Description
Without access logs for an operating API Gateway stage, it can be harder to investigate call times, request identifiers and response status. The actual stage settings can be managed through a deployment’s StageDescription or a separate Stage resource.
An absent logging setting in the deployment alone does not establish that all request records are missing. Check the actual stage configuration and other collection paths, such as backend logs.
Potential impact
- It can be harder to connect failures or suspicious calls to individual requests.
- Failed delivery or short retention can leave too little evidence for later investigation.
Remediation
Configure the AccessLogSetting destination log group ARN and a format containing a request identifier in the configuration that manages the stage. Prepare API Gateway delivery permissions and log retention and access policies, then verify records from actual requests. Configure execution logs and alerts separately as needed.
Examples
This excerpt covers a REST API deployment and stage settings. Prepare GreetingApi, the methods to deploy and necessary deployment dependencies separately. Replace the log group ARN with the actual value.
Before
Resources:
ApiDeployment:
Type: AWS::ApiGateway::Deployment
Properties:
RestApiId: !Ref GreetingApi
StageName: prod
StageDescription:
CacheClusterEnabled: false
This does not specify access logging for the prod stage. Check the settings applied to the actual operating stage.
After
Resources:
ApiDeployment:
Type: AWS::ApiGateway::Deployment
Properties:
RestApiId: !Ref GreetingApi
StageName: prod
StageDescription:
AccessLogSetting:
DestinationArn: arn:aws:logs:us-east-1:123456789012:log-group:apigw-prod
Format: '{"requestId":"$context.requestId","status":"$context.status","ip":"$context.identity.sourceIp"}'
This specifies the access log destination and format for the stage managed by the deployment. Prepare the log group and delivery permissions, then verify actual records.