Data sources and variables
Look up the four data sources a stream reads and every variable each one offers, with an example value and the preset templates that carry it.
A data source is where the logs of a Data Stream stream come from. Each stream reads one data source, and that choice decides which variables its template can place in a log line. A variable holds one piece of information about an event and belongs to a specific data source.
Azion Console names each data source differently from its API slug. The Console sets it in the Data Source field of the Input section, and the API in inputs[0].attributes.data_source:
| Console option | API slug | Carries | Needs on the account |
|---|---|---|---|
| Activity History | activity_history | The changes made on the account in Azion Console | none |
| Applications | workloads | The requests made to your applications | none |
| Functions | functions_console | The requests your functions handle and the messages they log | Functions |
| WAF Events | waf | The requests WAF analyzed | Firewall with WAF |
In a template’s Data Set, a variable is written with a leading $, such as $request_id. The In preset column of each table below names the preset templates whose Data Set carries the variable, or reads none. In the list of streams, the Source column shows the API slug rather than the Console option.
The API lists the data sources with a GET request:
Each result carries the slug you send in a stream, the API name, and active. The API name reads Workloads and Functions Console where the Console shows Applications and Functions. A data_source outside the four slugs is refused with 10039, as listed in Stream settings.
Activity History
Activity History carries the account’s Activity History: each change a user makes on the account in Azion Console. These events belong to the account rather than to a workload, so a stream on this data source uses sampling, as described in Stream settings.
| Variable | Description | Example | In preset |
|---|---|---|---|
$account_id | Identifier of the Azion account. | 8437 | Activity History Collector |
$author_email | Email address of the Azion Console user who made the change. | user@example.com | Activity History Collector |
$author_name | Name of the Azion Console user who made the change. | User name | Activity History Collector |
$client | Unique identifier of the Azion customer. | 4529r | Activity History Collector |
$comment | Comment the user can add when making the change. Optional. | Changed Rule | Activity History Collector |
$created_at | Date and time the resource was created. Use it to filter and sort by creation time. | 2026-01-01T12:00:00Z | none |
$parent_resource_id | Unique identifier of the parent resource, when there is one. | 1234567890 | Activity History Collector |
$parent_resource_name | Name of the parent resource, when there is one. | APIv4 | Activity History Collector |
$parent_resource_type | Type of the parent resource, when there is one. | Application | Activity History Collector |
$referer_header | Referer header of the page that called the API. Present only when the call comes from an interface. | https://console.azion.com/applications/edit/1234567890/rules-engine | Activity History Collector |
$remote_port | Source port of the request. | 80 | Activity History Collector |
$request_data | Payload of the request the user sent. | {"id": 123456, "name": "Debug rule", "active": true, …} | Activity History Collector |
$resource_id | Unique identifier of the resource created or changed. | 123456 | Activity History Collector |
$resource_name | Name of the resource created or changed. | Debug rule | Activity History Collector |
$resource_type | Type of the resource created or changed. | Application Response Rule | Activity History Collector |
$time | Date and time of the request. | 2026-01-01T12:00:00Z | Activity History Collector |
$title | Title of the activity, made of the model name, the resource name, and the type of action. | Application Response Rule Debug rule was edited | Activity History Collector |
$type | Type of action performed in Azion Console. | edited | Activity History Collector |
$user_agent | User-Agent header of the request. | Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/146.0.0.0 Safari/537.36 | Activity History Collector |
$user_id | Unique identifier of the user who made the change. | 1234 | Activity History Collector |
$user_ip | IP address of the user or source that sent the request. | 203.0.113.10 | Activity History Collector |
Applications
Applications carries the requests made to your Applications. Its API slug is workloads, and a stream on it collects from every workload on the account or from a list of workloads, set in Stream settings.
Two presets read this data source. Applications Event Collector carries 36 variables. Applications + WAF Event Collector carries 51. It adds seven WAF variables and $asn, $request_id, $server_addr, $server_port, $session_id, $ssl_server_name, $ssl_session_reused, $stream, $upstream_addr, and $upstream_bytes_sent. It leaves out $upstream_local_addr and $version. To correlate a log line with other records of the same request, use $request_id, the unique identifier of the request, which the Functions data source also carries.
| Variable | Description | Example | In preset |
|---|---|---|---|
$asn | Autonomous System Number (ASN): a network of IP addresses that one or more operators manage under one routing policy. | AS52580 | Applications + WAF Event Collector |
$bytes_sent | Number of bytes sent to the client. | 191 | Applications Event Collector, Applications + WAF Event Collector |
$client | Unique identifier of the Azion customer. | 4529r | Applications Event Collector, Applications + WAF Event Collector |
$configuration | Unique identifier of the Azion configuration, set in the virtual host configuration file. | 1595368520 | Applications Event Collector, Applications + WAF Event Collector |
$country | Country of the client, from IP address geolocation. | United States | Applications Event Collector, Applications + WAF Event Collector |
$host | Host of the request: the host name in the request line, the host name in the Host request header, or the server name that matches the request. | none | Applications Event Collector, Applications + WAF Event Collector |
$http_referrer | Value of the Referer header: the address of the page the request came from. | https://example.com | Applications Event Collector, Applications + WAF Event Collector |
$http_user_agent | Value of the User-Agent header: the application, operating system, vendor, or version of the client. | Mozilla/5.0 (Windows NT 10.0; Win64; x64) | Applications Event Collector, Applications + WAF Event Collector |
$proxy_status | HTTP error status code, or origin, when the upstream returns no response. - when the response comes from cache. | 520 | Applications Event Collector, Applications + WAF Event Collector |
$remote_addr | IP address that sent the request. | none | Applications Event Collector, Applications + WAF Event Collector |
$remote_port | Remote port that sent the request. | none | Applications Event Collector, Applications + WAF Event Collector |
$request_id | Unique identifier of the request. | 5f222ae5938482c32a822dbf15e19f0f | Applications + WAF Event Collector |
$request_length | Length of the request, counting the request line, the headers, and the body. | none | Applications Event Collector, Applications + WAF Event Collector |
$request_method | HTTP method of the request. | GET, POST | Applications Event Collector, Applications + WAF Event Collector |
$request_time | Time spent processing the request, in seconds, counted from the first bytes read from the client. | 0.234 | Applications Event Collector, Applications + WAF Event Collector |
$request_uri | URI of the request with its arguments, without the host and the protocol. | /v1?v=bo%20dim | Applications Event Collector, Applications + WAF Event Collector |
$requestPath | URI of the request without the query string, the host, and the protocol. For /jira/plans/48/scenarios/27?vid=320#plan/backlog, it holds /jira/plans/48/scenarios/27. | /jira/plans/48/scenarios/27 | Applications Event Collector, Applications + WAF Event Collector |
$requestQuery | Parameters of the request URI. | vid=320#plan/backlog | Applications Event Collector, Applications + WAF Event Collector |
$scheme | Scheme of the request. | HTTP, HTTPS | Applications Event Collector, Applications + WAF Event Collector |
$sent_http_content_type | Content-Type header of the origin’s response. | text/html; charset=UTF-8 | Applications Event Collector, Applications + WAF Event Collector |
$sent_http_x_original_image_size | X-Original-Image-Size header of the origin’s response, which reports the original size of an image. | 987390 | Applications Event Collector, Applications + WAF Event Collector |
$server_addr | IP address of the server that received the request. | none | Applications + WAF Event Collector |
$server_port | Port of the server that received the request. | 443 | Applications + WAF Event Collector |
$server_protocol | Protocol of the request. | HTTP/1.1, HTTP/2.0, HTTP/3.0 | Applications Event Collector, Applications + WAF Event Collector |
$session_id | Identifier of the session. | none | Applications + WAF Event Collector |
$ssl_cipher | Cipher string used to establish the TLS connection. | TLS_AES_256_GCM_SHA384 | Applications Event Collector, Applications + WAF Event Collector |
$ssl_protocol | Protocol of the established TLS connection. | TLS v1.2 | Applications Event Collector, Applications + WAF Event Collector |
$ssl_server_name | Server name the client sent when it connected. | www.example.com | Applications + WAF Event Collector |
$ssl_session_reused | Whether the TLS session was reused: r when it was, . otherwise. | r, . | Applications + WAF Event Collector |
$state | State of the client, from IP address geolocation. | CA | Applications Event Collector, Applications + WAF Event Collector |
$status | HTTP status code of the request. | 200 | Applications Event Collector, Applications + WAF Event Collector |
$stream | ID set in the virtual host configuration file, based on the location directive. | none | Applications + WAF Event Collector |
$tcpinfo_rtt | Round-trip time (RTT) to the client, in microseconds, measured by Azion. Available on systems that support the TCP_INFO socket option. | 72052 | Applications Event Collector, Applications + WAF Event Collector |
$time | Date and time of the request. | Oct. 31st, 2022 - 19:30:41 | Applications Event Collector, Applications + WAF Event Collector |
$traceback | Names of the Rules Engine rules of the application and of the firewall that ran on the request. Needs Debug Rules on the application. | none | none |
$upstream_addr | Address and port of the server, or servers, the request was sent to. Can hold several servers or server groups. 127.0.0.1:1666 means the upstream is Azion Runtime. | 192.168.1.1:80 | Applications + WAF Event Collector |
$upstream_bytes_received | Number of bytes received from the origin when the content is not cached. | 8304 | Applications Event Collector, Applications + WAF Event Collector |
$upstream_bytes_sent | Number of bytes sent to the origin. | 2733 | Applications + WAF Event Collector |
$upstream_cache_status | Status of the local cache. | MISS, BYPASS, EXPIRED, STALE, UPDATING, REVALIDATED, HIT | Applications Event Collector, Applications + WAF Event Collector |
$upstream_connect_time | Time spent connecting to the origin, in seconds, including the TLS handshake. 0 for a KeepAlive connection, - when the response comes from cache. | 0.123 | Applications Event Collector, Applications + WAF Event Collector |
$upstream_header_time | Time spent receiving the response header from the origin, in seconds. - when the response comes from cache. | 0.345 | Applications Event Collector, Applications + WAF Event Collector |
$upstream_local_addr | Local IP address Azion uses to connect to the origin server: the outgoing (source) IP toward the upstream. | 10.0.12.34 | Applications Event Collector |
$upstream_response_time | Time spent receiving the full response from the origin, headers and body, in seconds. - when the response comes from cache. | 0.876 | Applications Event Collector, Applications + WAF Event Collector |
$upstream_status | HTTP status code of the origin. Keeps 502 (Bad Gateway) when no server can be selected. - when the response comes from cache. | 200 | Applications Event Collector, Applications + WAF Event Collector |
$version | Azion Log version. | v5 | Applications Event Collector |
$waf_attack_action | Action WAF took on the request. | $BLOCK, $PASS, $LEARNING_BLOCK, $LEARNING_PASS | Applications Event Collector, Applications + WAF Event Collector |
$waf_attack_family | Class of the WAF infraction found in the request. | SQL, XSS, TRAVERSAL | Applications Event Collector, Applications + WAF Event Collector |
$waf_block | Whether WAF blocked the request: 1 when it did, 0 when it did not. While $waf_learning is 1, no request is blocked, whatever this value. | 0, 1 | Applications + WAF Event Collector |
$waf_headers | Base64 string of the request headers when WAF tags them as blocked, with $waf_block at 1. - otherwise. Applies whatever the WAF mode. | - | Applications + WAF Event Collector |
$waf_learning | Learning flag of WAF. While it is 1, WAF blocks no request. | 0, 1 | Applications + WAF Event Collector |
$waf_match | Infractions found in the request, as key-value pairs: the key is the type of violation, and the value is the string that caused it. | none | Applications + WAF Event Collector |
$waf_score | Score added when the request matches the rules set for WAF. | none | Applications + WAF Event Collector |
$waf_total_blocked | Total number of blocked requests. | none | Applications + WAF Event Collector |
$waf_total_processed | Total number of processed requests. | none | Applications + WAF Event Collector |
Several values in one field
Six variables can hold more than one value, one per connection the request opened: $upstream_bytes_received, $upstream_cache_status, $upstream_connect_time, $upstream_header_time, $upstream_response_time, and $upstream_status. A request opens several connections when it is redirected internally, or when Load Balancer chooses another origin. $upstream_addr lists the servers the same way. Two separators split the values:
- A comma separates the servers contacted while processing the request, such as
192.168.1.1:80, 192.168.1.2:80. - A colon marks an internal redirect from one server group to another, started by X-Accel-Redirect or by Error Responses, such as
192.168.1.1:80, 192.168.1.2:80, unix:/tmp/sock : 192.168.10.1:80, 192.168.10.2:80.
When no server can be selected, $upstream_addr keeps the name of the server group, and $upstream_status keeps 502.
Read the values as transitions of the connection: the last value is usually the one that matters most. With Error Responses set for status 502 on an application, the upstream fields carry two values, typically 502 : 200. The first try to fetch the content from the origin returned 502, so Azion requested the URI set in Error Responses and delivered that page with 200. Every upstream field keeps the values in the same positions.
Values served from cache
When the response comes from cache, $proxy_status, $upstream_connect_time, $upstream_header_time, $upstream_response_time, and $upstream_status hold -. $upstream_connect_time holds 0 for a KeepAlive connection, and $upstream_bytes_received counts bytes only when the content is not cached.
Rules a request ran
No preset carries $traceback. To receive it, use a custom template on the Applications data source with $traceback in its Data Set, and turn on Debug Rules on the application.
The value groups the rule names by where they ran. edge_application_request holds the Request Phase rules of the application, edge_application_response holds its Response Phase rules, and edge_firewall holds the rules of the firewall. A request that passed through a firewall and an application can carry all three keys. A firewall rule that applies WAF lets the other rules of the firewall run alongside it, so the value can list more firewall rules for a request WAF blocked, and the block still applies.
Functions
Functions carries the requests your Functions handle, with the messages each function writes to the log. Its API slug is functions_console, and the data source needs Functions on the account.
The Functions Event Collector preset carries all eight variables, but places six of them under keys with other names, such as edgeFunctionID for $edge_function_id. For each key, refer to Templates and payload.
| Variable | Description | Example | In preset |
|---|---|---|---|
$client | Unique identifier of the Azion customer. | 4529r | Functions Event Collector |
$edge_function_id | Identifier of the function. | 1321 | Functions Event Collector |
$global_id | Identifier of the settings. | none | Functions Event Collector |
$log_level | Level of the log. | ERROR, WARN, INFO, DEBUG, TRACE | Functions Event Collector |
$log_message | Message passed to the log function. You write it to identify and report a behavior. | none | Functions Event Collector |
$message_source | Source of the message: CONSOLE for a message generated by the Console API, RUNTIME for an error message. | CONSOLE, RUNTIME | Functions Event Collector |
$request_id | Unique identifier of the request. | 5f222ae5938482c32a822dbf15e19f0f | Functions Event Collector |
$time | Date and time of the request. | Oct. 31st, 2022 - 19:30:41 | Functions Event Collector |
WAF Events
WAF Events carries the requests WAF analyzed, so you can map the score each request received, the WAF rules it matched, and the reason it was blocked. Its API slug is waf, and the data source needs Firewall with WAF on the account.
The WAF Event Collector preset does not carry $headers: it sends the literal - under its headers key.
| Variable | Description | Example | In preset |
|---|---|---|---|
$blocked | Whether WAF blocked the request: 1 when it did, 0 when it did not. While $waf_learning is 1, no request is blocked, whatever this value. | 0, 1 | WAF Event Collector |
$client | Unique identifier of the Azion customer. | 4529r | WAF Event Collector |
$configuration | Unique identifier of the Azion configuration, set in the virtual host configuration file. | 1595368520 | WAF Event Collector |
$country | Country of the client, from IP address geolocation. | United States | WAF Event Collector |
$headers | Base64 string of the request headers when WAF blocked the request. - otherwise. | - | none |
$host | Host of the request: the host name in the request line, the host name in the Host request header, or the server name that matches the request. | none | WAF Event Collector |
$remote_addr | IP address that sent the request. | none | WAF Event Collector |
$requestPath | URI of the request without the query string, the host, and the protocol. For /jira/plans/48/scenarios/27?vid=320#plan/backlog, it holds /jira/plans/48/scenarios/27. | /jira/plans/48/scenarios/27 | WAF Event Collector |
$requestQuery | Parameters of the request URI. | vid=320#plan/backlog | WAF Event Collector |
$server_protocol | Protocol of the request. | HTTP/1.1, HTTP/2.0, HTTP/3.0 | WAF Event Collector |
$time | Date and time of the request. | Oct. 31st, 2022 - 19:30:41 | WAF Event Collector |
$truncated_body | Deprecated. Holds - and no value. | - | WAF Event Collector |
$version | Azion Log version. | v5 | WAF Event Collector |
$waf_args | Arguments of the request. | none | WAF Event Collector |
$waf_attack_action | Action WAF took on the request. | $BLOCK, $PASS, $LEARNING_BLOCK, $LEARNING_PASS | WAF Event Collector |
$waf_attack_family | Class of the WAF infraction found in the request. | SQL, XSS, TRAVERSAL | WAF Event Collector |
$waf_learning | Learning flag of WAF. While it is 1, WAF blocks no request. | 0, 1 | WAF Event Collector |
$waf_match | Infractions found in the request, as key-value pairs: the key is the type of violation, and the value is the string that caused it. | none | WAF Event Collector |
$waf_score | Score added when the request matches the rules set for WAF. | none | WAF Event Collector |
$waf_server | Host name of the request WAF analyzed. | api-login.azion.com.br | WAF Event Collector |
$waf_uri | URI of the request WAF analyzed. | /access/v2/after-login | WAF Event Collector |