Skip to content

DeleteLogGroup

AWS

DeleteLogGroup

service: AWS - CloudWatchLogs
techniques:

Event

Deletes the specified log group and permanently removes its stored events. The effect is scoped to that group in the account and Region; independently exported or delivered copies require separate assessment.

Security Context

An attacker may remove logs to impair investigation. Approved workload retirement or retention cleanup can also explain deletion. For a CloudTrail destination, do not assume the trail or its S3 evidence was also deleted. Missing metric input does not guarantee alarms become silent; examine alarm configuration and missing-data handling.

The T1685.002 mapping applies to deliberate defensive impairment; the API name alone does not establish malicious intent.

Log Source

CloudTrail management event with eventSource: logs.amazonaws.com and eventName: DeleteLogGroup. Search regional Event history or your retained management-event collection; collection scope and retention determine the available evidence.

Key Fields

FieldInvestigation use
requestParameters.logGroupNameDeleted group; identify its producers and consumers.
userIdentity, eventTime, sourceIPAddress, userAgentAttribute the request and correlate with approved work.
awsRegion, recipientAccountIdScope the affected environment.
errorCode, errorMessageCheck rejection before inferring a completed change; null responseElements alone is not proof of success.

What to Investigate

  1. Confirm authorization and inspect request errors. Verify current group existence and any subsequent recreation.
  2. Recover the group’s sources, filters, subscriptions, and dependent queries or alarms from retained configuration.
  3. Preserve independent evidence, including CloudTrail S3 delivery where configured; establish which historical events were lost only from this group.
  4. Correlate with DeleteTrail and DeleteAlarms. Verify resumed ingestion and dependent detection after restoration; recreation does not recover deleted history.

Sample Event

Synthetic impairment scenario. Draco requests deletion of a fictional CloudTrail destination group. Its producer configuration is assumed for illustration; this event does not prove trail deletion, loss of S3 copies, or a particular alarm outcome. No top-level error is shown. Exact CloudTrail serialization and optional fields have not been validated by capture.

{
"eventVersion": "1.09",
"userIdentity": {
"type": "IAMUser",
"principalId": "AIDADRAC0MALF0YBADGY",
"arn": "arn:aws:iam::555123456789:user/draco",
"accountId": "555123456789",
"accessKeyId": "ASIADRAC0MALF0YEXAMP5",
"userName": "draco",
"sessionContext": {
"attributes": {
"creationDate": "2026-04-15T19:02:11Z",
"mfaAuthenticated": "false"
}
}
},
"eventTime": "2026-04-15T20:21:33Z",
"eventSource": "logs.amazonaws.com",
"eventName": "DeleteLogGroup",
"awsRegion": "us-east-1",
"sourceIPAddress": "203.0.113.66",
"userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6",
"requestParameters": {
"logGroupName": "fantasticlogs-cloudtrail-management"
},
"responseElements": null,
"requestID": "90000000-0000-4000-8000-000011100110",
"eventID": "90000000-0000-4000-8000-000011100111",
"readOnly": false,
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "555123456789",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "logs.us-east-1.amazonaws.com"
}
}

Sources

MITRE ATT&CK Mapping

Tactics: Defense Impairment

Techniques:
  • T1685.002 — Disable or Modify Cloud Log — An adversary may disable or modify cloud logging capabilities and integrations to limit what data is collected on their activities and avoid detection. Cloud environments allow for collection and analysis of audit and application logs that provide insight into what activities a user does within t...
Documentation reviewed: September 29, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.