Description
A CloudWatch Logs retention policy determines how long logs remain. A new log group without a retention policy keeps them indefinitely by default; verify the actual policy on existing groups as well.
Potential impact
Excessive retention increases storage costs, while short retention can delete logs needed for analysis or audits.
Remediation
Set retention to the required number of days and verify the deployed policy. If indefinite retention is required, document that decision explicitly.
Examples
The examples set 30-day retention on a new log group. Thirty days is illustrative and is not suitable for every service.
Before
yaml
- name: Create example log group
community.aws.cloudwatchlogs_log_group:
log_group_name: test-log-group
After
yaml
- name: Create example log group
community.aws.cloudwatchlogs_log_group:
log_group_name: test-log-group
retention: 30