Description
SAM API access logs record per-request details such as the request ID and response status. Without them, API Gateway request history may be unavailable for analysis.
Potential impact
Records needed to investigate failures or suspicious calls may be missing.
Remediation
Set AccessLogSetting on AWS::Serverless::Api or AccessLogSettings on AWS::Serverless::HttpApi. Configure the destination, a format containing a request ID, delivery permissions and retention.
Examples
The excerpts log the request ID and status for a REST API. Create the log group separately and configure API Gateway log delivery permissions.
Before
yaml
Resources:
ApiGatewayApi:
Type: AWS::Serverless::Api
Properties:
StageName: prod
TracingEnabled: true
After
yaml
Resources:
ApiGatewayApi:
Type: AWS::Serverless::Api
Properties:
StageName: prod
TracingEnabled: true
AccessLogSetting:
DestinationArn: arn:aws:logs:ap-northeast-2:123456789012:log-group:api-access-log
Format: '{"requestId":"$context.requestId","status":"$context.status"}'