Read the report log for one instance
Query the functionConsoleEvents dataset over the GraphQL API for the report lines a Bot Manager Lite instance wrote, and read the values one line carries.
You can read the report lines a Bot Manager Lite instance wrote by querying the functionConsoleEvents dataset over the GraphQL API. A scored request leaves one line behind it, carrying the score, the rules that produced it, and the verdict the function reached.
Prerequisites
- A Bot Manager Lite instance with
internal_logsat2and alog_tagof its own, run by a firewall rule. To create both, refer to Run Bot Manager in observation mode and Run Bot Manager on every request; for the values those arguments take, refer to Arguments. - A personal token. To create one, refer to Personal Tokens.
Query the report lines
The functionConsoleEvents dataset serves these lines. Send the query to https://api.azion.com/v4/events/graphql with an Authorization: Token [TOKEN VALUE] header and a tsRange covering the window you care about:
The response is 200, with one record for each line the function wrote. level reads LOG and lineSource reads CONSOLE on a Bot Manager record. functionId is the id of the installed function, and configurationId is the id of the workload the request arrived on, not the id of the firewall that ran the instance. The GraphiQL Playground runs the same query without a request of your own.
line carries the whole report line: a prefix, then one JSON object.
Four values answer what the instance did with the request. score is the number the function reached, matched_rules holds the rules that produced it, action is what the function applied at the threshold in force, and classified is the verdict it recorded. For every field a line carries, refer to Logs.