Send logs to Apache Kafka
Create a stream that sends the logs of your applications as messages to an Apache Kafka topic, in Azion Console or with the Azion API.
You can send the logs of a stream to a topic of an Apache Kafka cluster from Azion Console or with the Azion API. To send the WAF events of a firewall to a SIEM, refer to Stream WAF events to a SIEM.
Data Stream sends the log lines as messages to one topic of the cluster. In the stream form, the endpoint is set in the field labeled Connector, and Apache Kafka is one of its options. For every field and its bounds, refer to Endpoints.
The example collects the requests of one workload with the Applications data source.
Select your interface once. The prerequisites and every task below show only that path.
Prerequisites
- An Azion account with the Edit Data Stream permission. For the permissions, refer to Stream settings.
- A workload on the account that receives requests.
- An Apache Kafka cluster and the host and port of the servers for the initial connection. You need only these servers, not every server of the cluster.
- The name of the topic that receives the messages. The stream sends to one topic.
- To encrypt the data with Transport Layer Security (TLS), a digital certificate on the receiving servers, issued by a trusted certificate authority (CA) such as IdenTrust, DigiCert, Sectigo, GoDaddy, GlobalSign, or Let’s Encrypt.
The Apache Kafka endpoint has no credential field: the stream connects with the server addresses, the topic, and the TLS setting.
- Access to Azion Console. To sign in, refer to How to access Azion Console.
Create the stream
The stream collects from the workload you choose, through a workload filter. Unlike sampling, a workload filter leaves your other streams active.
To create the stream with the API, send a POST request to https://api.azion.com/v4/workspace/stream/streams. Replace [TOKEN VALUE] with your personal token, <workload-id> with the ID of your workload, and the cluster values with your own:
The workloads data source is Applications in the Console, and template 2 is Applications Event Collector. The API requires use_tls: send true to encrypt the data with TLS, or false to send it unencrypted. The API answers 201 with the stored stream:
Keep the id: it identifies the stream in every later request, such as /v4/workspace/stream/streams/12348. For every key of the body, refer to Stream settings.
The API and the Console save the stream without contacting the cluster. A wrong server address or topic surfaces only when the stream sends. An activation takes effect after one to two minutes.
Confirm the delivery
Real-Time Events records every send of a stream, delivered or not, with the status code the endpoint returned. Send a few requests to the workload, then wait about a minute. A stream sends a batch every 60 seconds, or sooner when it reaches 2,000 log lines.
To read the sends with the API, query the dataStreamedEvents dataset of the Real-Time Events GraphQL API. Replace the dates with a range that covers the activation of the stream:
The API answers 200 with one record for each send, the latest first:
A send to Apache Kafka carries KAFKA in endpointType. A statusCode of 200 means the endpoint accepted the batch, and streamedLines and dataStreamed give its size in log lines and bytes. An empty dataStreamedEvents list means the stream has not sent in the range. For every field, refer to Real-Time Events GraphQL fields.
A status other than 200 is the answer of the endpoint, and 503 means Data Stream found the endpoint unavailable. For the causes, refer to Troubleshoot Data Stream.