Stream settings
Look up every stream field in Azion Console and the Azion API, with its values, defaults, and bounds, from data source to endpoint.
A stream is the Data Stream object that collects the logs of one data source, shapes each log line with a template, and sends the lines to one endpoint. Azion Console and the Azion API write the same object, so each table on this page names the Console label beside the API field. API fields are written as paths inside the request body, such as inputs[0].attributes.data_source.
Stream object
The JSON body below is a complete stream. It sends every Activity History event, shaped by the Activity History Collector template, to a bucket over the S3 protocol:
The three arrays carry the parts of the stream:
inputsholds one data source.transformholds onerender_templateitem and exactly one ofsamplingandfilter_workloads. Each item has atypeandattributes, sotransform[sampling].attributes.ratenames theattributes.ratekey of the item whosetypeissampling.outputsholds one endpoint. The API keeps the first entry and drops any other entry without an error.
The API path is /v4/workspace/stream/streams, and one stream is /v4/workspace/stream/streams/<stream-id>. Every request carries the header Authorization: Token [TOKEN VALUE], a personal token of the account. A POST answers 201 with "state": "executed" and the stored object, which adds the read-only fields id, last_editor, created, last_modified, and product_version. A PATCH changes only the keys you send: {"active": true} activates a stream and returns it with its data source, transforms, and endpoint unchanged. A PUT takes the same required keys as a create. For every operation, refer to the Azion API reference. For the token and the first request, refer to Azion API.
A saved stream has no deployment step. A change of active state takes effect after one to two minutes, and during that window the previously active stream keeps sending. An account with 3,000 workloads or more manages its streams through the API only, because the Console blocks the create and edit forms at that count.
General
The General section names the stream. The API requires name, inputs, transform, and outputs on every create.
| Console | API field | Type | Required | Default | Values |
|---|---|---|---|---|---|
| Name | name | string | Yes | none | 1 to 100 characters. A longer name is refused with 10046. |
Input
The Input section picks the data source the stream collects from. Each data source has its own variables, listed on Data sources and variables.
| Console | API field | Type | Required | Default | Values |
|---|---|---|---|---|---|
| Data Source | inputs[0].attributes.data_source | enum | Yes | none in the API, Applications in the Console | activity_history, workloads, functions_console, or waf. Any other value is refused with 10039. |
| none | inputs[0].type | enum | Yes | none | raw_logs, the only value. |
The Console names each data source differently from its API slug:
| Console option | API slug | Variables |
|---|---|---|
| Activity History | activity_history | Activity History |
| Applications | workloads | Applications |
| Functions | functions_console | Functions |
| WAF Events | waf | WAF Events |
Activity History carries the account’s Activity History. Functions needs Functions on the account, and WAF Events needs Firewall with WAF.
Transform
The Transform section sets which workloads the stream collects from and what share of their events it sends.
The Option radio picks the scope. Each choice sends a different item:
| Option | What the stream collects | API item |
|---|---|---|
| All Current and Future Workloads, the default | Every workload on the account, including workloads created later. Shows Sampling. | sampling |
| Filter Workloads | Only the workloads you move to Chosen Workload. | filter_workloads |
A stream carries exactly one of the two items. Without either, the API refuses it with 32002, whatever its data source. With both, the API refuses it with 32007. The API sets no default for the fields below; the defaults are the Console’s.
| Console | API field | Console default | Values |
|---|---|---|---|
| Workloads | transform[filter_workloads].attributes.workloads | None | The workloads in Chosen Workload: an array of 1 to 600 workload IDs, each a workload on the account. An ID from another account is refused with 32003. |
| Sampling | transform[sampling] | On | On sends a sampling object. Off sends none, and resets Sampling Rate (%) to 100. |
| Sampling Rate (%) | transform[sampling].attributes.rate | 100 | Integer from 1 to 100, required in a sampling item: the percentage of events the stream sends. 0 is refused with 10050, and 101 with 10068. |
Activity History events belong to the account rather than to a workload, so an Activity History stream uses sampling. On some accounts, the Console reads All Current and Future Domains and Filter Domains instead.
Saving an active stream with a sampling item deactivates every other stream on the account, and the API returns no error. A rate of 100 counts as sampling. Before saving, the Console shows After activating and saving these settings, all other Data Streams will be disabled. and adds When multiple Data Streams have different sampling rates, the system uses the lowest percentage. To run several streams at once, give each one a filter_workloads item instead of sampling.
Render Template
The Render Template section picks the template that turns each event into a log line. The Console groups the Template options under Azion’s Templates and Custom Templates, and shows the variables of the selected template in the read-only Data Set field.
| Console | API field | Type | Required | Default | Values |
|---|---|---|---|---|---|
| Template | transform[render_template].attributes.template | integer, template ID | Yes | none in the API, the first template by name in the Console | The ID of a preset or of a custom template on the account. Without the item, the request is refused with 32008, and an ID that does not exist with 32004. |
Azion provides five preset templates:
| Preset | template |
|---|---|
| Activity History Collector | 251 |
| Applications Event Collector | 2 |
| Applications + WAF Event Collector | 184 |
| Functions Event Collector | 86 |
| WAF Event Collector | 4 |
Create Custom Template opens a drawer that creates a custom template on the account, listed under Custom Templates. For the variables of each preset and the custom template format, refer to Templates and payload.
Output
The Output section sets the endpoint that receives the log lines. The Console labels the field Connector, and the API carries the choice in outputs[0].type.
| Console | API field | Type | Required | Default | Values |
|---|---|---|---|---|---|
| Connector | outputs[0].type | enum | Yes | none in the API, Standard HTTP/HTTPS POST in the Console | One of the 11 values below. The endpoint’s own fields go in outputs[0].attributes. |
| Console option | API type | Fields |
|---|---|---|
| Standard HTTP/HTTPS POST | standard | Standard HTTP/HTTPS POST |
| Apache Kafka | kafka | Apache Kafka |
| Simple Storage Service (S3) | s3 | Simple Storage Service (S3) |
| Google BigQuery | big_query | Google BigQuery |
| Elasticsearch | elasticsearch | Elasticsearch |
| Splunk | splunk | Splunk |
| AWS Kinesis Data Firehose | aws_kinesis_firehose | AWS Kinesis Data Firehose |
| Datadog | datadog | Datadog |
| IBM QRadar | qradar | IBM QRadar |
| Azure Monitor | azure_monitor | Azure Monitor |
| Azure Blob Storage | azure_blob_storage | Azure Blob Storage |
Status
The Status section turns the stream on or off. The list of streams shows each one as Active or Inactive.
| Console | API field | Type | Required | Default | Values |
|---|---|---|---|---|---|
| Active | active | boolean | No | true, and on in the Console | false stops the stream and keeps its settings. true starts it again. |
A change of active state takes effect after one to two minutes. Activating a stream that has a sampling item deactivates every other stream on the account.
Permissions
Account permissions decide who can change a stream. For how permissions are granted, refer to Teams and permissions. View Data Stream shows the account’s streams but does not allow creating, editing, or deleting them. Creating, editing, and deleting need Edit Data Stream.
With View Data Stream only, the Console disables + Stream and every form field, and the edit page shows no Save. Six key fields are masked, with an icon that reveals the value: S3 Access Key, Secret Key, and Object Key Prefix; AWS Kinesis Data Firehose Access Key and Secret Key; and Azure Monitor Shared Key. Without the edit permission, a lock icon replaces the reveal icon.
Errors
The API refuses each request below with HTTP 400, except 10002 with 401, and creates nothing. The errors array carries the code, the title, and a source.pointer to the field; the number in a pointer is the item’s position in its array.
| Code | Title | Pointer | Cause | What to do |
|---|---|---|---|---|
10002 | Not Authenticated | source.headers Authorization | The request has no token: Authentication credentials were not provided. | Send Authorization: Token [TOKEN VALUE]. |
10046 | Max Length | /data/name | name is longer than 100 characters. | Shorten the name to 100 characters or fewer. |
10039 | Invalid Choice | /data/inputs/0/attributes/data_source | data_source is not a known slug, such as "nope". | Send activity_history, workloads, functions_console, or waf. |
32002 | Workloads Must Be Provided | /data/transform | transform has neither a sampling nor a filter_workloads item: If sampling is disabled, workloads must be provided. | Add a sampling item, or a filter_workloads item with workload IDs. |
32007 | Sampling And Workloads Are Exclusive | /data/transform | transform has both a sampling and a filter_workloads item: If sampling is enabled, workloads must not be provided. | Keep one of them: sampling for every workload, or the workload filter. |
32003 | Workloads Not Belong Account | /data/transform/0/attributes/workloads | A workload ID is not on the account. meta.invalid_workloads lists the IDs, such as [1]. | Send IDs of workloads on the account. |
10050 | Min Value | /data/transform/0/attributes/rate | rate is 0. | Send a rate from 1 to 100. |
10068 | Max Value | /data/transform/0/attributes/rate | rate is above 100. | Send a rate from 1 to 100. |
32008 | Template Must Be Provided | /data/transform | transform has no render_template item. | Add a render_template item with a template ID. |
32004 | Template Does Not Exist | /data/transform/1/attributes/template | template is not the ID of a preset or of a custom template on the account. | Send an ID from the template list. |
10050 | Min Value | /data/outputs/0/max_size | A standard endpoint has a max_size below 1000000. | Send 1000000 or more, or leave max_size out. |
10059 | Required Field | /data/outputs/0/headers | A standard endpoint has no headers. | Send headers, or {} for none. |
10059 | Required Field | /data/outputs/0/kafka_topic | A kafka endpoint has no kafka_topic. | Send kafka_topic. |
32006 and 10032 | Invalid URL Scheme and Invalid Url | /data/outputs/0/url | A standard endpoint has a url that is not an http or https URL, such as not-a-url. | Send a full URL that starts with http:// or https://. |
Two behaviors return no error. A second entry in outputs is dropped, and the stream keeps the first one. Saving an active stream with a sampling item deactivates every other stream on the account.