CloudWatch log group retention should be at least 90 days

Medium AWS General aws-logs-loggroup-cloudwatch-log-group-retention-2

Applies to

  • AWS::Logs::LogGroup

What CGPulse checks

A resource passes this rule when retentionInDays must be greater than 89. Anything else is reported as a finding with the evaluated property value attached as evidence.

How to fix it

Set data retention to at least 90 days for adequate security incident investigation. In AWS Console: CloudWatch > Log groups > set retention to 90+ days. See: https://docs.aws.amazon.com/AmazonCloudWatch/latest/logs/Working-with-log-groups-and-streams.html

Terraform

resource "aws_cloudwatch_log_group" "{name}" {
  retention_in_days = 90
}

Compliance frameworks

Is your environment compliant with this rule?

CGPulse checks it — and 621 others — against your Azure and AWS accounts with read-only access.

Run a free scan

Related AWS rules

Rejoining the server...

Rejoin failed... trying again in seconds.

Failed to rejoin.
Please retry or reload the page.

The session has been paused by the server.

Failed to resume the session.
Please reload the page.