---
name: azion-query-http-request-events
description: >-
  Read the event records of requests to a workload from the workloadEvents dataset, in Azion Console and with a GraphQL query.
---

# Query HTTP request events

You can read the event record of a single request from [Real-Time Events](/en/documentation/platform/real-time-events/), in Azion Console or with a query to its GraphQL API. The records sit in the HTTP Requests data source, which the API serves as the `workloadEvents` dataset: one record per request an [application](/en/documentation/platform/applications/) or a [firewall](/en/documentation/platform/firewall/) received.

The two interfaces name the same value differently. Azion Console takes the variable name in lowercase with underscores, such as `status='400'`. The GraphQL API takes the camelCase field, such as `statusIn: [400]`.

---

## Prerequisites

- An application or a firewall already serving traffic, so the HTTP Requests data source holds records to read.
- A value that identifies the request: a host, an HTTP status code, or the request id a response carries in its `x-azion-request-id` header.
- Access to Azion Console, for the Console procedure. To sign in, refer to [How to access Azion Console](/en/documentation/guides/platform/account-and-billing/how-to-access-azion-console/).
- A personal token, for the GraphQL query. To create one, refer to [Personal Tokens](/en/documentation/fundamentals/personal-tokens/).

The period a query can ask for is bounded by how long an event record is kept. For that bound and the others a query carries, refer to [Limits](/en/documentation/platform/real-time-events/limits/).

---

## Read the record of a request

**Console**

A search is one data source, one period, and one filter over them. To open the record of a request in Azion Console:

1. **Open Real-Time Events**

   Access [Azion Console](https://console.azion.com) > **Products menu** > **Observe** > **Real-Time Events**.

2. **Select the data source**

   In **Data Sources**, select *HTTP Requests*.

3. **Set the period**

   In **Time Filter**, select a period that contains the request. The filter opens on *Last 15 minutes*.

4. **Narrow the result**

   In **Filter by**, enter a condition built from the values you have:

   ```text
   host='<your-workload-domain>' AND status='400'
   ```

5. **Select Refresh**

6. **Open the record**

   Select the row of the request in the results table.

The **More details** view opens, carrying every variable the HTTP Requests data source holds for that one request.

**Filter by** reads SQL, and `AND`, `OR`, and `NOT` combine terms. For the full syntax, refer to [Filter events](/en/documentation/guides/platform/observability/add-filters-events/). For what each variable of this data source means, refer to [Data sources](/en/documentation/platform/real-time-events/data-sources/).

> **Note**
>
> Azion Console also offers a newer Real-Time Events view, in Preview, reached from **Switch to new view**. The steps above follow the classic view, which is the one Real-Time Events opens on.

**API**

The GraphQL API serves the same records at `https://api.azion.com/v4/events/graphql`. That address also serves the GraphiQL Playground in a browser: sign in to Azion Console at `https://console.azion.com`, then open the endpoint. To send the query from a terminal instead, post it with an `Authorization: Token [TOKEN VALUE]` header, as [GraphQL API first steps](/en/documentation/devtools/graphql/first-steps/) describes.

A query over `workloadEvents` carries the same three choices. `tsRange` bounds the period, a filter argument such as `requestIdEq` narrows what is read inside it, and the selection set names the fields the response comes back with.

To return the record of one request, replacing the timestamps and the request id with your own:

```graphql
{
  workloadEvents(
    limit: 1
    filter: {
      tsRange: { begin: "2026-01-01T11:55:00", end: "2026-01-01T12:05:00" }
      requestIdEq: "0123456789abcdef0123456789abcdef"
    }
  ) {
    ts
    requestId
    host
    status
    upstreamStatus
  }
}
```

The query returns a single row:

```json
{
  "ts": "2026-01-01T12:00:00Z",
  "requestId": "0123456789abcdef0123456789abcdef",
  "host": "<your-workload-domain>",
  "status": 400,
  "upstreamStatus": 0
}
```

The row is the event record of that request. An `upstreamStatus` of `0` means the request never reached an origin.

A response carries the fields the query selected and no others, so reading more of a record means naming more fields. For every field `workloadEvents` carries, refer to [Real-Time Events GraphQL API fields](/en/documentation/devtools/graphql/gql-real-time-events-fields/).

---

## Next steps

- [Filter events](/en/documentation/guides/platform/observability/add-filters-events.md): The whole Filter by syntax, with an example condition per variable.
- [Read an event record](/en/documentation/guides/platform/observability/understand-logs.md): What the values of an open record mean, variable by variable.
- [Investigate a request with the GraphQL API](/en/documentation/guides/platform/observability/investigate-requests-graphql-api.md): Group the records by country and host before narrowing to a single one.
- [Data sources](/en/documentation/platform/real-time-events/data-sources.md): The eight data sources, the dataset behind each one, and the variables it carries.
