Review API Gateway stage logging

Configure stage logs so API requests and errors can be investigated.

Description

Without the required access or execution logs for an API Gateway stage, request handling and errors can be harder to trace. Access logging and execution logging are separate settings; also check logs collected by other systems.

Access logs can record request identifiers and response status. Execution logs help investigate processing in REST and WebSocket APIs; HTTP APIs do not use the same execution logging settings.

Potential impact

  • Insufficient request records can hinder investigation of suspicious calls or service failures.
  • Excessive recording of sensitive request data or broad log access can expose information.

Remediation

Configure the access log destination and format for the API type and audit purpose. Set an execution logging level when needed for REST or WebSocket APIs. Prepare delivery permissions, retention and access controls, and verify that actual request records arrive. Restrict logging of sensitive payloads.

Examples

This is a partial WebSocket stage configuration. Prepare the API and deployment separately and replace the log group ARN with the actual value. The log group and API Gateway log delivery permissions are omitted.

Before

yaml
Resources:
  WebSocketStage:
    Type: AWS::ApiGatewayV2::Stage
    Properties:
      StageName: Prod
      ApiId: !Ref MyApi
      DeploymentId: !Ref MyDeployment

This stage has no access log delivery configuration. Check separately for execution logging and backend logs.

After

yaml
Resources:
  WebSocketStage:
    Type: AWS::ApiGatewayV2::Stage
    Properties:
      StageName: Prod
      ApiId: !Ref MyApi
      DeploymentId: !Ref MyDeployment
      AccessLogSettings:
        DestinationArn: arn:aws:logs:us-east-1:123456789012:log-group:api-gateway-prod
        Format: '{"requestId":"$context.requestId","ip":"$context.identity.sourceIp","routeKey":"$context.routeKey","status":"$context.status"}'

This records the request identifier, source IP, route key and status in the specified log group. It does not automatically configure execution logs or alerts.

References