# Real-Time Events quickstart

This guide instructs you through reading your first event record in [Real-Time Events](/en/documentation/platform/real-time-events/).

- Open Real-Time Events and identify the controls a search is built from.
- Read the records of the HTTP Requests data source over a period you set.
- Narrow the result to the records that carry one value.
- Open one record and read the fields the request wrote.

A search creates nothing. It is three choices, and every result comes from the combination of them:

1. The **data source** is the index the records are read from. It decides which product's records a search can return at all, and a search always names one.
2. The **Time Filter** bounds the period. A record outside that period is not read, whatever else matches it.
3. **Filter by** narrows what the first two selected. It never widens them.

The Real-Time Events GraphQL API makes the same three choices with a dataset name, a `tsRange` argument, and the other filter arguments on that dataset.

---

Select the interface you will use. The prerequisites and every stage below follow that choice.

## Prerequisites

- An Azion account. To create one, refer to [How to create an account on Azion](/en/documentation/fundamentals/creating-account/).
- An [application](/en/documentation/platform/applications/) or a [firewall](/en/documentation/platform/firewall/) already serving traffic, so the HTTP Requests data source holds records to read.

**Console**

- Access to Azion Console. To sign in, refer to [How to access Azion Console](/en/documentation/guides/platform/account-and-billing/how-to-access-azion-console/).

**API**

- A personal token, for a query sent from a terminal. To create one, refer to [Personal Tokens](/en/documentation/fundamentals/personal-tokens/).

---

## Open Real-Time Events

The records are reached two ways, and both read the same store.

**Console**

To open the page, access [Azion Console](https://console.azion.com) > **Products menu** > **Observe** > **Real-Time Events**.

The page presents four controls:

- **Data Sources** selects the product whose records the search reads.
- **Time Filter** bounds the period the search covers.
- **Filter by** narrows the result to the records that match a value.
- **Refresh**, which reruns the search with the data source and period currently selected.

Those four controls are the whole search surface, and a search is one combination of them.

> **Note**
>
> Azion Console also offers a newer Real-Time Events view, in Preview, reached from **Switch to new view**. This page documents the classic view, which is the one Real-Time Events opens on.

**API**

The GraphQL API serves the same records at `https://api.azion.com/v4/events/graphql`. That address also serves the GraphiQL Playground in a browser: sign in to Azion Console at `https://console.azion.com`, then open the endpoint. Every query below runs there.

A query sent from a terminal instead carries an `Authorization: Token [TOKEN VALUE]` header. For that path, refer to [GraphQL API first steps](/en/documentation/devtools/graphql/first-steps/).

The Playground is where each query in the stages below is written and sent.

---

## Search the records of one data source

HTTP Requests carries one record per request an application or a firewall received. The period a search can ask for is bounded by how long an event record is kept. For that bound and the others a query carries, refer to [Limits](/en/documentation/platform/real-time-events/limits/).

**Console**

To read the records of one data source in Azion Console:

1. **Select the data source**

   In **Data Sources**, select *HTTP Requests*.

2. **Set the period**

   In **Time Filter**, select *Last 15 minutes*, which is the period the filter opens on.

3. **Select Refresh**

The records of that period appear in a table, one row per request.

**Data Sources** offers one entry per product that writes records. For each one and the variables it carries, refer to [Data sources](/en/documentation/platform/real-time-events/data-sources/).

**API**

In the GraphQL API the HTTP Requests data source is the `workloadEvents` dataset, and the controls of Azion Console are arguments on it:

- `tsRange` carries the period, as a `begin` and an `end` timestamp.
- `orderBy` sets the order the rows come back in, such as `[ts_DESC]` for the most recent first.
- `limit` caps how many rows the query returns.

Those three arguments are what the next stage sends. For the dataset each data source maps to, refer to [Data sources](/en/documentation/platform/real-time-events/data-sources/), and for the fields each dataset carries, to [Real-Time Events GraphQL API fields](/en/documentation/devtools/graphql/gql-real-time-events-fields/).

---

## Narrow the search

A search over a period with no other condition returns every record in it. One value cuts that down to the records worth reading, and it is also what keeps a search inside the bounds the log database enforces.

**Console**

To narrow the result in Azion Console:

1. **Enter the filter**

   In **Filter by**, enter the following:

   ```text
   status='400'
   ```

2. **Select Refresh**

The table now holds only the records whose **Status** is `400`.

**Filter by** reads SQL. `key='value'` matches a value exactly, `key like '%value%'` matches a similar one, and `AND`, `OR`, and `NOT` combine terms. For the full syntax and more examples, refer to [Filter events](/en/documentation/guides/platform/observability/add-filters-events/).

**API**

A filter argument narrows the dataset the same way. `statusIn` takes a list of status codes, so the condition the Console search expresses as `status='400'` reads `statusIn: [400]` here.

To return the most recent record that matched:

```graphql
{
  workloadEvents(
    limit: 1
    filter: {
      tsRange: { begin: "2026-01-01T12:00:00", end: "2026-01-01T12:10:00" }
      statusIn: [400]
    }
    orderBy: [ts_DESC]
  ) {
    ts
    requestId
    host
    status
  }
}
```

The row the query returns:

```json
{
  "ts": "2026-01-01T12:03:51Z",
  "requestId": "0123456789abcdef0123456789abcdef",
  "host": "<your-workload-domain>",
  "status": 400
}
```

The row is one event record, and its `requestId` identifies the request that produced it.

---

## Read one event record

A record carries far more than the few values a result list shows. Reading all of it is what the search was for.

**Console**

To open the whole record in Azion Console, select a row in the results table.

The **More details** view opens, carrying every variable of the selected data source for that one record. You now have the values a single request wrote, variable by variable.

For what each variable means, data source by data source, refer to [Data sources](/en/documentation/platform/real-time-events/data-sources/). For how to read the values of one record, refer to [Read an event record](/en/documentation/guides/platform/observability/understand-logs/).

**API**

A response carries the fields the query selected and no others, so reading more of a record means naming more fields. Filter on the `requestId` the previous stage returned and extend the selection set:

```graphql
{
  workloadEvents(
    limit: 1
    filter: {
      tsRange: { begin: "2026-01-01T12:00:00", end: "2026-01-01T12:10:00" }
      requestIdEq: "0123456789abcdef0123456789abcdef"
    }
  ) {
    ts
    requestId
    host
    requestUri
    status
    upstreamStatus
  }
}
```

The row carries one value per field named:

```json
{
  "ts": "2026-01-01T12:03:51Z",
  "requestId": "0123456789abcdef0123456789abcdef",
  "host": "<your-workload-domain>",
  "requestUri": "/?q=1%27%20OR%20%271%27%3D%271",
  "status": 400,
  "upstreamStatus": 0
}
```

You now have the record of one request, field by field. `upstreamStatus` reads `0` because the request never reached an origin. For every field `workloadEvents` carries, and the fields of the other datasets, refer to [Real-Time Events GraphQL API fields](/en/documentation/devtools/graphql/gql-real-time-events-fields/).

---

## Next steps

- [Data sources](/en/documentation/platform/real-time-events/data-sources.md): Every data source, the product that writes its records, the dataset that holds them, and the variables each one carries.
- [How Real-Time Events works](/en/documentation/platform/real-time-events/how-it-works.md): What a query reads before it answers, and why one filter matters more than a shorter period.
- [Filter events](/en/documentation/guides/platform/observability/add-filters-events.md): The full Filter by syntax, with an example query per variable.
- [Investigate a request with the GraphQL API](/en/documentation/guides/platform/observability/investigate-requests-graphql-api.md): Count the records first, then narrow to one status code and read the client behind it.
