Send logs to Google BigQuery
Create a stream that writes the logs of your applications as rows in a Google BigQuery table, in Azion Console or with the Azion API, and confirm the delivery.
You can send the logs of a stream to a table in Google BigQuery from Azion Console or with the Azion API.
Data Stream sends the log lines as rows to a table of a BigQuery dataset. In the stream form, the endpoint is set in the field labeled Connector, and BigQuery is its Google BigQuery option. For every field and its bounds, refer to Endpoints.
The stream signs in to Google with a service account key that you provide. Data Stream performs the Google OAuth 2.0 authentication and generates the JSON Web Tokens, so the key is the only credential you set. The example collects the requests of one workload with the Applications data source.
Select your interface once. The prerequisites and every task below show only that path.
Prerequisites
- An Azion account with the Edit Data Stream permission. For the permissions, refer to Stream settings.
- A workload on the account that receives requests.
- A Google Cloud project with the BigQuery API enabled, and the ID of the project.
- Billing enabled on the project. The free tier does not accept rows streamed into a table. Google Cloud lists the fees for these inserts under Streaming Inserts in the BigQuery price table.
- A dataset in the project, and its dataset ID. The dataset ID is case sensitive.
- A table in the dataset, with a schema for the data the stream sends, and its table ID. The table ID is the name you give the table.
- A Google Cloud service account with the BigQuery Admin role, and a key of the service account in JSON format. Google Cloud downloads the key as a JSON file when you create it.
The key file holds the keys below. Data Stream takes the whole content of the file:
- Access to Azion Console. To sign in, refer to How to access Azion Console.
Create the stream
The stream collects from the workload you choose, through a workload filter. A workload filter keeps your other streams active, which a sampled stream does not.
To create the stream with the API, send a POST request to https://api.azion.com/v4/workspace/stream/streams. Replace [TOKEN VALUE] with your personal token, <workload-id> with the ID of your workload, and the table values with your own. Replace [SERVICE ACCOUNT KEY] with the content of the key file as one JSON string, with each quotation mark and backslash of the file escaped with a \:
The workloads data source is Applications in the Console, and template 2 is Applications Event Collector. The API answers 201 with the stored stream:
Keep the id: it identifies the stream in every later request, such as /v4/workspace/stream/streams/12350. For every key of the body, refer to Stream settings.
The API and the Console save the stream without contacting Google Cloud. A wrong project, dataset, table, or key surfaces only when the stream sends. An activation takes effect after one to two minutes.
Confirm the delivery
Real-Time Events records every send of a stream, delivered or not, with the status code the endpoint returned. Send a few requests to the workload, then wait about a minute: a stream sends a batch every 60 seconds, or sooner when it reaches 2,000 log lines.
To read the sends with the API, query the dataStreamedEvents dataset of the Real-Time Events GraphQL API. Replace the dates with a range that covers the activation of the stream:
The API answers 200 with one record for each send, the latest first:
A send to BigQuery carries BIG_QUERY in endpointType. A statusCode of 200 means the endpoint accepted the batch, and an empty dataStreamedEvents list means the stream has not sent in the range. For every field, refer to Real-Time Events GraphQL fields.
A status other than 200 is the answer of the endpoint, and 503 means Data Stream found the endpoint unavailable. For the causes, refer to Troubleshoot Data Stream.