CloudWatch logs are all kept without deletion by default, however this can become costly over time so many administrators will configure a retention period. It is important to ensure that this is configured with a specific timeframe in accordance with regulatory requirements. This can also be used in conjunction with the archive setting to rotate logs. For more information, see the AWS documentation.
References:
https://docs.aws.amazon.com/AmazonCloudWatch/latest/logs/WhatIsCloudWatchLogs.html
In AWS Console -
In Terraform -