resource "aws_cloudwatch_log_group" "ct-cwl" { name_prefix = "cloudtrail/" retention_in_days = var.cloudtrail-retain-days kms_key_id = aws_kms_key.ctbucket-key.arn tags = var.default-tags } resource "aws_cloudwatch_log_metric_filter" "cwl-metric-filter-cis11" { name = "cis11-rootaccess-filter" pattern = <