NewDestinationLogGroups
Every new destination log group created by this rule uses the configured KmsKeyArn, regardless of whether the source log group is encrypted with a customer managed key or Amazon Web Services owned encryption.