rule namerds-instance-enabled-auditing
Rule identifierrds-instance-enabled-auditing
TagRDS, SQLAuditing, and AuditBaseline
Automatic remediationSupported
Trigger typeConfiguration change
Supported resource typeApsaraDB RDS instance
Input parameterNone.