Send logs to Amazon S3
Create a stream that writes the logs of your applications as objects in an Amazon S3 bucket, in Azion Console or with the Azion API, and confirm the delivery.
You can send the logs of a stream to an Amazon S3 bucket from Azion Console or with the Azion API. To send them to an Azion Object Storage bucket, whose credential needs other capabilities, refer to Send Data Stream data to Object Storage.
Data Stream writes each batch of log lines as one object in the bucket. In the stream form, the endpoint is set in the field labeled Connector, and Amazon S3 is its Simple Storage Service (S3) option. For every field and its bounds, refer to Endpoints.
The example collects the requests of one workload with the Applications data source.
Select your interface once. The prerequisites and every task below show only that path.
Prerequisites
- An Azion account with the Edit Data Stream permission. For the permissions, refer to Stream settings.
- A workload on the account that receives requests.
- An Amazon S3 bucket. The bucket must exist before the stream sends to it. It can use server-side encryption with Amazon S3 managed keys (SSE-S3).
- The region code of the bucket, such as
us-east-1. - An AWS Identity and Access Management (IAM) credential with an access key ID and a secret access key. The credential needs the
s3:ListBucketpermission, to list the objects of the bucket, and thes3:PutObjectpermission, to write objects in it.
- Access to Azion Console. To sign in, refer to How to access Azion Console.
Create the stream
The stream collects from the workload you choose, through a workload filter. Unlike sampling, a workload filter leaves your other streams active.
To create the stream with the API, send a POST request to https://api.azion.com/v4/workspace/stream/streams. Replace [TOKEN VALUE] with your personal token, <workload-id> with the ID of your workload, and the bucket values with your own:
The workloads data source is Applications in the Console, and template 2 is Applications Event Collector. The API answers 201 with the stored stream:
Keep the id: it identifies the stream in every later request, such as /v4/workspace/stream/streams/12349. For every key of the body, refer to Stream settings.
The API and the Console save the stream without contacting the bucket. A wrong URL, region, or credential surfaces only when the stream sends. An activation takes effect after one to two minutes.
Confirm the delivery
Real-Time Events records every send of a stream, delivered or not, with the status code the endpoint returned. Send a few requests to the workload, then wait about a minute: a stream sends a batch every 60 seconds, or sooner when it reaches 2,000 log lines.
To read the sends with the API, query the dataStreamedEvents dataset of the Real-Time Events GraphQL API. Replace the dates with a range that covers the activation of the stream:
The API answers 200 with one record for each send, the latest first:
A statusCode of 200 means the bucket accepted the batch, and streamedLines and dataStreamed give its size in log lines and bytes. An empty dataStreamedEvents list means the stream has not sent in the range. For every field, refer to Real-Time Events GraphQL fields.
A status other than 200 is the answer of the endpoint, and 503 means Data Stream found the endpoint unavailable. For the causes, refer to Troubleshoot Data Stream.
In the bucket, each object name is the Object Key Prefix, a /, the date and time of the send in the YYYY/MM/DD/hh/mm/ format, and a UUID. With the prefix azion/logs, an object name starts with a path such as azion/logs/2026/01/01/12/02/, followed by the UUID.