CloudWatch Log Group TTL
Require TTL on CloudWatch logs
Summary
Log groups are always created without a TTL. They build up over time and while storage of them is not costly, there isn't an easy way to purge data if you were to be logging something sensitive. Aging it off will keep your account hygiene good. Require TTL on CloudWatch logs to limit bill and age potential sensitive logs away
Applicable To
All scaled usage of CloudWatch
Resources
CloudWatch
Maturity
Medium
Functions
CSPS
AWS
Author
Will Bengtson
Additional Links