Skip to content

Export Aurora Postgres Logs to CloudWatch


​​In addition to viewing and downloading database logs, you can publish logs to Amazon CloudWatch Logs to allow real-time analysis of logs data and store the data in durable storage. AWS retains log data published to CloudWatch Logs for an indefinite time period unless you specify a retention period.

For extra information about Amazon RDS Aurora logging documentation."


You should export your Amazon RDS Aurora Postgres logs to have a record of activity events. By default, Aurora PostgreSQL logging parameters capture all server errors, including the following: * Query failures * Login failures * Fatal server errors * Deadlocks

Applies To

  • Databases


This rule is applied when the following tags are present:

Tag With Value
secureclouddb/provider aws
secureclouddb/service rds
secureclouddb/resource-type cluster
secureclouddb/engine mysql

Default Rule

const { isEmptyArray } = module
const { isAwsRdsCluster } = aws

 * @param {Object} databaseSettings - database settings object
 * @returns {boolean} true if database instance is exporting the logs to Amazon Cloudwatch
function validate(databaseSettings) {
    const success = isAwsRdsCluster(databaseSettings) &&
                    !isEmptyArray(databaseSettings.awsDatabaseInstance.rdsCluster.enabledCloudwatchLogsExports) &&

    return {

// invoke