Docs
DocumentationQuery ReferenceAPI Reference
Open Console→→
DocumentationQuery ReferenceAPI Reference

Platform overview

What is Axiom?QuickstartArchitectureFeatures
Fundamentals
Datasets
Edge deployments
Limits
Performance
Optimize usage
Requirements
Semantic conventions
Glossary
Tour
SecurityRoadmap

Send data

Reference architecturesMethods

Understand data

Console
Query
Builder
Editor
Query results
Visualize
Traces
Metrics
Correlations
Save queries
Stream
Dashboard
Create
Elements
Create
Configure
Element types
Gauge
Heatmap
Log stream
Monitor list
Note
Pie chart
Scatter plot
Statistic
Table
Time series
Sections
Configure
Filter
Annotate
Monitor
Overview
View status
Configure
Examples
Monitor types
Anomaly
Match
Threshold
Alerting
Overview
Configure
Notifier types
Custom Webhook
Discord
Email
Microsoft Teams
Opsgenie
PagerDuty
Slack
Manage
Datasets
Overview
Views
Virtual fields
Access
RBAC
Tokens
CLI
Organization
Audit log
Settings
Usage and billing
Profile
Extend
Overview
AWS Lambda
AWS PrivateLink
Cloudflare Workers
Cloudflare Logpush
Convex
Grafana
Hex
Netlify
Supabase
Tailscale
Terraform
Unkey
Vercel
Intelligence
Overview
Spotlight
AI agents
Overview
MCP Server
Overview
Tools
Query cost limits
Agent-created orgs
Skills
Overview
Axiom alerting
Build dashboards
Control costs
Query metrics
SRE
Translate SPL to APL
Splunk
Overview
Splunk app
Install and configure
Commands
Examples
Portal
How it works
Set up standard mode
Set up transparent mode
Observability Cloud
OCSF data
OCSF as CIM
SPL command support
Examples
Monitor and troubleshoot

Use cases

ObservabilityProduct analytics
OCSF security data
Overview
Send data
Query data
LLM observability
Overview
Use Axiom AI SDK
Manual instrumentation
GenAI attributes
Redaction policies

Miscellaneous

LLMs
Overview
List of docs pages
Full docs
Query reference
FAQs
Legal
Acceptable use policy
Axiom for Startups terms
Cookies
Data processing
HIPAA
Partner agreement
Partner program guide
Privacy policy
SLA
Terms of service
Terms of use
Understand data/Console

Connect Axiom with Unkey

Stream Unkey audit logs, key verifications, gateway HTTP requests, runtime logs, and rate-limit decisions to Axiom.

Unkey provides infrastructure for building and operating APIs. Connect Unkey with Axiom to send audit logs, key verifications, gateway HTTP requests, runtime logs, and rate-limit decisions to an Axiom dataset.

Prerequisites

  • Create an Axiom account.
  • Create a dataset in Axiom where you send your data.
  • Create an API token in Axiom with permissions to ingest data to the dataset you have created.
  • Create an Unkey account.

Supported event streams

Each log drain sends one event stream. To send all five streams, create five drains. You can send them to the same Axiom dataset and use the stream field to distinguish them, or use a separate dataset for each stream.

Streamstream valueEvents
Audit logsaudit_logsWorkspace actions, such as creating projects or changing configuration
Key verificationskey_verificationsAPI key verification results, including successful and rejected verifications
Gateway HTTP requestsgateway_requestsRecorded HTTP requests served through Unkey's gateway
Runtime logsruntime_logsCollected application output, including structured logs and multiline messages
Rate limitsratelimitsRecorded API rate-limit decisions, including passed and blocked checks

Set up an Axiom log drain

Create a log drain in your Unkey workspace.

  1. In the Unkey dashboard, select your workspace, and then go to Settings > Log Drains.
  2. Click Create Log Drain.
  3. Select Axiom as the destination.
  4. Enter a descriptive name for the log drain.
  5. In Stream, select Audit logs, Key verifications, Gateway HTTP requests, Runtime logs, or Rate limits.
  6. Optional: Configure stream filters to limit which events Unkey sends.
  7. Enter the name of your Axiom dataset and your Axiom API token.
  8. Click Create Log Drain.
  9. Repeat these steps for each additional stream you want to send.

Drains start at creation time. Historical backfill isn't supported. Unkey sends events asynchronously in batches, so events can take several minutes to appear in Axiom.

Explore your Unkey events

After you create a drain, open the Stream tab in Axiom to verify that events arrive in your dataset. Filter by stream to inspect an event type.

Each event includes _time, when it occurred, and stream, its event type.

Audit logs

The audit_logs stream records who performed a workspace action and which resources it affected.

JSON
{
  "_time": "2026-09-10T12:34:56.789Z",
  "stream": "audit_logs",
  "id": "evt_123",
  "action": "key.create",
  "occurred_at": "2026-09-10T12:34:56.789Z",
  "actor": {
    "id": "user_123",
    "type": "user",
    "name": "Ada",
    "metadata": null
  },
  "targets": [
    {
      "id": "key_123",
      "type": "key",
      "name": "Production API key",
      "metadata": null
    }
  ],
  "context": {
    "location": "203.0.113.10",
    "user_agent": "Mozilla/5.0"
  },
  "metadata": null,
  "description": "Created Production API key",
  "correlation_id": "req_123"
}

See Unkey audit log event types for the complete list of actions.

Key verifications

The key_verifications stream records API key verification outcomes.

JSON
{
  "_time": "2026-09-10T12:34:56.789Z",
  "stream": "key_verifications",
  "request_id": "req_123",
  "key_space_id": "ks_production",
  "key_id": "key_123",
  "identity": {
    "id": "id_123",
    "externalId": "customer_123"
  },
  "region": "eu-west-1",
  "source": { "type": "api" },
  "outcome": "VALID",
  "tags": ["paid"],
  "spent_credits": 1
}

See Unkey key verification payloads for field details.

Gateway HTTP requests

The gateway_requests stream records gateway request metadata, response status, latency, and captured request details.

JSON
{
  "_time": "2026-09-10T12:34:56.789Z",
  "stream": "gateway_requests",
  "request_id": "req_123",
  "project_id": "proj_store",
  "app_id": "app_backend",
  "environment_id": "env_production",
  "deployment_id": "dep_release",
  "region": "eu-west-1",
  "request": {
    "method": "GET",
    "host": "api.example.com",
    "path": "/orders",
    "query_string": "status=paid",
    "query_params": { "status": ["paid"] },
    "headers": ["Accept: application/json"],
    "body": "",
    "user_agent": "store-client/1.0",
    "ip_address": "203.0.113.10"
  },
  "response": {
    "status": 200,
    "headers": ["Content-Type: application/json"],
    "body": "{\"orders\":[]}"
  },
  "latency": { "total": 52, "instance": 41, "gateway": 11 }
}

Captured details follow your Unkey logging policy. See Unkey gateway request payloads for field details and capture limits.

Runtime logs

The runtime_logs stream forwards collected application output, including multiline messages and nested structured attributes.

JSON
{
  "_time": "2026-09-10T12:34:56.789Z",
  "stream": "runtime_logs",
  "log_id": "rlog_123",
  "severity": "error",
  "message": "Payment failed",
  "attributes": { "order": { "id": 42 }, "retry": false },
  "project_id": "proj_store",
  "app_id": "app_backend",
  "environment_id": "env_production",
  "deployment_id": "dep_release",
  "region": "eu-west-1"
}

See Unkey runtime log payloads for field details and handling of application output.

Rate limits

The ratelimits stream exports recorded decisions from ratelimit.limit and ratelimit.multiLimit. These are rate-limit checks, not audit events for configuration changes.

JSON
{
  "_time": "2026-09-10T12:34:56.789Z",
  "stream": "ratelimits",
  "request_id": "req_123",
  "namespace_id": "rl_payments",
  "identifier": "customer_123",
  "passed": false,
  "limit": 100,
  "remaining": 0,
  "reset_at": 1789043756789,
  "tokens": 3,
  "source": "api"
}

See Unkey rate-limit payloads for field details and which decisions are recorded.

Delivery and troubleshooting

For delivery status, retention, retries, and troubleshooting, see the Unkey log drain documentation.

Was this page helpful?
Suggest edits on GitHub
PreviousConnect Axiom with TerraformNextConnect Axiom with Vercel
On this page
Supported event streamsSet up an Axiom log drainExplore your Unkey eventsAudit logsKey verificationsGateway HTTP requestsRuntime logsRate limitsDelivery and troubleshooting