Description
Disabling provider.logs.restApi.accessLogging in Serverless Framework prevents API Gateway REST API access logs from being generated. Application logs alone may not cover every request handled by API Gateway.
Potential impact
Per-request records may be missing when investigating failures or suspicious calls.
Remediation
Set provider.logs.restApi.accessLogging: true and configure a format containing a request ID, delivery permissions and retention. Keep secrets and unnecessary request bodies out of logs.
Examples
The examples apply to a REST API created by the Framework. For an external API imported through provider.apiGateway.restApiId, configure logging on that API separately.
Before
yaml
provider:
name: aws
logs:
restApi:
accessLogging: false
format: 'requestId: $context.requestId'
After
yaml
provider:
name: aws
logs:
restApi:
accessLogging: true
format: 'requestId: $context.requestId'