Description
API Gateway access logs record selected fields, such as request IDs and response status, to support operational and security investigations. Without collection at the required stage, records for tracing individual requests may be missing.
Potential impact
- Investigating unusual requests and error paths can become harder.
- Analysis can be delayed when metrics alone cannot explain a failure.
Remediation
Set the actual CloudWatch log-group ARN and a format containing the request ID in the Stage accessLogSettings. Configure write permissions and retention, then send requests and verify collection. Review the fields to avoid logging sensitive data.
Examples
These excerpts compare access logging for an API Gateway v2 stage. Prepare exampleApi, exampleLogGroup, the stage name and deployment settings separately.
Before
resources:
example:
type: aws:apigatewayv2:Stage
properties:
apiId: ${exampleApi.id}
After
resources:
example:
type: aws:apigatewayv2:Stage
properties:
apiId: ${exampleApi.id}
accessLogSettings:
destinationArn: ${exampleLogGroup.arn}
format: '{"requestId":"$context.requestId","status":"$context.status"}'
The after example specifies JSON containing the request ID and response status. Add operational fields as needed, without unnecessarily recording credentials or secrets.