Overview
Lab Details
- This lab walks you through the steps to enable CloudWatch Logs in API Gateway.
- You will practice using AWS CloudWatch to view logs produced by API Gateway.
- Duration: 30 minutes
- AWS Region: US East (N. Virginia) us-east-1
Introduction
Amazon API Gateway
- Amazon API Gateway is a fully managed service that makes it easy for developers to create, publish, maintain, monitor, and secure APIs at any scale.
- APIs act as the front door for applications to access data, business logic, or functionality from your backend services.
- API Gateway handles all the tasks involved in accepting and processing up to hundreds of thousands of concurrent API calls, including traffic management, CORS support, authorization and access control, throttling, monitoring, and API version management.
- Using API Gateway, you can create RESTful APIs and WebSocket APIs that enable real-time two-way communication applications. API Gateway supports containerized and serverless workloads, as well as web applications.
Architecture Diagram

Task Details
- Sign into the AWS Management Console
- Create an API.
- Copy the ARN of the IAM Role.
- Create a Resource
- Create a Method.
- Deploy API
Launching Lab Environment
- To launch the lab environment, click on the Start Lab button.
- Please wait until the cloud environment is provisioned. It will take less than a minute to provision.
- Once the Lab is started, you will be provided with IAM username, Password, Access Key, and Secret Access Key.
Lab guide
Lab Steps
Task 1: Sign in to AWS Management Console
- Click on the open console button, and you will get redirected to AWS Console in a new browser tab.
- On the AWS sign-in page,
- Leave the Account ID as default. Never edit/remove the 12 digit Account ID present in the AWS Console. otherwise, you cannot proceed with the lab.
- Now copy your User Name and Password in the Lab Console to the IAM Username and Password in AWS Console and click on the Sign in button
Task 2: Create an API
- Make sure you are in the US East (N. Virginia) us-east-1 Region.
- Navigate to services menu at the top, then click on API Gateway in the Network and Content Delivery section.
- Click on build in REST API.(Close the pop up message for Create your first API,if it is present and ignore the error warning)

- Choose create new API. Under settings, enter the API name as Whizlab API and click on create API.
- Note: If any pop-ups appear, ignore them.

Task 3: Copy the ARN of the IAM role
- Navigate to Services at the top and choose IAM under Security, Identity, & Compliance. Select Roles in left side panel.
- There is a role already created for you. Search using whiz and you will find a role with the name whiz_apigateway_role-<RANDOM_NUMBER>

- Click on the Role and copy its ARN. This will be used in POST setup of the API gateway method.

Task 4: Creating a Resource
- Navigate to Services and click on API Gateway under Networking & Content Delivery.
- Once the API is created, select the Whizlab API.
- Select create resource in actions.
- Resource Name: TestResource
- Once you enter the resource name, click on create resource.
Task 5: Creating Method
- Once you create the resource, click on Create method. Select Post in the drop-down list of Method Type.
- Ignore this error if it appears:
- Select the Integration Type as AWS service.

- Enter the following details:
- Select AWS Region: us-east-1
- Select AWS Service**: CloudWatch Logs**
- Http Method: POST
- Action: Enter GetLogsEvent
- On the execution role, copy and paste the ARN of your role which we noted down earlier**.**
-
Leave other options as default and click on the Create method.

- Once it has been created, you will see this page.

Task 6: Deploy API
- Once the resource and the method have been created successfully, you can deploy the API.
- Click on deploy API.
- Set the Deployment Stage in the drop-down as New Stage.
- Enter Stage Name : TestingAPI
- Click on deploy.
- Navigate to Stages and click on Testing API.
- After deploying the API, scroll down and click the Edit button in the logs and tracing section.

-
Under CloudWatch logs click on the dropdown list and select Errors and info logs and then click on Save button.

Note: If any error occurs**,** we have to replace our IAM role ARN. To do that copy the ARN of our IAM Role and paste it in the CloudWatch Log role ARN (under Settings in left sidebar) and click on save.

- Navigate to Logs Groups under CloudWatch Logs to see the logs. (Wait for 3-5 minutes to see log group)

- You have successfully created CloudWatch logs for API Gateway. Whenever traffic passes through API Gateway, streams will be generated.
Do you know?
Enabling CloudWatch Logs in API Gateway allows you to capture and store log files for your API Gateway APIs in Amazon CloudWatch Logs. CloudWatch Logs is a fully managed service provided by AWS that enables you to collect, monitor, and analyze log data from various AWS resources and applications.
Completion and Conclusion
- You have successfully created an API.
- You have successfully created an API Gateway Resource and API Method.
- You have successfully deployed the API.
- You have successfully created CloudWatch Logs for API Gateway.
- You have successfully validated the lab.
End Lab
- Sign out of the AWS Account.
- You have successfully completed the lab.
- Once you have completed the steps, click on End Lab from the IP Lab Portal dashboard.
What gets checked
When you press Check my work, the platform verifies each of these:- Create a API Gateway — Check whether a REST/HTTP?WEBSOCKET API gateway is created or not