GraphiQL Playground
Open GraphiQL on a GraphQL API endpoint URL, run queries in the browser, and adapt sample queries for the schema, attacks, and attack IPs.
The GraphiQL Playground is an in-browser editor for the GraphQL API. In it, you write, validate, and run queries against the endpoint URL that serves it, and the editor checks the query for errors as you type. Use it to explore the datasets and fields of an endpoint, and to test a query before you send it from code.
Access GraphiQL PlaygroundOpen the Playground
Each GraphQL API endpoint URL serves the Playground when you open it in a browser. The Playground of an endpoint runs only the datasets that endpoint serves:
| Endpoint URL | Data |
|---|---|
https://api.azion.com/v4/metrics/graphql | Aggregated metrics, such as the workloadMetrics dataset |
https://api.azion.com/v4/events/graphql | Raw events, such as the workloadEvents dataset |
https://api.azion.com/v4/billing/graphql | Billing data |
https://api.azion.com/v4/accounting/graphql | Accounting data |
https://api.azion.com/v4/consumption/graphql | Consumption data |
To open the Playground, sign in to Azion Console, then go to the endpoint URL in the same browser. Without a signed-in session, the URL returns HTTP 401 with this body instead of the Playground:
Run a query
To run a query, paste it into the Playground editor and run it. The Playground validates the query against the schema of its endpoint as you type and marks each error it finds. The response is JSON: a data object with one array per dataset in the query, or a detail message when the API refuses the query.
A query for a dataset the endpoint does not serve is refused. For example, a workloadEvents query sent to the metrics endpoint returns HTTP 400:
To run that query, open the Playground of the events endpoint instead.
Sample queries
The queries in this section run in the Playground as written. Each one names the endpoint whose Playground runs it. Paste a query, then change its fields, filters, and dates to see how the response changes.
Schema introspection
This introspection query runs in the Playground of any of the five endpoints. It returns the schema of that endpoint: every type, with its fields, arguments, and enum values, including the deprecated ones and the reason each one is deprecated:
The response names Query as the query type and returns null for the mutation and subscription types: the GraphQL API reads data and has no mutations.
Data transferred over time
The HttpCalculatedDataTransferred query reads the workloadMetrics dataset in the Playground of the metrics endpoint. It selects ts, dataTransferredIn, dataTransferredOut, and dataTransferredTotal for the window in tsRange, groups the rows by ts, sorts them with ts_ASC, and sets limit to 2000. The deprecated httpMetrics dataset takes the same query; use workloadMetrics.
Top IPs behind attacks
The TOP5IPsWAFRequests query reads the workloadEvents dataset, so it runs in the Playground of the events endpoint, https://api.azion.com/v4/events/graphql. It counts the requests WAF flagged as attacks, groups them by client IP address and attack family, and returns the five largest counts. In the Playground of the metrics endpoint, the same query returns HTTP 400.
The events endpoint keeps records for about 7 days. Replace the begin and end values with a window inside the last 7 days:
When WAF flagged no request in the window, the workloadEvents array comes back empty. For what each argument and field does, refer to Find the IPs behind attack traffic.
Top attack families
The Top5Attacks query reads the workloadMetrics dataset in the Playground of the metrics endpoint. It groups the requests by attack family, ranks the families by wafRequestsThreat, the number of requests WAF flagged as threats, and returns the five highest. Replace the begin and end values with your window:
For a window in which WAF flagged no request, the response holds one row, with - as the attack family and 0 threat requests:
For what each argument and field does, refer to Find the top attacks with GraphQL.