Review CloudWatch log retention

Choose CloudWatch log retention to meet investigation, audit and data-retention needs.

Description

CloudWatch Logs retention determines how long records remain available for investigation and how much storage they use. Log groups without a retention policy retain events indefinitely by default. Too short a period can remove needed records; unnecessarily long retention increases costs and the amount of sensitive information held.

Retention is separate from enabling log collection. An unsupported value can prevent the intended retention policy from being applied.

Potential impact

  • Missing historical records can hinder incident analysis or audits.
  • Excessive retention can increase costs and the impact of information exposure.

Remediation

Set a supported retentionInDays value based on investigation, audit and data-retention requirements. Preserve required records elsewhere before shortening retention, and verify the actual log-group policy after deployment. Physical deletion of expired events may not be immediate.

Examples

Before

yaml
apiVersion: cloudwatchlogs.aws.crossplane.io/v1alpha1
kind: LogGroup
metadata:
  name: lg-3
spec:
  forProvider:
    logGroupName: /aws/eks/sample-cluster/cluster
    region: us-east-1
    retentionInDays: 0

0 is not supported by the AWS retention API. Do not use it to mean indefinite retention.

After

yaml
apiVersion: cloudwatchlogs.aws.crossplane.io/v1alpha1
kind: LogGroup
metadata:
  name: lg-1
spec:
  forProvider:
    logGroupName: /aws/eks/sample-cluster/cluster
    region: us-east-1
    retentionInDays: 30

This specifies a supported retention period of 30 days. That period is not suitable for every service; retain the identity of the Crossplane resource you actually intend to update.

References