Review CloudWatch Logs retention

Keep logs for the period required by the workload.

Description

A CloudWatch Logs retention policy determines how long logs remain. A new log group without a retention policy keeps them indefinitely by default; verify the actual policy on existing groups as well.

Potential impact

Excessive retention increases storage costs, while short retention can delete logs needed for analysis or audits.

Remediation

Set retention to the required number of days and verify the deployed policy. If indefinite retention is required, document that decision explicitly.

Examples

The examples set 30-day retention on a new log group. Thirty days is illustrative and is not suitable for every service.

Before

yaml
- name: Create example log group
  community.aws.cloudwatchlogs_log_group:
    log_group_name: test-log-group

After

yaml
- name: Create example log group
  community.aws.cloudwatchlogs_log_group:
    log_group_name: test-log-group
    retention: 30

References