A Config rule that checks whether a log group in Amazon CloudWatch Logs is encrypted. The rule is NON_COMPLIANT if CloudWatch Logs has a log group without encryption enabled.

This config rule supports the following parameters:

  • KmsKeyId
    • Required: No
    • Type: String
    • Description:Amazon Resource Name (ARN) of the ID for the KMS key that is used to encrypt the log group.

CloudFormation Template