Skip to content
CrowdStrike LogoLogScale Documentation Library Guidance Release Notes Integrations Query Examples Getting Started API GraphQL Search Archives Contacting Support
🔖 🔔 ੆ Help Button

Falcon LogScale Documentation

Full Search with Filtering
Set as My Default Homepage
Falcon LogScale Cloud Administration Manual
Falcon LogScale Self-Hosted Administration Manual
Falcon LogScale Data Management & Analysis

Favorite Bookmarks

Specific Searches

  • Release Notes Search

  • Guidance Articles Search

  • Integrations Search

  • Query Examples Search

Getting Started

  • LogScale Introduction

    Learn how to get started using LogScale

  • LogScale Overview

    Introduction to log management and LogScale's core capabilities

  • What is LogScale

    Learn how LogScale ingests, stores, and queries your log data

  • LogScale Product Tutorial with Demo Data

    A hands-on walkthrough using sample data, no setup required

  • LogScale Video Series

    Short videos covering core concepts and common tasks

  • LogScale Internal Architecture

    How LogScale works internally — from data ingestion to query processing

  • LogScale Web Interface

    A tour of the UI — search bar, widgets, and navigation

  • Terminology Reference

    Definitions for LogScale-specific terms you will see throughout the docs

Ingesting Data

  • LogScale Getting Data In

    Learn about methods and tools for ingesting data into Falcon LogScale

  • Getting Data In

    Understand the baics of Getting Data In to LogScale

  • Getting Data In Process

    Learn about the procesess involved in getting data into Falcon LogScale

  • Falcon LogScale Collector

    The native log shipper that collects and forwards logs to LogScale

  • Falcon LogScale Collector Releases

    Release notes and version history for Falcon LogScale Collector

  • Popular Ingest Methods

    Learn about different ingest solutions

  • Fleet and Group Management

    Centrally monitor and configure multiple Collector instances

  • CrowdStrike Parsing Standard 1.2

    The schema standard for normalising fields across data sources

  • Manage Data Ingest

    Configure and control data ingestion

New Pages

  • Key Ingestion Terms

  • Deploying Single PDF Render Services

  • Deploying Multiple PDF Render Services

  • Configuring Logging for the PDF Service

  • PDF Render Server Configuration Options

  • Adding PDF Render to LogScale Configuration

  • Basic Configuration

  • Configure Postmark

  • Enabling and Disabling Feature Flags

  • HTTP Proxy Client Configuration

  • IOC Configuration

Show more...

Updated Content

  • Certificate Rotation

  • CrowdStream

  • Differences from Other Regex Implementations

  • Time point

  • Miscellaneous Cluster Management API Endpoints

  • Log Collector Metadata

  • Calculate Total Log Volume Per Service

  • Calculate Total Log Volume Per Service

  • Release Notes

  • Falcon LogScale 1.258.1 LTS (2026-10-07)

  • Falcon LogScale 1.261.0 GA (2026-10-06)

Show more...

Managing LogScale Cloud

  • LogScale Cloud

    Administration and monitoring guide for Cloud deployments

  • Instance Administration

    Monitor usage, manage data lifecycle, and track system health

  • Understand Organizations

    How organizations, users, and permissions are structured in Cloud

  • Organization Settings

    Configure account-wide preferences for your Cloud organisation

  • Configure Security

    Set up authentication, access controls, and security policies

  • Limits and Standards

    Operating parameters and system limits for LogScale

  • Archive Data

    Move older data to long-term, lower-cost storage

  • LogScale URLs and Endpoints

    The base URLs and endpoints for your Cloud environment

Managing LogScale Self-Hosted

  • LogScale Self-Hosted

    Administration and configuration guide for self-hosted deployments

  • Instance Administration

    Monitor users, manage retention, and oversee licensing

  • Organization Settings

    Configure organization owners, permissions, and settings

  • Configure Security

    Set up authentication, access controls, and security policies

  • Cluster Management

    Monitor cluster health, replication, and node availability

  • Limits and Standards

    Operating parameters and system limits for LogScale

  • Archive Data

    Set up long-term archiving to S3 or Google Cloud Storage

  • Configuration Variables

    Reference for all available cluster configuration settings

  • Health Checks

    Verify your self-hosted cluster is running correctly

  • LogScale URLs and Endpoints

    API endpoints and URLs for your LogScale instance

Deploying LogScale

  • LogScale Self-Hosted Deployment

    Step-by-step instructions for a new self-hosted install

  • Planning to install LogScale

    Sizing, prerequisites, and decisions to make before deploying

  • Humio Operator

    Deploy and manage LogScale on Kubernetes

  • Reference Architectures

    Build a LogScale cluster quickly using a reference architecture for a supported cloud platform.

  • Updating LogScale

    How to safely upgrade a self-hosted cluster to a new version

  • Authentication and identity providers

    Configure SSO and identity providers for user authentication

  • Configuration Settings

    Available settings for tuning a self-hosted deployment

LogScale Internal Repo Reference

  • LogScale System Repository Schema Guide

    Reference for LogScale's built-in repositories and their schema definitions

  • The humio Repository

    Schema for LogScale's main internal system repository

  • The humio-activity repository

    Schema for the internal user activity log repository

  • The humio-audit repository

    Schema for the internal audit log repository

  • The humio-fleet Repository

    Schema for fleet management and log shipper metadata

  • The humio-measurements Repository

    Schema for detailed per-event ingest measurements and data volume tracking

  • The humio-metrics Repository

    Schema for the internal platform metrics repository

  • The humio-usage Repository

    Schema for hourly aggregated usage metrics and storage tracking

  • The humio-trigger-execution-info Repository

    Schema for triggers and automations within LogScale

Data Management & Analysis

  • CrowdStrike Query Language (CQL)

    Learn how to write queries and access data

  • Manage Repositories and Views

    Organize data in repositories and control access with views

  • Search Data

    Use the search interface to explore and filter your events

  • Examples Library

    Our examples library contains detaile query examples and step-by-step descriptions of what the query is doing and how the query achieves the original goal.

  • Write Queries

    An introduction to building CQL queries step by step

  • Query Language Syntax

    The grammar and structure of CQL — pipes, filters, and operators

  • Query Functions

    The full suite of functions in LogScale that support the CrowdStrike Query Language

  • Data Visualization

    Turn query results into charts, tables, and dashboards

  • Getting Data Out

    Learn the basics of getting data out of your LogScale instance

  • CrowdStrike Query Language Grammar Subset

    Formal grammar reference for the CrowdStrike Query Language

  • Triggers

    Automate actions with continuous alerts or scheduled searches

  • Schedule PDF Reports

    Create and schedule shareable PDF reports

  • Scheduled Searches

    Run a saved query automatically on a recurring schedule

  • Actions

    Configure automated responses: email, webhooks, Slack, and more

APIs, Integrating, & CLI

  • Application Programming Interfaces (APIs)

    Overview of all the ways to interact with LogScale programmatically

  • Ingest API

    Send data into LogScale programmatically over HTTP

  • Search API

    Run CQL queries programmatically and retrieve results over HTTP

  • Package Marketplace

    Browse and install pre-built dashboards, parsers, and saved searches

  • Package Management

    Build, publish, and manage your own reusable packages

  • Third-Party Log Shippers

    Send data into LogScale from external shipping tools

  • Command-Line Interface (humioctl)

    Manage LogScale from your terminal with the humioctl CLI

  • Log Formats

    Supported log formats and how LogScale parses them

  • Other Integrations

    Connect LogScale with other tools in your stack

GraphQL API

  • GraphQL API

    Basic information for using the GraphQL API with LogScale

  • GraphQL Queries

    Reference for every available GraphQL query

  • GraphQL Mutations

    Reference for every available GraphQL mutation

  • GraphQL Datatypes

    All data types available in the GraphQL schema

Full Document Library

Falcon LogScale Cloud Administration
Falcon LogScale Cloud 1.253-1.261.0
Falcon LogScale Self-Hosted Administration
Falcon LogScale Self-Hosted 1.253-1.261.0 (GA)
Falcon LogScale Self-Hosted 1.247.0-1.252.1 (LTS)
Falcon LogScale Self-Hosted 1.241.0-1.246.1
Falcon LogScale Self-Hosted 1.235.0-1.240.5
Falcon LogScale Self-Hosted 1.229.0-1.234.3
Falcon LogScale Self-Hosted 1.220.0-1.228.3
Falcon LogScale Self-Hosted 1.214.0-1.219.0
Falcon LogScale Self-Hosted 1.209.0-1.213.0
Falcon LogScale Self-Hosted 1.202.0-1.208.0
Falcon LogScale Self-Hosted 1.202.0-1.207.0
LogScale Self-Hosted Deployment
Deployment 1.253-1.261.0 (GA)
Deployment 1.247.0-1.252.1 (LTS)
Deployment 1.241.0-1.246.1
Deployment 1.235.0-1.240.5
Deployment 1.229.0-1.234.3
Deployment 1.220.0-1.228.3
Deployment 1.214.0-1.219.0
Deployment 1.209.0-1.213.0
Deployment 1.202.0-1.208.0
Deployment 1.202.0-1.207.0 (LTS)
LogScale Data Analysis
Data Analysis 1.253-1.261.0
Data Analysis 1.247.0-1.252.1
Data Analysis 1.241.0-1.246.1
Data Analysis 1.235.0-1.240.5
Data Analysis 1.229.0-1.234.3
Data Analysis 1.220.0-1.228.3
Data Analysis 1.214.0-1.219.0
Data Analysis 1.209.0-1.213.0
Data Analysis 1.202.0-1.208.0
Data Analysis 1.202.0-1.207.0
Humio Operator
Humio Operator 0.37.0 (GA)
Falcon LogScale Reference Architectures Manual
Reference Architectures
Falcon LogScale Collector
Falcon LogScale Collector 1.9.0-1.11.7
Falcon LogScale Collector 1.3.0-1.8.3
LogScale APIs
Falcon LogScale APIs 1.118.0-1.261.0
LogScale GraphQL Reference
LogScale GraphQL Reference - Queries
LogScale GraphQL Reference - Mutations
LogScale GraphQL Reference - Datatypes
Supporting Information
Logscale Architecture
LogScale System Repository Schema Guide
LogScale Parsing Standard 1.2
LogScale Parsing Standard 1.0
Integrations
Guidance
CrowdStrike Query Language 1.253-1.261.0
Release Notes
Getting Data In (GDI)
Getting Data Out (GDO)
LogScale Third-Party Log Shippers
LogScale Parsing Standard 1.1
LogScale Command Line
Falcon LogScale Query Examples
Getting Started
LogScale Query Language Grammar Subset
LogScale Query Language Grammar Subset
PDF
LogScale Terminology

Getting Started

  • LogScale Introduction

    Learn how to get started using LogScale

  • LogScale Overview

    Introduction to log management and LogScale's core capabilities

  • What is LogScale

    Learn how LogScale ingests, stores, and queries your log data

  • LogScale Product Tutorial with Demo Data

    A hands-on walkthrough using sample data, no setup required

  • LogScale Video Series

    Short videos covering core concepts and common tasks

  • LogScale Internal Architecture

    How LogScale works internally — from data ingestion to query processing

  • LogScale Web Interface

    A tour of the UI — search bar, widgets, and navigation

  • Terminology Reference

    Definitions for LogScale-specific terms you will see throughout the docs

Managing LogScale Cloud

  • LogScale Cloud

    Administration and monitoring guide for Cloud deployments

  • Instance Administration

    Monitor usage, manage data lifecycle, and track system health

  • Understand Organizations

    How organizations, users, and permissions are structured in Cloud

  • Organization Settings

    Configure account-wide preferences for your Cloud organisation

  • Configure Security

    Set up authentication, access controls, and security policies

  • Limits and Standards

    Operating parameters and system limits for LogScale

  • Archive Data

    Move older data to long-term, lower-cost storage

  • LogScale URLs and Endpoints

    The base URLs and endpoints for your Cloud environment

Managing LogScale Self-Hosted

  • LogScale Self-Hosted

    Administration and configuration guide for self-hosted deployments

  • Instance Administration

    Monitor users, manage retention, and oversee licensing

  • Organization Settings

    Configure organization owners, permissions, and settings

  • Configure Security

    Set up authentication, access controls, and security policies

  • Cluster Management

    Monitor cluster health, replication, and node availability

  • Limits and Standards

    Operating parameters and system limits for LogScale

  • Archive Data

    Set up long-term archiving to S3 or Google Cloud Storage

  • Configuration Variables

    Reference for all available cluster configuration settings

  • Health Checks

    Verify your self-hosted cluster is running correctly

  • LogScale URLs and Endpoints

    API endpoints and URLs for your LogScale instance

Data Management & Analysis

  • CrowdStrike Query Language (CQL)

    Learn how to write queries and access data

  • Manage Repositories and Views

    Organize data in repositories and control access with views

  • Search Data

    Use the search interface to explore and filter your events

  • Examples Library

    Our examples library contains detaile query examples and step-by-step descriptions of what the query is doing and how the query achieves the original goal.

  • Write Queries

    An introduction to building CQL queries step by step

  • Query Language Syntax

    The grammar and structure of CQL — pipes, filters, and operators

  • Query Functions

    The full suite of functions in LogScale that support the CrowdStrike Query Language

  • Data Visualization

    Turn query results into charts, tables, and dashboards

  • Getting Data Out

    Learn the basics of getting data out of your LogScale instance

  • CrowdStrike Query Language Grammar Subset

    Formal grammar reference for the CrowdStrike Query Language

  • Triggers

    Automate actions with continuous alerts or scheduled searches

  • Schedule PDF Reports

    Create and schedule shareable PDF reports

  • Scheduled Searches

    Run a saved query automatically on a recurring schedule

  • Actions

    Configure automated responses: email, webhooks, Slack, and more

Ingesting Data

  • LogScale Getting Data In

    Learn about methods and tools for ingesting data into Falcon LogScale

  • Getting Data In

    Understand the baics of Getting Data In to LogScale

  • Getting Data In Process

    Learn about the procesess involved in getting data into Falcon LogScale

  • Falcon LogScale Collector

    The native log shipper that collects and forwards logs to LogScale

  • Falcon LogScale Collector Releases

    Release notes and version history for Falcon LogScale Collector

  • Popular Ingest Methods

    Learn about different ingest solutions

  • Fleet and Group Management

    Centrally monitor and configure multiple Collector instances

  • CrowdStrike Parsing Standard 1.2

    The schema standard for normalising fields across data sources

  • Manage Data Ingest

    Configure and control data ingestion

APIs, Integrating, & CLI

  • Application Programming Interfaces (APIs)

    Overview of all the ways to interact with LogScale programmatically

  • Ingest API

    Send data into LogScale programmatically over HTTP

  • Search API

    Run CQL queries programmatically and retrieve results over HTTP

  • Package Marketplace

    Browse and install pre-built dashboards, parsers, and saved searches

  • Package Management

    Build, publish, and manage your own reusable packages

  • Third-Party Log Shippers

    Send data into LogScale from external shipping tools

  • Command-Line Interface (humioctl)

    Manage LogScale from your terminal with the humioctl CLI

  • Log Formats

    Supported log formats and how LogScale parses them

  • Other Integrations

    Connect LogScale with other tools in your stack

New Pages

  • Key Ingestion Terms

  • Deploying Single PDF Render Services

  • Deploying Multiple PDF Render Services

  • Configuring Logging for the PDF Service

  • PDF Render Server Configuration Options

  • Adding PDF Render to LogScale Configuration

  • Basic Configuration

  • Configure Postmark

  • Enabling and Disabling Feature Flags

  • HTTP Proxy Client Configuration

  • IOC Configuration

Updated Content

  • Certificate Rotation

  • CrowdStream

  • Differences from Other Regex Implementations

  • Time point

  • Miscellaneous Cluster Management API Endpoints

  • Log Collector Metadata

  • Calculate Total Log Volume Per Service

  • Calculate Total Log Volume Per Service

  • Release Notes

  • Falcon LogScale 1.258.1 LTS (2026-10-07)

  • Falcon LogScale 1.261.0 GA (2026-10-06)

CrowdStrike.com
Support
  • Twitter
  • LinkedIn
  • Youtube

© 2026 CrowdStrike All other marks contained herein are the property of their respective owners.

Enter search term