---
name: azion-read-an-event-record
description: >-
  Open one record from a Real-Time Events search and read its variables, and choose between a general search and a filtered one for the question you have.
---

# Read an event record

You can read one event record of [Real-Time Events](/en/documentation/platform/real-time-events/) from Azion Console. What the record answers depends on the variables you read. Each data source carries its own set of preorganized variables. They report on the access, the behavior, and the performance of your applications and the related products.

For every variable a data source carries, with its description and an example, refer to [Data sources](/en/documentation/platform/real-time-events/data-sources/).

Two searches lead to that record. Run a [general search](#run-a-general-search) to return every record a data source wrote in the period. Run a [filtered search](#run-a-filtered-search) instead to return only the records that match the values you name.

---

## Prerequisites

- An Azion account. To create one, refer to [How to create an account on Azion](/en/documentation/fundamentals/creating-account/).
- Access to Azion Console. To sign in, refer to [How to access Azion Console](/en/documentation/guides/platform/account-and-billing/how-to-access-azion-console/).
- A product that already wrote records to the data source you want to search.

---

## Run a general search

A general search returns every record a data source wrote in the period, with every variable it carries. Run one when you want as much information as possible, or when you do not yet know what to investigate.

To run a general search in Azion Console:

1. **Open Real-Time Events**

   Access [Azion Console](https://console.azion.com) > **Products menu** > **Observe** > **Real-Time Events**.

2. **Select the data source**

   In **Data Sources**, select the product whose records you want to read.

3. **Set the period**

   In **Time Filter**, select the period the search covers.

4. **Leave Filter by empty**

5. **Select Refresh**

The results table holds every record that data source wrote in the period.

Consider an application that does not show what you configured on a [function](/en/documentation/platform/functions/). Select the **Functions** data source and read every variable of the records it returns. They show whether the right function ran, and what message it returned.

---

## Run a filtered search

A filtered search returns only the records that match the variables and values you name. Run one when you already know what you are going to analyze.

To run a filtered search in Azion Console:

1. **Open Real-Time Events**

   Access [Azion Console](https://console.azion.com) > **Products menu** > **Observe** > **Real-Time Events**.

2. **Select the data source**

   In **Data Sources**, select the product whose records you want to read.

3. **Set the period**

   In **Time Filter**, select the period the search covers.

4. **Enter the filter**

   In **Filter by**, enter one condition per variable you want to match.

5. **Select Refresh**

The results table holds only the records that match the filter.

Consider a suspicion that malicious users are trying to reach your application. Select the **HTTP Requests** data source and filter on the variables that identify the client. `Host`, `HTTP Referer`, `Remote Address`, and `Request Uri` each narrow the result to a different property of the request.

For the full **Filter by** syntax, with an example per variable, refer to [Filter events](/en/documentation/guides/platform/observability/add-filters-events/).

---

## Search by request ID

A request ID reaches the record of one request and no others. The `requestId` field stores a unique identifier for each request, such as `5f222ae5938482c32a822dbf15e19f0f`.

A value you take from an HTTP response header, such as `X-Request-Id`, can carry a numeric suffix after a hyphen. For example: `5f222ae5938482c32a822dbf15e19f0f-1234`. The network layer appends that suffix, and the event record does not store it.

Search Real-Time Events, or the [GraphQL API](/en/documentation/devtools/graphql/overview/), with the base identifier alone. A search that includes the suffix can return no results, or a `400` error.

Where the header returns `5f222ae5938482c32a822dbf15e19f0f-1234`, filter by `5f222ae5938482c32a822dbf15e19f0f`.

---

## Open one record

A row in the results table shows a few variables of the record behind it. Opening the record shows the rest.

To open one record in Azion Console, select its row in the results table.

The **More details** view opens. It carries every variable of that data source for the record you selected.

For what each of those variables means, refer to [Data sources](/en/documentation/platform/real-time-events/data-sources/).

---

## Next steps

- [Data sources](/en/documentation/platform/real-time-events/data-sources.md): Every data source, the dataset that holds its records, and the variables each one carries.
- [Filter events](/en/documentation/guides/platform/observability/add-filters-events.md): The full Filter by syntax, with an example query per variable.
- [Real-Time Events quickstart](/en/documentation/platform/real-time-events/quickstart.md): Open Real-Time Events, search one data source, and narrow the result to a single request.
- [Investigate a request with the GraphQL API](/en/documentation/guides/platform/observability/investigate-requests-graphql-api.md): Count the records first, then narrow to one status code and read the client behind it.
