Skip to content
LogoLogScale DocumentationFull Library Knowledge Base Release Notes Integrations Query Examples Training API GraphQL API Contacting Support
help

Versions of this Page

    • APIs
    • Action API
    • Alert API
    • API Authentication
    • Cluster Management API
      • Manage Bucket Storage Targets
      • List Cluster Members
      • Manage Nodes in a Cluster
      • Manage Cluster Segments
      • Manage Digest Partitions
      • Manage Kafka Queue Settings
      • Manage Repositories in the Cluster
      • Miscellaneous Cluster Management API Endpoints
    • Health Check API
    • Ingest API
      • Ingesting Unstructured Data
      • Ingesting Structured Data
      • Ingesting Raw Data
      • Ingesting Raw JSON Data
      • Ingesting with HTTP Event Collector (HEC)
        • Ingesting Into Multiple Repositories
      • Ingesting with Raw HEC
      • Ingesting with OpenTelemetry
    • Lookup API
    • Redact Events API
    • Search API
      • Running Query Jobs
        • Creating a Query Job
        • Polling a Query Job
          • Query metaData
          • Query extraData
          • Query warnings
        • Pagination of Results
        • Deleting a Query Job
      • Streaming Search Request
        • Triggering Direct Download of the Results
        • Live Search Request
      • Search API Time Specification
      • Search Response Format
      • Returned Event Count
    • Software Libraries
Falcon LogScale Documentation
/ LogScale APIs 1.0.0-1.117.0

Search API

The Search API is the primary endpoint for running queries for a specific repository or view.

There are two main types of queries in LogScale:

  • Static Query

    This is the normal query on event data, such as you would type directly into the search box in LogScale.

  • Live Query

    A live query returns information as a stream of data that is updated as new events are ingested into the repository. Live queries return any immediate results and then stream additional results after ingest, leaving the request open to stream additional data. In LogScale you select the Live checkbox to enable live queries.

In addition, there are two main endpoints on which both Static and Live queries can be submitted:

  • Query Jobs endpoint

    Query jobs is the recommended endpoint for submitting queries. This endpoint provides an asynchronous method for submitted queries, enabling a request to be submitted, with the results accessed later without the client having to actively wait for a response (non-blocking). Query jobs are useful if you have repetitive or complex queries, such as ones with aggregations.

    The base endpoint is /api/v1/repositories/repo/queryjobs.

  • Streaming Query endpoint

    The streaming query endpoint supports a single synchronous query. This is suitable only for simple, filter-only queries over short timeframes, as it blocks the client for the duration the query is run.

    The base endpoint is /api/v1/repositories/repo/query.

For a list of the supported endpoint and methods, see the following table:

Table:

HTTP MethodURIAvailabilityDescription
GET/api/v1/repositories/repo/queryjobs/id  Request the current query status and results
POST/api/v1/repositories/repo/queryjobs  Create a query job
DELETE/api/v1/repositories/repo/queryjobs/id  Delete a previously created query job
POST/api/v1/repositories/repo/query  Submit a search query

Support
  • Twitter
  • LinkedIn
  • Youtube

© 2025 CrowdStrike All other marks contained herein are the property of their respective owners.

Children of this Page

Running Query Jobs
Creating a Query Job
Polling a Query Job
Query metaData
Query extraData
Query warnings
Pagination of Results
Deleting a Query Job
Streaming Search Request
Triggering Direct Download of the Results
Live Search Request
Search API Time Specification
Search Response Format
Returned Event Count
  • Other articles on this topic

    • Alerts and Saved Searches Best Practices
    • Create Dashboards and Widgets
    • Create Dashboards and Widgets
    • Create Dashboards and Widgets
    • Create Dashboards and Widgets
    • Create Dashboards and Widgets
    • Create Dashboards and Widgets
    • Create Dashboards and Widgets
    • Create Dashboards and Widgets
    • Create Dashboards and Widgets
    • Create Dashboards and Widgets
    • Create Dashboards and Widgets
    • Create Dashboards and Widgets
    • Create Dashboards and Widgets
    • Create Dashboards and Widgets
    • Create Dashboards and Widgets
    • Create Dashboards and Widgets
    • Create Dashboards and Widgets
    • Create Dashboards and Widgets
    • Create Dashboards and Widgets
    • Create Dashboards and Widgets
    • Create Dashboards and Widgets
    • Create Dashboards and Widgets
    • Create triggers
    • Create triggers
    • Create triggers
    • Create triggers
    • Creating Alerts
    • Creating Alerts
    • Creating Alerts
    • Creating Alerts
    • Creating Alerts
    • Creating Alerts
    • Export Dashboards as PDF
    • Export Dashboards as PDF
    • Export Dashboards as PDF
    • Export Dashboards as PDF
    • Export Dashboards as PDF
    • Export Dashboards as PDF
    • Export Dashboards as PDF
    • Export Dashboards as PDF
    • Export Dashboards as PDF
    • Export Dashboards as PDF
    • Export Dashboards as PDF
    • Export Dashboards as PDF
    • Export Dashboards as PDF
    • Export Dashboards as PDF
    • Export Dashboards as PDF
    • Export Dashboards as PDF
    • Frequent query operations
    • Frequent query operations
    • Frequent query operations
    • Frequent query operations
    • Frequent query operations
    • Frequent query operations
    • Frequent query operations
    • Frequent query operations
    • Frequent query operations
    • Frequent query operations
    • Frequent query operations
    • Frequent query operations
    • Frequent query operations
    • Frequent query operations
    • Frequent query operations
    • Frequent query operations
    • Frequent query operations
    • Frequent query operations
    • Frequent query operations
    • Frequent query operations
    • Frequent query operations
    • Frequent query operations
    • General information about triggers
    • General information about triggers
    • General information about triggers
    • General information about triggers
    • Insights Errors Dashboard
    • Query Filters
    • Query Filters
    • Query Filters
    • Query Filters
    • Query Filters
    • Query Filters
    • Query Filters
    • Query Filters
    • Query Filters
    • Query Filters
    • Query Filters
    • Query Filters
    • Query Filters
    • Query Filters
    • Query Filters
    • Query Filters
    • Query Filters
    • Query Filters
    • Query Filters
    • Query Filters
    • Query Filters
    • Query Filters
    • Repository & View Permissions
    • Repository & View Permissions
    • Repository & View Permissions
    • Repository & View Permissions
    • Repository & View Permissions
    • Repository & View Permissions
    • Repository & View Permissions
    • Repository & View Permissions
    • Repository & View Permissions
    • Repository & View Permissions
    • Repository & View Permissions
    • Repository & View Permissions
    • Repository & View Permissions
    • Repository & View Permissions
    • Repository & View Permissions
    • Repository & View Permissions
    • Repository & View Permissions
    • Repository & View Permissions
    • Repository & View Permissions (Cloud)
    • Repository & View Permissions (Self-Hosted)
    • Search Data
    • Search Data
    • Search Data
    • Search Data
    • Search Data
    • Search Data
    • Search Data
    • Search Data
    • Search Data
    • Search Data
    • Search Data
    • Search Data
    • Search Data
    • Search Data
    • Search Data
    • Search Data
    • Search Data
    • Search Data
    • Search Data
    • Search Data
    • Search Data
    • Search Data
    • Write new queries
    • Write new queries
    • Write new queries
    • Write new queries
    • Write new queries
    • Write new queries
    • Write new queries
    • Write new queries
    • Write new queries
    • Write new queries
    • Write new queries
    • Write new queries
    • Write new queries
    • Write new queries
    • Write new queries
    • Write new queries
    • Write new queries
    • Write new queries
    • Write new queries
    • Write new queries
    • Write new queries
    • Write new queries
    • automated-alerts-create-new
    • automated-alerts-getting-started
    • dashboards-pdfexport
    • security-authorization-role-permissions
  • Training

    • Ingestion
    • LogScale Video Series

Enter search term