AWS-CloudWatchLogs-CloudWatch-Log-Retention-Period
Severity: Medium
Description: This control ensures that CloudWatch log groups have retention period set. CloudWatch log groups will store data infinite number of days. While the costs are not high, this is one of those services that can quietly sneak up and end up costing a fair amount every month. According to the requirement, we can set the retention policy.
Remediation Steps:
Perform following to configure CloudWatch log retention period :
Login to the AWS Management Console at https://console.aws.amazon.com
Go to CloudWatch in services
In left navigation panel under Logs, select Log groups .
Select the Log group that need to reconfigure.
Select Actions dropdown.
Select the Edit retention setting, select retention days from the dropdown.
Click on Save.
Important:
Reference:
Blue Hexagon Proprietary