Description
When REST API execution logging is enabled, API Gateway uses a log group named API-Gateway-Execution-Logs_{rest-api-id}/{stage_name}. To manage it through Terraform, match the API ID and stage name. Access logging is separate and uses the log group specified by access_log_settings.destination_arn.
Incorrect CloudWatch delivery reduces the evidence available to trace requests, failures and suspicious activity.
Potential impact
- Request histories can be harder to reconstruct.
- Investigating abnormal requests or error patterns can take longer.
- Usage and failure trends can be harder to analyze.
Remediation
- Enable the execution logs you need and configure CloudWatch delivery permissions. Import an existing execution log group before managing it with Terraform.
- Match execution log group names to the actual API and stage. Configure a valid
destination_arnand format separately for access logs, which do not require the execution-log naming convention. - Limit retention and read access, and verify that real request logs arrive.
Examples
These excerpts compare execution log group names. Other required API and stage settings, execution logging enablement and delivery permissions are omitted. Creating or correctly naming a group does not itself enable logging.
Before
hcl
variable "stage_name" {
default = "example"
type = string
}
variable "stage_names" {
default = "examples"
type = string
}
resource "aws_api_gateway_rest_api" "example" {
# ... other configuration ...
}
resource "aws_api_gateway_stage" "example" {
depends_on = [aws_cloudwatch_log_group.example]
stage_name = var.stage_name
# ... other configuration ...
}
resource "aws_cloudwatch_log_group" "example" {
name = "API-Gateway-Execution-Logs_${aws_api_gateway_rest_api.example.id}/${var.stage_names}"
retention_in_days = 7
}
After
hcl
variable "stage_name" {
default = "example"
type = string
}
resource "aws_api_gateway_rest_api" "example" {
# ... other configuration ...
}
resource "aws_api_gateway_stage" "example" {
depends_on = [aws_cloudwatch_log_group.example]
stage_name = var.stage_name
# ... other configuration ...
}
resource "aws_cloudwatch_log_group" "example" {
name = "API-Gateway-Execution-Logs_${aws_api_gateway_rest_api.example.id}/${var.stage_name}"
retention_in_days = 7
}
Explanation:
- Before: The stage and execution log group use different stage names.
- After: The same variable supplies both names. Separate logging enablement and delivery permissions remain necessary.