New feature

Amazon CloudWatch log centralization now supports log group tag propagation

Amazon CloudWatch log centralization now copies tags from source log groups to destination groups, allowing teams to use them for access control and cost reporting.

Amazon CloudWatch log centralization now copies tags from source log groups to destination log groups and keeps them synchronized based on the tag propagation behavior selected in the centralization rule setup. This allows platform teams to preserve tags such as Application and CostCenter on centralized log groups, then use those tags to scope access with IAM conditions and report centralized log spend by team in AWS Cost Explorer. Tag propagation is available in all AWS Regions where CloudWatch Centralization is offered. It can be enabled via the CloudWatch console, AWS CLI, or AWS SDKs.

Why it matters

This update benefits users centralizing logs from multiple accounts and regions, enabling more granular access control and cost management through preserved log group tags.

Read the original AWS announcement