Learn how to get started using LogScale
Introduction to log management and LogScale's core capabilities
Learn how LogScale ingests, stores, and queries your log data
A hands-on walkthrough using sample data, no setup required
Short videos covering core concepts and common tasks
How LogScale works internally — from data ingestion to query processing
A tour of the UI — search bar, widgets, and navigation
Definitions for LogScale-specific terms you will see throughout the docs
Learn about different ingest solutions
The native log shipper that collects and forwards logs to LogScale
Release notes and version history for Falcon LogScale Collector
Centrally monitor and configure multiple Collector instances
The schema standard for normalising fields across data sources
Send data into LogScale from external shipping tools
Administration and monitoring guide for Cloud deployments
Monitor usage, manage data lifecycle, and track system health
How organizations, users, and permissions are structured in Cloud
Configure account-wide preferences for your Cloud organisation
Set up authentication, access controls, and security policies
Operating parameters and system limits for LogScale
Move older data to long-term, lower-cost storage
The base URLs and endpoints for your Cloud environment
Administration and configuration guide for self-hosted deployments
Monitor users, manage retention, and oversee licensing
Configure organization owners, permissions, and settings
Set up authentication, access controls, and security policies
Monitor cluster health, replication, and node availability
Operating parameters and system limits for LogScale
Set up long-term archiving to S3 or Google Cloud Storage
Reference for all available cluster configuration settings
Verify your self-hosted cluster is running correctly
API endpoints and URLs for your LogScale instance
Step-by-step instructions for a new self-hosted install
Sizing, prerequisites, and decisions to make before deploying
Deploy and manage LogScale on Kubernetes
How to safely upgrade a self-hosted cluster to a new version
Configure SSO and identity providers for user authentication
Available settings for tuning a self-hosted deployment
Reference for LogScale's built-in repositories and their schema definitions
Schema for LogScale's main internal system repository
Schema for the internal user activity log repository
Schema for the internal audit log repository
Schema for fleet management and log shipper metadata
Schema for detailed per-event ingest measurements and data volume tracking
Schema for the internal platform metrics repository
Schema for hourly aggregated usage metrics and storage tracking
Learn how to write queries and access data
Create and manage data repositories
Use the search interface to explore and filter your events
The grammar and structure of CQL — pipes, filters, and operators
Turn query results into charts, tables, and dashboards
Formal grammar reference for the CrowdStrike Query Language
Automate actions with continuous alerts or scheduled searches
Create and schedule shareable PDF reports
Run a saved query automatically on a recurring schedule
Configure automated responses: email, webhooks, Slack, and more
Overview of all the ways to interact with LogScale programmatically
Send data into LogScale programmatically over HTTP
Run CQL queries programmatically and retrieve results over HTTP
Browse and install pre-built dashboards, parsers, and saved searches
Build, publish, and manage your own reusable packages
Send data into LogScale from external shipping tools
Manage LogScale from your terminal with the humioctl CLI
Supported log formats and how LogScale parses them
Connect LogScale with other tools in your stack
Reference for every available GraphQL query
Reference for every available GraphQL mutation
All data types available in the GraphQL schema
LogScale Query Language Grammar Subset | |||
Learn how to get started using LogScale
Introduction to log management and LogScale's core capabilities
Learn how LogScale ingests, stores, and queries your log data
A hands-on walkthrough using sample data, no setup required
Short videos covering core concepts and common tasks
How LogScale works internally — from data ingestion to query processing
A tour of the UI — search bar, widgets, and navigation
Definitions for LogScale-specific terms you will see throughout the docs
Administration and monitoring guide for Cloud deployments
Monitor usage, manage data lifecycle, and track system health
How organizations, users, and permissions are structured in Cloud
Configure account-wide preferences for your Cloud organisation
Set up authentication, access controls, and security policies
Operating parameters and system limits for LogScale
Move older data to long-term, lower-cost storage
The base URLs and endpoints for your Cloud environment
Administration and configuration guide for self-hosted deployments
Monitor users, manage retention, and oversee licensing
Configure organization owners, permissions, and settings
Set up authentication, access controls, and security policies
Monitor cluster health, replication, and node availability
Operating parameters and system limits for LogScale
Set up long-term archiving to S3 or Google Cloud Storage
Reference for all available cluster configuration settings
Verify your self-hosted cluster is running correctly
API endpoints and URLs for your LogScale instance
Learn how to write queries and access data
Create and manage data repositories
Use the search interface to explore and filter your events
The grammar and structure of CQL — pipes, filters, and operators
Turn query results into charts, tables, and dashboards
Formal grammar reference for the CrowdStrike Query Language
Automate actions with continuous alerts or scheduled searches
Create and schedule shareable PDF reports
Run a saved query automatically on a recurring schedule
Configure automated responses: email, webhooks, Slack, and more
Learn about different ingest solutions
The native log shipper that collects and forwards logs to LogScale
Release notes and version history for Falcon LogScale Collector
Centrally monitor and configure multiple Collector instances
The schema standard for normalising fields across data sources
Send data into LogScale from external shipping tools
Overview of all the ways to interact with LogScale programmatically
Send data into LogScale programmatically over HTTP
Run CQL queries programmatically and retrieve results over HTTP
Browse and install pre-built dashboards, parsers, and saved searches
Build, publish, and manage your own reusable packages
Send data into LogScale from external shipping tools
Manage LogScale from your terminal with the humioctl CLI
Supported log formats and how LogScale parses them
Connect LogScale with other tools in your stack