You must be logged in to view saved presets
CloudFormation guard rules template for CloudWatch Log groups
The following rules are included:
let logGroups = Resources.*[
Type == "AWS::Logs::LogGroup"
]
rule cloudwatchlogs_retention when %logGroups !empty {
%logGroups {
Properties {
RetentionInDays exists <<Retention policy is not configured.>>
}
}
}
rule cloudwatchlogs_kms_encrypted when %logGroups !empty {
%logGroups {
Properties {
KmsKeyId exists <<KMS encryption is not configured.>>
}
}
}