Send logs to AWS Kinesis Data Firehose
Create a stream that sends the logs of your applications to an Amazon Kinesis Data Firehose delivery stream, in Azion Console or with the Azion API.
You can send the logs of a stream to an Amazon Kinesis Data Firehose delivery stream from Azion Console or with the Azion API. To write the logs straight to an Amazon S3 bucket, with no delivery stream in between, refer to Send logs to Amazon S3.
Data Stream sends the log lines to the delivery stream in batches. In the stream form, the endpoint is set in the field labeled Connector, and Kinesis is its AWS Kinesis Data Firehose option. For every field and its bounds, refer to Endpoints.
The example collects the requests of one workload with the Applications data source.
Select your interface once. The prerequisites and every task below show only that path.
Prerequisites
- An Azion account with the Edit Data Stream permission. For the permissions, refer to Stream settings.
- A workload on the account that receives requests.
- An AWS account with an Amazon Kinesis Data Firehose delivery stream. The delivery stream must use Direct PUT as its source, and it needs a destination, such as an Amazon S3 bucket.
- The name of the delivery stream, up to 64 characters.
- The region code where the delivery stream runs, such as
us-east-1. - An AWS access key: an access key ID and its secret access key, created in AWS Identity and Access Management (IAM).
- Access to Azion Console. To sign in, refer to How to access Azion Console.
Create the stream
A workload filter limits the stream to the workload you choose. Sampling would deactivate your other streams, and a workload filter keeps them active.
To create the stream with the API, send a POST request to https://api.azion.com/v4/workspace/stream/streams. Replace [TOKEN VALUE] with your personal token, <workload-id> with the ID of your workload, and the delivery stream values with your own:
The workloads data source is Applications in the Console, and template 2 is Applications Event Collector. The API answers 201 with the stored stream:
Keep the id. It identifies the stream in every later request, such as /v4/workspace/stream/streams/12353. For every key of the body, refer to Stream settings.
The API and the Console save the stream without contacting AWS. A wrong stream name, region, or access key surfaces only when the stream sends. An activation takes effect after one to two minutes.
Confirm the delivery
Real-Time Events records every send of a stream, delivered or not, with the status code the endpoint returned. Send a few requests to the workload, then wait about a minute. A stream sends a batch to Kinesis every 60 seconds, or sooner when it reaches 500 log lines.
To read the sends with the API, query the dataStreamedEvents dataset of the Real-Time Events GraphQL API. Replace the dates with a range that covers the activation of the stream:
The API answers 200 with one record for each send, the latest first:
A send to Kinesis carries AWS_KINESIS_FIREHOSE in endpointType. A statusCode of 200 means the endpoint accepted the batch, and streamedLines and dataStreamed give its size in log lines and bytes. An empty dataStreamedEvents list means the stream has not sent in the range. For every field, refer to Real-Time Events GraphQL fields.
A status other than 200 is the answer of the endpoint, and 503 means Data Stream found the endpoint unavailable. For the causes, refer to Troubleshoot Data Stream.