What you will be able to do
- Create and activate a consumer event table so app telemetry is captured
- Enable event sharing and tell required event definitions apart from optional ones
- Explain how SHARE_EVENTS_WITH_PROVIDER behaves when an app has event definitions
- Set up provider event accounts for each region, or centralized event routing, so shared events aren't lost
1.Consumer-side event table setup
A Native App can emit three kinds of telemetry: log messages, trace events, and metrics. None of it is kept unless the consumer account has an event table. An account can hold several event tables, but only one can be the active event table at a time. Without an active table, everything the app emits is dropped, even when its procedures call the logging and tracing APIs directly.
Setup takes two statements. First create the event table in a database and schema. Then make it the account's active event table with ALTER ACCOUNT. Be careful when you change the active table in Snowsight. One event table holds the events from the whole account, so switching it moves where every event in the account is stored, not only the app's events.
CREATE EVENT TABLE event_db.event_schema.my_event_table;ALTER ACCOUNT SET EVENT_TABLE=event_db.event_schema.my_event_table;Checkpoint 1 of 4· Fill the gap
Which account parameter makes this table the active event table?
ALTER ACCOUNT SET ? =event_db.event_schema.my_event_table;ALTER ACCOUNT SET EVENT_TABLE sets the single active event table for the account. The other names aren't the documented parameter.
Source: docs.snowflake.comSources1
2.Enabling event sharing and event definitions
Event sharing copies events from the consumer's event table into an event table in the provider's account. Event definitions are filters that decide which events get copied. They are a separate thing from the log and trace levels the provider sets. Those levels decide what reaches the consumer table in the first place, and the consumer can't change them.
A provider can mark each event definition as required or optional. Required definitions are turned on automatically at install. If the app has any, the listing install steps say the consumer must set up an event table before installing. The tracing guide adds that without an active event table, the emitted events are discarded. Optional definitions also need an active event table, but they aren't needed to install or use the app. If an app has no event definitions, Snowsight shows only the All type, and the consumer can switch sharing on and off freely.
To enable sharing, use a role with MANAGE EVENT SHARING, which ACCOUNTADMIN has by default. Open the app's Settings, go to the Events and logs tab, set the sliders, and select Save. SHOW TELEMETRY EVENT DEFINITIONS IN APPLICATION lists the app's definitions. Some limits to keep in mind: sharing is free, but the consumer pays for ingesting and storing events. Historical events are never shared, and once events have been shared, access to them can't be revoked.
| Name | Shares |
|---|---|
| SNOWFLAKE$ALL | All log messages and trace events the app emits |
| SNOWFLAKE$ALL_EVENTS | All events from the application |
| SNOWFLAKE$ERRORS_AND_WARNINGS | Logs for errors, warnings and fatal events |
| SNOWFLAKE$METRICS | CPU and memory metrics Snowflake generates |
| SNOWFLAKE$TRACES | Detailed traces of user activities and journeys |
| SNOWFLAKE$USAGE_LOGS | High-level logs related to user actions and app events |
| SNOWFLAKE$DEBUG_LOGS | Technical logs used to troubleshoot the app |
The older SHARE_EVENTS_WITH_PROVIDER property still works, with limits. If the app has both required and optional definitions, setting it to true turns on all of them. Setting it to false is allowed only when every definition is optional. Reading the property returns TRUE only when every definition is enabled.
Checkpoint 2 of 4· Check yourself
An app defines one required and two optional event definitions. The consumer has enabled only one of the optional ones. What does SHARE_EVENTS_WITH_PROVIDER report?
The property is TRUE only when every event definition is enabled. One optional definition is still off, so it reports FALSE.
“SHARE_EVENTS_WITH_PROVIDER is TRUE only when all event definitions are enabled, otherwise it is FALSE.”Source: docs.snowflake.com
Snowsight is not the only way to turn sharing on. The CREATE APPLICATION command accepts an AUTHORIZE_TELEMETRY_EVENT_SHARING = { TRUE | FALSE } clause, which enables logging and event sharing in the app. To check the state of an installed app, run DESC APPLICATION. Its output includes share_events_with_provider and authorize_telemetry_event_sharing, the status of the AUTHORIZE_TELEMETRY_EVENT_SHARING flag.
DESC APPLICATION hello_snowflake_app;3.Multi-region event sharing: the provider's side
Shared events don't cross regions. Snowflake sends them to a designated provider account in the same region as the consumer. So for every region where consumers install the app, the provider needs an event account with an active event table. An organization administrator role designates that account with SYSTEM$SET_EVENT_SHARING_ACCOUNT_FOR_REGION. The account can't be locked, suspended, a reader account, a trial account, or a Snowflake managed account. If a region has no event account when a consumer there installs the app, the provider loses the shared copy of those events. The consumer's own event table still records them.
SELECT SYSTEM$SET_EVENT_SHARING_ACCOUNT_FOR_REGION('<snowflake_region>', '<region_group>', '<account_name>')For new deployments, Snowflake recommends centralized event sharing instead. The provider creates an event routing table whose rules map regions to a destination account, then activates it for the organization. A rule that names specific regions overrides the ALL rule, and a rule that uses ALL must be named default. An organization can have only one active routing table, and each table can hold up to 200 rules.
CREATE EVENT ROUTING TABLE org_table
WITH RULES
default = (REGION_GROUP='PUBLIC', REGIONS=('ALL'), DESTINATION_ACCOUNT = org.account1)
{rule_name} = (REGION_GROUP='PUBLIC', REGIONS=('AWS_US_EAST_1', 'AWS_US_EAST_2'),
DESTINATION_ACCOUNT = org.account1);Checkpoint 3 of 4· Check yourself
A provider has an event account only in AWS_US_WEST_2 and no centralized event sharing. A consumer in an EU region installs the app and enables sharing. What happens to the events?
Without an event account in the consumer's region, the shared copy is dropped. The consumer's local table still captures the events.
“Consumer event tables continue to capture the data locally; only the shared copy that would have flowed to the provider is lost.”Source: docs.snowflake.com
Checkpoint 4 of 4· Exam question
Which privilege must a role in the provider account hold in order to create and manage the application package that consumers will later install?
Correct answer: A — CREATE APPLICATION PACKAGE
- A. CREATE APPLICATION PACKAGE is the provider-side privilege needed to build and manage the package artifact that is later published or shared for installation.
- B. CREATE APPLICATION is a consumer-side privilege used to install and create the application object in the consumer's own account, not to build the provider's package.
- C. IMPORT SHARE is required by the consumer to access a listing, not by the provider to build the application package.
- D. CREATE DATABASE ROLE manages database-level roles and has no bearing on creating or managing an application package.
Exam traps
Each one states something that sounds right. Open it to see what is actually true.
1.A consumer can always turn event sharing off after installing an app.Why is that wrong?
If the app has required event definitions, sharing for them is turned on at install and can't be disabled afterwards.
Covered in Enabling event sharing and event definitions
2.A single provider event account receives shared events from consumers in every region.Why is that wrong?
Without centralized event sharing, events go only to a provider event account in the consumer's own region.
Practise it for real
Get a consumer account ready to capture and share an installed app's telemetry
1.Run CREATE EVENT TABLE event_db.event_schema.my_event_table; in an existing database and schema
Why: Telemetry is stored only if an event table exists
You should see: The event table is created
2.Run ALTER ACCOUNT SET EVENT_TABLE=event_db.event_schema.my_event_table;
Why: Only the active event table receives app events, and an account has just one
You should see: The account's active event table is now my_event_table
3.Run SHOW TELEMETRY EVENT DEFINITIONS IN APPLICATION hello_snowflake; against your installed app
Why: Shows which event definitions you can toggle
You should see: The type column shows ALL if the provider defined no event definitions; otherwise the optional definitions are listed
4.With a role that has MANAGE EVENT SHARING, open the app's Settings, go to Events and logs, enable the optional definitions you want, and select Save
Why: Optional definitions are shared with the provider only when the consumer turns them on
You should see: The chosen definitions show as enabled
Stuck? Get a nudge
Look at what's in the event table before you enable sharing. Events can't be recalled once shared.
Sources
Every claim above is drawn from one of these pages, quoted as it was written on the date shown.
- 1.
“only one of them can be set as the active event table in a Snowflake account at a time.”
↩︎ Consumer-side event table setup“consumers must set up an event table in their account to collect this information.”
↩︎ Consumer-side event table setup“Optional event definitions require an active event table, but they are not required to install or use the app.”
↩︎ Enabling event sharing and event definitions“if the consumer does not have an active event table, the log messages and trace events emitted by the app are discarded.”
↩︎ Enabling event sharing and event definitions“Use a role with the MANAGE EVENT SHARING global privilege.”
↩︎ Enabling event sharing and event definitions“After enabling event sharing with a provider, you cannot revoke access to shared trace events and log messages.”
↩︎ Enabling event sharing and event definitions“Snowflake sends the shared events to a designated provider account within the same region as your account.”
↩︎ Multi-region event sharing: the provider's side“event sharing and the required event definitions are enabled during installation and cannot be disabled later.”
↩︎ Exam trap 1“event sharing and the required event definitions are enabled during installation and cannot be disabled later.”
↩︎ Prediction“SHARE_EVENTS_WITH_PROVIDER is TRUE only when all event definitions are enabled, otherwise it is FALSE.”
↩︎ Checkpoint - 2.
“If the provider includes required event definitions in the app, the consumer must set up an event table before installing the app.”
↩︎ Enabling event sharing and event definitions - 3.
“Enables logging and event sharing in the app.”
↩︎ Enabling event sharing and event definitions - 4.
“The status of the AUTHORIZE_TELEMETRY_EVENT_SHARING flag.”
↩︎ Enabling event sharing and event definitions - 5.
“You must use an organization administrator role to set an account as the account used to store events.”
↩︎ Multi-region event sharing: the provider's side“A provider can collect logs and shared events only in the same region where a consumer installs an app.”
↩︎ Exam trap 2“Consumer event tables continue to capture the data locally; only the shared copy that would have flowed to the provider is lost.”
↩︎ Checkpoint - 6.
“Each organization can have only one event routing table activated for it.”
↩︎ Multi-region event sharing: the provider's side“Rules with specific regions take precedence over rules for ALL.”
↩︎ Multi-region event sharing: the provider's side