Review API Gateway access logging

Collect access logs needed for request tracing and investigation.

Description

API Gateway access logs record selected fields, such as request IDs and response status, to support operational and security investigations. Without collection at the required stage, records for tracing individual requests may be missing.

Potential impact

  • Investigating unusual requests and error paths can become harder.
  • Analysis can be delayed when metrics alone cannot explain a failure.

Remediation

Set the actual CloudWatch log-group ARN and a format containing the request ID in the Stage accessLogSettings. Configure write permissions and retention, then send requests and verify collection. Review the fields to avoid logging sensitive data.

Examples

These excerpts compare access logging for an API Gateway v2 stage. Prepare exampleApi, exampleLogGroup, the stage name and deployment settings separately.

Before

yaml
resources:
  example:
    type: aws:apigatewayv2:Stage
    properties:
      apiId: ${exampleApi.id}

After

yaml
resources:
  example:
    type: aws:apigatewayv2:Stage
    properties:
      apiId: ${exampleApi.id}
      accessLogSettings:
        destinationArn: ${exampleLogGroup.arn}
        format: '{"requestId":"$context.requestId","status":"$context.status"}'

The after example specifies JSON containing the request ID and response status. Add operational fields as needed, without unnecessarily recording credentials or secrets.

References