The log desensitization delivery feature of DAS lets you deliver SQL audit logs from your database instances to a specified Log Service Logstore in real time after automatic desensitization. This feature automatically identifies and replaces sensitive data values in SQL statements (for example, values in WHERE clauses and data values in INSERT statements) with placeholders. This helps you meet security, compliance, and audit requirements while preventing core business data leakage.
Notes
-
Supported database types:
-
RDS MySQL
-
PolarDB for MySQL
-
-
Supported regions: Singapore, China (Hong Kong)
-
Version requirements: The log desensitization delivery feature is available only for instances that have DAS V3 audit logs enabled. This feature is not supported for earlier V0 to V2 versions.
-
Billing: This is a paid feature. Enabling this feature incurs charges for the DAS Enterprise Edition and for Log Service storage and usage. For more information, see DAS Billing.
Enable delivery
This section describes how to enable log desensitization delivery for an instance.
-
Go to the delivery page:
-
Log on to the DAS console.
-
In the left navigation pane, click .
-
Find the target instance and click the instance ID to open the instance details page.
-
In the left navigation pane of the instance, click .
-
At the top of the page, click the Deliver tab.
-
-
Enable the delivery feature:
-
On the Audit Log and Insights Delivery page, click Enable Now.
-
In the Activate Audit Logs dialog box, select Redacted Log Delivery, and then click Submit.
-
After the feature is enabled, the system automatically creates and configures the required resources. The page then displays information about the destination Logstore.
The Audit Log Shipment status is displayed as Enabled. The table contains information such as Delivery Target, Storage Duration at Destination, Data Desensitization, Delivery Trend, Running Status, and Delivery Time. The Insight Shipment section below is disabled by default.
-
-
Access and manage delivered logs: On the Deliver tab, you can click the link under Destination to access the corresponding Log Service Logstore.
Disable delivery
If you no longer need this feature, you can disable it at any time.
-
Log on to the DAS console.
-
In the left navigation pane, click .
-
Find the target instance and click the instance ID to open the instance details page.
-
In the left navigation pane of the instance, click .
-
At the top of the page, click the Deliver tab.
-
In the Audit Log and Insights Delivery section, click Disable Feature.
-
In the Activate Audit Logs dialog box, clear the Redacted Log Delivery checkbox, and then click Submit.
-
After the feature is disabled, DAS stops delivering new desensitized logs to Log Service.
Batch delivery
-
Log on to the DAS console.
-
In the left navigation pane, click .
-
Select the target instances, and in the lower-left corner, click .
-
In the Activate Audit Logs dialog box, select Redacted Log Delivery, and then click Submit.