Getting Data into LogScale
Learn ingestion concepts and how to configure sources, parse data, and send logs.
GDI Fundamentals
Learn GDI basics, data ingestion concepts, and data flows.
- What is GDI?
- What is a Repository?
- Identify Data Sources
- What Ingest Methods are available?
- Data Parsing and Timestamps
- Monitor Ingest
Ingest and Parse
Configure repositories, select ingest methods, and build parsers.
- Generate An Ingest Token and verify data retention policies
- Choose an Ingest Method
- Configure Data Ingest
- Parse Data
Cloud-Native Ingestion
Ingest logs and metrics from cloud platforms with native integrations. Ideal for SecOps, DevOps, and SRE teams.
- AWS CloudTrail, CloudWatch and S3 Integration
- Azure Event Hubs and Blob Storage
- Google Cloud Logging and Pub/Sub
- Cloud-Native Parsing and Enrichment
On-Premises and Traditional Systems
Collect logs from syslog sources, Windows servers, network devices, and databases. Ideal for ITOps teams.
- Syslog Configuration for Network Devices
- Windows Event Log Collection
- Database and Application Server Logs
- Legacy System Integration
Container and Kubernetes Logs
Deploy LogScale Collector in container environments with Helm charts and DaemonSets. Ideal for DevOps and SRE teams.
- Kubernetes DaemonSet Deployment
- Docker Container Log Collection
- Pod and Node Log Aggregation
- Container Metadata Enrichment
Security and SIEM Integration
Integrate EDR platforms, SIEM connectors, firewalls, and threat intelligence feeds. Ideal for SecOps and security analysts.
- CrowdStrike Falcon EDR Integration
- SIEM Connector Setup (Splunk, QRadar, Sentinel)
- Firewall and IDS/IPS Logs (Palo Alto, Cisco, Fortinet)
- Threat Intelligence Feed Integration
Path 1: GDI Fundamentals
Learn the fundamentals of data ingestion. These concepts make configuring ingest and parsing straightforward.
What is GDI?
Understand the fundamentals of getting data into LogScale
What is a Repository?
Learn how repositories organize and store your data
Identify Data Sources
Understand what types of data you can send to LogScale
What Ingest Methods are Available?
Compare different methods to send data to LogScale
Ingest Methods Overview
guideintermediateCompare all available ingestion methods
Ingest API
guideintermediateSend data directly through HTTP endpoints
Log Collectors
guideintermediateUse agents to collect and forward logs
Pre-built Integrations
guideintermediateIntegrations for common platforms and services
Data Parsing and Timestamps
Learn how LogScale parses data and handles timestamps
Monitor Ingestion and Data Impact
Track ingested data and understand how the ingest process impacts data
Path 2: Implement Ingestion and Parsing
Master GDI capabilities with this hands-on progression through repository setup, data ingestion, and parsing configuration.
Generate Ingest Token and Verify Data Retention
Create authentication tokens and confirm retention policies
Choose an Ingest Method
Select and configure the best ingestion method for your data source
Ingest Methods Overview
guideintermediateComplete reference of all ingestion methods
Ingest API
guideintermediateHTTP endpoints for direct data ingestion
Log Collectors
guideintermediateAgent-based log collection and forwarding
Integrations
guideintermediatePre-built integrations for common data sources
Configure Data Ingest
Set up and configure your data ingestion pipeline
Parse Data
Create or Choose and apply parsers to extract fields from your data
Workflow 3: On-Premises and Traditional Systems
Collect logs from syslog sources, Windows servers, network devices, and databases.
Syslog Configuration
Configure syslog for network devices, firewalls, and legacy systems
Syslog
guideintermediateStep-by-step guide for syslog ingestion (Setup effort: Low to Medium)
Cisco Network Devices
guideintermediateConfigure syslog on Cisco routers and switches
Palo Alto Firewalls
guideintermediateForward Palo Alto firewall logs via syslog
Fortinet FortiGate
guideintermediateConfigure FortiGate firewall syslog forwarding
Syslog Parser Configuration
guideintermediateParse standard and custom syslog formats
Windows Event Logs
Collect Windows Event Logs from servers and workstations
Windows Event Collector
guideintermediateStep-by-step guide for Windows Event Collector (Setup effort: Medium)
WMI-Based Collection
guideintermediateUse WMI for Windows Event Log collection
LogScale Collector for Windows
guideintermediateDeploy collector agent on Windows systems
Windows Event Parsers
guideintermediateParse Windows Security, Application, and System logs
Database and Application Servers
Ingest logs from databases, web servers, and application platforms
Database Logs (JDBC)
guideintermediateStep-by-step guide for database log collection via JDBC (Setup effort: High)
SNMP Traps
guideintermediateStep-by-step guide for SNMP trap ingestion (Setup effort: Medium)
Apache Web Server Logs
guideintermediateConfigure Apache access and error log ingestion
NGINX Logs
guideintermediateIngest NGINX access and error logs
Microsoft IIS Logs
guideintermediateCollect IIS web server logs
Legacy System Best Practices
Optimize traditional system log collection and troubleshooting
Workflow 4: Container and Kubernetes Logs
Deploy LogScale Collector in container environments. Collect logs from Docker containers and Kubernetes pods.
Kubernetes DaemonSet Deployment
Deploy LogScale Collector to Kubernetes using Helm charts
Falcon LogScale Collector
guideintermediateStep-by-step guide for deploying the LogScale Collector (Setup effort: Low to Medium)
Deploy via Helm Chart
guideintermediateInstall LogScale Collector using Helm
DaemonSet Configuration
guideintermediateConfigure DaemonSet for cluster-wide collection
RBAC Configuration
guideintermediateSet up service accounts and permissions
Pod and Container Log Collection
Collect logs from pods, containers, and container runtime
Pod Log Collection
guideintermediateAutomatically collect logs from all pods
Pod Annotations for Parsing
guideintermediateUse annotations to assign parsers
Multi-line Log Handling
guideintermediateConfigure multi-line log parsing for stack traces
JSON Log Parsing
guideintermediateParse structured JSON logs from containers
Docker Container Logs
Collect logs from Docker containers on standalone hosts
Docker Collector
guideintermediateStep-by-step guide for Docker log collection (Setup effort: Medium)
Kafka
guideintermediateStep-by-step guide for Kafka ingestion (Setup effort: High)
Docker Compose Configuration
guideintermediateAdd LogScale Collector to Docker Compose stacks
Docker Swarm Deployment
guideintermediateDeploy collector in Docker Swarm mode
Metadata Enrichment and Best Practices
Enrich logs with container and Kubernetes metadata
Workflow 5: Security and SIEM Integration
Integrate EDR platforms, SIEM connectors, firewalls, and threat intelligence feeds for security monitoring.
CrowdStrike Falcon EDR Integration
Ingest detections, events, and telemetry from Falcon platform
Crowdstream
guideintermediateStep-by-step guide for Crowdstream ingestion (Setup effort: Medium to High)
Falcon Detections
guideintermediateIngest Falcon intel indicators and detection streams
Falcon Spotlight Vulnerabilities
guideintermediateImport vulnerability assessment data
Falcon Device Package
guideintermediatePre-built dashboards and queries for Falcon devices
SIEM Connector Setup
Configure bidirectional integration with existing SIEM platforms
Firewall and Network Security Logs
Ingest logs from firewalls, IDS/IPS, and network security devices
Palo Alto Networks
guideintermediateIngest Palo Alto firewall logs
Cisco ASA Firewalls
guideintermediateConfigure Cisco ASA log forwarding
Fortinet FortiGate
guideintermediateIngest FortiGate security logs
Check Point Firewalls
guideintermediateForward Check Point logs to LogScale
CEF and LEEF Parsing
referenceintermediateParse Common Event Format and LEEF security logs
Threat Intelligence and Security Packages
Integrate threat feeds and install pre-built security packages
Workflow 6: Custom and Application Integration
Build custom integrations with the Ingest API. Configure log shippers, develop parsers, and instrument applications.
Ingest API Setup
Use the REST API to send data directly to LogScale
HTTP / HTTPS API
apiintermediateStep-by-step guide for HTTP/HTTPS API ingestion (Setup effort: Medium)
API Authentication
apiintermediateAuthenticate with ingest tokens
Send Structured Data
apiintermediateIngest JSON, NDJSON, and structured logs
Send Unstructured Data
apiintermediateIngest raw text logs via API
Bulk Ingestion
apiintermediateOptimize throughput with batch ingestion
Log Shipper Configuration
Configure Filebeat, Fluentd, Logstash, and other forwarders
Filebeat
guideintermediateStep-by-step guide for Filebeat configuration (Setup effort: Medium)
Fluentd
guideintermediateStep-by-step guide for Fluentd integration (Setup effort: High)
Logstash
guideintermediateStep-by-step guide for Logstash pipeline configuration (Setup effort: High)
LogScale Collector
guideintermediateNative lightweight collector agent
Rsyslog Forwarding
guideintermediateConfigure rsyslog to forward to LogScale
Custom Parser Development
Build and test parsers for proprietary or unique log formats
Create Custom Parsers
guideintermediateBuild parsers using LogScale parsing language
Regular Expression Parsing
referenceintermediateExtract fields using regex patterns
JSON Path Extraction
guideintermediateParse JSON logs with JSON path expressions
Parsers Validation
guideintermediateValidate parser logic with sample data
Managing Parsers
guideintermediatePerformance optimization and maintainability
Application Log Instrumentation
Instrument applications to send logs directly to LogScale