REST API access logging disabled in Serverless Framework

Enable access logs to retain REST API request history.

Description

Disabling provider.logs.restApi.accessLogging in Serverless Framework prevents API Gateway REST API access logs from being generated. Application logs alone may not cover every request handled by API Gateway.

Potential impact

Per-request records may be missing when investigating failures or suspicious calls.

Remediation

Set provider.logs.restApi.accessLogging: true and configure a format containing a request ID, delivery permissions and retention. Keep secrets and unnecessary request bodies out of logs.

Examples

The examples apply to a REST API created by the Framework. For an external API imported through provider.apiGateway.restApiId, configure logging on that API separately.

Before

yaml
provider:
  name: aws
  logs:
    restApi:
      accessLogging: false
      format: 'requestId: $context.requestId'

After

yaml
provider:
  name: aws
  logs:
    restApi:
      accessLogging: true
      format: 'requestId: $context.requestId'

References