1 Answer
- Newest
- Most votes
- Most comments
0
Hi,
Cloudwatch log groups are encrypted at rest by default using a 256-bit AES-GCM server side encryption, but you can also employ a KMS key to encrypt them, either when you create the log group or after it exists.
The following AWS documentation page and Knowledge Center article describes step by step how to implement it.
Relevant content
- asked 2 years ago
- AWS OFFICIALUpdated 2 months ago
- AWS OFFICIALUpdated 10 months ago