Review CloudWatch log retention

Set CloudWatch log retention to meet operational and regulatory needs, avoiding both lost evidence and unnecessary storage.

Description

When retention_in_days is omitted for a CloudWatch log group, logs do not expire by default. A Terraform value of 0 also keeps logs without expiration. Conversely, an overly short period can remove logs needed for investigations.

Keeping more logs is not always the right answer: retention should meet operational and regulatory requirements. If long-term storage is necessary, document its purpose and the access and cost controls.

Potential impact

  • Unnecessary retention can cause storage costs to keep growing.
  • Inconsistent retention across resources can make operational policy harder to apply.
  • Required logs can be deleted too early, or sensitive records can remain longer than necessary.

Remediation

  • Specify retention_in_days according to investigation and audit requirements, and apply the same policy to new log groups.
  • Before shortening retention, assess the effect on existing logs and preserve records that must be kept separately. Deletion of expired logs can take time.
  • Regularly review log access, storage cost and changes to retention requirements.

Examples

Thirty days is illustrative, not a universal requirement for every service or regulation.

Before

hcl
resource "aws_cloudwatch_log_group" "app" {
  name = "/aws/app/service"
}

After

hcl
resource "aws_cloudwatch_log_group" "app" {
  name              = "/aws/app/service"
  retention_in_days = 30
}

Explanation:

  • Before: Retention is omitted, so logs do not expire.
  • After: Log retention is set to 30 days. Also review existing records that will become eligible for expiration because of this change.

References