AWSHow-To & HardeningRetrospectives

Security Lake Source and Retention Planning Checklist

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from November 2022, written in 2026 with the benefit of hindsight.

Use this checklist to plan which data goes into Amazon Security Lake and how long you keep it.

Requirements

  • Regulatory retention requirements for security logs identified (for example, one year minimum for many frameworks).
  • Investigation needs defined (how far back do you need to look after an incident?).
  • SIEM and analytics consumers identified.

Sources

  • CloudTrail management events — all accounts and regions.
  • CloudTrail data events — only for sensitive S3 buckets and critical Lambda functions (volume and cost).
  • VPC Flow Logs — production VPCs at minimum.
  • Route 53 resolver query logs — for DNS-based detection.
  • Security Hub findings — all accounts.
  • EKS audit logs — if running Kubernetes.
  • WAF logs — for internet-facing applications.
  • Third-party sources: identity provider, endpoint, firewall.

Retention

  • Hot (frequently queried) period defined (for example, 30–90 days).
  • Transition to infrequent access and archive storage classes configured.
  • Total retention period meets requirements.
  • Deletion configured after retention period.

Cost

  • Estimated daily volume per source.
  • Monthly cost estimate reviewed.
  • Budget alerts set.

Access

  • Subscribers configured with least privilege.
  • Access to raw data restricted and logged.

Review

  • Sources and retention reviewed every six months.
security lake retention planning checklistre:Invent 2022 Security Lake2022

More on this story