Description
Without API Gateway request and error logs, unusual calls can be harder to detect and investigate. Creating a CloudWatch log group alone does not enable API Gateway logging; the stage settings and permission to write logs also matter.
Access logs and execution logs have separate settings. Collect needed request identifiers and error information while preventing tokens, passwords and sensitive request bodies from being logged unnecessarily.
Potential impact
- Authentication failures and unusual requests may be discovered late.
- Difficulty reconstructing request activity can delay incident response.
Remediation
Configure the log_group_name, retention and access permissions. Enable the required access and execution logging on the API stage, setting the access-log destination ARN and format and required service write permissions. Confirm that test requests produce logs and avoid excessive recording of sensitive information.
Examples
These excerpts show only log-group configuration. Replace kms_key_id with the actual key ARN and provide CloudWatch Logs with the required key permissions. API stage settings are still needed.
Before
- name: Setup CloudWatch log group
community.aws.cloudwatchlogs_log_group:
state: present
kms_key_id: arn:aws:kms:region:account-id:key/key-id
The required log-group name is missing. This task does not establish that a valid log group is created.
After
- name: Setup CloudWatch log group
community.aws.cloudwatchlogs_log_group:
state: present
log_group_name: test-log-group
kms_key_id: arn:aws:kms:region:account-id:key/key-id
The log-group name is specified. Creating it alone does not cause API Gateway to send logs to it.