Send logs to Azure Monitor
Create a stream that sends the logs of your applications to an Azure Monitor workspace, in Azion Console or with the Azion API, and confirm the delivery.
You can send the logs of a stream to an Azure Monitor workspace from Azion Console or with the Azion API. To write the logs as files in an Azure storage container instead, refer to Send logs to Azure Blob Storage.
Data Stream sends each batch of log lines to the workspace, which stores them in the table that Log Type names. In the stream form, the endpoint is set in the field labeled Connector, and the Azure Monitor option selects this endpoint. For every field and its bounds, refer to Endpoints.
The example collects the requests of one workload with the Applications data source.
Select your interface once. The prerequisites and every task below show only that path.
Prerequisites
- An Azion account with the Edit Data Stream permission. For the permissions, refer to Stream settings.
- A workload on the account that receives requests.
- An Azure account with a Log Analytics workspace, added to Microsoft Sentinel.
- The Workspace ID and the Primary Key of the workspace. The workspace shows both under Agents Management. The Primary Key is the credential of the stream.
- Access to Azion Console. To sign in, refer to How to access Azion Console.
Create the stream
The stream collects from the workload you choose, through a workload filter. A workload filter keeps your other streams active, which sampling does not.
To create the stream with the API, send a POST request to https://api.azion.com/v4/workspace/stream/streams. Replace [TOKEN VALUE] with your personal token, <workload-id> with the ID of your workload, and the workspace values with your own:
The workloads data source is Applications in the Console, and template 2 is Applications Event Collector. The API answers 201 with the stored stream:
Keep the id: it identifies the stream in every later request, such as /v4/workspace/stream/streams/12356. The time_generated_field key is optional: omit it to use the ingestion time. For every key of the body, refer to Stream settings.
The API and the Console save the stream without contacting the workspace. A wrong workspace ID or key surfaces only when the stream sends. An activation takes effect after one to two minutes.
Confirm the delivery
Real-Time Events records every send of a stream, delivered or not, with the status code the endpoint returned. Send a few requests to the workload, then wait about a minute: a stream sends a batch every 60 seconds, or sooner when it reaches 2,000 log lines.
To read the sends with the API, query the dataStreamedEvents dataset of the Real-Time Events GraphQL API. Replace the dates with a range that covers the activation of the stream:
The API answers 200 with one record for each send, the latest first:
A send to Azure Monitor carries AZURE_MONITOR in endpointType. A statusCode of 200 means the endpoint accepted the batch of streamedLines log lines and dataStreamed bytes. An empty dataStreamedEvents list means the stream has not sent in the range. For every field, refer to Real-Time Events GraphQL fields.
A status other than 200 is the answer of the endpoint, and 503 means Data Stream found the endpoint unavailable. For the causes, refer to Troubleshoot Data Stream.
In Azure, open the Logs section of the workspace and query the table that Log Type names. Its records are the log lines of the stream.