How to set up an alarm that particularly monitors throttling (429 - Too Many Requests) of an AWS API Gateway API?

Viewed 878

One way is to make the alarm monitor the auto-emitted Cloudwatch metric 4XXError. However, the problem with that is that it would not distinguish throttling errors (429) from other 4xx errors. So my alarm may be triggered for reasons other than throttling, which goes against the particular purpose of the alarm - to specifically monitor throttling only.

2 Answers

Api Gateway Logs, as long as they are enabled at stage level, should print a log similar to

*******vit5mg exceeded quota limit for API Stage abc123npx8/qa: Key quota exhausted for Usage Plan ID v2tyvt. Limit: 1 Period: DAY Method

completed with status: 429

We can have a cloudwatch logs Metric filter on text completed with status: 429 with metric value 1. And we can create a dashboard or an alarm on it, etc.

Yes, it is now possible to set it up with the right configuration:

  1. use the right settings for api access logging as per the image enclosed: aws api, logging levels
  2. for the log format, include the following JSON (some fields are excessive, make sure they match your needs, StatusCode will provide you the required 429 response in case of throttling)
{"APIId":"$context.apiId","DomainName":"$context.domainName","ErrResponse":"$context.error.responseType","ErrValidString":"$context.error.validationErrorString","ErrorMessg":"$context.error.message","RequestId":"$context.requestId","RequestPath":"$context.path","RequestTime":"$context.requestTime","ResourcePath":"$context.resourcePath","SourceIp":"$context.identity.sourceIp","Stage":"$context.stage", "StatusCode":"$context.status"}
  1. Set up a metric filter with the right json pattern, e.g. { $.StatusCode = 429 }
  2. Set up an alarm based on the filter

and voila !

Related