Send logs to Splunk
Create a stream that sends application logs to a Splunk HTTP Event Collector, in Azion Console or with the Azion API, and confirm the delivery.
You can send the logs of a stream to Splunk from Azion Console or with the Azion API.
Data Stream sends each batch of log lines to the HTTP Event Collector (HEC) of your Splunk instance and authenticates with a HEC token. In the stream form, the endpoint is set in the field labeled Connector, and Splunk is its Splunk option. For every field and its bounds, refer to Endpoints.
The example collects the requests of one workload with the Applications data source.
Select your interface once. The prerequisites and every task below show only that path.
Prerequisites
- An Azion account with the Edit Data Stream permission. For the permissions, refer to Stream settings.
- A workload on the account that receives requests.
- A Splunk account.
- An HTTP Event Collector set up for the type of your Splunk instance, and its URL. The URL format depends on the instance type: self-hosted or Splunk Cloud. For the formats, refer to Endpoints.
- A HEC token. The token must be enabled in Splunk.
- Access to Azion Console. To sign in, refer to How to access Azion Console.
Create the stream
The stream collects from the workload you choose, through a workload filter. A workload filter, unlike sampling, does not deactivate your other streams.
To create the stream with the API, send a POST request to https://api.azion.com/v4/workspace/stream/streams. Replace [TOKEN VALUE] with your personal token, <workload-id> with the ID of your workload, and the Splunk values with your own:
The workloads data source is Applications in the Console, and template 2 is Applications Event Collector. The api_key attribute takes the HEC token. The API answers 201 with the stored stream:
The id identifies the stream in every later request, such as /v4/workspace/stream/streams/12352. For every key of the body, refer to Stream settings.
The API and the Console save the stream without contacting Splunk. A wrong URL or HEC token surfaces only when the stream sends. An activation takes effect after one to two minutes.
Confirm the delivery
Real-Time Events records every send of a stream, delivered or not, with the status code the endpoint returned. Send a few requests to the workload, then wait about a minute: a stream sends a batch every 60 seconds, or sooner when it reaches 2,000 log lines.
To read the sends with the API, query the dataStreamedEvents dataset of the Real-Time Events GraphQL API. Replace the dates with a range that covers the activation of the stream:
The API answers 200 with one record for each send, the latest first:
A send to Splunk carries SPLUNK in endpointType. A statusCode of 200 means Splunk accepted the batch, and streamedLines and dataStreamed give its size in log lines and bytes. An empty dataStreamedEvents list means the stream has not sent in the range. For every field, refer to Real-Time Events GraphQL fields.
Any status other than 200 is the answer of Splunk, except 503, which means Data Stream found the endpoint unavailable. For the causes, refer to Troubleshoot Data Stream.