CloudWatch Log Group No Retention
With retention set to Never Expire the group's stored bytes are billed every month forever, and log volume only grows.
Free to start. No card. The playground just needs your work email.
AWS
Found, explained, fixed.
Findings with a dollar figure attached, idle, oversized, orphaned, unscheduled and undiscounted spend.
Detect
ZopNight checks this automatically across AWS, with read-only access to the account.
Explain
Every finding says exactly what to change: Set a retention policy on the CloudWatch log group. Where the saving can be proven it is priced; where it cannot, the finding says so.
Fix
After a guided review, where you confirm the change, ZopNight applies a lifecycle policy, then checks the change took.
- Applies to
- Log Groups on AWS
- The fix, by hand
- CloudWatch Console → Log groups → select the resource.
- Decide retention: prod-app 90d, prod-access 30d, dev/test 7 to 14d. Check compliance requirements first.
- (Optional) Configure a one-time export to S3 with Glacier Deep Archive lifecycle for anything past retention you must keep.
- Actions → Edit retention setting → pick the new value → Save.
- CloudWatch deletes anything older than the new retention within 72h.
ZopNight does this for you after a guided review.
- Category
- Rightsizing. Resources sized for headroom they never use. A smaller size runs the same workload for less.
- Where it appears
- The Savings tab of Recommendations, with every affected resource listed.
- Rule ID
RC-057- Full reference
Related checks
See the oversized resources in your account.
Connect a read-only role and the first pass runs on your own estate. This check, and the rest of the catalogue, with it.
Prefer to talk it through first? Book 20 minutes with the team.
- $30M+annualised cloud spend under management
- 550K+resources tracked since launch
- 20-60%off the bill in the first month
- SOC 2Type II report, plus ISO 27001
Figures published on zop.dev.