Retention not configured for failed asynchronous Lambda events

Provide a path to investigate and retry failed asynchronous events.

Description

Lambda can send asynchronous events that exhaust retries or event-age limits to a separate target. Without a dead-letter queue or failure destination, those events may not be retained.

Potential impact

Losing the failed input can make investigation and reprocessing harder.

Remediation

Set DeadLetterConfig.TargetArn to a standard SQS queue or SNS topic, or configure an asynchronous failure destination. Check delivery permissions and retention and replay procedures. For an SQS event source, configure the source queue’s DLQ.

Examples

The examples add a DLQ for asynchronous invocations. Set LambdaRuntime to a supported runtime compatible with the function ZIP, and provide the target queue and execution-role permissions separately.

Before

yaml
AWSTemplateFormatVersion: '2010-09-09'
Description: VPC function.
Resources:
  Function:
    Type: AWS::Lambda::Function
    Properties:
      Handler: index.handler
      Role: arn:aws:iam::123456789012:role/lambda-role
      Code:
        S3Bucket: my-bucket
        S3Key: function.zip
      Runtime: !Ref LambdaRuntime
      Timeout: 5
      TracingConfig:
        Mode: Active
      VpcConfig:
        SecurityGroupIds:
          - sg-085912345678492fb
        SubnetIds:
          - subnet-071f712345678e7c8
          - subnet-07fd123456788a036
      Tags:
        - Key: Description
          Value: VPC Function
        - Key: Type
          Value: AWS Lambda Function

After

yaml
AWSTemplateFormatVersion: '2010-09-09'
Description: VPC function.
Resources:
  Function3:
    Type: AWS::Lambda::Function
    Properties:
      Handler: index.handler
      Role: arn:aws:iam::123456789012:role/lambda-role
      Code:
        S3Bucket: my-bucket
        S3Key: function.zip
      Runtime: !Ref LambdaRuntime
      Timeout: 5
      TracingConfig:
        Mode: Active
      VpcConfig:
        SecurityGroupIds:
          - sg-085912345678492fb
        SubnetIds:
          - subnet-071f712345678e7c8
          - subnet-07fd123456788a036
      Tags:
        - Key: Description
          Value: VPC Function
        - Key: Type
          Value: AWS Lambda Function
      DeadLetterConfig:
        TargetArn: arn:aws:sqs:us-east-1:123456789012:aaa

References