TF 0371 - SymbioticSec/Symbiotic-Vulnerability-Database GitHub Wiki

SAM State machine must have X-Ray tracing enabled

Property Value
Language terraform
Severity low
Service sam
Provider AWS

Description

The AWS SAM State Machine is configured without X-Ray tracing enabled, preventing comprehensive tracing and visibility into the execution flow of state machine activities. This limits the ability to debug and analyze distributed workflows.

Impact

Without X-Ray tracing, failures and performance issues within the state machine are difficult to track and diagnose, leading to longer incident response times and increased operational risk. This lack of observability can hinder troubleshooting and may allow issues or malicious activity to go undetected.

Resolution

Enable tracing