Send logs to Datadog
Create a stream that sends the logs of your applications to a Datadog log intake URL, in Azion Console or with the Azion API, and confirm the delivery.
You can send the logs of a stream to Datadog from Azion Console or with the Azion API.
Data Stream sends each batch of log lines to the log intake URL of your Datadog account and authenticates with a Datadog API key. In the stream form, the endpoint is set in the field labeled Connector, and Datadog is its Datadog option. For every field and its bounds, refer to Endpoints.
In this guide, the stream reads the requests that one workload receives, through the Applications data source.
Choose Console or API here. Every section of the page follows that choice.
Prerequisites
- An Azion account with the Edit Data Stream permission. For the permissions, refer to Stream settings.
- A workload on the account that receives requests.
- A Datadog account.
- The log intake URL of your Datadog account, with its scheme, such as
https://http-intake.logs.datadoghq.com/v1/input. - A Datadog API key, created in the Datadog dashboard.
- Access to Azion Console. To sign in, refer to How to access Azion Console.
Create the stream
A workload filter limits the stream to the workload you pick. Unlike a stream with sampling, a stream with a workload filter leaves your other streams active.
Send a POST request to https://api.azion.com/v4/workspace/stream/streams. In the body, put the ID of your workload in place of <workload-id>, and your intake URL and API key in the outputs entry. Use your personal token in place of [TOKEN VALUE]:
In the body, workloads is the API name of the Applications data source, and template 2 is Applications Event Collector. A 201 response returns the stream as Azion stored it:
The id identifies the stream in every later request, such as /v4/workspace/stream/streams/12354. For every key of the body, refer to Stream settings.
Neither the Console nor the API contacts Datadog when you save. A mistyped URL or an invalid API key shows up only as a failed send. The stream starts to send one to two minutes after you activate it.
Confirm the delivery
Each attempt of the stream to send a batch, successful or not, appears in Real-Time Events with the status code Datadog returned. Make a few requests to the workload and allow about a minute. The stream sends a batch every 60 seconds, or earlier when the batch holds 2,000 log lines.
To read the sends with the API, query the dataStreamedEvents dataset of the Real-Time Events GraphQL API. Replace the dates with a range that covers the activation of the stream:
The API answers 200 with one record for each send, the latest first:
A send to Datadog carries DATADOG in endpointType. A statusCode of 200 means Datadog accepted the batch, and streamedLines and dataStreamed give its size in log lines and bytes. An empty dataStreamedEvents list means the stream has not sent in the range. For every field, refer to Real-Time Events GraphQL fields.
Any status other than 200 is the answer of Datadog, except 503, which means Data Stream found the endpoint unavailable. For the causes, refer to Troubleshoot Data Stream.