{"Entry":{"collection":"guc","key":"log_connections","name":"log_connections","aliases":[],"metadata":{"baseline":true,"boot_human":"Not specified","boot_val":null,"category":"Reporting and Logging / What to Log","category_zh":"","changed_in":["9.5","18"],"changes":[{"documentation_changed":true,"fields":{},"from":"7.4","status":"changed","to":"8.0"},{"documentation_changed":true,"fields":{},"from":"8.0","status":"changed","to":"8.1"},{"documentation_changed":true,"fields":{},"from":"8.1","status":"changed","to":"8.2"},{"documentation_changed":true,"fields":{},"from":"8.2","status":"changed","to":"8.3"},{"documentation_changed":true,"fields":{},"from":"9.0","status":"changed","to":"9.1"},{"documentation_changed":true,"fields":{"context":{"from":"backend","to":"superuser-backend"}},"from":"9.4","status":"changed","to":"9.5"},{"documentation_changed":true,"fields":{},"from":"9.6","status":"changed","to":"10"},{"documentation_changed":true,"fields":{},"from":"13","status":"changed","to":"14"},{"documentation_changed":true,"fields":{},"from":"14","status":"changed","to":"15"},{"documentation_changed":true,"fields":{"boot_val":{"from":"off","to":""},"short_desc":{"from":"Logs each successful connection.","to":"Logs specified aspects of connection establishment and setup."},"vartype":{"from":"bool","to":"string"}},"from":"17","status":"changed","to":"18"}],"content_hash":"a5c3e1d204e28bc06b92464640122713d696031629a0c6547956d3c302347335","context":"","default_changed_in":["18"],"default_history":[{"from":"9.0","to":"17","value":"off"},{"from":"18","to":"19","value":"Empty string"}],"editorial":{"advice":{"olap":"Analytical sessions are fewer but longer, so authorization plus setup_durations can be useful for attributing expensive connection setup; do not use all merely because query volume is lower.","oltp":"For routine OLTP, log only the stages required by an audit or latency question; authorization is a lower-volume successful-connection trail, while receipt and authentication add pre-authorization evidence. Add setup_durations only when connection startup latency is being investigated.","small":"Keep the list minimal and retain failed-authentication monitoring, which is independent of this setting. Verify that log storage and redaction can safely retain original identities and application names."},"mechanism":["In PostgreSQL 10–17, log_connections is a Boolean that logs successful connections when enabled. PostgreSQL 18 changed it to a string list whose exact options are receipt, authentication, authorization, setup_durations, and all; the empty string disables connection logging. For compatibility, on, true, yes, and 1 mean receipt,authentication,authorization, while off, false, no, and 0 mean the empty list. Failed authentication is logged regardless of this setting.","log_connections has SUPERUSER_BACKEND context: it may be selected by a superuser or a role with the appropriate SET privilege at session start, but it cannot be changed after the backend session has started. A configuration change therefore affects new sessions only.","receipt records arrival, authentication records the original identity presented by the authentication method, authorization records successful authorization with user/database/application context, and setup_durations records total setup, backend-fork, and authentication timing. log_disconnections controls session-end records separately; connection identities and topology remain sensitive log data."],"pitfalls":["Using setup instead of the valid PostgreSQL 18 option setup_durations.","Assuming the compatibility value on means all; it omits setup_durations and maps only to receipt, authentication, and authorization.","Expecting existing sessions to inherit a changed value even though the setting is fixed at backend startup.","Treating duplicate receipt records as attacks without accounting for clients such as psql that can probe twice, or retaining original identities without an access-control policy."],"references":[{"title":"PostgreSQL 19 Beta 4: log_connections","url":"https://www.postgresql.org/docs/19/runtime-config-logging.html#GUC-LOG-CONNECTIONS"},{"title":"PostgreSQL 19 release notes","url":"https://www.postgresql.org/docs/19/release-19.html"}],"related":["log_statement","log_duration","log_disconnections","log_parameter_max_length","log_parameter_max_length_on_error"],"summary":"log_connections is the PostgreSQL setting that controls whether PostgreSQL logs specified aspects of connection establishment and setup."},"enumvals":[],"first_version":"7.4","group":"Reporting and Logging","group_slug":"logging","imported_at":"2026-09-30T00:40:57.288803+08:00","intro_commit":{},"key":"log_connections","last_version":"20","max_val":"","min_val":"","name":"log_connections","position":220,"present_in":["7.4","8.0","8.1","8.2","8.3","8.4","9.0","9.1","9.2","9.3","9.4","9.5","9.6","10","11","12","13","14","15","16","17","18","19","20"],"short_desc":"Causes aspects of each connection to the server to be logged.","short_desc_zh":"","source_rev":"english-manuals:d1aa1205ab03836060f589eb1cc56b51412a4c5aa3f8d189883e627ac43730a8","unit":"","vartype":"string"}},"Definition":{"Collection":"guc","Key":"log_connections","SourceDatabase":"center","Version":"18","SourceTable":"guc","SourceKey":"log_connections","SourceRevision":"english-manuals:d1aa1205ab03836060f589eb1cc56b51412a4c5aa3f8d189883e627ac43730a8","Facts":{"boot_val":"","category":"Reporting and Logging / What to Log","context":"superuser-backend","description":"Causes aspects of each connection to the server to be logged. The default is the empty string, '', which disables all connection logging. The following options may be specified alone or in a comma-separated list: Table 19.3. Log Connection Options Name Description receipt Logs receipt of a connection. authentication Logs the original identity used by an authentication method to identify a user. In most cases, the identity string matches the PostgreSQL username, but some third-party authentication methods may alter the original user identifier before the server stores it. Failed authentication is always logged regardless of the value of this setting. authorization Logs successful completion of authorization. At this point the connection has been established but the backend is not yet fully set up. The log message includes the authorized username as well as the database name and application name, if applicable. setup_durations Logs the time spent establishing the connection and setting up the backend until the connection is ready to execute its first query. The log message includes three durations: the total setup duration (starting from the postmaster accepting the incoming connection and ending when the connection is ready for query), the time it took to fork the new backend, and the time it took to authenticate the user. all A convenience alias equivalent to specifying all options. If all is specified in a list of other options, all connection aspects will be logged. Disconnection logging is separately controlled by log_disconnections. For the purposes of backwards compatibility, on, off, true, false, yes, no, 1, and 0 are still supported. The positive values are equivalent to specifying the receipt, authentication, and authorization options. Only superusers and users with the appropriate SET privilege can change this parameter at session start, and it cannot be changed at all within a session. Note Some client programs, like psql, attempt to connect twice while determining if a password is required, so duplicate “connection received” messages do not necessarily indicate a problem.","doc":{"anchor":"GUC-LOG-CONNECTIONS","file":"runtime-config-logging.html","lang":"en","sha256":"93c48c522a72fca19705c4c91a71e951eae653662008eee2e4a9a74a11127fde","slug":"18"},"documented":true,"enumvals":null,"extra_desc":null,"lang":"en","max_val":null,"metadata_version":"18","min_val":null,"name":"log_connections","short_desc":"Logs specified aspects of connection establishment and setup.","source":"pg-settings-source-snapshot","unit":null,"vartype":"string"},"ManualEvidence":{"doc":{"anchor":"GUC-LOG-CONNECTIONS","file":"runtime-config-logging.html","lang":"en","sha256":"93c48c522a72fca19705c4c91a71e951eae653662008eee2e4a9a74a11127fde","slug":"18"}},"MeasuredEvidence":{"metadata_version":"18"}},"Text":{"Collection":"guc","Key":"log_connections","SourceDatabase":"pgweb","Version":"18","Locale":"zh-Hans","Title":"log_connections","Summary":"","BodyHTML":"\u003cp\u003e控制是否记录到服务器的每次连接的相关信息。默认值为空字符串 \u003ccode\u003e\u0026#39;\u0026#39;\u003c/code\u003e，表示禁用所有连接日志。下列选项既可以单独指定，也可以用逗号分隔的列表指定：\u003c/p\u003e\u003cdiv\u003e\u003cp\u003e\u003cstrong\u003e表 19.3. 连接日志选项\u003c/strong\u003e\u003c/p\u003e\u003cdiv\u003e\u003ctable\u003e\u003cthead\u003e\u003ctr\u003e\u003cth\u003e名字\u003c/th\u003e\u003cth\u003e描述\u003c/th\u003e\u003c/tr\u003e\u003c/thead\u003e\u003ctbody\u003e\u003ctr\u003e\u003ctd\u003e\u003ccode\u003ereceipt\u003c/code\u003e\u003c/td\u003e\u003ctd\u003e记录收到连接。\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003e\u003ccode\u003eauthentication\u003c/code\u003e\u003c/td\u003e\u003ctd\u003e记录认证方法用于识别用户的原始身份。在大多数情况下，该身份字符串与\u003cspan\u003ePostgreSQL\u003c/span\u003e用户名一致，但某些第三方认证方法可能会在服务器存储之前修改原始用户标识符。无论此设置为何值，认证失败始终都会被记录。\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003e\u003ccode\u003eauthorization\u003c/code\u003e\u003c/td\u003e\u003ctd\u003e记录授权成功完成。此时连接已经建立，但后端尚未完全初始化。日志消息会包含授权后的用户名，以及数据库名和应用名（如果适用）。\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003e\u003ccode\u003esetup_durations\u003c/code\u003e\u003c/td\u003e\u003ctd\u003e记录从 postmaster 接受传入连接开始，到连接准备好执行第一条查询为止，建立连接并完成后端初始化所花费的时间。日志消息会包含三个时长：总设置时长、fork 新后端所花费的时间，以及用户认证所花费的时间。\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003e\u003ccode\u003eall\u003c/code\u003e\u003c/td\u003e\u003ctd\u003e一个便捷别名，相当于指定所有选项。如果在其他选项列表中包含\u003ccode\u003eall\u003c/code\u003e，则会记录连接的所有方面。\u003c/td\u003e\u003c/tr\u003e\u003c/tbody\u003e\u003c/table\u003e\u003c/div\u003e\u003c/div\u003e\u003cbr\u003e\u003cp\u003e断开连接的日志由\u003ca href=\"/docs/18/runtime-config-logging.html#GUC-LOG-DISCONNECTIONS\" rel=\"nofollow\"\u003elog_disconnections\u003c/a\u003e单独控制。\u003c/p\u003e\u003cp\u003e出于向后兼容性考虑，\u003ccode\u003eon\u003c/code\u003e、\u003ccode\u003eoff\u003c/code\u003e、\u003ccode\u003etrue\u003c/code\u003e、\u003ccode\u003efalse\u003c/code\u003e、\u003ccode\u003eyes\u003c/code\u003e、\u003ccode\u003eno\u003c/code\u003e、\u003ccode\u003e1\u003c/code\u003e和\u003ccode\u003e0\u003c/code\u003e仍然受支持。表示启用的值等价于指定\u003ccode\u003ereceipt\u003c/code\u003e、\u003ccode\u003eauthentication\u003c/code\u003e和 \u003ccode\u003eauthorization\u003c/code\u003e选项。\u003c/p\u003e\u003cp\u003e只有超级用户和具有适当\u003ccode\u003eSET\u003c/code\u003e权限的用户可以在会话开始时更改此参数，并且在会话内部完全不能更改。\u003c/p\u003e\u003cdiv\u003e\n注意\u003cp\u003e某些客户端程序（例如\u003cspan\u003epsql\u003c/span\u003e）在判断是否需要密码时会尝试连接两次，因此重复的\u003cspan\u003e“\u003cspan\u003e收到连接\u003c/span\u003e”\u003c/span\u003e消息并不一定表示一个错误。\u003c/p\u003e\u003c/div\u003e","SourceRevision":"2026-09-11@29c86d9","ContentHash":"9f4f2f9944e8ddf685380156fc046e9265218e743a598977549cd47fdb63f2e4","Payload":{"carried_from":"","carry_reason":"","doc_html":"\u003cp\u003e控制是否记录到服务器的每次连接的相关信息。默认值为空字符串 \u003ccode class=\"literal\"\u003e''\u003c/code\u003e，表示禁用所有连接日志。下列选项既可以单独指定，也可以用逗号分隔的列表指定：\u003c/p\u003e\u003cdiv class=\"table\"\u003e\u003cp class=\"title\"\u003e\u003cstrong\u003e表 19.3. 连接日志选项\u003c/strong\u003e\u003c/p\u003e\u003cdiv class=\"table-contents\"\u003e\u003ctable class=\"table\"\u003e\u003cthead\u003e\u003ctr\u003e\u003cth\u003e名字\u003c/th\u003e\u003cth\u003e描述\u003c/th\u003e\u003c/tr\u003e\u003c/thead\u003e\u003ctbody\u003e\u003ctr\u003e\u003ctd\u003e\u003ccode class=\"literal\"\u003ereceipt\u003c/code\u003e\u003c/td\u003e\u003ctd\u003e记录收到连接。\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003e\u003ccode class=\"literal\"\u003eauthentication\u003c/code\u003e\u003c/td\u003e\u003ctd\u003e记录认证方法用于识别用户的原始身份。在大多数情况下，该身份字符串与\u003cspan class=\"productname\"\u003ePostgreSQL\u003c/span\u003e用户名一致，但某些第三方认证方法可能会在服务器存储之前修改原始用户标识符。无论此设置为何值，认证失败始终都会被记录。\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003e\u003ccode class=\"literal\"\u003eauthorization\u003c/code\u003e\u003c/td\u003e\u003ctd\u003e记录授权成功完成。此时连接已经建立，但后端尚未完全初始化。日志消息会包含授权后的用户名，以及数据库名和应用名（如果适用）。\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003e\u003ccode class=\"literal\"\u003esetup_durations\u003c/code\u003e\u003c/td\u003e\u003ctd\u003e记录从 postmaster 接受传入连接开始，到连接准备好执行第一条查询为止，建立连接并完成后端初始化所花费的时间。日志消息会包含三个时长：总设置时长、fork 新后端所花费的时间，以及用户认证所花费的时间。\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003e\u003ccode class=\"literal\"\u003eall\u003c/code\u003e\u003c/td\u003e\u003ctd\u003e一个便捷别名，相当于指定所有选项。如果在其他选项列表中包含\u003ccode class=\"literal\"\u003eall\u003c/code\u003e，则会记录连接的所有方面。\u003c/td\u003e\u003c/tr\u003e\u003c/tbody\u003e\u003c/table\u003e\u003c/div\u003e\u003c/div\u003e\u003cbr\u003e\u003cp\u003e断开连接的日志由\u003ca href=\"/docs/18/runtime-config-logging.html#GUC-LOG-DISCONNECTIONS\"\u003elog_disconnections\u003c/a\u003e单独控制。\u003c/p\u003e\u003cp\u003e出于向后兼容性考虑，\u003ccode class=\"literal\"\u003eon\u003c/code\u003e、\u003ccode class=\"literal\"\u003eoff\u003c/code\u003e、\u003ccode class=\"literal\"\u003etrue\u003c/code\u003e、\u003ccode class=\"literal\"\u003efalse\u003c/code\u003e、\u003ccode class=\"literal\"\u003eyes\u003c/code\u003e、\u003ccode class=\"literal\"\u003eno\u003c/code\u003e、\u003ccode class=\"literal\"\u003e1\u003c/code\u003e和\u003ccode class=\"literal\"\u003e0\u003c/code\u003e仍然受支持。表示启用的值等价于指定\u003ccode class=\"literal\"\u003ereceipt\u003c/code\u003e、\u003ccode class=\"literal\"\u003eauthentication\u003c/code\u003e和 \u003ccode class=\"literal\"\u003eauthorization\u003c/code\u003e选项。\u003c/p\u003e\u003cp\u003e只有超级用户和具有适当\u003ccode class=\"literal\"\u003eSET\u003c/code\u003e权限的用户可以在会话开始时更改此参数，并且在会话内部完全不能更改。\u003c/p\u003e\u003cdiv class=\"note\"\u003e\n注意\u003cp\u003e某些客户端程序（例如\u003cspan class=\"application\"\u003epsql\u003c/span\u003e）在判断是否需要密码时会尝试连接两次，因此重复的\u003cspan class=\"quote\"\u003e“\u003cspan class=\"quote\"\u003e收到连接\u003c/span\u003e”\u003c/span\u003e消息并不一定表示一个错误。\u003c/p\u003e\u003c/div\u003e","doc_same_as":""}},"RequestedLocale":"zh-Hans","Fallback":false,"Versions":["10","11","12","13","14","15","16","17","18","19","20","7.4","8.0","8.1","8.2","8.3","8.4","9.0","9.1","9.2","9.3","9.4","9.5","9.6"],"Locales":["en","zh-Hans"],"Signatures":null,"Spellings":null,"SQLState":null,"Evidence":null}
