Amazon CloudWatch pipelines introduces new compliance and governance capabilities

Amazon CloudWatch Pipelines Updates
CloudWatch pipelines now includes new compliance and governance capabilities to help maintain data integrity and control access when processing logs. These features are available at no additional cost, with standard CloudWatch Logs storage rates applying to both original and transformed copies of your log data.
New Features
- Keep Original Logs: Enable a toggle to store a copy of your raw logs before any transformation, ensuring unmodified data is always available.
- Metadata for Transformed Logs: New metadata added to processed log entries to indicate transformation, aiding in distinguishing between original and processed data.
- IAM Condition Keys: New keys to restrict pipeline creation based on log source name and type, providing fine-grained control over pipeline creation.
What to do
- Enable the "keep original" toggle in the CloudWatch console to store raw logs.
- Use new metadata to differentiate between original and processed logs during audits.
- Configure IAM policies with new condition keys to control pipeline creation.
Source: AWS release notes
If you need further guidance on AWS, our experts are available at AWS@westloop.io. You may also reach us by submitting the Contact Us form.



