Description
When retention_in_days is omitted for a CloudWatch log group, logs do not expire by default. A Terraform value of 0 also keeps logs without expiration. Conversely, an overly short period can remove logs needed for investigations.
Keeping more logs is not always the right answer: retention should meet operational and regulatory requirements. If long-term storage is necessary, document its purpose and the access and cost controls.
Potential impact
- Unnecessary retention can cause storage costs to keep growing.
- Inconsistent retention across resources can make operational policy harder to apply.
- Required logs can be deleted too early, or sensitive records can remain longer than necessary.
Remediation
- Specify
retention_in_daysaccording to investigation and audit requirements, and apply the same policy to new log groups. - Before shortening retention, assess the effect on existing logs and preserve records that must be kept separately. Deletion of expired logs can take time.
- Regularly review log access, storage cost and changes to retention requirements.
Examples
Thirty days is illustrative, not a universal requirement for every service or regulation.
Before
hcl
resource "aws_cloudwatch_log_group" "app" {
name = "/aws/app/service"
}
After
hcl
resource "aws_cloudwatch_log_group" "app" {
name = "/aws/app/service"
retention_in_days = 30
}
Explanation:
- Before: Retention is omitted, so logs do not expire.
- After: Log retention is set to 30 days. Also review existing records that will become eligible for expiration because of this change.