CloudWatch log group must have a retention period configured
Medium
AWS
General
aws-logs-loggroup-cloudwatch-log-group-retention
Applies to
AWS::Logs::LogGroup
What CGPulse checks
A resource passes this rule when retentionInDays must be set true. Anything else is reported as a finding with the evaluated property value attached as evidence.
How to fix it
Set log group retention to at least 365 days to preserve audit logs and control costs. In AWS Console: CloudWatch > Log groups > select group > Edit retention > set to 365 days. See: https://docs.aws.amazon.com/AmazonCloudWatch/latest/logs/Working-with-log-groups-and-streams.html
Terraform
resource "aws_cloudwatch_log_group" "{name}" {
retention_in_days = 365
}
Compliance frameworks
Is your environment compliant with this rule?
CGPulse checks it — and 621 others — against your Azure and AWS accounts with read-only access.
Related AWS rules
- ACM certificate must be eligible for renewal
- ACM certificate must be in issued status
- Amplify app should have basic auth disabled for production
- API Gateway REST API must have an endpoint configuration
- API Gateway V2 API must be properly configured
- App Runner service must have encryption enabled
- AppSync API must have logging configured
- AppSync API must have X-Ray tracing enabled