I need to give read only access for AWS services. There is a read only built in policy in IAM. This overall work fine. But user can see EC2 launch logs (EC2 > Instance settings > Get System Logs). Here user can see ssh keys. So is there any way we can restrict this as well? any EC2 get system logs deny policy?