Jump to Content

This API Documentation is now deprecated

We are excited to announce our new API Documentation.

Interface CreateLogGroupCommandInputProtected

The input for CreateLogGroupCommand.



kmsKeyId?: string

The Amazon Resource Name (ARN) of the KMS key to use when encrypting log data. For more information, see Amazon Resource Names.

logGroupName: undefined | string

The name of the log group.

tags?: Record<string, string>

The key-value pairs to use for the tags.

You can grant users access to certain log groups while preventing them from accessing other log groups. To do so, tag your groups and use IAM policies that refer to those tags. To assign tags when you create a log group, you must have either the logs:TagResource or logs:TagLogGroup permission. For more information about tagging, see Tagging Amazon Web Services resources. For more information about using tags to control access, see Controlling access to Amazon Web Services resources using tags.