Send logs to Azure Blob Storage
Create a stream that writes the logs of your applications to an Azure Blob Storage container, in Azion Console or with the Azion API, and confirm the delivery.
You can send the logs of a stream to an Azure Blob Storage container from Azion Console or with the Azion API. To send them to a workspace in Azure Monitor instead, refer to Send logs to Azure Monitor.
Data Stream writes the log lines to a container of your Azure storage account. The stream form sets the endpoint in the field labeled Connector, where Azure Blob Storage is the Azure Blob Storage option. For every field and its bounds, refer to Endpoints.
The example collects the requests of one workload with the Applications data source.
Select your interface once. The prerequisites and every task below show only that path.
Prerequisites
- An Azion account with the Edit Data Stream permission. For the permissions, refer to Stream settings.
- A workload on the account that receives requests.
- An Azure storage account and its name, such as
mystorageaccount. - A container in the storage account. The container must exist before the stream sends to it.
- A shared access signature (SAS) token for the container, with the create, read, write, and list permissions.
- Access to Azion Console. To sign in, refer to How to access Azion Console.
Create the stream
A workload filter selects the workload the stream collects from. Your other streams stay active, which is not the case with sampling.
To create the stream with the API, send a POST request to https://api.azion.com/v4/workspace/stream/streams. Replace [TOKEN VALUE] with your personal token, <workload-id> with the ID of your workload, and the storage values with your own:
The workloads data source is Applications in the Console, and template 2 is Applications Event Collector. The API answers 201 with the stored stream:
The id identifies the stream in every later request, such as /v4/workspace/stream/streams/12357. For every key of the body, refer to Stream settings.
Neither the API nor the Console contacts the container when it saves the stream. A wrong storage account, container name, or SAS token appears only when the stream sends. An activation takes effect after one to two minutes.
Confirm the delivery
Real-Time Events records every send of a stream, with the status code the endpoint returned, whether the send succeeds or fails. Send a few requests to the workload, then wait about a minute. A stream sends a batch every 60 seconds, or earlier when the batch reaches 2,000 log lines.
To read the sends with the API, query the dataStreamedEvents dataset of the Real-Time Events GraphQL API. Replace the dates with a range that starts at the activation of the stream:
The API answers 200 with one record for each send, the latest first:
A send to Azure Blob Storage carries AZURE_BLOB_STORAGE in endpointType. A statusCode of 200 means the container accepted the batch of streamedLines log lines and dataStreamed bytes. An empty dataStreamedEvents list means the stream has not sent in the range. For every field, refer to Real-Time Events GraphQL fields.
A status other than 200 comes from the endpoint, except 503, which means Data Stream found the endpoint unavailable. For the causes, refer to Troubleshoot Data Stream.