A large enterprise uses AWS Organizations to manage multiple AWS accounts. The security team requires that all CloudWatch Logs for critical applications across all accounts are centralized into a single, dedicated security account for long-term archival and analysis. The solution must be scalable, secure, and ensure that logs are not accidentally deleted.
- AEnable CloudWatch Logs resource policies in each application account to allow the security account to directly retrieve log events for archival.
- BDeploy a custom Lambda function in each application account to periodically export CloudWatch Logs to an S3 bucket in the security account with S3 Object Lock.
- CConfigure CloudWatch Logs subscription filters in each application account to stream logs to a Kinesis Data Firehose in the security account, which then delivers to S3.
- DUse AWS Organizations delegated administrator feature for CloudWatch Logs and configure cross-account resource policies to allow logging to a central log group.
Show answer & explanationAnswer & explanation
Correct answer: C. Configure CloudWatch Logs subscription filters in each application account to stream logs to a Kinesis Data Firehose in the security account, which then delivers to S3.
CloudWatch Logs subscription filters allow real-time streaming of log events to other AWS services. By streaming from each application account to a Kinesis Data Firehose in the centralized security account, logs can be reliably delivered to an S3 bucket for long-term, immutable archival (with S3 Object Lock). This provides a scalable, secure, and real-time centralization solution across accounts.
Why the other options are wrong
- A. Resource policies allow other accounts to access existing log groups, but they don't facilitate the *ingestion* of logs from multiple accounts into a *single* centralized log group or S3 bucket in another account.
- B. Periodic Lambda exports are not real-time, add operational overhead, and are less efficient than subscription filters for continuous streaming of logs.
- D. CloudWatch Logs does not support AWS Organizations delegated administrator for centralizing log groups directly. It's for delegating management of CloudWatch features, not for cross-account log ingestion into a single log group.
Cross-Account CloudWatch Logs Centralization
Centralizing CloudWatch Logs from multiple AWS accounts into a single security or logging account for unified analysis and long-term archival.
- Uses CloudWatch Logs subscription filters.
- Often streams logs to Kinesis Data Firehose or Lambda.
- Target destination is typically S3 for archival.
- Requires appropriate IAM roles and resource policies for cross-account access.
Memory trick: CloudWatch's 'Subscription Stream' funnels all logs to one safe place.