Description
Without the required access or execution logs for an API Gateway stage, request handling and errors can be harder to trace. Access logging and execution logging are separate settings; also check logs collected by other systems.
Access logs can record request identifiers and response status. Execution logs help investigate processing in REST and WebSocket APIs; HTTP APIs do not use the same execution logging settings.
Potential impact
- Insufficient request records can hinder investigation of suspicious calls or service failures.
- Excessive recording of sensitive request data or broad log access can expose information.
Remediation
Configure the access log destination and format for the API type and audit purpose. Set an execution logging level when needed for REST or WebSocket APIs. Prepare delivery permissions, retention and access controls, and verify that actual request records arrive. Restrict logging of sensitive payloads.
Examples
This is a partial WebSocket stage configuration. Prepare the API and deployment separately and replace the log group ARN with the actual value. The log group and API Gateway log delivery permissions are omitted.
Before
Resources:
WebSocketStage:
Type: AWS::ApiGatewayV2::Stage
Properties:
StageName: Prod
ApiId: !Ref MyApi
DeploymentId: !Ref MyDeployment
This stage has no access log delivery configuration. Check separately for execution logging and backend logs.
After
Resources:
WebSocketStage:
Type: AWS::ApiGatewayV2::Stage
Properties:
StageName: Prod
ApiId: !Ref MyApi
DeploymentId: !Ref MyDeployment
AccessLogSettings:
DestinationArn: arn:aws:logs:us-east-1:123456789012:log-group:api-gateway-prod
Format: '{"requestId":"$context.requestId","ip":"$context.identity.sourceIp","routeKey":"$context.routeKey","status":"$context.status"}'
This records the request identifier, source IP, route key and status in the specified log group. It does not automatically configure execution logs or alerts.