DeleteLogStream
DeleteLogStream
Event
Deletes the named log stream and its stored events within a log group. It does not delete the parent group or other streams. Any independent copies and subsequent producer activity must be checked separately.
Security Context
Unauthorized stream deletion can remove evidence from a specific source or interval. Approved cleanup is also possible. The narrower scope does not establish that the operation evades alerts, and an existing parent group does not establish that historical evidence is intact.
The T1685.002 mapping applies to deliberate defensive impairment; the API name alone does not establish malicious intent.
Log Source
CloudTrail management event with eventSource: logs.amazonaws.com and eventName: DeleteLogStream. Search regional Event history or your retained management-event collection; collection scope and retention determine the available evidence.
Key Fields
| Field | Investigation use |
|---|---|
requestParameters.logGroupName, requestParameters.logStreamName | Together identify the deleted stream. |
userIdentity, eventTime, sourceIPAddress, userAgent | Attribute the request and correlate with approved work. |
awsRegion, recipientAccountId | Scope the affected environment. |
errorCode, errorMessage | Check rejection before inferring a completed change; null responseElements alone is not proof of success. |
What to Investigate
- Confirm authorization and inspect errors; verify the stream’s current state and any recreation.
- Identify its producer and actual event interval from retained metadata, not just the stream name.
- Compare sibling streams, exports, and independent destinations to assess the evidence gap.
- Correlate with DeleteLogGroup and check resumed ingestion. A newly created stream with the same name does not restore deleted events.
Sample Event
Synthetic impairment scenario. Draco requests deletion of one fictional stream in a CloudTrail destination group. The name is illustrative, not a verified CloudTrail naming convention or proof of its contents. No claim is made about whether a defender alerts on the request. No top-level error is shown. Exact CloudTrail serialization and optional fields have not been validated by capture.
{ "eventVersion": "1.09", "userIdentity": { "type": "IAMUser", "principalId": "AIDADRAC0MALF0YBADGY", "arn": "arn:aws:iam::555123456789:user/draco", "accountId": "555123456789", "accessKeyId": "ASIADRAC0MALF0YEXAMP5", "userName": "draco", "sessionContext": { "attributes": { "creationDate": "2026-04-15T19:02:11Z", "mfaAuthenticated": "false" } } }, "eventTime": "2026-04-15T20:18:12Z", "eventSource": "logs.amazonaws.com", "eventName": "DeleteLogStream", "awsRegion": "us-east-1", "sourceIPAddress": "203.0.113.66", "userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6", "requestParameters": { "logGroupName": "fantasticlogs-cloudtrail-management", "logStreamName": "555123456789_CloudTrail_us-east-1_20260415" }, "responseElements": null, "requestID": "90000000-0000-4000-8000-000011101010", "eventID": "90000000-0000-4000-8000-000011101011", "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "555123456789", "eventCategory": "Management", "tlsDetails": { "tlsVersion": "TLSv1.3", "cipherSuite": "TLS_AES_128_GCM_SHA256", "clientProvidedHostHeader": "logs.us-east-1.amazonaws.com" }}Sources
MITRE ATT&CK Mapping
Tactics: Defense Impairment
- T1685.002 — Disable or Modify Cloud Log — An adversary may disable or modify cloud logging capabilities and integrations to limit what data is collected on their activities and avoid detection. Cloud environments allow for collection and analysis of audit and application logs that provide insight into what activities a user does within t...