AWS Certified DevOps Engineer – ProfessionalMonitoring and LoggingHard

A large enterprise uses AWS Organizations to manage multiple AWS accounts. The security team requires that all CloudWatch Logs for critical applications across all accounts are centralized into a single, dedicated security account for long-term archival and analysis. The solution must be scalable, secure, and ensure that logs are not accidentally deleted.

  1. AEnable CloudWatch Logs resource policies in each application account to allow the security account to directly retrieve log events for archival.
  2. BDeploy a custom Lambda function in each application account to periodically export CloudWatch Logs to an S3 bucket in the security account with S3 Object Lock.
  3. CConfigure CloudWatch Logs subscription filters in each application account to stream logs to a Kinesis Data Firehose in the security account, which then delivers to S3.
  4. DUse AWS Organizations delegated administrator feature for CloudWatch Logs and configure cross-account resource policies to allow logging to a central log group.
Show answer & explanation

Correct answer: C. Configure CloudWatch Logs subscription filters in each application account to stream logs to a Kinesis Data Firehose in the security account, which then delivers to S3.

CloudWatch Logs subscription filters allow real-time streaming of log events to other AWS services. By streaming from each application account to a Kinesis Data Firehose in the centralized security account, logs can be reliably delivered to an S3 bucket for long-term, immutable archival (with S3 Object Lock). This provides a scalable, secure, and real-time centralization solution across accounts.

Why the other options are wrong

  • A. Resource policies allow other accounts to access existing log groups, but they don't facilitate the *ingestion* of logs from multiple accounts into a *single* centralized log group or S3 bucket in another account.
  • B. Periodic Lambda exports are not real-time, add operational overhead, and are less efficient than subscription filters for continuous streaming of logs.
  • D. CloudWatch Logs does not support AWS Organizations delegated administrator for centralizing log groups directly. It's for delegating management of CloudWatch features, not for cross-account log ingestion into a single log group.

Cross-Account CloudWatch Logs Centralization

Centralizing CloudWatch Logs from multiple AWS accounts into a single security or logging account for unified analysis and long-term archival.

  • Uses CloudWatch Logs subscription filters.
  • Often streams logs to Kinesis Data Firehose or Lambda.
  • Target destination is typically S3 for archival.
  • Requires appropriate IAM roles and resource policies for cross-account access.

Memory trick: CloudWatch's 'Subscription Stream' funnels all logs to one safe place.

More Monitoring and Logging questions