AWS::Logs::AccountPolicyThe AWS::Logs::AccountPolicy resource specifies a CloudWatch Logs AccountPolicy.
5 configurable properties. 3 required. Click a row to see details.
| Property | Type | Flags |
|---|---|---|
PolicyDocument | string | Required |
PolicyName | string | RequiredCreate-only |
PolicyType | string | RequiredCreate-only |
Scope | string | |
SelectionCriteria | string |
Values returned after the resource is created. Access these with Fn::GetAtt.
| Attribute | Type | Description |
|---|---|---|
AccountId | string | User account id |
A minimal template with required properties and common optional ones.
AWSTemplateFormatVersion: "2010-09-09"
Description: Sample template for AWS::Logs::AccountPolicy
Resources:
MyResource:
Type: AWS::Logs::AccountPolicy
Properties:
PolicyName: "my-policyname"
PolicyType: "DATA_PROTECTION_POLICY"
PolicyDocument: "value"Permissions CloudFormation needs in your IAM role to manage this resource.
logs:PutAccountPolicylogs:PutIndexPolicylogs:PutDataProtectionPolicylogs:DescribeAccountPolicieslogs:CreateLogDeliverys3:REST.PUT.OBJECTfirehose:TagDeliveryStreamlogs:PutSubscriptionFilterlogs:DescribeAccountPolicieslogs:GetTransformerlogs:GetMetricExtractionPolicylogs:PutAccountPolicylogs:PutIndexPolicylogs:PutDataProtectionPolicylogs:DescribeAccountPolicieslogs:DeleteAccountPolicylogs:DeleteIndexPolicylogs:DeleteDataProtectionPolicylogs:CreateLogDeliverylogs:DeleteAccountPolicylogs:DeleteIndexPolicylogs:DeleteDataProtectionPolicylogs:DescribeAccountPolicieslogs:DeleteSubscriptionFilterlogs:DeleteTransformerlogs:DeleteMetricExtractionPolicyiam:PassRolelogs:DescribeAccountPolicieslogs:GetTransformerlogs:GetMetricExtractionPolicyOur bi-weekly newsletter teaches hands-on AWS fundamentals. No certification fluff - just practical knowledge.
Subscribe to NewsletterAccountIdThese properties cannot be changed after the resource is created. Updating them triggers a replacement.
PolicyNamePolicyType