Getting Started
Begin your LogScale journey with tutorials, quickstarts, and foundational concepts
LogScale Introduction
Learn how to get started using LogScale
LogScale Overview
Introduction to log management and LogScale's core capabilities
What is LogScale
Learn how LogScale ingests, stores, and queries your log data
LogScale Product Tutorial with Demo Data
A hands-on walkthrough using sample data, no setup required
LogScale Video Series
Short videos covering core concepts and common tasks
LogScale Internal Architecture
How LogScale works internally — from data ingestion to query processing
LogScale Web Interface
A tour of the UI — search bar, widgets, and navigation
Terminology Reference
Definitions for LogScale-specific terms you will see throughout the docs
Data Management, Queries and Dashboards
Master the LogScale interface, query language, and core terminology
CrowdStrike Query Language (CQL)
Learn how to write queries and access data
Manage Repositories and Views
Create and manage data repositories
Search Data
Use the search interface to explore and filter your events
Query Language Syntax
The grammar and structure of CQL — pipes, filters, and operators
Data Visualization
Turn query results into charts, tables, and dashboards
CrowdStrike Query Language Grammar Subset
Formal grammar reference for the CrowdStrike Query Language
Triggers
Automate actions with continuous alerts or scheduled searches
Schedule PDF Reports
Create and schedule shareable PDF reports
Scheduled searches
Run a saved query automatically on a recurring schedule
Actions
Configure automated responses: email, webhooks, Slack, and more
Ingesting Data
Connect data sources, configure parsers, and stream logs into LogScale
Popular Ingest Methods
Learn about different ingest solutions
Falcon LogScale Collector
The native log shipper that collects and forwards logs to LogScale
Falcon LogScale Collector Releases
Release notes and version history for Falcon LogScale Collector
Fleet and Group Management
Centrally monitor and configure multiple Collector instances
CrowdStrike Parsing Standard 1.2
The schema standard for normalising fields across data sources
Third-Party Log Shippers
Send data into LogScale from external shipping tools
Managing LogScale Cloud
Configure organizations, manage users, and control access in your cloud environment
LogScale Cloud
Administration and monitoring guide for Cloud deployments
Instance Administration
Monitor usage, manage data lifecycle, and track system health
Understand Organizations
How organizations, users, and permissions are structured in Cloud
Organization Settings
Configure account-wide preferences for your Cloud organisation
Configure Security
Set up authentication, access controls, and security policies
Limits and Standards
Operating parameters and system limits for LogScale
Archive Data
Move older data to long-term, lower-cost storage
LogScale URLs and Endpoints
The base URLs and endpoints for your Cloud environment
Managing LogScale Self-Hosted
Configure organizations, manage users, and control access in your self-hosted deployments
LogScale Self-Hosted
Administration and configuration guide for self-hosted deployments
Instance Administration
Monitor users, manage retention, and oversee licensing
Organization Settings
Configure organization owners, permissions, and settings
Configure Security
Set up authentication, access controls, and security policies
Cluster Management
Monitor cluster health, replication, and node availability
Limits and Standards
Operating parameters and system limits for LogScale
Archive Data
Set up long-term archiving to S3 or Google Cloud Storage
Configuration Variables
Reference for all available cluster configuration settings
Health Checks
Verify your self-hosted cluster is running correctly
LogScale URLs and Endpoints
API endpoints and URLs for your LogScale instance
Deploying LogScale
Plan, install, and configure LogScale for your infrastructure needs
LogScale Self-Hosted Deployment
Step-by-step instructions for a new self-hosted install
Planning to install LogScale
Sizing, prerequisites, and decisions to make before deploying
Humio Operator
Deploy and manage LogScale on Kubernetes
Updating LogScale
How to safely upgrade a self-hosted cluster to a new version
Authentication and identity providers
Configure SSO and identity providers for user authentication
Configuration Settings
Available settings for tuning a self-hosted deployment
APIs, Integrating, & CLI
Integrate LogScale with REST APIs, CLI tools, and third-party services automation
Application Programming Interfaces (APIs)
Overview of all the ways to interact with LogScale programmatically
Ingest API
Send data into LogScale programmatically over HTTP
Search API
Run CQL queries programmatically and retrieve results over HTTP
Package Marketplace
Browse and install pre-built dashboards, parsers, and saved searches
Package Management
Build, publish, and manage your own reusable packages
Third-Party Log Shippers
Send data into LogScale from external shipping tools
Command-Line Interface (
humioctl )Manage LogScale from your terminal with the humioctl CLI
Log Formats
Supported log formats and how LogScale parses them
Other Integrations
Connect LogScale with other tools in your stack
GraphQL API
Programmatically manage LogScale resources with the GraphQL API
GraphQL Queries
Reference for every available GraphQL query
GraphQL Mutations
Reference for every available GraphQL mutation
GraphQL Datatypes
All data types available in the GraphQL schema
LogScale Internal Repo Reference
Reference for LogScale's built-in repositories and their schema definitions
LogScale System Repository Schema Guide
Reference for LogScale's built-in repositories and their schema definitions
The
humio RepositorySchema for LogScale's main internal system repository
The
humio-activity repositorySchema for the internal user activity log repository
The
humio-audit repositorySchema for the internal audit log repository
The
humio-fleet RepositorySchema for fleet management and log shipper metadata
The
humio-measurements RepositorySchema for detailed per-event ingest measurements and data volume tracking
The
humio-metrics RepositorySchema for the internal platform metrics repository
The
humio-usage RepositorySchema for hourly aggregated usage metrics and storage tracking