Send logs to Elasticsearch
Create a stream that sends the logs of your applications to an Elasticsearch index, in Azion Console or with the Azion API, and confirm the delivery.
You can send the logs of a stream to an Elasticsearch index from Azion Console or with the Azion API.
Data Stream sends each batch of log lines to the index that ends the URL of the endpoint. In the stream form, the endpoint is set in the field labeled Connector, and Elasticsearch is one of its options. For every field and its bounds, refer to Endpoints.
The example collects the requests of one workload with the Applications data source.
Select your interface once. The prerequisites and every task below show only that path.
Prerequisites
- An Azion account with the Edit Data Stream permission. For the permissions, refer to Stream settings.
- A workload on the account that receives requests.
- An Elasticsearch instance. It can run on any cloud platform, such as an Elastic Cloud deployment.
- The URL of the instance followed by the name of the index, such as
https://elasticsearch.example.com/azion-logs. On Elastic Cloud, the Copy endpoint action of the deployment gives the address of the instance. - An Elasticsearch API key. When Elasticsearch creates the key, it returns an
encodedvalue in Base64. Data Stream takes thatencodedvalue. On Elastic Cloud, you create the key in the API console of the deployment.
- Access to Azion Console. To sign in, refer to How to access Azion Console.
Create the stream
The stream collects from the workload you choose, through a workload filter. Saving a stream with sampling deactivates your other streams, and a workload filter does not.
To create the stream with the API, send a POST request to https://api.azion.com/v4/workspace/stream/streams. Replace [TOKEN VALUE] with your personal token, <workload-id> with the ID of your workload, [API KEY] with the encoded value of your API key, and the URL with your own:
The workloads data source is Applications in the Console, and template 2 is Applications Event Collector. The API answers 201 with the stored stream:
The id identifies the stream in every later request, such as /v4/workspace/stream/streams/12351. For every key of the body, refer to Stream settings.
The API and the Console save the stream without contacting the instance. A wrong URL, index, or API key surfaces only when the stream sends. An activation takes effect after one to two minutes.
Confirm the delivery
Real-Time Events records every send of a stream, delivered or not, with the status code the endpoint returned. Send a few requests to the workload, then wait about a minute: a stream sends a batch every 60 seconds, or sooner when it reaches 2,000 log lines.
To read the sends with the API, query the dataStreamedEvents dataset of the Real-Time Events GraphQL API. Replace the dates with a range that covers the activation of the stream:
The API answers 200 with one record for each send, the latest first:
For a stream that sends to Elasticsearch, endpointType reads ELASTICSEARCH. A statusCode of 200 means the endpoint accepted the batch, and streamedLines and dataStreamed give its size in log lines and bytes. An empty dataStreamedEvents list means the stream has not sent in the range. For every field, refer to Real-Time Events GraphQL fields.
A status other than 200 is the answer of the endpoint, and 503 means Data Stream found the endpoint unavailable. For the causes, refer to Troubleshoot Data Stream.