> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-gcp-108.md).

# GCP PostgreSQL instance database flag log\_hostname is not set to off misconfiguration detected in co

## Rule Details

|                        |                                      |
| ---------------------- | ------------------------------------ |
| Cortex AppSec Rule ID  | APPSEC\_GCP\_108                     |
| Category - Subcategory | Logging - Disabled or missing        |
| Provider               | GCP                                  |
| Severity               | LOW                                  |
| Framework              | Terraform, Terraform Plan            |
| Mapped CSPM/KSPM Rule  | e4885f20-2e9d-4dab-aa72-61dff2ebda66 |

## Impact

This rule is concerned with monitoring and logging activities within Google Cloud Platform's (GCP) PostgreSQL databases. It verifies that hostnames are being logged. The absence of this feature could hinder an organization's ability to track user activities, troubleshoot issues or conduct forensic investigations in the event of a data breach or an attack. Proper logging could help in detecting foul play quicker and in responding to regulatory compliance checks or audits. Thus, it's critical to ensure hostnames are logged for GCP PostgreSQL databases for robust security control.

## How to Fix

*Resource:* google\_sql\_database\_instance

To correct this issue, you should set the flag, log\_hostname, to ON. This will ensure that all hostnames of clients attempting to connect to the database are logged.

## In this code, setting the log\_hostname flag to ON means that PostgreSQL will include the hostname of connecting clients in the logs. This is helpful for security purposes, because if there are unauthorized attempts to access the database, the log information can help identify where the attempts are coming from. \[source,go]

## resource "google\_sql\_database\_instance" "database\_instance" { database\_version = "POSTGRES\_13" settings { database\_flags { name = "log\_hostname" value = "on" } } }


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-gcp-108.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
