Real-Time Events quickstart
Open Real-Time Events, read the records of one data source, narrow them to a single request, and run the same query against the GraphQL API.
This guide instructs you through reading your first event record in Real-Time Events.
- Open Real-Time Events and identify the controls a search is built from.
- Read the records of the HTTP Requests data source over a period you set.
- Narrow the result to the records that carry one value.
- Open one record and read the fields the request wrote.
A search creates nothing. It is three choices, and every result comes from the combination of them:
- The data source is the index the records are read from. It decides which product’s records a search can return at all, and a search always names one.
- The Time Filter bounds the period. A record outside that period is not read, whatever else matches it.
- Filter by narrows what the first two selected. It never widens them.
The Real-Time Events GraphQL API makes the same three choices with a dataset name, a tsRange argument, and the other filter arguments on that dataset.
Select the interface you will use. The prerequisites and every stage below follow that choice.
Prerequisites
- An Azion account. To create one, refer to How to create an account on Azion.
- An application or a firewall already serving traffic, so the HTTP Requests data source holds records to read.
- Access to Azion Console. To sign in, refer to How to access Azion Console.
Open Real-Time Events
The records are reached two ways, and both read the same store.
The GraphQL API serves the same records at https://api.azion.com/v4/events/graphql. That address also serves the GraphiQL Playground in a browser: sign in to Azion Console at https://console.azion.com, then open the endpoint. Every query below runs there.
A query sent from a terminal instead carries an Authorization: Token [TOKEN VALUE] header. For that path, refer to GraphQL API first steps.
The Playground is where each query in the stages below is written and sent.
Search the records of one data source
HTTP Requests carries one record per request an application or a firewall received. The period a search can ask for is bounded by how long an event record is kept. For that bound and the others a query carries, refer to Limits.
In the GraphQL API the HTTP Requests data source is the workloadEvents dataset, and the controls of Azion Console are arguments on it:
tsRangecarries the period, as abeginand anendtimestamp.orderBysets the order the rows come back in, such as[ts_DESC]for the most recent first.limitcaps how many rows the query returns.
Those three arguments are what the next stage sends. For the dataset each data source maps to, refer to Data sources, and for the fields each dataset carries, to Real-Time Events GraphQL API fields.
Narrow the search
A search over a period with no other condition returns every record in it. One value cuts that down to the records worth reading, and it is also what keeps a search inside the bounds the log database enforces.
A filter argument narrows the dataset the same way. statusIn takes a list of status codes, so the condition the Console search expresses as status='400' reads statusIn: [400] here.
To return the most recent record that matched:
The row the query returns:
The row is one event record, and its requestId identifies the request that produced it.
Read one event record
A record carries far more than the few values a result list shows. Reading all of it is what the search was for.
To open the whole record in Azion Console, select a row in the results table.
The More details view opens, carrying every variable of the selected data source for that one record. You now have the values a single request wrote, variable by variable.
For what each variable means, data source by data source, refer to Data sources. For how to read the values of one record, refer to Read an event record.