5.7 Ensure server parameter 'error_server_log_file' is Enabled for MySQL Database Server (Manual)
Profile Applicability
- Level 2
Description
Enable error logs on MySQL flexible servers.
Rationale
With error_server_log_file enabled, MySQL Database will log database errors to a logging solution. These logs assist in producing a forensic trail that can be used for investigation or for detection when paired with a SIEM.
Impact
There are further costs incurred for storage of logs. For high traffic databases these logs will be significant. Determine your organization's needs before enabling.
Audit
Audit from Azure Portal
- Login to Azure Portal using https://portal.azure.com.
- Go to
Azure Database for MySQL Servers. - For each database, under
Settings, clickServer parameters. - In the row under
Save, selectAll. - In the filter bar, type
error_server_log_file. - Ensure that the
VALUEforerror_server_log_fileisON.
Audit from PowerShell
Ensure the below command returns a Value of on:
Get-AzMySqlFlexibleServerConfiguration -ResourceGroupName <resourceGroup> -ServerName <serverName> -Name error_server_log_file
Expected Result
The error_server_log_file server parameter should return a value of ON.
Remediation
Remediate from Azure Portal
Part 1 - Turn on audit logs
- Login to Azure Portal using https://portal.azure.com.
- Go to
Azure Database for MySQL flexible servers. - For each database, under
Settings, clickServer parameters. - Set
error_server_log_filetoON. - Click
Save.
Part 2 - Capture audit logs (diagnostic settings is for example only, send these logs to the appropriate data sink for your logging needs)
- Under Monitoring, select
Diagnostic settings. - Select
+ Add diagnostic setting. - Provide a diagnostic setting name.
- Under Categories, select
MySQL Audit Logs. - Specify destination details.
- Click
Save.
It may take up to 10 minutes for the logs to appear in the configured destination.
Remediate from PowerShell
Use the below command to enable error_server_log_file:
Update-AzMySqlFlexibleServerConfiguration -ResourceGroupName <resourceGroup> -ServerName <serverName> -Name error_server_log_file -Value on
Default Value
error_server_log_file is set to OFF by default.
References
- https://learn.microsoft.com/en-us/azure/mysql/flexible-server/tutorial-configure-audit
- https://learn.microsoft.com/en-us/security/benchmark/azure/mcsb-logging-threat-detection#lt-3-enable-logging-for-security-investigation
- https://learn.microsoft.com/en-us/azure/mysql/flexible-server/concepts-error-logs
CIS Controls
| Controls Version | Control | IG 1 | IG 2 | IG 3 |
|---|---|---|---|---|
| v8 | 8.2 Collect Audit Logs | X | X | X |
| v7 | 6.2 Activate audit logging | X | X | X |