DeleteLogGroup
DeleteLogGroup
Event
Deletes the specified log group and permanently removes its stored events. The effect is scoped to that group in the account and Region; independently exported or delivered copies require separate assessment.
Security Context
An attacker may remove logs to impair investigation. Approved workload retirement or retention cleanup can also explain deletion. For a CloudTrail destination, do not assume the trail or its S3 evidence was also deleted. Missing metric input does not guarantee alarms become silent; examine alarm configuration and missing-data handling.
The T1685.002 mapping applies to deliberate defensive impairment; the API name alone does not establish malicious intent.
Log Source
CloudTrail management event with eventSource: logs.amazonaws.com and eventName: DeleteLogGroup. Search regional Event history or your retained management-event collection; collection scope and retention determine the available evidence.
Key Fields
| Field | Investigation use |
|---|---|
requestParameters.logGroupName | Deleted group; identify its producers and consumers. |
userIdentity, eventTime, sourceIPAddress, userAgent | Attribute the request and correlate with approved work. |
awsRegion, recipientAccountId | Scope the affected environment. |
errorCode, errorMessage | Check rejection before inferring a completed change; null responseElements alone is not proof of success. |
What to Investigate
- Confirm authorization and inspect request errors. Verify current group existence and any subsequent recreation.
- Recover the group’s sources, filters, subscriptions, and dependent queries or alarms from retained configuration.
- Preserve independent evidence, including CloudTrail S3 delivery where configured; establish which historical events were lost only from this group.
- Correlate with DeleteTrail and DeleteAlarms. Verify resumed ingestion and dependent detection after restoration; recreation does not recover deleted history.
Sample Event
Synthetic impairment scenario. Draco requests deletion of a fictional CloudTrail destination group. Its producer configuration is assumed for illustration; this event does not prove trail deletion, loss of S3 copies, or a particular alarm outcome. No top-level error is shown. Exact CloudTrail serialization and optional fields have not been validated by capture.
{ "eventVersion": "1.09", "userIdentity": { "type": "IAMUser", "principalId": "AIDADRAC0MALF0YBADGY", "arn": "arn:aws:iam::555123456789:user/draco", "accountId": "555123456789", "accessKeyId": "ASIADRAC0MALF0YEXAMP5", "userName": "draco", "sessionContext": { "attributes": { "creationDate": "2026-04-15T19:02:11Z", "mfaAuthenticated": "false" } } }, "eventTime": "2026-04-15T20:21:33Z", "eventSource": "logs.amazonaws.com", "eventName": "DeleteLogGroup", "awsRegion": "us-east-1", "sourceIPAddress": "203.0.113.66", "userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6", "requestParameters": { "logGroupName": "fantasticlogs-cloudtrail-management" }, "responseElements": null, "requestID": "90000000-0000-4000-8000-000011100110", "eventID": "90000000-0000-4000-8000-000011100111", "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "555123456789", "eventCategory": "Management", "tlsDetails": { "tlsVersion": "TLSv1.3", "cipherSuite": "TLS_AES_128_GCM_SHA256", "clientProvidedHostHeader": "logs.us-east-1.amazonaws.com" }}Sources
MITRE ATT&CK Mapping
Tactics: Defense Impairment
- T1685.002 — Disable or Modify Cloud Log — An adversary may disable or modify cloud logging capabilities and integrations to limit what data is collected on their activities and avoid detection. Cloud environments allow for collection and analysis of audit and application logs that provide insight into what activities a user does within t...