Security Lake Source and Retention Planning Checklist
Retrospective: this article looks back at events from November 2022, written in 2026 with the benefit of hindsight.
Use this checklist to plan which data goes into Amazon Security Lake and how long you keep it.
Requirements
- Regulatory retention requirements for security logs identified (for example, one year minimum for many frameworks).
- Investigation needs defined (how far back do you need to look after an incident?).
- SIEM and analytics consumers identified.
Sources
- CloudTrail management events — all accounts and regions.
- CloudTrail data events — only for sensitive S3 buckets and critical Lambda functions (volume and cost).
- VPC Flow Logs — production VPCs at minimum.
- Route 53 resolver query logs — for DNS-based detection.
- Security Hub findings — all accounts.
- EKS audit logs — if running Kubernetes.
- WAF logs — for internet-facing applications.
- Third-party sources: identity provider, endpoint, firewall.
Retention
- Hot (frequently queried) period defined (for example, 30–90 days).
- Transition to infrequent access and archive storage classes configured.
- Total retention period meets requirements.
- Deletion configured after retention period.
Cost
- Estimated daily volume per source.
- Monthly cost estimate reviewed.
- Budget alerts set.
Access
- Subscribers configured with least privilege.
- Access to raw data restricted and logged.
Review
- Sources and retention reviewed every six months.
- re:Invent 2022: Amazon Security Lake and Verified Access Previews Platform Changes
- How to Centralize AWS Security Logs With Amazon Security Lake How-To & Hardening
- CIO Brief: Owning Your Security Data — The OCSF Shift CIO Briefings