---
name: azion-read-the-report-log-for-one-instance
description: >-
  Query the functionConsoleEvents dataset over the GraphQL API for the report lines a Bot Manager Lite instance wrote, and read the values one line carries.
---

# Read the report log for one instance

You can read the report lines a [Bot Manager Lite](/en/documentation/platform/firewall/bot-manager/bot-manager-lite/) instance wrote by querying the `functionConsoleEvents` dataset over the GraphQL API. A scored request leaves one line behind it, carrying the score, the rules that produced it, and the verdict the function reached.

---

## Prerequisites

- A Bot Manager Lite instance with `internal_logs` at `2` and a `log_tag` of its own, run by a firewall rule. To create both, refer to [Run Bot Manager in observation mode](/en/documentation/guides/application-security/bots-and-network/observation-mode/) and [Run Bot Manager on every request](/en/documentation/guides/application-security/bots-and-network/run-on-every-request/); for the values those arguments take, refer to [Arguments](/en/documentation/platform/firewall/bot-manager/arguments/).
- A personal token. To create one, refer to [Personal Tokens](/en/documentation/fundamentals/personal-tokens/).

---

## Query the report lines

The `functionConsoleEvents` dataset serves these lines. Send the query to `https://api.azion.com/v4/events/graphql` with an `Authorization: Token [TOKEN VALUE]` header and a `tsRange` covering the window you care about:

```graphql
{
  functionConsoleEvents(
    limit: 200
    filter: { tsRange: { begin: "2026-01-01T11:30:00", end: "2026-01-01T13:00:00" } }
    orderBy: [ts_ASC]
  ) {
    ts
    line
    level
    lineSource
    functionId
    configurationId
  }
}
```

The response is `200`, with one record for each line the function wrote. `level` reads `LOG` and `lineSource` reads `CONSOLE` on a Bot Manager record. `functionId` is the id of the installed function, and `configurationId` is the id of the workload the request arrived on, not the id of the firewall that ran the instance. The [GraphiQL Playground](/en/documentation/devtools/graphql/graphql-playground/) runs the same query without a request of your own.

`line` carries the whole report line: a prefix, then one JSON object.

```text
[Bot-Protection][storefront-bots] Report:  {"request_id":"0123456789abcdef0123456789abcdef","remote_addr":"203.0.113.42","fingerprint":"ge20cn020000_000000000000_000000000000_000000000000","host":"<your-workload-domain>","http_user_agent":"","request_uri":"/","geoip_country":"BR","geoip_region":"SP","asn":"64496","score":28,"bot_category":"Bad Bot Signatures, Malicious Intent detected","classified":"legitimate","action":"allow","matched_rules":[1,10,18,19,20]}
```

Four values answer what the instance did with the request. `score` is the number the function reached, `matched_rules` holds the rules that produced it, `action` is what the function applied at the threshold in force, and `classified` is the verdict it recorded. For every field a line carries, refer to [Logs](/en/documentation/platform/firewall/bot-manager/logs/#fields).

> **Note**
>
> The second bracket of the prefix carries the `log_tag` from the instance's arguments, not the host. That tag is the only way to tell one instance's lines from another's, because every instance of the installed function shares `functionId`. Give each instance a tag of its own before you go looking for its lines. `configurationId` is the workload id, so a filter built around a firewall id returns nothing rather than an error. `classified` is relative to the threshold in force, not a property of the request; for how the threshold sets it, refer to [Bot scoring](/en/documentation/platform/firewall/bot-manager/bot-scoring/).

---

## Next steps

- [Refuse requests above the threshold](/en/documentation/guides/application-security/bots-and-network/refuse-above-threshold.md): Raise the action once the lines have shown you what your own traffic scores.
- [Logs](/en/documentation/platform/firewall/bot-manager/logs.md): Every field a report line carries, with what each one holds.
