Skip to content
CrowdStrike LogoLogScale Documentation Library Guidance Release Notes Integrations Query Examples Getting Started API GraphQL Search Archives Contacting Support
🔖 🔔 ੆ Help Button

Falcon LogScale Documentation

Full Search with Filtering
Set as My Default Homepage
Falcon LogScale Cloud Administration Manual
Falcon LogScale Self-Hosted Administration Manual
Falcon LogScale Data Management & Analysis

Favorite Bookmarks

Specific Searches

  • Release Notes Search

  • Guidance Articles Search

  • Integrations Search

  • Query Examples Search

Getting Started

  • LogScale Introduction

    Learn how to get started using LogScale

  • LogScale Overview

    Introduction to log management and LogScale's core capabilities

  • What is LogScale

    Learn how LogScale ingests, stores, and queries your log data

  • LogScale Product Tutorial with Demo Data

    A hands-on walkthrough using sample data, no setup required

  • LogScale Video Series

    Short videos covering core concepts and common tasks

  • LogScale Internal Architecture

    How LogScale works internally — from data ingestion to query processing

  • LogScale Web Interface

    A tour of the UI — search bar, widgets, and navigation

  • Terminology Reference

    Definitions for LogScale-specific terms you will see throughout the docs

Ingesting Data

  • Popular Ingest Methods

    Learn about different ingest solutions

  • Falcon LogScale Collector

    The native log shipper that collects and forwards logs to LogScale

  • Falcon LogScale Collector Releases

    Release notes and version history for Falcon LogScale Collector

  • Fleet and Group Management

    Centrally monitor and configure multiple Collector instances

  • Creating a Repository or View

  • CrowdStrike Parsing Standard 1.2

    The schema standard for normalising fields across data sources

  • Third-Party Log Shippers

    Send data into LogScale from external shipping tools

New Pages

  • Falcon LogScale 1.255.0 GA (2026-08-25)

  • Falcon LogScale 1.240.7 LTS (2026-08-21)

  • Falcon LogScale 1.246.2 LTS (2026-08-20)

  • Falcon LogScale 1.234.5 LTS (2026-08-20)

  • How LogScale interacts with the Kafka Admin API

  • Falcon LogScale 1.254.0 GA (2026-08-18)

  • Time Zone Options for Shared Dashboards

  • Optimize Dashboard Performance with Persisted Aggregations

  • Falcon LogScale 1.253.0 GA (2026-08-11)

  • Query Commands - Reference

  • readPersistedAggregation()

Show more...

Updated Content

  • Query Quotas

  • The humio Repository

  • Falcon LogScale 1.255.0 GA (2026-08-25)

  • Instance Sizing

  • Falcon LogScale 1.240.7 LTS (2026-08-21)

  • Falcon LogScale 1.246.2 LTS (2026-08-20)

  • Falcon LogScale 1.234.5 LTS (2026-08-20)

  • Persisted Aggregations Syntax

  • summary_installation-baremetal-kafka

  • Kafka Configuration

  • summary_dashboards-organize-sections

Show more...

Managing LogScale Cloud

  • LogScale Cloud

    Administration and monitoring guide for Cloud deployments

  • Instance Administration

    Monitor usage, manage data lifecycle, and track system health

  • Understand Organizations

    How organizations, users, and permissions are structured in Cloud

  • Organization Settings

    Configure account-wide preferences for your Cloud organisation

  • Configure Security

    Set up authentication, access controls, and security policies

  • Manage Data Ingest

  • Limits and Standards

    Operating parameters and system limits for LogScale

  • Archive Data

    Move older data to long-term, lower-cost storage

  • LogScale URLs and Endpoints

    The base URLs and endpoints for your Cloud environment

Managing LogScale Self-Hosted

  • LogScale Self-Hosted

    Administration and configuration guide for self-hosted deployments

  • Instance Administration

    Monitor users, manage retention, and oversee licensing

  • Organization Settings

    Configure organization owners, permissions, and settings

  • Configure Security

    Set up authentication, access controls, and security policies

  • Cluster Management

    Monitor cluster health, replication, and node availability

  • Limits and Standards

    Operating parameters and system limits for LogScale

  • Archive Data

    Set up long-term archiving to S3 or Google Cloud Storage

  • Configuration Variables

    Reference for all available cluster configuration settings

  • Health Checks

    Verify your self-hosted cluster is running correctly

  • LogScale URLs and Endpoints

    API endpoints and URLs for your LogScale instance

Deploying LogScale

  • LogScale Self-Hosted Deployment

    Step-by-step instructions for a new self-hosted install

  • Planning to install LogScale

    Sizing, prerequisites, and decisions to make before deploying

  • Humio Operator

    Deploy and manage LogScale on Kubernetes

  • Updating LogScale

    How to safely upgrade a self-hosted cluster to a new version

  • Authentication and identity providers

    Configure SSO and identity providers for user authentication

  • Configuration Settings

    Available settings for tuning a self-hosted deployment

LogScale Internal Repo Reference

  • LogScale System Repository Schema Guide

    Reference for LogScale's built-in repositories and their schema definitions

  • The humio Repository

    Schema for LogScale's main internal system repository

  • The humio-activity repository

    Schema for the internal user activity log repository

  • The humio-audit repository

    Schema for the internal audit log repository

  • The humio-fleet Repository

    Schema for fleet management and log shipper metadata

  • The humio-measurements Repository

    Schema for detailed per-event ingest measurements and data volume tracking

  • The humio-metrics Repository

    Schema for the internal platform metrics repository

  • The humio-usage Repository

    Schema for hourly aggregated usage metrics and storage tracking

  • The humio-trigger-execution-info Repository

Data Management & Analysis

  • CrowdStrike Query Language (CQL)

    Learn how to write queries and access data

  • Manage Repositories and Views

    Create and manage data repositories

  • Search Data

    Use the search interface to explore and filter your events

  • Query Language Syntax

    The grammar and structure of CQL — pipes, filters, and operators

  • Query Functions

  • Data Visualization

    Turn query results into charts, tables, and dashboards

  • CrowdStrike Query Language Grammar Subset

    Formal grammar reference for the CrowdStrike Query Language

  • Triggers

    Automate actions with continuous alerts or scheduled searches

  • Schedule PDF Reports

    Create and schedule shareable PDF reports

  • Scheduled searches

    Run a saved query automatically on a recurring schedule

  • Actions

    Configure automated responses: email, webhooks, Slack, and more

APIs, Integrating, & CLI

  • Application Programming Interfaces (APIs)

    Overview of all the ways to interact with LogScale programmatically

  • Ingest API

    Send data into LogScale programmatically over HTTP

  • Search API

    Run CQL queries programmatically and retrieve results over HTTP

  • Package Marketplace

    Browse and install pre-built dashboards, parsers, and saved searches

  • Package Management

    Build, publish, and manage your own reusable packages

  • Third-Party Log Shippers

    Send data into LogScale from external shipping tools

  • Command-Line Interface (humioctl)

    Manage LogScale from your terminal with the humioctl CLI

  • Log Formats

    Supported log formats and how LogScale parses them

  • Other Integrations

    Connect LogScale with other tools in your stack

GraphQL API

  • GraphQL API

  • GraphQL Queries

    Reference for every available GraphQL query

  • GraphQL Mutations

    Reference for every available GraphQL mutation

  • GraphQL Datatypes

    All data types available in the GraphQL schema

Full Document Library

Falcon LogScale Cloud Administration
Falcon LogScale Cloud 1.247-1.255.0
Falcon LogScale Self-Hosted Administration
Falcon LogScale Self-Hosted 1.247-1.255.0 (GA)
Falcon LogScale Self-Hosted 1.241.0-1.246.1 (LTS)
Falcon LogScale Self-Hosted 1.235.0-1.240.5
Falcon LogScale Self-Hosted 1.229.0-1.234.3
Falcon LogScale Self-Hosted 1.220.0-1.228.3
Falcon LogScale Self-Hosted 1.214.0-1.219.0
Falcon LogScale Self-Hosted 1.209.0-1.213.0
Falcon LogScale Self-Hosted 1.202.0-1.208.0
Falcon LogScale Self-Hosted 1.202.0-1.207.0
Falcon LogScale Self-Hosted 1.196.0-1.201.0
Falcon LogScale Self-Hosted 1.190.0-1.195.0
Falcon LogScale Self-Hosted 1.184.0-1.189.0
Falcon LogScale Self-Hosted 1.178.0-1.183.0
Falcon LogScale Self-Hosted 1.177.0-1.177.2
Falcon LogScale Self-Hosted 1.172.0-1.176.0
LogScale Data Analysis
Data Analysis 1.247-1.255.0
Data Analysis 1.241.0-1.246.1
Data Analysis 1.235.0-1.240.5
Data Analysis 1.229.0-1.234.3
Data Analysis 1.220.0-1.228.3
Data Analysis 1.214.0-1.219.0
Data Analysis 1.209.0-1.213.0
Data Analysis 1.202.0-1.208.0
Data Analysis 1.202.0-1.207.0
Data Analysis 1.196.0-1.201.0
Data Analysis 1.190.0-1.195.0
Data Analysis 1.184.0-1.189.0
Data Analysis 1.178.0-1.183.0
Data Analysis 1.177.0-1.177.2
Data Analysis 1.172.0-1.176.0
Humio Operator
Humio Operator 0.36.0 (GA)
LogScale Self-Hosted Deployment
Deployment 1.247-1.255.0 (GA)
Deployment 1.241.0-1.246.1 (LTS)
Deployment 1.235.0-1.240.5
Deployment 1.229.0-1.234.3
Deployment 1.220.0-1.228.3
Deployment 1.214.0-1.219.0
Deployment 1.209.0-1.213.0
Deployment 1.202.0-1.208.0
Deployment 1.202.0-1.207.0 (LTS)
Deployment 1.196.0-1.201.0 (LTS)
Deployment 1.190.0-1.195.0
Deployment 1.184.0-1.189.0
Deployment 1.178.0-1.183.0
Deployment 1.177.0-1.177.2
Deployment 1.172.0-1.176.0
Falcon LogScale Collector
Falcon LogScale Collector 1.9.0-1.11.5
Falcon LogScale Collector 1.3.0-1.8.3
Falcon LogScale Reference Architectures Manual
Reference Architectures
LogScale APIs
Falcon LogScale APIs 1.118.0-1.255.0
LogScale GraphQL Reference
LogScale GraphQL Reference - Queries
LogScale GraphQL Reference - Mutations
LogScale GraphQL Reference - Datatypes
Supporting Information
Logscale Architecture
LogScale System Repository Schema Guide
LogScale Parsing Standard 1.2
LogScale Parsing Standard 1.0
Integrations
Guidance
CrowdStrike Query Language 1.247-1.255.0
Release Notes
CrowdStrike Query Language 1.247-1.255.0
Getting Data In (GDI)
Getting Data Out (GDO)
LogScale Third-Party Log Shippers
LogScale Parsing Standard 1.1
LogScale Command Line
Falcon LogScale Query Examples
Getting Started
LogScale Query Language Grammar Subset
LogScale Query Language Grammar Subset
PDF
LogScale Terminology

Getting Started

  • LogScale Introduction

    Learn how to get started using LogScale

  • LogScale Overview

    Introduction to log management and LogScale's core capabilities

  • What is LogScale

    Learn how LogScale ingests, stores, and queries your log data

  • LogScale Product Tutorial with Demo Data

    A hands-on walkthrough using sample data, no setup required

  • LogScale Video Series

    Short videos covering core concepts and common tasks

  • LogScale Internal Architecture

    How LogScale works internally — from data ingestion to query processing

  • LogScale Web Interface

    A tour of the UI — search bar, widgets, and navigation

  • Terminology Reference

    Definitions for LogScale-specific terms you will see throughout the docs

Managing LogScale Cloud

  • LogScale Cloud

    Administration and monitoring guide for Cloud deployments

  • Instance Administration

    Monitor usage, manage data lifecycle, and track system health

  • Understand Organizations

    How organizations, users, and permissions are structured in Cloud

  • Organization Settings

    Configure account-wide preferences for your Cloud organisation

  • Configure Security

    Set up authentication, access controls, and security policies

  • Manage Data Ingest

  • Limits and Standards

    Operating parameters and system limits for LogScale

  • Archive Data

    Move older data to long-term, lower-cost storage

  • LogScale URLs and Endpoints

    The base URLs and endpoints for your Cloud environment

Managing LogScale Self-Hosted

  • LogScale Self-Hosted

    Administration and configuration guide for self-hosted deployments

  • Instance Administration

    Monitor users, manage retention, and oversee licensing

  • Organization Settings

    Configure organization owners, permissions, and settings

  • Configure Security

    Set up authentication, access controls, and security policies

  • Cluster Management

    Monitor cluster health, replication, and node availability

  • Limits and Standards

    Operating parameters and system limits for LogScale

  • Archive Data

    Set up long-term archiving to S3 or Google Cloud Storage

  • Configuration Variables

    Reference for all available cluster configuration settings

  • Health Checks

    Verify your self-hosted cluster is running correctly

  • LogScale URLs and Endpoints

    API endpoints and URLs for your LogScale instance

Data Management & Analysis

  • CrowdStrike Query Language (CQL)

    Learn how to write queries and access data

  • Manage Repositories and Views

    Create and manage data repositories

  • Search Data

    Use the search interface to explore and filter your events

  • Query Language Syntax

    The grammar and structure of CQL — pipes, filters, and operators

  • Query Functions

  • Data Visualization

    Turn query results into charts, tables, and dashboards

  • CrowdStrike Query Language Grammar Subset

    Formal grammar reference for the CrowdStrike Query Language

  • Triggers

    Automate actions with continuous alerts or scheduled searches

  • Schedule PDF Reports

    Create and schedule shareable PDF reports

  • Scheduled searches

    Run a saved query automatically on a recurring schedule

  • Actions

    Configure automated responses: email, webhooks, Slack, and more

Ingesting Data

  • Popular Ingest Methods

    Learn about different ingest solutions

  • Falcon LogScale Collector

    The native log shipper that collects and forwards logs to LogScale

  • Falcon LogScale Collector Releases

    Release notes and version history for Falcon LogScale Collector

  • Fleet and Group Management

    Centrally monitor and configure multiple Collector instances

  • Creating a Repository or View

  • CrowdStrike Parsing Standard 1.2

    The schema standard for normalising fields across data sources

  • Third-Party Log Shippers

    Send data into LogScale from external shipping tools

APIs, Integrating, & CLI

  • Application Programming Interfaces (APIs)

    Overview of all the ways to interact with LogScale programmatically

  • Ingest API

    Send data into LogScale programmatically over HTTP

  • Search API

    Run CQL queries programmatically and retrieve results over HTTP

  • Package Marketplace

    Browse and install pre-built dashboards, parsers, and saved searches

  • Package Management

    Build, publish, and manage your own reusable packages

  • Third-Party Log Shippers

    Send data into LogScale from external shipping tools

  • Command-Line Interface (humioctl)

    Manage LogScale from your terminal with the humioctl CLI

  • Log Formats

    Supported log formats and how LogScale parses them

  • Other Integrations

    Connect LogScale with other tools in your stack

New Pages

  • Falcon LogScale 1.255.0 GA (2026-08-25)

  • Falcon LogScale 1.240.7 LTS (2026-08-21)

  • Falcon LogScale 1.246.2 LTS (2026-08-20)

  • Falcon LogScale 1.234.5 LTS (2026-08-20)

  • How LogScale interacts with the Kafka Admin API

  • Falcon LogScale 1.254.0 GA (2026-08-18)

  • Time Zone Options for Shared Dashboards

  • Optimize Dashboard Performance with Persisted Aggregations

  • Falcon LogScale 1.253.0 GA (2026-08-11)

  • Query Commands - Reference

  • readPersistedAggregation()

Updated Content

  • Query Quotas

  • The humio Repository

  • Falcon LogScale 1.255.0 GA (2026-08-25)

  • Instance Sizing

  • Falcon LogScale 1.240.7 LTS (2026-08-21)

  • Falcon LogScale 1.246.2 LTS (2026-08-20)

  • Falcon LogScale 1.234.5 LTS (2026-08-20)

  • Persisted Aggregations Syntax

  • summary_installation-baremetal-kafka

  • Kafka Configuration

  • summary_dashboards-organize-sections

CrowdStrike.com
Support
  • Twitter
  • LinkedIn
  • Youtube

© 2026 CrowdStrike All other marks contained herein are the property of their respective owners.

Enter search term