API Gateway access logging is not configured for FireTail

firetail:aws-api-gateway-firetail-logging-off

Type:

CSPM

Rule Severity:

Low

FireTail log capture is not configured for the API Gateway

Without FireTail access logging enabled, API request and response data is not being sent to FireTail for monitoring, analysis, or alerting. This lack of integration prevents visibility into API traffic, which may affect your ability to:

  • Detect and Respond to Security Threats: Without access logs in FireTail, malicious activity, unauthorized access attempts, or abnormal patterns in API usage may go unnoticed.
  • Monitor API Performance: Key performance metrics such as response times, error rates, and request patterns are not logged into FireTail, making it difficult to analyze and optimize API performance.
  • Troubleshoot Issues: Without logs in FireTail, diagnosing API failures or performance degradation becomes challenging, delaying incident response times.

Remediation

Follow the instructions for setting up shipping logs from API Gateway to the FireTail platform.

Example Attack Scenario

How to Identify with Example Scenario

How to Resolve with Example Scenario

How to Identify with Example Scenario

Find the text in bold to identify issues such as these in API specifications

How to Resolve with Example Scenario

Modify the text in bold to resolve issues such as these in API specifications
References:

More findings

All Findings