Review access logging for an API Gateway deployment stage

Retain request records for the operating stage and verify actual log delivery.

Description

Without access logs for an operating API Gateway stage, it can be harder to investigate call times, request identifiers and response status. The actual stage settings can be managed through a deployment’s StageDescription or a separate Stage resource.

An absent logging setting in the deployment alone does not establish that all request records are missing. Check the actual stage configuration and other collection paths, such as backend logs.

Potential impact

  • It can be harder to connect failures or suspicious calls to individual requests.
  • Failed delivery or short retention can leave too little evidence for later investigation.

Remediation

Configure the AccessLogSetting destination log group ARN and a format containing a request identifier in the configuration that manages the stage. Prepare API Gateway delivery permissions and log retention and access policies, then verify records from actual requests. Configure execution logs and alerts separately as needed.

Examples

This excerpt covers a REST API deployment and stage settings. Prepare GreetingApi, the methods to deploy and necessary deployment dependencies separately. Replace the log group ARN with the actual value.

Before

yaml
Resources:
  ApiDeployment:
    Type: AWS::ApiGateway::Deployment
    Properties:
      RestApiId: !Ref GreetingApi
      StageName: prod
      StageDescription:
        CacheClusterEnabled: false

This does not specify access logging for the prod stage. Check the settings applied to the actual operating stage.

After

yaml
Resources:
  ApiDeployment:
    Type: AWS::ApiGateway::Deployment
    Properties:
      RestApiId: !Ref GreetingApi
      StageName: prod
      StageDescription:
        AccessLogSetting:
          DestinationArn: arn:aws:logs:us-east-1:123456789012:log-group:apigw-prod
          Format: '{"requestId":"$context.requestId","status":"$context.status","ip":"$context.identity.sourceIp"}'

This specifies the access log destination and format for the stage managed by the deployment. Prepare the log group and delivery permissions, then verify actual records.

References