# Data Stream quickstart

This guide instructs you through sending your first logs with [Data Stream](/en/documentation/platform/data-stream/). By the end you will have:

- Your first stream, which sends the [Activity History](/en/documentation/fundamentals/activity-history/) of your account to an Object Storage bucket.
- An Activity History event that you produce yourself.
- The first log lines stored as an object in the bucket, which confirms the delivery.

The guide uses Activity History because any change you make in the account produces an event. You trigger the delivery yourself, and you need no account outside Azion.

The result rests on four objects, in this order:

1. An Object Storage **bucket** receives the logs, and an Object Storage **credential** lets Data Stream write to it. You create both before you start.
2. The **stream** collects the logs of one data source, *Activity History*. It sends every event, with sampling at 100%. The [*Activity History Collector*](/en/documentation/platform/data-stream/templates-and-payload/#preset-templates) template shapes each event into one log line. The endpoint is *Simple Storage Service (S3)*, pointed at the bucket. The Console labels the endpoint field **Connector**.
3. An **event**: a change you make in the account, which Activity History records.
4. An **object** in the bucket that holds the log lines of that event.

Each setting of the stream is described on [Stream settings](/en/documentation/platform/data-stream/stream-settings/).

---

Select the interface you will use. The prerequisites and every stage below follow that choice.

## Prerequisites

- An Azion account. To create one, refer to [Create an account](/en/documentation/fundamentals/creating-account/).
- The **Edit Data Stream** permission on the account, which allows creating, editing, and deleting streams. For more information, refer to [Teams Permissions](/en/documentation/fundamentals/teams-permissions/).
- An Object Storage bucket. To create one, refer to [Object Storage quickstart](/en/documentation/platform/object-storage/quickstart/).
- An Object Storage credential that reaches the bucket, with four capabilities: **List Files**, **Write Files**, **List All Bucket Names**, and **List Buckets**. In the API, these are `listFiles`, `writeFiles`, `listAllBucketNames`, and `listBuckets`. Without the two bucket-list capabilities, every send fails with status `503` and no object reaches the bucket. The secret key shows only once, when the credential is created. To create the credential, refer to [S3 protocol compatibility credentials](/en/documentation/platform/object-storage/s3-compatibility/#credentials).

**Console**

- Access to Azion Console. To sign in, refer to [Access Azion Console](/en/documentation/guides/platform/account-and-billing/how-to-access-azion-console/).

**API**

- A [personal token](/en/documentation/guides/platform/account-and-billing/personal-tokens/) and `curl`.

> **Caution**
>
> Saving an active stream with sampling on deactivates every other stream on the account, and this stream uses sampling.

---

## Create the stream

The stream reads the *Activity History* data source, sends every event, and writes the log lines to the bucket. A stream needs either sampling or a workload filter; this one keeps sampling on at 100%. To collect the logs of chosen workloads instead, refer to [Stream settings](/en/documentation/platform/data-stream/stream-settings/#transform).

**Console**

To create the stream in Azion Console:

1. **Open the Data Stream page**

   Access [Azion Console](https://console.azion.com/) > **Data Stream**.

2. **Select + Stream**

3. **Name the stream**

   In the **General** section, in **Name**, enter `activity-to-bucket`.

4. **Select the data source**

   In the **Input** section, set **Data Source** to *Activity History*.

5. **Keep every event**

   In the **Transform** section, keep **Option** as *All Current and Future Workloads*. Keep **Sampling** on and **Sampling Rate (%)** at `100`, the defaults.

6. **Select the template**

   In the **Render Template** section, set **Template** to *Activity History Collector*.

7. **Select the endpoint**

   In the **Output** section, set **Connector** to *Simple Storage Service (S3)*.

8. **Point the endpoint at the bucket**

   Enter the values of your bucket and credential:

   - **URL**: `https://s3.us-east-005.azionstorage.net`
   - **Bucket Name**: the name of your bucket
   - **Region**: `us-east-005`
   - **Access Key** and **Secret Key**: the keys of your credential
   - **Object Key Prefix**: `activity`
   - **Content Type**: *plain/text*

9. **Keep the stream active**

   In the **Status** section, keep **Active** on.

10. **Select Save**

11. **Confirm the sampling warning**

    The **Attention** dialog warns that saving disables every other stream on the account. Select **Confirm**.

The Console shows `Your data stream has been created`, and the **Data Stream** list shows the stream with the status *Active*.

**API**

To create the stream with the Azion API, send a `POST` request to the streams endpoint. Replace `[TOKEN VALUE]` with your personal token, `<your-bucket>` with the name of your bucket, and the two keys with the keys of your credential:

```bash
curl --request POST \
  --url https://api.azion.com/v4/workspace/stream/streams \
  --header 'Accept: application/json' \
  --header 'Authorization: Token [TOKEN VALUE]' \
  --header 'Content-Type: application/json' \
  --data '{
  "name": "activity-to-bucket",
  "active": true,
  "inputs": [
    { "type": "raw_logs", "attributes": { "data_source": "activity_history" } }
  ],
  "transform": [
    { "type": "sampling", "attributes": { "rate": 100 } },
    { "type": "render_template", "attributes": { "template": 251 } }
  ],
  "outputs": [
    {
      "type": "s3",
      "attributes": {
        "host_url": "https://s3.us-east-005.azionstorage.net",
        "bucket_name": "<your-bucket>",
        "region": "us-east-005",
        "access_key": "[ACCESS KEY]",
        "secret_key": "[SECRET KEY]",
        "object_key_prefix": "activity",
        "content_type": "plain/text"
      }
    }
  ]
}'
```

Template `251` is *Activity History Collector*. A `201` carries the stream:

```json
{
  "state": "executed",
  "data": {
    "id": 12345,
    "name": "activity-to-bucket",
    "last_editor": "user@example.com",
    "created": "2026-01-01T11:30:47.000000Z",
    "last_modified": "2026-01-01T11:30:47.000000Z",
    "product_version": "1.0",
    "active": true,
    "inputs": [
      { "type": "raw_logs", "attributes": { "data_source": "activity_history" } }
    ],
    "transform": [
      { "type": "sampling", "attributes": { "rate": 100 } },
      { "type": "render_template", "attributes": { "template": 251 } }
    ],
    "outputs": [
      {
        "type": "s3",
        "attributes": {
          "access_key": "[ACCESS KEY]",
          "secret_key": "[SECRET KEY]",
          "region": "us-east-005",
          "object_key_prefix": "activity",
          "bucket_name": "<your-bucket>",
          "content_type": "plain/text",
          "host_url": "https://s3.us-east-005.azionstorage.net"
        }
      }
    ]
  }
}
```

The stream exists and is active. Keep the value of `id`, which identifies the stream in the next stage. A request without the `sampling` item fails with `400` and the code `32002`, `Workloads Must Be Provided`.

Saving the stream checks the format of each field. It does not contact the bucket, so a wrong key shows only as a failed send.

---

## Generate an event

A stream starts to send one to two minutes after you save it as active. Wait two minutes, then make one change in the account. Each save of the stream is an Activity History event, so renaming the stream is enough.

**Console**

To rename the stream in Azion Console:

1. **Open the stream**

   In the **Data Stream** list, select `activity-to-bucket`.

2. **Change the name**

   In **Name**, enter `activity-to-bucket-2`.

3. **Select Save**

4. **Confirm the sampling warning**

   If the **Attention** dialog opens, select **Confirm**.

The Console shows `Your data stream has been updated`. Activity History records the edit as one event.

**API**

To rename the stream with the Azion API, send a `PATCH` request to the stream. Replace `<stream-id>` with the `id` of the stream you created:

```bash
curl --request PATCH \
  --url https://api.azion.com/v4/workspace/stream/streams/<stream-id> \
  --header 'Accept: application/json' \
  --header 'Authorization: Token [TOKEN VALUE]' \
  --header 'Content-Type: application/json' \
  --data '{
  "name": "activity-to-bucket-2"
}'
```

A `200` carries the stream with the changed name and a later `last_modified`:

```json
{
  "state": "executed",
  "data": {
    "id": 12345,
    "name": "activity-to-bucket-2",
    "last_editor": "user@example.com",
    "created": "2026-01-01T11:30:47.000000Z",
    "last_modified": "2026-01-01T12:01:39.000000Z",
    "product_version": "1.0",
    "active": true,
    …
  }
}
```

Activity History records the edit as one event.

Within about a minute of the event, Data Stream sends its log line to the bucket.

---

## Confirm the logs arrived

Data Stream writes each send as one object. The object name is the prefix `activity`, a `/`, the date and time of the send in the `YYYY/MM/DD/hh/mm/` format, and a UUID.

**Console**

To find the object in Azion Console:

1. **Open the bucket list**

   Access [Azion Console](https://console.azion.com/) > **Object Storage** > **Buckets**.

2. **Select the bucket**

   Select the bucket the stream sends to.

3. **Find the object under the prefix**

   The object is listed under a key that starts with `activity/`. Each `/` in the key groups the object under a prefix, not a folder.

The object is in the bucket, which confirms that the stream delivered the event.

**API**

To list the objects in the bucket with the Azion API, send a `GET` request to the bucket. Replace `<your-bucket>` with the name of your bucket:

```bash
curl --request GET \
  --url https://api.azion.com/v4/workspace/storage/buckets/<your-bucket>/objects \
  --header 'Accept: application/json' \
  --header 'Authorization: Token [TOKEN VALUE]'
```

The response lists the object that the stream wrote, with its key, its time, and its size in bytes:

```json
{
  "continuation_token": null,
  "results": [
    {
      "key": "activity/2026/01/01/12/02/11111111-1111-1111-1111-111111111111",
      "last_modified": "2026-01-01T12:02:03.000000Z",
      "size": 2797,
      "is_folder": false
    },
    …
  ]
}
```

The object is in the bucket, which confirms that the stream delivered the event.

With **Content Type** *plain/text*, the object holds one Activity History record per line, as a JSON object. The keys are the ones the *Activity History Collector* template sets. One line, trimmed:

```json
{"comment": "-", "user_ip": "203.0.113.10", "request_data": "…", "resource_name": "activity-to-bucket-2", …, "title": "Stream activity-to-bucket-2 was edited", "author_email": "user@example.com", …, "resource_id": "12345", …, "time": "2026-01-01T12:01:39Z", "type": "edited", …, "resource_type": "Stream"}
```

Your first stream delivers the Activity History of your account to the bucket. Every send, delivered or rejected, also leaves a record with its HTTP status in [Real-Time Events](/en/documentation/platform/real-time-events/data-sources/#data-stream).

---

## Next steps

- [Endpoints](/en/documentation/platform/data-stream/endpoints.md): Send the logs to your SIEM, big-data, or stream-processing platform.
- [Data sources and variables](/en/documentation/platform/data-stream/data-sources-and-variables.md): Collect the logs of applications, functions, or WAF, and read what each variable holds.
- [Create a custom template](/en/documentation/guides/application-development/frameworks/data-stream-custom-template.md): Choose the variables each log line carries.
- [How Data Stream works](/en/documentation/platform/data-stream/how-it-works.md): How a stream filters, batches, and delivers each log line.
