Skip to content
LogoLogScale DocumentationLibraryGuidance Release Notes Integrations Query Examples Training APIGraphQLSearch Archives Contact Support
🔖 🔔 ੆Help button for documentation
    • Getting Data In

      • Basic Concepts
      • Assess Your Data Before Ingestion
      • What are Data Sources?
      • What Data Can LogScale Ingest?
      • Methods for Data Ingest
        • Falcon LogScale Collector
        • CrowdStream
        • HTTP / HTTPS API
        • Syslog
        • Amazon S3 Bucket
        • Azure Event Hubs
        • Google Cloud Logging
        • Kafka
        • SNMP Traps
        • Docker Collector
        • Windows Event Collector
        • Database Logs (JDBC)
        • Filebeat
        • Logstash
        • Fluentd
      • What is Data Parsing?
      • How is Data Impacted?
        • Types of Event Fields
          • Metadata Fields
          • Tag Fields
          • User Fields
        • Parsing Log Data Example
        • Important System Fields
          • Field @rawstring
          • Field @timestamp
          • Field @ingesttimestamp
          • Field #repo
          • Field #type
      • Example GDI Data Flows
    • How to Get Data in

      • Getting Data In Process
      • Popular Ingest Methods
        • Amazon S3 Bucket
          • Set up Amazon S3 as an ingest method
        • Azure Event Hubs
          • Set up Azure Event Hubs as an ingest method
        • Database Source
          • Set up a database as an ingest method
        • Falcon LogScale Collector
          • Install Falcon LogScale Collector
        • Filebeat
          • Set up Filebeat as an ingest method
        • Fluentd
          • Set up Fluentd as an ingest method
        • Google Cloud Logging
          • Set up Google Cloud Logging as an ingest method
        • HTTP / HTTPS API
          • Set up HTTP / HTTPS API as an ingest method
        • Kafka
          • Set up Kafka as an ingest method
        • Logstash
          • Set up Logstash as an ingest method
        • SNMP Traps
          • Set up SNMP Traps as an ingest method
        • Syslog
          • Set up Syslog as an ingest method
        • Windows Event Collector
          • Set up Windows Event Collector as an ingest method
    • Manage Data Ingest
      • Log Shippers
      • Backfilling Data
      • Disabling Ingestion
      • Event Forwarding
        • Event Forwarders
        • Event Forwarding Rules
      • Ingesting FDR Data
        • Cluster Configuration
        • Adjust Polling Nodes Per Feed
        • Ingest FDR Data
          • Troubleshooting FDR Ingest
        • Error Handling
      • Ingest Listeners
      • Ingest Tokens
      • Ingest Feeds
        • Ingest Data from AWS S3
          • Set up a New AWS Ingest Feed
          • Edit Ingest Feed Configuration
          • Delete an Ingest Feed
          • Enable and Disable Ingest Feeds
        • Ingest Data from Azure Event Hubs
          • Set up a New Azure Ingest Feed
          • Edit Azure Ingest Feed Configuration
          • Delete an Azure Ingest Feed
          • Enable and Disable Azure Ingest Feeds

 

    • Falcon LogScale Collector
      • Key Concepts
      • Prerequisities and Sizing
              • Memory Usage Log Messages
      • Installation
        • Full Installation
        • Custom Installation
          • Custom Installation Linux
          • Custom Installation macOS
          • Custom Installation Windows
            • Run the Falcon LogScale Collector Manually with Options
          • Download Installers from the Command-line
          • Update your Custom Log Collector Installation
      • Configuration
        • Create a Configuration - Remote
        • Create a Configuration - Local
        • Validate a Configuration
        • Minimal Configuration Example
        • Configuration Reference and Examples
          • Configuration Reference
            • Sources (sources)
              • Database Source
              • File Source
              • Windows Event Log Source
              • Syslog Source
              • Syslog via TLS Source
              • Unified Logs Source
              • Journal Source
              • Internal (loopback) Source
              • Command (Exec) Source
            • Sinks (sinks)
              • TLS
              • Queue (queue)
                • Queue Memory
                • Queue Disk
            • Settings (settings)
            • Optional Flags(flags)
            • Fleet Management (fleetManagement)
                • Full (full)
                • Local(localConfig)
                • Legacy (legacy)
            • Data Directory (dataDirectory)
          • Configuration Examples
              • Database Source
              • Exec (cmd) Source
              • File (Linux) Source
              • File (Linux) Source (NG-SIEM)
              • File Source
              • File Source with Transforms
              • File Source with Windows file paths
              • Journal Source
              • Syslog Source
              • Syslog Source (NG-SIEM)
              • Syslog Source Multi-Destination
              • Syslog-tls Source
              • Unified Log Source
              • Windows Event Log Source
              • Windows Multi-Source
              • Windows Multi-Source (NG-SIEM)
              • Windows Source (NG-SIEM)
          • Configuration Use Cases
            • All Sources: How to Use Transforms
            • All Sources: Use a Parser
            • All Sources: Set a Proxy Server
            • Syslog Source: Multi-Destinations Sinks
            • File Source: Read Compressed Files
            • File Source: File Rotation Support
            • Windows Source: Filters and Customizations
      • Fleet and Group Management
        • Fleet Overview
        • Security Advisories
        • Fleet Insights
          • View Metrics and Errors
          • Aggregate Data
          • Filter Data
        • Manage Groups
        • Manage Remote Configurations
        • Enroll Instances
        • Internal Logging
      • Troubleshooting
        • Debug Commands
        • Query Commands - Reference
          • Query Internal Logs
          • Query Metrics
      • Metrics
      • Metadata
      • Deployment Architectures
        • Collect Kubernetes Pod Logs
          • Configure a Falcon LogScale Collector Helm Chart
          • Falcon LogScale Collector Helm Chart
          • Helm Chart Adding Additional Metadata
          • Helm Chart with Falcon CWP (Cloud Workload Protection)
      • Related KB Articles
      • Falcon LogScale Collector Releases
        • Falcon LogScale Collector 1.11.5 GA (2026-06-17)
        • Falcon LogScale Collector 1.11.4 GA (2026-05-20)
        • Falcon LogScale Collector 1.11.2 GA (2026-04-21)
        • Falcon LogScale Collector 1.11.1 GA (2026-02-25)
        • Falcon LogScale Collector 1.11.0 GA (2026-01-27)
        • Falcon LogScale Collector 1.10.3 GA (2025-11-25)
        • Falcon LogScale Collector 1.10.2 GA (2025-10-20)
        • Falcon LogScale Collector 1.10.1 GA (2025-08-20)
        • Falcon LogScale Collector 1.10.0 GA (2025-08-15)
        • Falcon LogScale Collector 1.9.1 GA (2025-05-20)
        • Falcon LogScale Collector 1.9.0 GA (2025-04-14)
        • Falcon LogScale Collector 1.8.3 GA (2025-03-25)
        • Falcon LogScale Collector 1.8.2 GA (2025-03-12)
        • Falcon LogScale Collector 1.8.1 GA (2024-11-20)
        • Falcon LogScale Collector 1.7.4 GA (2024-10-03)
        • Falcon LogScale Collector 1.7.3 GA (2024-08-13)
        • Falcon LogScale Collector 1.7.2 GA (2024-07-09)
        • Falcon LogScale Collector 1.7.1 GA (2024-06-27)
        • Falcon LogScale Collector 1.7.0 GA (2024-06-03)
        • Falcon LogScale Collector 1.6.6 GA (2024-06-13)
        • Falcon LogScale Collector 1.6.5 GA (2024-04-29)
        • Falcon LogScale Collector 1.6.2 GA (2024-02-26)
        • Falcon LogScale Collector 1.6.1 GA (2023-12-12)
        • Falcon LogScale Collector 1.5.3 GA (2023-10-16)
        • Falcon LogScale Collector 1.5.2 GA (2023-10-03)
        • Falcon LogScale Collector 1.5.1 GA (2023-8-28)
        • Falcon LogScale Collector 1.5.0 GA (2023-8-23)
        • Falcon LogScale Collector 1.4.1 GA (2023-6-13)
        • Falcon LogScale Collector 1.4.0 GA (2023-5-08)
        • Falcon LogScale Collector 1.3.4 GA (2023-3-30)
        • Falcon LogScale Collector 1.3.3 Withdrawn (2023-3-21)
        • Falcon LogScale Collector 1.3.2 GA (2023-3-16)
        • Falcon LogScale Collector 1.3.1 GA (2023-3-9)
        • Falcon LogScale Collector 1.3.0 GA (2023-2-7)
        • Falcon LogScale Collector 1.2.3 GA (2023-1-23)
        • Falcon LogScale Collector 1.2.2 GA (2023-1-16)
        • Falcon LogScale Collector 1.2.1 GA (2022-11-10)
        • Falcon LogScale Collector 1.2.0 GA (2022-10-27)
        • Humio Log Collector 1.1.4 GA (2022-10-12)
        • Humio Log Collector 1.1.3 GA (2022-10-03)
        • Humio Log Collector 1.1.2 Not Released (2022-09-29)
        • Humio Log Collector 1.1.1 GA (2022-09-19)
        • Humio Log Collector 1.1.0 GA (2022-06-25)
        • Humio Log Collector 1.0.2 LTS (2022-05-05)
        • Humio Log Collector 1.0.1 LTS (2022-04-25)
        • Humio Log Collector 1.0.0 LTS (2022-04-23)
        • Full Falcon LogScale Collector Release Notes Index

 

    • Package Marketplace
      • Akamai Technologies, Inc.
        • akamai/asec
          • Package akamai/asec Release Notes
          • Parsers and Generated Fields
      • Amazon Web Services, Inc.
        • aws/cloudtrail
          • Package aws/cloudtrail Release Notes
          • Parsers and Generated Fields
        • aws/fsx
          • Package aws/fsx Release Notes
          • Parsers and Generated Fields
        • aws/guardduty
          • Package aws/guardduty Release Notes
          • Parsers and Generated Fields
        • aws/s3-server-access
          • Package aws/s3-server-access Release Notes
          • Parsers and Generated Fields
        • aws/vpcflow
          • Package aws/vpcflow Release Notes
          • Parsers and Generated Fields
        • aws/waf
          • Package aws/waf Release Notes
          • Parsers and Generated Fields
      • AppOmni, Inc
        • appomni/appomni
          • Parsers and Generated Fields
      • Apple Inc.
        • apple/unifiedlog
          • Parsers and Generated Fields
      • Armis, Inc.
        • armis/centrix-iot
          • Parsers and Generated Fields
      • Asimily
        • asimily/iomt
          • Package asimily/iomt Release Notes
          • Parsers and Generated Fields
      • Broadcom Inc.
        • broadcom/proxysg
          • Package broadcom/proxysg Release Notes
          • Parsers and Generated Fields
      • Check Point Software Technologies Ltd.
        • checkpoint/ngfw
          • Package checkpoint/ngfw Release Notes
          • Parsers and Generated Fields
      • Cisco Systems, Inc.
        • cisco/asa
          • Package cisco/asa Release Notes
          • cisco/asa Dashboards
        • cisco/duo
          • Package cisco/duo Release Notes
          • Parsers and Generated Fields
        • cisco/firepower
          • Package cisco/firepower Release Notes
          • Parsers and Generated Fields
        • cisco/ios
          • Package cisco/ios Release Notes
          • Parsers and Generated Fields
        • cisco/ise
          • Package cisco/ise Release Notes
          • Parsers and Generated Fields
        • cisco/meraki
          • Package cisco/meraki Release Notes
          • Parsers and Generated Fields
        • cisco/umbrella
          • Package cisco/umbrella Release Notes
          • Parsers and Generated Fields
      • Citrix Systems, Inc.
        • citrix/netscaler
          • Package citrix/netscaler Release Notes
          • Parsers and Generated Fields
      • Claroty Ltd.
        • claroty/ctd
          • Package claroty/ctd Release Notes
          • Parsers and Generated Fields
      • CloudFlare, Inc.
        • cloudflare/area1emailsecurity
          • Installing the Package
          • Configuring Ingest for Cloudflare Area 1 Logs
          • Verify Data is Arriving in LogScale
          • cloudflare/area1emailsecurity Dashboards
        • cloudflare/zerotrust
          • Package cloudflare/zerotrust Release Notes
          • Parsers and Generated Fields
      • Corelight, Inc.
        • corelight/threathuntingguide
          • Parsers and Generated Fields
          • Using Corelight Packages
          • Sample Queries
          • Zeek (Bro) Network Security Monitor
      • CrowdStrike Holdings, Inc.
        • crowdstrike/falcon-devices
          • crowdstrike/falcon-devices Dashboards
        • crowdstrike/fdr
          • Parsers and Generated Fields
          • crowdstrike/fdr Dashboards
        • crowdstrike/fltr-core
          • Package crowdstrike/fltr-core Release Notes
          • crowdstrike/fltr-core Dashboards
        • crowdstrike/fltr-firewall-adversaries
          • crowdstrike/fltr-firewall-adversaries Dashboards
        • crowdstrike/fltr-identityprotection
          • Package crowdstrike/fltr-identityprotection Release Notes
          • crowdstrike/fltr-identityprotection Dashboards
        • crowdstrike/fltr-lolbins
          • Package crowdstrike/fltr-lolbins Release Notes
        • crowdstrike/fltr-tutorial
          • Package crowdstrike/fltr-tutorial Release Notes
          • crowdstrike/fltr-tutorial Dashboards
        • crowdstrike/intel-indicators
          • crowdstrike/intel-indicators Dashboards
        • crowdstrike/ioc
          • Package crowdstrike/ioc Release Notes
          • crowdstrike/ioc Dashboards
        • crowdstrike/logscale-opsgenie
        • crowdstrike/logscale-pagerduty
        • crowdstrike/logscale-slack
        • crowdstrike/logscale-splunk-on-call
        • crowdstrike/siem-connector
          • crowdstrike/siem-connector Dashboards
        • crowdstrike/spotlight
          • Package crowdstrike/spotlight Release Notes
          • crowdstrike/spotlight Dashboards
      • CyberArk Software Ltd.
        • cyberark/pam
          • cyberark/pam Dashboards
        • cyberark/vault
          • cyberark/vault Dashboards
      • Darktrace Limited
        • darktrace/detect
          • Package darktrace/detect Release Notes
          • Parsers and Generated Fields
      • Dell, Inc.
        • dell/isilon
          • Package dell/isilon Release Notes
          • Parsers and Generated Fields
      • Docker Inc.
        • docker/metrics
          • docker/metrics Dashboards
      • Dragos
      • Everpure, Inc.
        • everpure/flasharray
          • Package everpure/flasharray Release Notes
          • Parsers and Generated Fields
        • everpure/flashblade
          • Package everpure/flashblade Release Notes
          • Parsers and Generated Fields
      • ExtraHop Networks, Inc.
        • extrahop/revealx
          • extrahop/revealx Dashboards
      • F5, Inc.
        • f5networks/bigip
          • Package f5networks/bigip Release Notes
          • Parsers and Generated Fields
      • Forcepoint LLC
        • forcepoint/dlp
          • Package forcepoint/dlp Release Notes
          • Parsers and Generated Fields
      • Fortinet Inc.
        • fortinet/fortigate
          • Package fortinet/fortigate Release Notes
          • Parsers and Generated Fields
        • fortinet/fortimail
          • Package fortinet/fortimail Release Notes
          • Parsers and Generated Fields
      • Github
        • github/events
          • github/events Dashboards
      • Google LLC
        • google/chrome-enterprise-security-events
          • Package google/chrome-enterprise-security-events Release Notes
          • Parsers and Generated Fields
          • google/chrome-enterprise-security-events Dashboards
        • google/chronicle-alerts
          • google/chronicle-alerts Dashboards
        • google/chronicle-ioc
          • google/chronicle-ioc Dashboards
        • google/gcp-audit
          • google/gcp-audit Dashboards
      • HAProxy Technologies LLC
        • haproxy/haproxy
          • Package haproxy/haproxy Release Notes
          • Parsers and Generated Fields
      • HPE Aruba Networking
        • aruba/clearpass
          • Package aruba/clearpass Release Notes
          • Parsers and Generated Fields
      • Humio
        • humio/activity
          • Package humio/activity Release Notes
          • humio/activity Dashboards
        • humio/insights
          • Package humio/insights Release Notes
          • Parsers and Generated Fields
          • humio/insights Dashboards
        • humio/vector-metrics
          • humio/vector-metrics Dashboards
      • Imperva, Inc.
        • imperva/cloud-waf
          • Package imperva/cloud-waf Release Notes
          • Parsers and Generated Fields
          • imperva/cloud-waf Dashboards
      • Infoblox, Inc.
        • infoblox/nios
          • Package infoblox/nios Release Notes
          • Parsers and Generated Fields
      • Island Technology, Inc
        • island/island
          • Package island/island Release Notes
          • Parsers and Generated Fields
          • island/island Dashboards
      • Juniper Networks, Inc.
        • juniper/srx
          • Package juniper/srx Release Notes
          • Parsers and Generated Fields
      • Medigate
      • Microsoft Corporation
        • microsoft/dhcp-client
          • Package microsoft/dhcp-client Release Notes
          • Parsers and Generated Fields
        • microsoft/dhcp-server
          • Package microsoft/dhcp-server Release Notes
          • Parsers and Generated Fields
        • microsoft/iis
          • Parsers and Generated Fields
          • Microsoft IIS Server Configuration
          • Installing the Package in LogScale
          • Configure Ingest for Microsoft IIS Server
          • Verify Data is Arriving in LogScale
          • Extending Parsers for Custom Logs
          • microsoft/iis Dashboards
        • microsoft/microsoft365
          • Package microsoft/microsoft365 Release Notes
          • Parsers and Generated Fields
          • microsoft/microsoft365 Dashboards
        • microsoft/sysmon
          • Package microsoft/sysmon Release Notes
          • Parsers and Generated Fields
        • microsoft/windows-dns-debug
          • Package microsoft/windows-dns-debug Release Notes
          • Parsers and Generated Fields
      • Mimecast Services Ltd.
        • mimecast/email-security
          • Package mimecast/email-security Release Notes
          • Parsers and Generated Fields
          • mimecast/email-security Dashboards
      • Netskope, Inc.
        • netskope/casb
          • Package netskope/casb Release Notes
          • netskope/casb Dashboards
      • Nginx
        • nginx/nginx
          • Package nginx/nginx Release Notes
          • Parsers and Generated Fields
          • NGINX Server Configuration
          • Installing the Package in LogScale
          • Configure Ingest for Nginx Server logs
          • Verify Data is Arriving in LogScale
          • Extending Parsers for Custom Access Logs
          • nginx/nginx Dashboards
      • Nozomi Networks Inc
        • nozomi/ids
          • Package nozomi/ids Release Notes
          • Parsers and Generated Fields
      • Obsidian Security, Inc.
        • obsidiansecurity/actionnotification
          • Parsers and Generated Fields
          • obsidiansecurity/actionnotification Dashboards
      • Okta, Inc.
        • okta/sso
          • Package okta/sso Release Notes
          • Parsers and Generated Fields
      • One Identity LLC
        • oneidentity/onelogin
          • Parsers and Generated Fields
      • Ordr, Inc.
        • ordr/ordr
          • Parsers and Generated Fields
          • ordr/ordr Dashboards
      • Palo Alto Networks, Inc.
        • palo-alto/prisma-sd-wan
          • Package palo-alto/prisma-sd-wan Release Notes
          • Parsers and Generated Fields
        • paloalto/firewall
          • Package paloalto/firewall Release Notes
          • Parsers and Generated Fields
      • Ping Identity Corporation
        • pingidentity/pingone
          • Package pingidentity/pingone Release Notes
          • Parsers and Generated Fields
          • Install the Package in LogScale
          • Configure Ingest for PingOne Service
          • Verify Data is Arriving in LogScale
          • pingidentity/pingone Dashboards
      • Proofpoint, Inc.
        • proofpoint/tap-siem-api
          • Package proofpoint/tap-siem-api Release Notes
          • Parsers and Generated Fields
      • Radware, Inc.
        • radware/alteon
          • Package radware/alteon Release Notes
          • Parsers and Generated Fields
      • Red Hat, Inc.
        • redhat/ansible
          • Package redhat/ansible Release Notes
          • Parsers and Generated Fields
          • redhat/ansible Dashboards
      • Robust Intelligence
      • Rubicon Communications LLC (Netgate)
        • netgate/pfsense
          • Package netgate/pfsense Release Notes
          • Parsers and Generated Fields
      • Rubrik, Inc.
        • rubrik/security-cloud
          • Package rubrik/security-cloud Release Notes
          • Parsers and Generated Fields
          • rubrik/security-cloud Dashboards
      • Ruby
        • ruby/logger
          • Parsers and Generated Fields
          • ruby/logger Dashboards
      • ServiceNow Inc.
        • servicenow/servicenow
          • Installing the Package in LogScale
          • servicenow/servicenow Dashboards
      • Talon
        • talon/talon-cyber-security
          • Parsers and Generated Fields
          • Configure the integration from the Talon Management Console
          • Verify Data is Arriving in LogScale
          • talon/talon-cyber-security Dashboards
      • Tausight Inc.
        • tausight/ephi-risk-posture
          • Package tausight/ephi-risk-posture Release Notes
          • Parsers and Generated Fields
      • The Apache Software Foundation (ASF)
        • apache/http-server
          • Package apache/http-server Release Notes
          • Parsers and Generated Fields
          • Apache HTTP Server Configuration
          • Installing the Package in LogScale
          • Configure Ingest for Apache HTTP Server
          • Verify Data is Arriving in LogScale
          • Extending Parsers for Custom Logs
          • apache/http-server Dashboards
        • apache/kafka-metricbeat
          • apache/kafka-metricbeat Dashboards
      • The Linux Foundation
        • linux/system-logs
          • Package linux/system-logs Release Notes
          • linux/system-logs Dashboards
      • Trellix
        • trellix/fireeye-nx
          • Package trellix/fireeye-nx Release Notes
          • Parsers and Generated Fields
      • Vectra AI, Inc.
        • vectra/detections
          • vectra/detections Dashboards
      • Veeam Software
        • veeam/veeamdataplatform
          • Package veeam/veeamdataplatform Release Notes
          • Parsers and Generated Fields
          • veeam/veeamdataplatform Dashboards
      • Zoom Video Communications, Inc.
        • zoom/qss
          • Package zoom/qss Release Notes
          • Parsers and Generated Fields
      • Zscaler, Inc.
        • zscaler/deception
          • Package zscaler/deception Release Notes
          • Parsers and Generated Fields
        • zscaler/internet-access
          • Package zscaler/internet-access Release Notes
          • Parsers and Generated Fields
          • Example Queries
          • zscaler/internet-access Dashboards
        • zscaler/private-access
          • Package zscaler/private-access Release Notes
          • Parsers and Generated Fields
    • Package Reference
    • Dashboard Reference
    • Package Management
      • Install & Update Packages
      • Package Marketplace
      • Create a Package
      • Package File Formats
      • Referencing Package Assets
      • Developer Guidelines
        • Improve an Existing Package or Create a New Package
        • Data Ingest Guidelines
        • Asset Guidelines
          • Parsers Best Practices
          • LogScale Query Language Best Practices
          • Dashboard Best Practices
          • Dashboard Widgets
          • Alerts and Saved Searches Best Practices
          • Naming and Informational Notes
        • Package Content Guidelines
        • Guidelines for Submitting a Package to LogScale Marketplace
      • Insights Package
        • Insights Overview Dashboard
        • Insights Ingest Dashboard
        • Insights Hosts Dashboard
        • Bucket Storage Dashboard
        • Kafka Dashboard
        • Insights Search Dashboard
        • Request-Response
        • Insights Segments & Datasources Dashboard
        • Insights Errors Dashboard
    • Other Integrations
      • Tines Alerts
      • XSOAR Security Management
      • Prometheus
      • Kubernetes Log Format
      • Grafana
      • Cribl CrowdStream
        • Simple or Complex Routing?
        • Navigate Between User Interfaces
        • Configure a Source
        • Configure a Destination
        • Connect: Passthru, Pipeline, or Pack
        • Commit/Deploy Config Changes
        • Moving Ahead with CrowdStream
    • Log Formats
      • NetFlow Log Format
      • Heroku Log Format
      • Linux
        • Linux System Logs
      • Azure Service Fabric Log Format
      • Docker Log Format
      • Kafka Connect Log Format
      • Amazon CloudWatch Log Format
Falcon LogScale Documentation
/ LogScale Getting Data In
/ How to Get Data in
/ Popular Ingest Methods
/ Falcon LogScale Collector

Install Falcon LogScale Collector

Step 1 - Create a LogScale Collector ingest token

Why? Installation places the Collector executable and supporting files on the host. The workflow depends on the deployment model.

Windows installation options:

Falcon LogScale Collector can be installed on Windows using different deployment models. These different methods of deployment result in the Collector being installed in different locations, and with different filenames:

Installation type Default executable path
Sensor managed C:\Program Files\LogScale Collector Sensor Managed\logscale-collector.exe
Custom Install C:\Program Files (x86)\CrowdStrike\Humio Log Collector\humio-log-collector.exe
Full Install C:\Program Files\LogScale Collector\Logscale Collector.exe

Option A - Full Install

Use CrowdStrike's Full Falcon LogScale Collector Installation workflow where available. CrowdStrike recommends this method because it supports Fleet version management and automatic enrollment in Fleet Management.

After installation, the default Windows executable path is:

C:\Program Files\LogScale Collector\Logscale Collector.exe

Verify that the Collector is installed and running before continuing to the source and sink configuration. Use the Troubleshooting documentation for supported verification commands.

Option B - Custom Install

Use Custom Install when you need to install and configure the Collector manually. Download the platform-appropriate Collector package and follow the Custom Falcon LogScale Collector Installation procedure

On Windows, the default Custom Install executable path is:

C:\Program Files (x86)\CrowdStrike\Humio Log Collector\humio-log-collector.exe

The legacy Humio naming in this path is expected for this installation type.

Option C - Sensor-managed Windows installation

For Sensor-managed deployments on Windows, the default executable path is:

C:\Program Files\LogScale Collector Sensor Managed\logscale-collector.exe

Linux installation

CrowdStrike provides a Custom Install package for supported Linux systems. Follow the current Install Falcon LogScale Collector on Linux - Custom Install procedure to get started.

macOS installation

CrowdStrike provides a Custom Install package for supported macOS systems. Follow the current Install Falcon LogScale Collector on macOS - Custom Install procedure to get started.

Kubernetes with Helm

For Kubernetes application/container logs, deploy Falcon LogScale Collector using the CrowdStrike Falcon LogScale Collector Helm Chart Helm chart.

Step 2 - Configure a source

Why? A source defines where the Collector obtains events. Each source type has its own required and optional settings.

Use the Popular Ingest Methods for detailed configuration options.

Step 3 - Configure transforms when required

Transforms are optional and can modify, enrich, filter, or route events between sources and sinks. Configure only the transforms required for the deployment. The Kubernetes Helm workflow applies Kubernetes-specific processing/enrichment to container events.

Step 4 - Configure the destination sink

Why? A sink defines where the Collector sends processed events.

For Falcon LogScale Collector, configure a Humio/LogScale sink with the destination URL and ingest token. Here's an example:

yaml
{
sinks:
  logscale:
    type: humio
    token: "${INGEST_TOKEN}"
    url: "https://<your-logscale-cluster>"
}

Use the URL appropriate for your deployment and protect ingest tokens and other credentials as necessary. Fleet-managed deployments can centralize configuration instead of relying solely on a local YAML file.

Step 5 - Validate and start the Collector

  1. Save or deploy the Collector configuration.

  2. Use the Collector configuration-validation capability to identify invalid or unsupported configuration.

  3. Start or restart the Collector as required. See below for reference commands.

  4. Confirm that the Collector service/process is running.

  5. Review Collector logs for source, transform, sink, authentication, TLS, or connectivity errors.

Reference commands:

  • To start the Collector service:

    • For Linux (systemd):

      sudo systemctl start logscale-collector
      sudo systemctl enable logscale-collector  # Enable auto-start on boot
    • For Linux (init.d):

      sudo service logscale-collector start
      sudo chkconfig logscale-collector on  # Enable auto-start on boot
    • For Windows:

      net start "LogScale Collector"
      # Or use Services management console (services.msc)
    • For Docker:

      docker start logscale-collector
    • For Kubernetes:

      # DaemonSet starts automatically after deployment
      kubectl rollout status daemonset/logscale-collector -n logging
  • To verify the Collector is running:

    • For Linux:

      sudo systemctl status logscale-collector
      # Check for "active (running)" status
    • For Windows:

      sc query "LogScale Collector"
      # Check for "RUNNING" state
    • For Docker:

      docker ps | grep logscale-collector
      docker logs logscale-collector
    • For Kubernetes:

      kubectl get pods -n logging -l app=logscale-collector
      kubectl logs -n logging -l app=logscale-collector

Step 6 - Verify ingestion

  1. Generate or identify a representative event at the configured source.

  2. Search the Falcon LogScale Collector destination for the event.

  3. Verify that the expected parser and fields are applied.

  4. If the event is missing, check the Collector logs, source configuration, network connectivity, sink configuration, ingest token, and destination URL.

You can verify that data is being ingested in the following ways:

  • Check Collector logs for startup messages:

    • Look for successful configuration loading

    • Verify connection to LogScale endpoint

    • Confirm input sources are initialized

    • Check for any error or warning messages

  • Verify log file monitoring:

    • Check Collector logs for file discovery messages

    • Verify the Collector has opened configured log files

    • Confirm file positions are being tracked

  • Generate test log entries:

    • Write test entries to monitored log files:

      echo "Test log entry $(date)" >> /var/log/app/test.log
    • For Windows Event Logs, generate test events using PowerShell:

      Write-EventLog -LogName Application -Source "TestApp" -EventId 1000 -Message "Test event"
  • Verify data in LogScale:

    • Navigate to your repository in LogScale

    • Run a query to find recently ingested events from the Collector:

      #type=collector OR @collector=*
    • Verify events have correct timestamps

    • Confirm fields are extracted correctly according to the parser

    • Check that custom tags and fields are present

    • Verify host metadata is included (hostname, IP address)

  • Check Collector metrics (if enabled):

    • Access the metrics endpoint:

      curl http://localhost:9090/metrics
    • Review key metrics:

      • events_read_total: Total events read from sources

      • events_sent_total: Total events sent to LogScale

      • events_failed_total: Failed event transmissions

      • buffer_size_bytes: Current buffer utilization

      • files_active: Number of actively monitored files

  • Verify continuous operation:

    • Monitor for several minutes to ensure stable operation

    • Check that events continue to flow to LogScale

    • Verify no error accumulation in Collector logs

    • Confirm resource usage (CPU, memory) is within acceptable limits

  • Test error handling and recovery:

    • Temporarily block network access to LogScale endpoint

    • Verify the Collector buffers events locally

    • Restore network access and confirm buffered events are sent

    • Verify no data loss occurred during the outage

  • Test Collector restart behavior:

    • Restart the Collector service

    • Verify it resumes from the last processed position (no duplicate events)

    • Confirm state files are being used correctly

Deploy Falcon LogScale Collector in Kubernetes

Use this workflow when the goal is to collect Kubernetes application/container logs.

  1. Create the ingest-token:

    shell
    Secret kubectl create secret generic logscale-collector-token --from-literal=ingestToken="YOUR INGEST TOKEN HERE"

    Create the Secret in the same namespace as the Helm release.

  2. Create a Helm values file:

    shell
    humioAddress https://<your-logscale-cluster>
    humioIngestTokenSecretName: logscale-collector-token

  3. Add the CrowdStrike Helm repository:

    shell
    helm repo add logscale-collector-helm https://registry.crowdstrike.com/log-collector-us1-prod

  4. Install the chart

    shell
    helm install my-install-name logscale-collector-helm/logscale-collector --values logscale-collector.yaml

  5. Understand the default container-log source:

    The Helm chart enables a container file source by default. The generated Collector configuration reads Kubernetes container logs from /var/log/containers/*.log and applies Kubernetes processing/enrichment. The chart excludes the Collector's own container log from the default source.

  6. Verify Kubernetes ingestion:

    1. Confirm that the Helm release and Collector pods are healthy.

    2. Review the Collector pod logs for errors.

    3. Generate or identify an application log from a pod.

    4. Confirm the event reaches the target repository.

    5. Verify the expected Kubernetes metadata.

Support
  • Twitter
  • LinkedIn
  • Youtube

© 2026 CrowdStrike All other marks contained herein are the property of their respective owners.

Enter search term