A DevOps team wants to implement a robust log archival strategy for compliance requirements. They need to store application logs from various EC2 instances for 10 years in the most cost-effective manner. The logs are initially collected by the CloudWatch Agent and sent to CloudWatch Logs. After a short period (e.g., 30 days) for immediate operational analysis, the logs should be moved to long-term, immutable storage. Which solution provides the most cost-effective and compliant archival?
- ASet a CloudWatch Logs retention policy for 10 years.
- BCreate a CloudWatch Logs subscription filter to stream logs to Amazon Kinesis Data Firehose, which delivers them to Amazon S3 Glacier Deep Archive.
- CSet a CloudWatch Logs retention policy for 30 days and configure a lifecycle policy on the CloudWatch Logs log group to automatically transition older logs to S3 Intelligent-Tiering.
- DConfigure a CloudWatch Logs export task to regularly move logs to an Amazon S3 bucket with a lifecycle policy to transition to S3 Glacier Deep Archive.
Show answer & explanationAnswer & explanation
Correct answer: D. Configure a CloudWatch Logs export task to regularly move logs to an Amazon S3 bucket with a lifecycle policy to transition to S3 Glacier Deep Archive.
To achieve cost-effective, long-term (10 years) immutable archival, logs should be moved from CloudWatch Logs to Amazon S3, and then transitioned to Amazon S3 Glacier Deep Archive. CloudWatch Logs export tasks (or subscription filters to Kinesis Firehose) are mechanisms to move logs out of CloudWatch Logs. An S3 lifecycle policy then automates the transition to S3 Glacier Deep Archive, which is the most cost-effective storage class for data accessed rarely over very long periods, satisfying the 10-year retention and cost-effectiveness requirements.
Why the other options are wrong
- A. While CloudWatch Logs supports 10-year retention, storing logs directly in CloudWatch Logs for that duration is significantly more expensive than archiving them in S3 Glacier Deep Archive.
- B. Streaming via Kinesis Data Firehose to S3 is a valid ingestion method, and Firehose can deliver directly to S3 Glacier Flexible Retrieval (formerly Glacier) or S3 Intelligent-Tiering, but Firehose does not directly support S3 Glacier Deep Archive as a final destination. An S3 lifecycle policy would still be needed from an intermediate S3 Standard/Intelligent-Tiering bucket.
- C. S3 Intelligent-Tiering is more expensive than S3 Glacier Deep Archive for data that is rarely accessed over 10 years. While it moves data between tiers, it doesn't offer the lowest cost for true cold archival.
Amazon S3 Glacier Deep Archive
Amazon S3 storage class designed for long-term archival and digital preservation with the lowest cost storage in the cloud, suitable for data that is rarely or never accessed.
- Lowest cost S3 storage class.
- Retrieval times typically 12-48 hours.
- Ideal for compliance and long-term archival (7-10+ years).
Memory trick: Logs Export to S3, Lifecycle to Deep Archive.