Skip to content
LogoLogScale DocumentationLibraryGuidance Release Notes Integrations Query Examples Getting Started APIGraphQLSearch Archives Contact Support
๐Ÿ”– ๐Ÿ”” เฉ†Help button for documentation
    • Cloud Overview
    • Instance Administration
      • Data Retention
      • Measure and Monitor
        • Cluster Statistics
        • Ingest Usage Management
          • What's Measured
            • Measurement Repositories
          • Measure Data Ingest
          • Optimize Ingestion
          • Monitor Usage
        • LogScale Internal Logging
      • Data Archiving
        • S3 Archiving
      • LogScale SaaS Upgrades
    • Query Administration
      • Query Monitor
      • Blocked Queries
        • Add Query to Blocklist
      • Organization-Owned Queries
        • Enable organization-owned queries for a role
          • View queries without organization ownership permissions
        • Update organization ownership for existing queries
    • Configure Security
      • Tokens in LogScale
        • API Tokens
          • Use API Tokens
          • Repository and View API Tokens
          • Organization API Tokens
          • Personal API Token
      • Organization Essentials
        • Users and Permissions
          • Manage Users
            • Manage User Roles
            • Grant Permissions to Specific Assets
          • Manage Groups
            • Group Roles
            • Group Memberships
            • Group Synchronization
          • Manage Roles
          • Permissions Requirements
            • Repository and View Permissions
        • Set User Defaults
      • Security policies
        • Dashboard security policies
        • API token security policies
          • Behavior when changing token security policies
          • Personal API token security policy
          • Repository and View API tokens security policy
          • Organization API tokens security policies
        • Actions security policies
      • IP Filters
        • IP Filter Rules
        • Manage IP Filters
        • Create an IP Filter
        • Edit an IP Filter
      • Session management
      • Audit Logging
    • Authentication and identity providers
      • SAML Authentication
        • Active Dir. Federation Svc.
        • Entra ID (formerly Azure Active Dir.)
        • Duo Security
        • Okta
        • PingOne
        • Google
        • Auth0
      • OpenID Connect
    • Reference Material
      • Dynamic Configuration Parameters
        • AdHocTablesLimit
        • AggregatorOutputRowLimit
        • AllowInPlaceMigration
        • ArchivingClusterWideDisabled
        • ArchivingClusterWideEndAt
        • ArchivingClusterWideRegexForRepoName
        • ArchivingClusterWideStartFrom
        • DisableAssetSharing
        • BlockSignup
        • BucketStorageKeySchemeVersion
        • BucketStorageUploadInfrequentThresholdDays
        • BucketStorageWriteVersion
        • CancelQueriesExceedingAggregateOutputRowLimit
        • CorrelateConstellationTickLimit
        • CorrelateConstraintLimit
        • CorrelateLinkValuesLimit
        • CorrelateLinkValuesMaxByteSize
        • CorrelateMinIterations
        • CorrelateNumberOfTimeBuckets
        • CorrelateQueryEventLimit
        • CorrelateQueryLimit
        • DebugAuditRequestTrace
        • defaultDigestReplicationFactor
        • defaultSegmentReplicationFactor
        • DeleteDuplicatedNameViewsAfterMerging
        • DisableAnalyticsJob
        • DisableNewRegexEngine
        • DisableUserTracking
        • DisableViewWithSameNameCleanup
        • DisableAssetSharing
        • EnableGlobalJsonStatsLogger
        • FdrEnable
        • FdrExcludedNodes
        • FdrMaxNodes
        • FdrMaxNodesPerFeed
        • FdrS3FileSizeMax
        • FileReplicationFactor
        • FlushSegmentsAndGlobalOnShutdown
        • GracePeriodBeforeDeletingDeadEphemeralHostsMs
        • GracefulShutdownConsideredAliveSeconds
        • GraphQLSelectionSizeLimit
        • GraphQLAliasCountLimit
        • GraphQLDirectiveCountLimit
        • GraphQLMaxErrorsCount
        • GraphQLQueryAnalysisDisabled
        • GraphQLQueryDepthLimit
        • GraphQLFragmentCountLimit
        • GraphQLFragmentDepthLimit
        • GraphQLOperationCountLimit
        • GraphQLUnauthenticatedAliasCountLimit
        • GraphQLUnauthenticatedDirectiveCountLimit
        • GraphQLUnauthenticatedFragmentCountLimit
        • GraphQLUnauthenticatedFragmentDepthLimit
        • GraphQLUnauthenticatedOperationCountLimit
        • GraphQLUnauthenticatedQueryDepthLimit
        • GraphQLUnauthenticatedSelectionSizeLimit
        • GroupDefaultLimit
        • GroupMaxLimit
        • IngestFeedAwsDownloadMaxObjectSize
        • IngestFeedAwsProcessingDownloadBufferSize
        • IngestFeedAwsProcessingEventBufferSize
        • IngestFeedAwsProcessingEventsPerBatch
        • IngestFeedGovernorRateOverride
        • IngestFeedGovernorIngestDelayHigh
        • IngestFeedGovernorIngestDelayLow
        • IsAutomaticUpdateCheckingAllowed
        • JoinDefaultLimit
        • JoinRowLimit
        • LiveAdhocTableUpdatePeriodMinimumMs
        • LiveQueryMemoryLimit
        • LookupTableSyncAwaitSeconds
        • MatchFilesMaxHeapFraction
        • MaxAccessTokenTTL
        • MaxQueryPenaltyCreditFactorForParkedQueries
        • MaxRelocatedDatasourcesInGlobal
        • MaxConcurrentQueriesOnWorker
        • MaxCsvFileUploadSizeBytes
        • MaxIngestRequestSize
        • MaxJsonFileUploadSizeBytes
        • MaxOpenSegmentsOnWorker
        • MaxQueryPollsForWorker
        • MaxScheduledReportsPerView
        • MaxScheduledReportsPerViewPerOrgOverride
        • MaxTableForQuerySizeBytes
        • MaxTableSize
        • MinQueryPermitsFactor
        • MinimumHumioVersion
        • MultiPassDefaultIterationLimit
        • MultiPassMaxIterationLimit
        • ParserBacktrackingLimit
        • ParserThrottlingAllocationFactor
        • QueryFSMSyncMergeThreshold
        • QueryBacktrackingLimit
        • QueryCoordinatorMaxHeapFraction
        • QueryCoordinatorMemoryLimit
        • QueryMemoryLimit
        • QueryPartitionAutoBalance
        • QueryResultRowCountLimit
        • QueryMaxLength
        • QuerySchedulerCostMetricsLoggingIntervalSeconds
        • RawSegmentSearchEnabled
        • RawSegmentSearchMaxSegments
        • RdnsDefaultLimit
        • RdnsMaxLimit
        • RejectIngestOnParserExceedingFraction
        • ReplaceANSIEscapeCodes
        • ReverseDnsConcurrentRequests
        • ReverseDnsDefaultLimit
        • ReverseDnsDefaultTimeoutInMs
        • ReverseDnsMaxLimit
        • ReverseDnsRequestsPerSecond
        • ReverseDnsConcurrentRequestsPerQuery
        • S3ArchivingClusterWideDisabled
        • S3ArchivingClusterWideEndAt
        • S3ArchivingClusterWideRegexForRepoName
        • S3ArchivingClusterWideStartFrom
        • SampleIntervalForDatasourceRates
        • SelfJoinLimit
        • StateRowLimit
        • TableCacheMaxStorageFraction
        • TableCacheMaxStorageFractionForIngestAndHttpOnly
        • TableCacheMemoryAllowanceFraction
        • TargetMaxRateForDatasource
        • TimeSlicerMinimumCacheableSliceMinutes
        • UnauthenticatedGraphQLSelectionSizeLimit
        • UndersizedMergingRetentionPercentage
        • Get Dynamic Configuration List
        • Set a Dynamic Configuration Value
      • LogScale URLs and Endpoints
      • Limits and Standards

 

    • CrowdStrike Query Language (CQL)
    • Data Representation in LogScale
      • Event Stream
      • Event Structure
      • Event Timestamps
      • Event Data During Queries
      • Event Time Selection and Sequence
      • Field Naming and Standards
      • Data Retention and Expiration
      • Ingesting Old Data
    • Query Operation
      • Query Pipeline
        • Query Pipeline Sequence
        • Event Data Sources
        • Query Statement Order
        • Query Processing
        • Modifying Event Data
        • Modifying an Event Set
        • Finalizing an Event Set
      • Subqueries
        • Subquery Syntax
        • Subquery Inputs: What Events Are Processed
        • Subquery Outputs: How Results Are Used
        • Subquery Examples
        • Subquery Categories
        • Subquery Context and Limitations
      • Query Context
      • Files
      • Query Prefix
      • Effects of Limits
        • Implied Limit
        • Function Limits
        • Variables Governing Limits
      • Query Performance
      • Query Readability and Format
    • Query Language Syntax
      • Comments
      • Query Filters
      • Operators
      • Adding Fields to Events
      • User Parameters/Variables
      • Conditional Evaluation
      • Array Syntax
      • Expressions
      • Saved Searches (User Functions)
      • Function Syntax
      • Time Syntax
        • Supported Time Zones
        • Relative Time Syntax
      • Referencing Resources
      • Regular Expression Syntax
        • Regular Expression Engine V2 Syntax Patterns
        • Regular Expression Syntax Patterns
          • Unsupported Regular Expression Patterns
        • Regular Expression Flags
        • LogScale Regular Expression Engines
        • Differences from Other Regex Implementations
      • Persisted Aggregations Syntax
    • Function Operation
      • Function Parameters
      • Function Location
      • Function Input/Output
      • Function Types
    • Datatypes in CQL
      • Aggregate Function
      • Array
      • Arrayname
      • Array of aggregate functions
      • Array of arrays of strings
      • Array of expressions
      • Array of fieldnames
      • Array of numbers
      • Array of strings
      • Boolean
      • Double
      • Fixed Values
      • Expression
      • Fieldname
      • File
      • Function
      • Integer
      • Long
      • Number
      • Regex
      • Relative time
      • String
      • Time point
      • Timezone
    • Query Functions
      • Aggregate Query Functions
      • Array Query Functions
      • Comparison Query Functions
      • Conditional Query Functions
      • Data Manipulation Query Functions
      • Event Information Query Functions
      • Filtering Query Functions
      • Formatting Query Functions
      • Geolocation Query Functions
      • Hash Query Functions
      • Join Query Functions
      • Query Debugging Functions
      • Math Query Functions
      • Network and Location Query Functions
      • Parsing Query Functions
      • Preamble Query Functions
      • Regular Expression Query Functions
      • Security Related Query Functions
      • Sequence Query Functions
      • Statistics Query Functions
      • String Query Functions
      • Time and Date Query Functions
      • Transformation Query Functions
      • Widget Query Functions
      • accumulate()
      • appendAggregation()
      • array:append()
      • array:contains()
      • array:dedup()
      • array:drop()
      • array:eval()
      • array:exists()
      • array:filter()
      • array:intersection()
      • array:length()
      • array:reduceAll()
      • array:reduceColumn()
      • array:reduceRow()
      • array:regex()
      • array:rename()
      • array:sort()
      • array:union()
      • asn()
      • avg()
      • base64Decode()
      • base64Encode()
      • beta:param()
      • beta:repeating()
      • bitfield:extractFlags()
      • bitfield:extractFlagsAsArray()
      • bitfield:extractFlagsAsString()
      • bucket()
      • callFunction()
      • cidr()
      • coalesce()
      • collect()
      • communityId()
      • concat()
      • concatArray()
      • copyEvent()
      • correlate()
      • count()
      • counterAsRate()
      • createEvents()
      • crypto:md5()
      • crypto:sha1()
      • crypto:sha256()
      • default()
      • defineTable()
      • drop()
      • dropEvent()
      • duration()
      • end()
      • eval()
      • eventFieldCount()
      • eventInternals()
      • eventSize()
      • explain:asTable()
          • Output Format
          • Time Measurement Details
          • Query Optimization Effects
      • fieldset()
      • fieldstats()
      • findTimestamp()
      • format()
      • formatDuration()
      • formatTime()
      • geography:distance()
      • geohash()
      • getField()
      • groupBy()
          • Grouping in groupBy()
          • Limits when using groupBy()
      • hash()
      • hashMatch()
      • hashRewrite()
      • head()
      • if()
      • in()
      • ioc:lookup()
      • ipLocation()
      • join()
      • json:prettyPrint()
      • kvParse()
      • length()
      • linReg()
      • lower()
      • lowercase()
      • match()
      • matchAsArray()
      • math:abs()
      • math:arccos()
      • math:arcsin()
      • math:arctan()
      • math:arctan2()
      • math:ceil()
      • math:cos()
      • math:cosh()
      • math:deg2rad()
      • math:exp()
      • math:expm1()
      • math:floor()
      • math:log()
      • math:log10()
      • math:log1p()
      • math:log2()
      • math:mod()
      • math:pow()
      • math:rad2deg()
      • math:sin()
      • math:sinh()
      • math:spherical2cartesian()
      • math:sqrt()
      • math:tan()
      • math:tanh()
      • max()
      • min()
      • neighbor()
      • now()
      • objectArray:eval()
      • objectArray:exists()
      • parseCEF()
      • parseCsv()
      • parseFixedWidth()
      • parseHexString()
      • parseInt()
      • parseJson()
      • parseLEEF()
      • parseTimestamp()
      • parseUri()
      • parseUrl()
      • parseXml()
      • partition()
      • percentage()
      • percentile()
      • range()
      • readFile()
      • readPersistedAggregation()
      • regex()
      • remoteTable()
      • rename()
      • replace()
      • reverseDns()
      • round()
      • sample()
      • sankey()
      • select()
      • selectFromMax()
      • selectFromMin()
      • selectLast()
      • selfJoin()
      • selfJoinFilter()
      • series()
      • session()
      • setField()
      • setTimeInterval()
      • shannonEntropy()
      • slidingTimeWindow()
      • slidingWindow()
      • sort()
      • split()
      • splitString()
      • start()
      • stats()
      • stdDev()
      • stripAnsiCodes()
      • subnet()
      • sum()
      • table()
      • tail()
      • test()
      • text:contains()
      • text:editDistance()
      • text:editDistanceAsArray()
      • text:endsWith()
      • text:length()
      • text:positionOf()
      • text:startsWith()
      • text:substring()
      • text:trim()
      • time:dayOfMonth()
      • time:dayOfWeek()
      • time:dayOfWeekName()
      • time:dayOfYear()
      • time:hour()
      • time:millisecond()
      • time:minute()
      • time:month()
      • time:monthName()
      • time:second()
      • time:weekOfYear()
      • time:year()
      • timeChart()
      • tokenHash()
      • top()
      • transpose()
      • unit:convert()
      • upper()
      • urlDecode()
      • urlEncode()
      • wildcard()
      • window()
      • worldMap()
      • writeJson()
      • xml:prettyPrint()
    • Common Query Patterns
      • Common Misconceptions
      • Converting Data
      • Modifying Data
      • Array Operations
      • Deduplicating Data
      • Limiting Returned Events
        • Grouping or Limting by Specific fields
      • Sorting Data
      • Formatting Values
      • LogScale and Time
      • Other Tricks and Recipes
    • Query Basics
    • Query management
      • Writing New Queries
      • Save searches
      • Grant Permissions for Saved Queries
      • Use Saved Queries in Interactions
    • Troubleshooting Queries
    • SQL to CQL
      • LogScale and Database Terminology
      • SQL to CQL: Basic Query Structure
      • SQL to CQL: Time-Based Queries
      • SQL to CQL: Pattern Matching and Search
      • SQL to CQL: Dynamic vs. Static Schema
      • SQL to CQL: Analytical Capabilities
      • SQL to CQL: Iterative Development Approach
      • SQL to CQL: Collaboration and Reusability
      • SQL to CQL: Sorting and Limiting Results
      • SQL to CQL: Filtering with Multiple Conditions
      • SQL to CQL: Data Aggregation
      • SQL to CQL: Subqueries
      • SQL to CQL: Joins and Correlations
LogScale Cloud
Falcon LogScale Documentation
/ Falcon LogScale Cloud 1.253-1.260.0
๐Ÿ“š
ReferenceLookup information and technical specifications
intermediate
admin
Reading timeCalculating...
Last updatedMay 22, 2026

Reference Material

The reference material gathered here can help you manage and administer your LogScale instance.

LogScale URLs and Endpoints

A list of commonly used endpoints.

Limits and Standards

Limits for various parameters in LogScale.

Dynamic Configuration Parameters

Dynamic configuration parameters give you a way to administer and control certain parts of LogScale. This reference describes all of the dynamic configuration variables and their default settings.

Support
  • Twitter
  • LinkedIn
  • Youtube

ยฉ 2026 CrowdStrike All other marks contained herein are the property of their respective owners.

Children of this Page

Dynamic Configuration Parameters
AdHocTablesLimit
AggregatorOutputRowLimit
AllowInPlaceMigration
ArchivingClusterWideDisabled
ArchivingClusterWideEndAt
ArchivingClusterWideRegexForRepoName
ArchivingClusterWideStartFrom
DisableAssetSharing
BlockSignup
BucketStorageKeySchemeVersion
BucketStorageUploadInfrequentThresholdDays
BucketStorageWriteVersion
CancelQueriesExceedingAggregateOutputRowLimit
CorrelateConstellationTickLimit
CorrelateConstraintLimit
CorrelateLinkValuesLimit
CorrelateLinkValuesMaxByteSize
CorrelateMinIterations
CorrelateNumberOfTimeBuckets
CorrelateQueryEventLimit
CorrelateQueryLimit
DebugAuditRequestTrace
defaultDigestReplicationFactor
defaultSegmentReplicationFactor
DeleteDuplicatedNameViewsAfterMerging
DisableAnalyticsJob
DisableNewRegexEngine
DisableUserTracking
DisableViewWithSameNameCleanup
DisableAssetSharing
EnableGlobalJsonStatsLogger
FdrEnable
FdrExcludedNodes
FdrMaxNodes
FdrMaxNodesPerFeed
FdrS3FileSizeMax
FileReplicationFactor
FlushSegmentsAndGlobalOnShutdown
GracePeriodBeforeDeletingDeadEphemeralHostsMs
GracefulShutdownConsideredAliveSeconds
GraphQLSelectionSizeLimit
GraphQLAliasCountLimit
GraphQLDirectiveCountLimit
GraphQLMaxErrorsCount
GraphQLQueryAnalysisDisabled
GraphQLQueryDepthLimit
GraphQLFragmentCountLimit
GraphQLFragmentDepthLimit
GraphQLOperationCountLimit
GraphQLUnauthenticatedAliasCountLimit
GraphQLUnauthenticatedDirectiveCountLimit
GraphQLUnauthenticatedFragmentCountLimit
GraphQLUnauthenticatedFragmentDepthLimit
GraphQLUnauthenticatedOperationCountLimit
GraphQLUnauthenticatedQueryDepthLimit
GraphQLUnauthenticatedSelectionSizeLimit
GroupDefaultLimit
GroupMaxLimit
IngestFeedAwsDownloadMaxObjectSize
IngestFeedAwsProcessingDownloadBufferSize
IngestFeedAwsProcessingEventBufferSize
IngestFeedAwsProcessingEventsPerBatch
IngestFeedGovernorRateOverride
IngestFeedGovernorIngestDelayHigh
IngestFeedGovernorIngestDelayLow
IsAutomaticUpdateCheckingAllowed
JoinDefaultLimit
JoinRowLimit
LiveAdhocTableUpdatePeriodMinimumMs
LiveQueryMemoryLimit
LookupTableSyncAwaitSeconds
MatchFilesMaxHeapFraction
MaxAccessTokenTTL
MaxQueryPenaltyCreditFactorForParkedQueries
MaxRelocatedDatasourcesInGlobal
MaxConcurrentQueriesOnWorker
MaxCsvFileUploadSizeBytes
MaxIngestRequestSize
MaxJsonFileUploadSizeBytes
MaxOpenSegmentsOnWorker
MaxQueryPollsForWorker
MaxScheduledReportsPerView
MaxScheduledReportsPerViewPerOrgOverride
MaxTableForQuerySizeBytes
MaxTableSize
MinQueryPermitsFactor
MinimumHumioVersion
MultiPassDefaultIterationLimit
MultiPassMaxIterationLimit
ParserBacktrackingLimit
ParserThrottlingAllocationFactor
QueryFSMSyncMergeThreshold
QueryBacktrackingLimit
QueryCoordinatorMaxHeapFraction
QueryCoordinatorMemoryLimit
QueryMemoryLimit
QueryPartitionAutoBalance
QueryResultRowCountLimit
QueryMaxLength
QuerySchedulerCostMetricsLoggingIntervalSeconds
RawSegmentSearchEnabled
RawSegmentSearchMaxSegments
RdnsDefaultLimit
RdnsMaxLimit
RejectIngestOnParserExceedingFraction
ReplaceANSIEscapeCodes
ReverseDnsConcurrentRequests
ReverseDnsDefaultLimit
ReverseDnsDefaultTimeoutInMs
ReverseDnsMaxLimit
ReverseDnsRequestsPerSecond
ReverseDnsConcurrentRequestsPerQuery
S3ArchivingClusterWideDisabled
S3ArchivingClusterWideEndAt
S3ArchivingClusterWideRegexForRepoName
S3ArchivingClusterWideStartFrom
SampleIntervalForDatasourceRates
SelfJoinLimit
StateRowLimit
TableCacheMaxStorageFraction
TableCacheMaxStorageFractionForIngestAndHttpOnly
TableCacheMemoryAllowanceFraction
TargetMaxRateForDatasource
TimeSlicerMinimumCacheableSliceMinutes
UnauthenticatedGraphQLSelectionSizeLimit
UndersizedMergingRetentionPercentage
Get Dynamic Configuration List
Set a Dynamic Configuration Value
LogScale URLs and Endpoints
Limits and Standards
  • Other articles on this topic

    • Action Type: Webhooks
    • Authenticate with a proxy
    • Basic Configuration
    • Cluster Admin/Ops
    • Commit/Deploy Config Changes
    • Configure a Destination
    • Connect: Passthru, Pipeline, or Pack
    • Datasources
    • Digest Rules
    • Event Forwarders
    • Event List Interactions
    • Fleet Management Configuration Wizard
    • Full Falcon LogScale Collector Installation
    • How-To: Install Kubernetes Reference Architecture
    • Ingest Listeners
    • Ingest Tokens
    • Ingestion: Storage Phase
    • Insights Errors Dashboard
    • Insights Hosts Dashboard
    • Insights Ingest Dashboard
    • Insights Overview Dashboard
    • Insights Request-Response Dashboard
    • Insights Search Dashboard
    • Insights Segments & Datasources Dashboard
    • Kafka Dashboard
    • License Installation
    • Managing Scheduled Reports
    • Navigate Between User Interfaces
    • Node-Level Metrics
    • Repository and View Settings
    • Searching with Field Aliasing
    • Security, Logins, and Access Control
    • Storage Rules
    • Switch Kafka using KRaft Mode
    • Switching Kafka
  • Similar Content

    • Assign Roles to Groups
    • Authentication and identity providers
    • Cluster Statistics
    • Data Retention
    • Dynamic Configuration Parameters
    • Get Dynamic Configuration List
    • Grant Permissions to Specific Assets
    • Group Memberships
    • Group Synchronization
    • Ingest Usage Management
    • Instance Administration
    • Limits and Standards
    • LogScale Internal Logging
    • LogScale Measurement Repositories
    • LogScale SaaS Upgrades
    • LogScale URLs and Endpoints
    • Manage Groups
    • Manage Roles
    • Manage User Roles
    • Manage Users
    • Manage Users and Permissions
    • Measure Data Ingest
    • Monitor Usage
    • Optimize Ingestion
    • Set a Dynamic Configuration Value
    • What's Measured
  • Related Language Syntax

    • Function Syntax
  • Terminology

    • Cluster Management
  • Training

    • Log Sources
    • Repositories

Enter search term