Fleet Management Configuration Wizard

Available: Configuration Wizard v1.258

Configuration Wizard is available from version 1.258.

The Configuration Wizard is a form-based interface for building and editing Falcon LogScale Collector configurations. It provides a guided, step-by-step alternative to manually writing YAML, making it significantly easier to configure data sources and destinations without sacrificing the flexibility that advanced users rely on.

The wizard is available from LogScale 1.258 as part of Fleet Management.

Note

Manual YAML editing is still fully supported. The wizard appears alongside the YAML editor and the two remain in sync at all times. You can work in whichever way suits you best.

Opening the Configuration Wizard

To open the Configuration Wizard:

  1. Navigate to Data Ingest and select Config Overview.

  2. Open an existing configuration, or create a new one.

    To create a new config, click New Config, type a config name, then click Create new.

  3. The Draft editor is shown, which consists of three panels:

    • the Form Assistant wizard panel on the left

    • the YAML editor in the middle

    • the Published version panel on the right, displaying the currently published config.

    Configuration editor showing the Form Assistant panel on the left listing sources and sinks, the YAML editor in the middle with syntax highlighting and line numbers, and the Published Version in the right panel.

    Figure 16. Configuration Wizard


Note

Both the Form Assistant and the Published Version panels are collapsible. Click the collapse control at the top of either panel to hide them as you prefer. Collapse both if you want to work exclusively in the YAML editor.

Editing with the Form

The Form Assistant consists of a list of connections, which are the links between a source and a sink in the config. The form lists the sources and sinks in your configuration, with one entry per connection.

Fields are grouped and labeled based on the configuration type you are editing, so you do not need to remember the exact YAML keys.

Changes you make in the form are written directly into the YAML in the middle panel. Comments and formatting in the YAML are preserved, so you do not lose notes added by you or a teammate.

At any point during configuration:

  • Click Save to save your draft config without publishing it

  • Click Publish to save the changes and publish them to all the instances which are assigned to this configuration

How the Form and YAML Stay in Sync

The form and YAML editor remain synchronized at all times:

  • Edit a field in the form - the YAML updates immediately in place, preserving comments and formatting.

  • Edit the YAML directly - the form updates automatically to reflect your changes.

If you enter something in the YAML that the form cannot yet represent, the form falls back gracefully, and the YAML remains the source of truth until it can be parsed again. Your changes are not lost.

Navigating Between Form and YAML

You can quickly jump between a form field and its corresponding YAML location, and vice versa. Here's how:

Action Result
Click a field in the form The YAML editor scrolls to and highlights the matching lines.
Ctrl+Click a section in the YAML (Windows/Linux) Jumps to the matching field in the form.
Cmd+Click a section in the YAML (macOS) Jumps to the matching field in the form.

This makes it easier to verify exactly which YAML lines a form field controls before making changes.

Managing Sources and Sinks

Each source and sink is listed as its own entry in the form. You can:

  • Add a new connection using the + control at the bottom of the connections list. New connections made with this control consist of a source and a sink.

  • Remove an existing connection.

  • Change the type of an existing connection using the type selector within the connection entry.

Sharing a Sink Between Multiple Sources

By default, each source has its own dedicated sink. However, a single sink can be shared across multiple sources when they all send data to the same destination.

To share a sink:

  1. In the Sink section of a source entry, click the gear icon to open the sink selector.

  2. View the list of all sinks already defined in your configuration. This view also gives you the option to create a new one.

  3. Select an existing sink to point the source at it. Several sources can then send data to the same destination.

Important

If a sink is already shared between sources, the Configuration Wizard warns you that modifying it will affect every source currently using it. Review the impact before making changes.

Cleaning Up Unused Sinks

If your configuration contains a sink that no source is sending data to, an information icon appears near the top of the Form Assistant panel:

Configuration editor highlighting an unused sink which is not connected to any source.
  • Hover over the icon to see how many sinks are unused.

  • Click the icon to open a dialog where you can review and remove the unused sinks.

Form and YAML Behaviour Reference

The following table summarises the key behaviours of the Configuration Wizard:

Scenario Behaviour
Edit a form field YAML updates immediately; comments and formatting are preserved.
Edit YAML directly Form updates automatically to reflect changes.
YAML contains content the form cannot represent Form degrades gracefully; YAML remains the source of truth until it can be parsed again.
Click a form field YAML editor scrolls to and highlights the matching lines.
Ctrl/Cmd+Click a YAML section Form scrolls to the matching field.
Modify a shared sink Wizard warns that all sources using the sink will be affected.
Unused sink detected Information icon appears near the top of the form; click to open the cleanup dialog.
No changes between draft and published (Compare mode) A notification confirms the draft is identical to the latest published configuration.