Prompt
Do I need API gateway logging if I have app logs?
Latest observation
Oct 5, 2026
OpenAI APIWeb search: off
Usually, yes—you still want API Gateway logs even if you have application logs.
Why app logs alone are not enough
Application logs only show what happens after the request reaches your service. API Gateway logs can capture things your app never sees, such as:
- Client/IP, request path, headers, auth failures
- Requests rejected by the gateway before hitting the app
- Rate limiting / throttling / WAF-type behavior
- Latency at the edge/gateway vs. inside the app
- Integration errors between gateway and backend
- Correlation for troubleshooting when the app never received the request
When app logs might be enough
You might skip gateway logs if:
- The gateway is just a thin pass-through
- Traffic volume is very high and logging cost is a concern
- You already have good access logs/trace IDs/metrics elsewhere
- You don’t need to debug auth, routing, throttling, or client-side issues at the gateway layer
Practical recommendation
A common approach is:
- Enable API Gateway access logs
- Keep them lean: status code, latency, request ID, route, auth result, integration status
- Use application logs for business logic and deeper debugging
- Add correlation IDs so you can connect gateway logs to app logs
Rule of thumb
If the gateway is doing more than simple forwarding, gateway logs are valuable and often necessary.
If it truly only passes traffic through and cost/volume is a concern, you may be able to rely mostly on app logs plus metrics.
If you want, I can also give you a decision checklist for whether to log at the gateway, app, or both.
Brands