Evaluates whether the log_connections parameter is set to on for each ApsaraDB RDS for PostgreSQL database. If so, the result is Compliant.
Scenarios
Use this rule to record server connection information for issue troubleshooting and security auditing.
Risk level
Default risk level: low.
You can change the risk level based on your business requirements.
Compliance evaluation logic
- If the log_connections parameter of each ApsaraDB RDS for PostgreSQL database is set to on, the evaluation result is Compliant.
- If the log_connections parameter of an ApsaraDB RDS for PostgreSQL database is set to off, the evaluation result is Incompliant.
For more information about how to remediate an incompliant configuration, see Incompliance remediation.
Rule details
| Item | Description |
| Rule name | rds-postgresql-parameter-log-connections |
| Rule identifier | rds-postgresql-parameter-log-connections |
| Tag | RDS and PostgreSQL |
| Automatic remediation | Not supported |
| Trigger type | Configuration change |
| Supported resource type | ApsaraDB RDS instance |
| Input parameter | None. |
Incompliance remediation
Modify the parameter settings of your ApsaraDB RDS for PostgreSQL database. For more information, see Modify instance parameters.