Access logging not configured for a SAM API

Configure access logs to retain SAM API request records.

Description

SAM API access logs record per-request details such as the request ID and response status. Without them, API Gateway request history may be unavailable for analysis.

Potential impact

Records needed to investigate failures or suspicious calls may be missing.

Remediation

Set AccessLogSetting on AWS::Serverless::Api or AccessLogSettings on AWS::Serverless::HttpApi. Configure the destination, a format containing a request ID, delivery permissions and retention.

Examples

The excerpts log the request ID and status for a REST API. Create the log group separately and configure API Gateway log delivery permissions.

Before

yaml
Resources:
  ApiGatewayApi:
    Type: AWS::Serverless::Api
    Properties:
      StageName: prod
      TracingEnabled: true

After

yaml
Resources:
  ApiGatewayApi:
    Type: AWS::Serverless::Api
    Properties:
      StageName: prod
      TracingEnabled: true
      AccessLogSetting:
        DestinationArn: arn:aws:logs:ap-northeast-2:123456789012:log-group:api-access-log
        Format: '{"requestId":"$context.requestId","status":"$context.status"}'

References