Skip to content
LogoLogScale DocumentationLibraryGuidance Release Notes Integrations Query Examples Training APIGraphQLSearch Archives Contact Support
๐Ÿ”– ๐Ÿ”” เฉ†Help button for documentation
    • Getting Data In

      • Basic Concepts
      • Assess Your Data Before Ingestion
      • What are Data Sources?
      • What Data Can LogScale Ingest?
      • Methods for Data Ingest
        • Falcon LogScale Collector
        • CrowdStream
        • HTTP / HTTPS API
        • Syslog
        • Amazon S3 Bucket
        • Azure Event Hubs
        • Google Cloud Logging
        • Kafka
        • SNMP Traps
        • Docker Collector
        • Windows Event Collector
        • Database Logs (JDBC)
        • Filebeat
        • Logstash
        • Fluentd
      • What is Data Parsing?
      • How is Data Impacted?
        • Types of Event Fields
          • Metadata Fields
          • Tag Fields
          • User Fields
        • Parsing Log Data Example
        • Important System Fields
          • Field @rawstring
          • Field @timestamp
          • Field @ingesttimestamp
          • Field #repo
          • Field #type
      • Example GDI Data Flows
    • How to Get Data in

      • Getting Data In Process
      • Popular Ingest Methods
        • Amazon S3 Bucket
          • Set up Amazon S3 as an ingest method
        • Azure Event Hubs
          • Set up Azure Event Hubs as an ingest method
        • Database Source
          • Set up a database as an ingest method
        • Falcon LogScale Collector
          • Install Falcon LogScale Collector
        • Filebeat
          • Set up Filebeat as an ingest method
        • Fluentd
          • Set up Fluentd as an ingest method
        • Google Cloud Logging
          • Set up Google Cloud Logging as an ingest method
        • HTTP / HTTPS API
          • Set up HTTP / HTTPS API as an ingest method
        • Kafka
          • Set up Kafka as an ingest method
        • Logstash
          • Set up Logstash as an ingest method
        • SNMP Traps
          • Set up SNMP Traps as an ingest method
        • Syslog
          • Set up Syslog as an ingest method
        • Windows Event Collector
          • Set up Windows Event Collector as an ingest method
    • Manage Data Ingest
      • Log Shippers
      • Backfilling Data
      • Disabling Ingestion
      • Event Forwarding
        • Event Forwarders
        • Event Forwarding Rules
      • Ingesting FDR Data
        • Cluster Configuration
        • Adjust Polling Nodes Per Feed
        • Ingest FDR Data
          • Troubleshooting FDR Ingest
        • Error Handling
      • Ingest Listeners
      • Ingest Tokens
      • Ingest Feeds
        • Ingest Data from AWS S3
          • Set up a New AWS Ingest Feed
          • Edit Ingest Feed Configuration
          • Delete an Ingest Feed
          • Enable and Disable Ingest Feeds
        • Ingest Data from Azure Event Hubs
          • Set up a New Azure Ingest Feed
          • Edit Azure Ingest Feed Configuration
          • Delete an Azure Ingest Feed
          • Enable and Disable Azure Ingest Feeds

 

    • Falcon LogScale Collector
      • Key Concepts
      • Prerequisities and Sizing
              • Memory Usage Log Messages
      • Installation
        • Full Installation
        • Custom Installation
          • Custom Installation Linux
          • Custom Installation macOS
          • Custom Installation Windows
            • Run the Falcon LogScale Collector Manually with Options
          • Download Installers from the Command-line
          • Update your Custom Log Collector Installation
      • Configuration
        • Create a Configuration - Remote
        • Create a Configuration - Local
        • Validate a Configuration
        • Minimal Configuration Example
        • Configuration Reference and Examples
          • Configuration Reference
            • Sources (sources)
              • Database Source
              • File Source
              • Windows Event Log Source
              • Syslog Source
              • Syslog via TLS Source
              • Unified Logs Source
              • Journal Source
              • Internal (loopback) Source
              • Command (Exec) Source
            • Sinks (sinks)
              • TLS
              • Queue (queue)
                • Queue Memory
                • Queue Disk
            • Settings (settings)
            • Optional Flags(flags)
            • Fleet Management (fleetManagement)
                • Full (full)
                • Local(localConfig)
                • Legacy (legacy)
            • Data Directory (dataDirectory)
          • Configuration Examples
              • Database Source
              • Exec (cmd) Source
              • File (Linux) Source
              • File (Linux) Source (NG-SIEM)
              • File Source
              • File Source with Transforms
              • File Source with Windows file paths
              • Journal Source
              • Syslog Source
              • Syslog Source (NG-SIEM)
              • Syslog Source Multi-Destination
              • Syslog-tls Source
              • Unified Log Source
              • Windows Event Log Source
              • Windows Multi-Source
              • Windows Multi-Source (NG-SIEM)
              • Windows Source (NG-SIEM)
          • Configuration Use Cases
            • All Sources: How to Use Transforms
            • All Sources: Use a Parser
            • All Sources: Set a Proxy Server
            • Syslog Source: Multi-Destinations Sinks
            • File Source: Read Compressed Files
            • File Source: File Rotation Support
            • Windows Source: Filters and Customizations
      • Fleet and Group Management
        • Fleet Overview
        • Security Advisories
        • Fleet Insights
          • View Metrics and Errors
          • Aggregate Data
          • Filter Data
        • Manage Groups
        • Manage Remote Configurations
        • Enroll Instances
        • Internal Logging
      • Troubleshooting
        • Debug Commands
        • Query Commands - Reference
          • Query Internal Logs
          • Query Metrics
      • Metrics
      • Metadata
      • Deployment Architectures
        • Collect Kubernetes Pod Logs
          • Configure a Falcon LogScale Collector Helm Chart
          • Falcon LogScale Collector Helm Chart
          • Helm Chart Adding Additional Metadata
          • Helm Chart with Falcon CWP (Cloud Workload Protection)
      • Related KB Articles
      • Falcon LogScale Collector Releases
        • Falcon LogScale Collector 1.11.5 GA (2026-06-17)
        • Falcon LogScale Collector 1.11.4 GA (2026-05-20)
        • Falcon LogScale Collector 1.11.2 GA (2026-04-21)
        • Falcon LogScale Collector 1.11.1 GA (2026-02-25)
        • Falcon LogScale Collector 1.11.0 GA (2026-01-27)
        • Falcon LogScale Collector 1.10.3 GA (2025-11-25)
        • Falcon LogScale Collector 1.10.2 GA (2025-10-20)
        • Falcon LogScale Collector 1.10.1 GA (2025-08-20)
        • Falcon LogScale Collector 1.10.0 GA (2025-08-15)
        • Falcon LogScale Collector 1.9.1 GA (2025-05-20)
        • Falcon LogScale Collector 1.9.0 GA (2025-04-14)
        • Falcon LogScale Collector 1.8.3 GA (2025-03-25)
        • Falcon LogScale Collector 1.8.2 GA (2025-03-12)
        • Falcon LogScale Collector 1.8.1 GA (2024-11-20)
        • Falcon LogScale Collector 1.7.4 GA (2024-10-03)
        • Falcon LogScale Collector 1.7.3 GA (2024-08-13)
        • Falcon LogScale Collector 1.7.2 GA (2024-07-09)
        • Falcon LogScale Collector 1.7.1 GA (2024-06-27)
        • Falcon LogScale Collector 1.7.0 GA (2024-06-03)
        • Falcon LogScale Collector 1.6.6 GA (2024-06-13)
        • Falcon LogScale Collector 1.6.5 GA (2024-04-29)
        • Falcon LogScale Collector 1.6.2 GA (2024-02-26)
        • Falcon LogScale Collector 1.6.1 GA (2023-12-12)
        • Falcon LogScale Collector 1.5.3 GA (2023-10-16)
        • Falcon LogScale Collector 1.5.2 GA (2023-10-03)
        • Falcon LogScale Collector 1.5.1 GA (2023-8-28)
        • Falcon LogScale Collector 1.5.0 GA (2023-8-23)
        • Falcon LogScale Collector 1.4.1 GA (2023-6-13)
        • Falcon LogScale Collector 1.4.0 GA (2023-5-08)
        • Falcon LogScale Collector 1.3.4 GA (2023-3-30)
        • Falcon LogScale Collector 1.3.3 Withdrawn (2023-3-21)
        • Falcon LogScale Collector 1.3.2 GA (2023-3-16)
        • Falcon LogScale Collector 1.3.1 GA (2023-3-9)
        • Falcon LogScale Collector 1.3.0 GA (2023-2-7)
        • Falcon LogScale Collector 1.2.3 GA (2023-1-23)
        • Falcon LogScale Collector 1.2.2 GA (2023-1-16)
        • Falcon LogScale Collector 1.2.1 GA (2022-11-10)
        • Falcon LogScale Collector 1.2.0 GA (2022-10-27)
        • Humio Log Collector 1.1.4 GA (2022-10-12)
        • Humio Log Collector 1.1.3 GA (2022-10-03)
        • Humio Log Collector 1.1.2 Not Released (2022-09-29)
        • Humio Log Collector 1.1.1 GA (2022-09-19)
        • Humio Log Collector 1.1.0 GA (2022-06-25)
        • Humio Log Collector 1.0.2 LTS (2022-05-05)
        • Humio Log Collector 1.0.1 LTS (2022-04-25)
        • Humio Log Collector 1.0.0 LTS (2022-04-23)
        • Full Falcon LogScale Collector Release Notes Index

 

    • Package Marketplace
      • Akamai Technologies, Inc.
        • akamai/asec
          • Package akamai/asec Release Notes
          • Parsers and Generated Fields
      • Amazon Web Services, Inc.
        • aws/cloudtrail
          • Package aws/cloudtrail Release Notes
          • Parsers and Generated Fields
        • aws/fsx
          • Package aws/fsx Release Notes
          • Parsers and Generated Fields
        • aws/guardduty
          • Package aws/guardduty Release Notes
          • Parsers and Generated Fields
        • aws/s3-server-access
          • Package aws/s3-server-access Release Notes
          • Parsers and Generated Fields
        • aws/vpcflow
          • Package aws/vpcflow Release Notes
          • Parsers and Generated Fields
        • aws/waf
          • Package aws/waf Release Notes
          • Parsers and Generated Fields
      • AppOmni, Inc
        • appomni/appomni
          • Parsers and Generated Fields
      • Apple Inc.
        • apple/unifiedlog
          • Parsers and Generated Fields
      • Armis, Inc.
        • armis/centrix-iot
          • Parsers and Generated Fields
      • Asimily
        • asimily/iomt
          • Package asimily/iomt Release Notes
          • Parsers and Generated Fields
      • Broadcom Inc.
        • broadcom/proxysg
          • Package broadcom/proxysg Release Notes
          • Parsers and Generated Fields
      • Check Point Software Technologies Ltd.
        • checkpoint/ngfw
          • Package checkpoint/ngfw Release Notes
          • Parsers and Generated Fields
      • Cisco Systems, Inc.
        • cisco/asa
          • Package cisco/asa Release Notes
          • cisco/asa Dashboards
        • cisco/duo
          • Package cisco/duo Release Notes
          • Parsers and Generated Fields
        • cisco/firepower
          • Package cisco/firepower Release Notes
          • Parsers and Generated Fields
        • cisco/ios
          • Package cisco/ios Release Notes
          • Parsers and Generated Fields
        • cisco/ise
          • Package cisco/ise Release Notes
          • Parsers and Generated Fields
        • cisco/meraki
          • Package cisco/meraki Release Notes
          • Parsers and Generated Fields
        • cisco/umbrella
          • Package cisco/umbrella Release Notes
          • Parsers and Generated Fields
      • Citrix Systems, Inc.
        • citrix/netscaler
          • Package citrix/netscaler Release Notes
          • Parsers and Generated Fields
      • Claroty Ltd.
        • claroty/ctd
          • Package claroty/ctd Release Notes
          • Parsers and Generated Fields
      • CloudFlare, Inc.
        • cloudflare/area1emailsecurity
          • Installing the Package
          • Configuring Ingest for Cloudflare Area 1 Logs
          • Verify Data is Arriving in LogScale
          • cloudflare/area1emailsecurity Dashboards
        • cloudflare/zerotrust
          • Package cloudflare/zerotrust Release Notes
          • Parsers and Generated Fields
      • Corelight, Inc.
        • corelight/threathuntingguide
          • Parsers and Generated Fields
          • Using Corelight Packages
          • Sample Queries
          • Zeek (Bro) Network Security Monitor
      • CrowdStrike Holdings, Inc.
        • crowdstrike/falcon-devices
          • crowdstrike/falcon-devices Dashboards
        • crowdstrike/fdr
          • Parsers and Generated Fields
          • crowdstrike/fdr Dashboards
        • crowdstrike/fltr-core
          • Package crowdstrike/fltr-core Release Notes
          • crowdstrike/fltr-core Dashboards
        • crowdstrike/fltr-firewall-adversaries
          • crowdstrike/fltr-firewall-adversaries Dashboards
        • crowdstrike/fltr-identityprotection
          • Package crowdstrike/fltr-identityprotection Release Notes
          • crowdstrike/fltr-identityprotection Dashboards
        • crowdstrike/fltr-lolbins
          • Package crowdstrike/fltr-lolbins Release Notes
        • crowdstrike/fltr-tutorial
          • Package crowdstrike/fltr-tutorial Release Notes
          • crowdstrike/fltr-tutorial Dashboards
        • crowdstrike/intel-indicators
          • crowdstrike/intel-indicators Dashboards
        • crowdstrike/ioc
          • Package crowdstrike/ioc Release Notes
          • crowdstrike/ioc Dashboards
        • crowdstrike/logscale-opsgenie
        • crowdstrike/logscale-pagerduty
        • crowdstrike/logscale-slack
        • crowdstrike/logscale-splunk-on-call
        • crowdstrike/siem-connector
          • crowdstrike/siem-connector Dashboards
        • crowdstrike/spotlight
          • Package crowdstrike/spotlight Release Notes
          • crowdstrike/spotlight Dashboards
      • CyberArk Software Ltd.
        • cyberark/pam
          • cyberark/pam Dashboards
        • cyberark/vault
          • cyberark/vault Dashboards
      • Darktrace Limited
        • darktrace/detect
          • Package darktrace/detect Release Notes
          • Parsers and Generated Fields
      • Dell, Inc.
        • dell/isilon
          • Package dell/isilon Release Notes
          • Parsers and Generated Fields
      • Docker Inc.
        • docker/metrics
          • docker/metrics Dashboards
      • Dragos
      • Everpure, Inc.
        • everpure/flasharray
          • Package everpure/flasharray Release Notes
          • Parsers and Generated Fields
        • everpure/flashblade
          • Package everpure/flashblade Release Notes
          • Parsers and Generated Fields
      • ExtraHop Networks, Inc.
        • extrahop/revealx
          • extrahop/revealx Dashboards
      • F5, Inc.
        • f5networks/bigip
          • Package f5networks/bigip Release Notes
          • Parsers and Generated Fields
      • Forcepoint LLC
        • forcepoint/dlp
          • Package forcepoint/dlp Release Notes
          • Parsers and Generated Fields
      • Fortinet Inc.
        • fortinet/fortigate
          • Package fortinet/fortigate Release Notes
          • Parsers and Generated Fields
        • fortinet/fortimail
          • Package fortinet/fortimail Release Notes
          • Parsers and Generated Fields
      • Github
        • github/events
          • github/events Dashboards
      • Google LLC
        • google/chrome-enterprise-security-events
          • Package google/chrome-enterprise-security-events Release Notes
          • Parsers and Generated Fields
          • google/chrome-enterprise-security-events Dashboards
        • google/chronicle-alerts
          • google/chronicle-alerts Dashboards
        • google/chronicle-ioc
          • google/chronicle-ioc Dashboards
        • google/gcp-audit
          • google/gcp-audit Dashboards
      • HAProxy Technologies LLC
        • haproxy/haproxy
          • Package haproxy/haproxy Release Notes
          • Parsers and Generated Fields
      • HPE Aruba Networking
        • aruba/clearpass
          • Package aruba/clearpass Release Notes
          • Parsers and Generated Fields
      • Humio
        • humio/activity
          • Package humio/activity Release Notes
          • humio/activity Dashboards
        • humio/insights
          • Package humio/insights Release Notes
          • Parsers and Generated Fields
          • humio/insights Dashboards
        • humio/vector-metrics
          • humio/vector-metrics Dashboards
      • Imperva, Inc.
        • imperva/cloud-waf
          • Package imperva/cloud-waf Release Notes
          • Parsers and Generated Fields
          • imperva/cloud-waf Dashboards
      • Infoblox, Inc.
        • infoblox/nios
          • Package infoblox/nios Release Notes
          • Parsers and Generated Fields
      • Island Technology, Inc
        • island/island
          • Package island/island Release Notes
          • Parsers and Generated Fields
          • island/island Dashboards
      • Juniper Networks, Inc.
        • juniper/srx
          • Package juniper/srx Release Notes
          • Parsers and Generated Fields
      • Medigate
      • Microsoft Corporation
        • microsoft/dhcp-client
          • Package microsoft/dhcp-client Release Notes
          • Parsers and Generated Fields
        • microsoft/dhcp-server
          • Package microsoft/dhcp-server Release Notes
          • Parsers and Generated Fields
        • microsoft/iis
          • Parsers and Generated Fields
          • Microsoft IIS Server Configuration
          • Installing the Package in LogScale
          • Configure Ingest for Microsoft IIS Server
          • Verify Data is Arriving in LogScale
          • Extending Parsers for Custom Logs
          • microsoft/iis Dashboards
        • microsoft/microsoft365
          • Package microsoft/microsoft365 Release Notes
          • Parsers and Generated Fields
          • microsoft/microsoft365 Dashboards
        • microsoft/sysmon
          • Package microsoft/sysmon Release Notes
          • Parsers and Generated Fields
        • microsoft/windows-dns-debug
          • Package microsoft/windows-dns-debug Release Notes
          • Parsers and Generated Fields
      • Mimecast Services Ltd.
        • mimecast/email-security
          • Package mimecast/email-security Release Notes
          • Parsers and Generated Fields
          • mimecast/email-security Dashboards
      • Netskope, Inc.
        • netskope/casb
          • Package netskope/casb Release Notes
          • netskope/casb Dashboards
      • Nginx
        • nginx/nginx
          • Package nginx/nginx Release Notes
          • Parsers and Generated Fields
          • NGINX Server Configuration
          • Installing the Package in LogScale
          • Configure Ingest for Nginx Server logs
          • Verify Data is Arriving in LogScale
          • Extending Parsers for Custom Access Logs
          • nginx/nginx Dashboards
      • Nozomi Networks Inc
        • nozomi/ids
          • Package nozomi/ids Release Notes
          • Parsers and Generated Fields
      • Obsidian Security, Inc.
        • obsidiansecurity/actionnotification
          • Parsers and Generated Fields
          • obsidiansecurity/actionnotification Dashboards
      • Okta, Inc.
        • okta/sso
          • Package okta/sso Release Notes
          • Parsers and Generated Fields
      • One Identity LLC
        • oneidentity/onelogin
          • Parsers and Generated Fields
      • Ordr, Inc.
        • ordr/ordr
          • Parsers and Generated Fields
          • ordr/ordr Dashboards
      • Palo Alto Networks, Inc.
        • palo-alto/prisma-sd-wan
          • Package palo-alto/prisma-sd-wan Release Notes
          • Parsers and Generated Fields
        • paloalto/firewall
          • Package paloalto/firewall Release Notes
          • Parsers and Generated Fields
      • Ping Identity Corporation
        • pingidentity/pingone
          • Package pingidentity/pingone Release Notes
          • Parsers and Generated Fields
          • Install the Package in LogScale
          • Configure Ingest for PingOne Service
          • Verify Data is Arriving in LogScale
          • pingidentity/pingone Dashboards
      • Proofpoint, Inc.
        • proofpoint/tap-siem-api
          • Package proofpoint/tap-siem-api Release Notes
          • Parsers and Generated Fields
      • Radware, Inc.
        • radware/alteon
          • Package radware/alteon Release Notes
          • Parsers and Generated Fields
      • Red Hat, Inc.
        • redhat/ansible
          • Package redhat/ansible Release Notes
          • Parsers and Generated Fields
          • redhat/ansible Dashboards
      • Robust Intelligence
      • Rubicon Communications LLC (Netgate)
        • netgate/pfsense
          • Package netgate/pfsense Release Notes
          • Parsers and Generated Fields
      • Rubrik, Inc.
        • rubrik/security-cloud
          • Package rubrik/security-cloud Release Notes
          • Parsers and Generated Fields
          • rubrik/security-cloud Dashboards
      • Ruby
        • ruby/logger
          • Parsers and Generated Fields
          • ruby/logger Dashboards
      • ServiceNow Inc.
        • servicenow/servicenow
          • Installing the Package in LogScale
          • servicenow/servicenow Dashboards
      • Talon
        • talon/talon-cyber-security
          • Parsers and Generated Fields
          • Configure the integration from the Talon Management Console
          • Verify Data is Arriving in LogScale
          • talon/talon-cyber-security Dashboards
      • Tausight Inc.
        • tausight/ephi-risk-posture
          • Package tausight/ephi-risk-posture Release Notes
          • Parsers and Generated Fields
      • The Apache Software Foundation (ASF)
        • apache/http-server
          • Package apache/http-server Release Notes
          • Parsers and Generated Fields
          • Apache HTTP Server Configuration
          • Installing the Package in LogScale
          • Configure Ingest for Apache HTTP Server
          • Verify Data is Arriving in LogScale
          • Extending Parsers for Custom Logs
          • apache/http-server Dashboards
        • apache/kafka-metricbeat
          • apache/kafka-metricbeat Dashboards
      • The Linux Foundation
        • linux/system-logs
          • Package linux/system-logs Release Notes
          • linux/system-logs Dashboards
      • Trellix
        • trellix/fireeye-nx
          • Package trellix/fireeye-nx Release Notes
          • Parsers and Generated Fields
      • Vectra AI, Inc.
        • vectra/detections
          • vectra/detections Dashboards
      • Veeam Software
        • veeam/veeamdataplatform
          • Package veeam/veeamdataplatform Release Notes
          • Parsers and Generated Fields
          • veeam/veeamdataplatform Dashboards
      • Zoom Video Communications, Inc.
        • zoom/qss
          • Package zoom/qss Release Notes
          • Parsers and Generated Fields
      • Zscaler, Inc.
        • zscaler/deception
          • Package zscaler/deception Release Notes
          • Parsers and Generated Fields
        • zscaler/internet-access
          • Package zscaler/internet-access Release Notes
          • Parsers and Generated Fields
          • Example Queries
          • zscaler/internet-access Dashboards
        • zscaler/private-access
          • Package zscaler/private-access Release Notes
          • Parsers and Generated Fields
    • Package Reference
    • Dashboard Reference
    • Package Management
      • Install & Update Packages
      • Package Marketplace
      • Create a Package
      • Package File Formats
      • Referencing Package Assets
      • Developer Guidelines
        • Improve an Existing Package or Create a New Package
        • Data Ingest Guidelines
        • Asset Guidelines
          • Parsers Best Practices
          • LogScale Query Language Best Practices
          • Dashboard Best Practices
          • Dashboard Widgets
          • Alerts and Saved Searches Best Practices
          • Naming and Informational Notes
        • Package Content Guidelines
        • Guidelines for Submitting a Package to LogScale Marketplace
      • Insights Package
        • Insights Overview Dashboard
        • Insights Ingest Dashboard
        • Insights Hosts Dashboard
        • Bucket Storage Dashboard
        • Kafka Dashboard
        • Insights Search Dashboard
        • Request-Response
        • Insights Segments & Datasources Dashboard
        • Insights Errors Dashboard
    • Other Integrations
      • Tines Alerts
      • XSOAR Security Management
      • Prometheus
      • Kubernetes Log Format
      • Grafana
      • Cribl CrowdStream
        • Simple or Complex Routing?
        • Navigate Between User Interfaces
        • Configure a Source
        • Configure a Destination
        • Connect: Passthru, Pipeline, or Pack
        • Commit/Deploy Config Changes
        • Moving Ahead with CrowdStream
    • Log Formats
      • NetFlow Log Format
      • Heroku Log Format
      • Linux
        • Linux System Logs
      • Azure Service Fabric Log Format
      • Docker Log Format
      • Kafka Connect Log Format
      • Amazon CloudWatch Log Format
Falcon LogScale Documentation
/ LogScale Getting Data In
/ How to Get Data in
/ Popular Ingest Methods
/ Google Cloud Logging

Set up Google Cloud Logging as an ingest method

Step 1 - Create a Cloud Logging ingest token

Why? Ingest tokens authenticate and authorize data flows from Google Cloud to send data to your repository. They control which parsers can be used and what fields can be populated from Cloud Logging data.

Detailed steps:

  1. Sign in to Falcon LogScale, and browse to your repository.

  2. Click Settings, Ingest Tokens.

  3. Click Add token.

  4. Type in a descriptive name (for example, gcp-cloud-logging-production).

  5. Set the appropriate permissions:

    • Assign parser to allow automatic parser selection based on GCP log types

    • Assign fields to enable field creation from Cloud Logging metadata and log entries

  6. Click Create token to save the token and securely store the generated string - you'll need this when configuring the Cloud Function or ingestion pipeline.

  7. Note your LogScale ingestion endpoint URL:

    • For cloud deployments: Typically https://cloud.humio.com or your regional endpoint

    • For on-premises deployments: Your self-hosted LogScale URL

    • The full ingestion endpoint will be: https://cloud.humio.com/api/v1/ingest/humio-structured

Step 2 - Plan your Cloud Logging integration

Why? Planning your integration strategy ensures you capture the right logs, optimize costs, and implement the most appropriate architecture for your GCP environment. Understanding Cloud Logging's structure and routing capabilities helps you design an efficient ingestion pipeline.

Detailed steps:

  1. Identify your integration architecture:

    • Pub/Sub + Cloud Function: Recommended approach for most use cases

      • Best for: Real-time log streaming, serverless architecture, automatic scaling

      • Advantages: No infrastructure management, automatic scaling, built-in retry logic

      • Considerations: Cloud Function execution costs, cold start latency

      • Flow: Cloud Logging โ†’ Log Router โ†’ Pub/Sub Topic โ†’ Cloud Function โ†’ LogScale

    • Pub/Sub + Dataflow: For high-volume, complex processing requirements

      • Best for: Very high log volumes (millions of events per second), complex transformations

      • Advantages: Horizontal scaling, sophisticated processing, exactly-once semantics

      • Considerations: Higher complexity, Dataflow job management, increased costs

      • Flow: Cloud Logging โ†’ Log Router โ†’ Pub/Sub Topic โ†’ Dataflow Job โ†’ LogScale

    • Pub/Sub + Custom Consumer: For specialized processing requirements

      • Best for: Custom processing logic, integration with existing systems

      • Advantages: Full control over processing, custom transformation logic

      • Considerations: Infrastructure management, scaling responsibility

      • Flow: Cloud Logging โ†’ Log Router โ†’ Pub/Sub Topic โ†’ Custom Application โ†’ LogScale

    • Cloud Storage + Batch Processing: For historical data or batch analytics

      • Best for: Archival, compliance, batch processing, cost optimization

      • Advantages: Lower costs, long-term storage, batch processing efficiency

      • Considerations: Higher latency, batch processing complexity

      • Flow: Cloud Logging โ†’ Log Router โ†’ Cloud Storage โ†’ Batch Job โ†’ LogScale

  2. Identify log sources to collect:

    • Platform logs: Automatically collected from GCP services

      • Audit logs (Admin Activity, Data Access, System Event, Policy Denied)

      • VPC Flow Logs

      • Cloud DNS logs

      • Load Balancer logs

      • Cloud NAT logs

    • Component logs: From GCP services and resources

      • Compute Engine VM logs

      • Google Kubernetes Engine (GKE) logs

      • Cloud Run logs

      • Cloud Functions logs

      • App Engine logs

      • Cloud SQL logs

    • User-written logs: Custom application logs

      • Application logs via Cloud Logging API

      • Structured logs from applications

      • Custom metrics and events

    • Multi-cloud logs: AWS logs via Cloud Logging

      • AWS CloudTrail logs

      • AWS VPC Flow Logs

  3. Understand Cloud Logging resource hierarchy:

    • Organization: Top-level container for all GCP resources

    • Folders: Organizational units within an organization

    • Projects: Individual GCP projects containing resources

    • Resources: Individual GCP services and components

    • Log routing can be configured at any level in the hierarchy

  4. Assess data volumes and costs:

    • Review current Cloud Logging ingestion volumes in GCP Console

    • Estimate Pub/Sub message volumes and costs

    • Calculate Cloud Function invocation costs (if using Cloud Functions)

    • Consider log filtering to reduce unnecessary data and costs

    • Plan for data egress costs from GCP to LogScale

  5. Plan filtering and exclusion strategies:

    • Identify high-volume, low-value logs to exclude (health checks, debug logs)

    • Define inclusion filters for critical security and audit logs

    • Plan sampling strategies for high-volume logs

    • Consider separate sinks for different log priorities

  6. Plan for multi-project and multi-organization scenarios:

    • Determine if you need aggregated logging across multiple projects

    • Plan for organization-level log sinks if managing multiple projects

    • Consider separate Pub/Sub topics per project or consolidated topics

    • Plan tagging strategy to identify log sources in LogScale

  7. Plan network connectivity:

    • Verify Cloud Functions can reach LogScale endpoints (public or VPC)

    • Configure VPC Service Controls if required for security

    • Plan for Private Service Connect if using private connectivity

    • Consider Cloud NAT for outbound connectivity from private resources

Step 3 - Configure Google Cloud IAM permissions

Why? Proper IAM configuration ensures secure, least-privilege access for the log routing pipeline. Cloud Functions and other components need specific permissions to read from Pub/Sub, write logs, and interact with GCP services.

Detailed steps:

  1. Create a service account for the Cloud Function:

    1. Navigate to IAM & Admin โ†’ Service Accounts in the GCP Console

    2. Click Create Service Account

    3. Provide a descriptive name (for example, logscale-log-forwarder)

    4. Add description: Service account for forwarding Cloud Logging data to LogScale

    5. Click Create and Continue

  2. Grant required IAM roles to the service account:

    • Pub/Sub Subscriber (roles/pubsub.subscriber):

      • Allows the Cloud Function to pull messages from Pub/Sub

      • Required for reading log entries from the Pub/Sub topic

    • Logging Log Writer (roles/logging.logWriter) (optional):

      • Allows the Cloud Function to write its own logs to Cloud Logging

      • Useful for monitoring and troubleshooting the function

  3. Grant Cloud Logging permission to publish to Pub/Sub:

    1. Identify the Cloud Logging service account:

      • Format: service-[PROJECT_NUMBER]@gcp-sa-logging.iam.gserviceaccount.com

      • Find your project number in GCP Console โ†’ Dashboard

    2. This permission will be granted when creating the log sink (Step 4)

  4. For organization-level log routing, grant additional permissions:

    • Logging Admin (roles/logging.admin) at organization level:

      • Required to create organization-level log sinks

    • Organization Administrator (roles/resourcemanager.organizationAdmin):

      • Required to manage organization-level resources

  5. Document the service account and permissions:

    • Record the service account email address

    • Document the granted roles and their purposes

    • Store this information securely for future reference

Step 4 - Create Pub/Sub topic and configure log routing

Why? Pub/Sub acts as a reliable, scalable message queue between Cloud Logging and your ingestion pipeline. Log routing (sinks) direct specific logs from Cloud Logging to the Pub/Sub topic based on filters you define.

Detailed steps:

  1. Create a Pub/Sub topic:

    1. Navigate to Pub/Sub โ†’ Topics in the GCP Console

    2. Click Create Topic

    3. Configure the topic:

      • Topic ID: Provide a descriptive name (for example, logscale-cloud-logging)

      • Add a default subscription: Leave unchecked (subscription will be created by Cloud Function)

      • Encryption: Choose Google-managed or customer-managed encryption key

    4. Configure advanced settings (optional):

      • Message retention duration: Default 7 days (adjust based on recovery requirements)

      • Message storage policy: Configure regions for data residency requirements

    5. Click Create

  2. Create a log sink (log router):

    1. Navigate to Logging โ†’ Log Router in the GCP Console

    2. Click Create Sink

    3. Configure sink details:

      • Sink name: Provide a descriptive name (for example, logscale-all-logs)

      • Sink description: Document the purpose (for example, Routes all logs to LogScale via Pub/Sub)

    4. Click Next

  3. Select sink destination:

    1. Choose Cloud Pub/Sub topic as the sink service

    2. Select the Pub/Sub topic created in the previous step

    3. Click Next

  4. Configure inclusion filters to select logs:

    # Include all logs (use with caution - high volume)
    # Leave filter empty or use:
    resource.type=*
    
    # Include specific resource types
    resource.type="gce_instance"
    OR resource.type="k8s_container"
    OR resource.type="cloud_function"
    
    # Include audit logs only
    logName:"cloudaudit.googleapis.com"
    
    # Include specific severity levels
    severity >= ERROR
    
    # Include logs from specific projects
    resource.labels.project_id="my-project-id"
    
    # Complex filter example: GKE logs excluding health checks
    resource.type="k8s_container"
    -httpRequest.requestUrl=~"/healthz"
    -httpRequest.requestUrl=~"/readyz"
    
    # Include VPC Flow Logs
    resource.type="gce_subnetwork"
    logName:"compute.googleapis.com/vpc_flows"
    • Filters use Cloud Logging query language syntax

    • More specific filters reduce data volume and costs

    • Test filters in Logs Explorer before applying to sinks

  5. Click Next

  6. Configure exclusion filters (optional but recommended):

    1. Click Add exclusion

    2. Define exclusion filters to reduce noise and costs:

      # Exclude health check logs
      httpRequest.requestUrl=~"/healthz"
      OR httpRequest.requestUrl=~"/readyz"
      OR httpRequest.requestUrl=~"/_ah/health"
      
      # Exclude debug logs
      severity="DEBUG"
      
      # Exclude specific user agents
      httpRequest.userAgent=~"GoogleHC"
      OR httpRequest.userAgent=~"kube-probe"
      
      # Exclude high-volume, low-value logs
      resource.type="k8s_container"
      resource.labels.container_name="istio-proxy"
      severity="INFO"
    3. Provide exclusion name and description

    4. Set exclusion percentage (0-100%) for sampling

  7. Review and create the sink:

    1. Review the sink configuration

    2. Click Create Sink

    3. GCP automatically grants the Cloud Logging service account permission to publish to the Pub/Sub topic

  8. Create additional sinks for different log categories (optional):

    • Separate sinks for audit logs, application logs, and infrastructure logs

    • Different Pub/Sub topics for different priorities or destinations

    • Organization-level sinks for centralized logging across projects

  9. Verify the sink is active:

    • Check the sink status in Log Router

    • Verify messages are being published to the Pub/Sub topic:

      gcloud pubsub topics list
      gcloud pubsub topics describe logscale-cloud-logging
    • Monitor Pub/Sub metrics in GCP Console for message throughput

Step 5 - Deploy Cloud Function to forward logs to LogScale

Why? The Cloud Function acts as the bridge between Pub/Sub and LogScale, consuming log messages from Pub/Sub, transforming them as needed, and forwarding them to LogScale's ingestion API. This serverless approach provides automatic scaling and minimal operational overhead.

Detailed steps:

  1. Prepare the Cloud Function code:

    1. Create a directory for the function code:

      mkdir logscale-forwarder
      cd logscale-forwarder
    2. Create main.py with the following code:

      import base64
      import json
      import os
      import requests
      from google.cloud import logging
      
      # Configuration from environment variables
      LOGSCALE_URL = os.environ.get('LOGSCALE_URL', 'https://cloud.humio.com/api/v1/ingest/humio-structured')
      LOGSCALE_TOKEN = os.environ['LOGSCALE_TOKEN']
      BATCH_SIZE = int(os.environ.get('BATCH_SIZE', '100'))
      
      def forward_to_logscale(event, context):
          """
          Cloud Function triggered by Pub/Sub to forward logs to LogScale.
          
          Args:
              event (dict): Event payload containing Pub/Sub message
              context (google.cloud.functions.Context): Metadata for the event
          """
          
          # Decode Pub/Sub message
          if 'data' in event:
              message_data = base64.b64decode(event['data']).decode('utf-8')
              log_entry = json.loads(message_data)
          else:
              print('No data in Pub/Sub message')
              return
          
          # Transform log entry for LogScale
          transformed_entry = transform_log_entry(log_entry)
          
          # Send to LogScale
          try:
              send_to_logscale([transformed_entry])
              print(f'Successfully forwarded log entry: {log_entry.get("logName", "unknown")}')
          except Exception as e:
              print(f'Error forwarding to LogScale: {str(e)}')
              raise  # Raise exception to trigger retry
      
      def transform_log_entry(log_entry):
          """
          Transform GCP log entry to LogScale format.
          
          Args:
              log_entry (dict): GCP Cloud Logging log entry
              
          Returns:
              dict: Transformed log entry for LogScale
          """
          
          # Extract timestamp
          timestamp = log_entry.get('timestamp', log_entry.get('receiveTimestamp'))
          
          # Build LogScale event
          event = {
              'timestamp': timestamp,
              'attributes': {
                  'log_name': log_entry.get('logName', ''),
                  'severity': log_entry.get('severity', 'DEFAULT'),
                  'insert_id': log_entry.get('insertId', ''),
              }
          }
          
          # Add resource information
          if 'resource' in log_entry:
              resource = log_entry['resource']
              event['attributes']['resource_type'] = resource.get('type', '')
              
              # Flatten resource labels
              if 'labels' in resource:
                  for key, value in resource['labels'].items():
                      event['attributes'][f'resource_{key}'] = value
          
          # Add log-specific fields
          if 'jsonPayload' in log_entry:
              # Structured JSON logs
              event['attributes'].update(flatten_dict(log_entry['jsonPayload']))
          elif 'textPayload' in log_entry:
              # Text logs
              event['attributes']['message'] = log_entry['textPayload']
          elif 'protoPayload' in log_entry:
              # Protocol buffer logs (audit logs)
              event['attributes'].update(flatten_dict(log_entry['protoPayload']))
          
          # Add HTTP request information if present
          if 'httpRequest' in log_entry:
              http_request = log_entry['httpRequest']
              event['attributes']['http_request_method'] = http_request.get('requestMethod', '')
              event['attributes']['http_request_url'] = http_request.get('requestUrl', '')
              event['attributes']['http_status'] = http_request.get('status', '')
              event['attributes']['http_user_agent'] = http_request.get('userAgent', '')
              event['attributes']['http_remote_ip'] = http_request.get('remoteIp', '')
          
          # Add labels
          if 'labels' in log_entry:
              for key, value in log_entry['labels'].items():
                  event['attributes'][f'label_{key}'] = value
          
          return event
      
      def flatten_dict(d, parent_key='', sep='_'):
          """
          Flatten nested dictionary.
          
          Args:
              d (dict): Dictionary to flatten
              parent_key (str): Parent key for nested items
              sep (str): Separator for nested keys
              
          Returns:
              dict: Flattened dictionary
          """
          items = []
          for k, v in d.items():
              new_key = f'{parent_key}{sep}{k}' if parent_key else k
              if isinstance(v, dict):
                  items.extend(flatten_dict(v, new_key, sep=sep).items())
              elif isinstance(v, list):
                  items.append((new_key, json.dumps(v)))
              else:
                  items.append((new_key, v))
          return dict(items)
      
      def send_to_logscale(events):
          """
          Send events to LogScale.
          
          Args:
              events (list): List of events to send
          """
          
          headers = {
              'Authorization': f'Bearer {LOGSCALE_TOKEN}',
              'Content-Type': 'application/json'
          }
          
          payload = [{'events': events}]
          
          response = requests.post(
              LOGSCALE_URL,
              headers=headers,
              json=payload,
              timeout=30
          )
          
          response.raise_for_status()
          
          return response
    3. Create requirements.txt:

      google-cloud-logging==3.5.0
      requests==2.31.0
  2. Deploy the Cloud Function:

    1. Using gcloud CLI:

      gcloud functions deploy logscale-forwarder \
        --runtime python311 \
        --trigger-topic logscale-cloud-logging \
        --entry-point forward_to_logscale \
        --service-account logscale-log-forwarder@PROJECT_ID.iam.gserviceaccount.com \
        --set-env-vars LOGSCALE_URL=https://cloud.humio.com/api/v1/ingest/humio-structured,LOGSCALE_TOKEN=YOUR_INGEST_TOKEN_HERE \
        --memory 256MB \
        --timeout 60s \
        --max-instances 100 \
        --region us-central1
    2. Using GCP Console:

      1. Navigate to Cloud Functions

      2. Click Create Function

      3. Configure basics:

        • Function name: logscale-forwarder

        • Region: Choose appropriate region

        • Trigger type: Cloud Pub/Sub

        • Topic: Select logscale-cloud-logging

      4. Configure runtime settings:

        • Memory: 256 MB

        • Timeout: 60 seconds

        • Max instances: 100

        • Service account: logscale-log-forwarder

      5. Add environment variables:

        • LOGSCALE_URL: https://cloud.humio.com/api/v1/ingest/humio-structured

        • LOGSCALE_TOKEN: YOUR_INGEST_TOKEN_HERE

      6. Click Next

      7. Configure code:

        • Runtime: Python 3.11

        • Entry point: forward_to_logscale

        • Copy the code from main.py into the inline editor

        • Copy requirements.txt content

      8. Click Deploy

  3. Verify the Cloud Function deployment:

    • Check deployment status in Cloud Functions console

    • Verify the function is triggered by the Pub/Sub topic

    • Check function logs for any deployment errors:

      gcloud functions logs read logscale-forwarder --region us-central1
  4. Configure advanced Cloud Function settings (optional):

    • VPC Connector: For private connectivity to LogScale

    • Secrets: Store ingest token in Secret Manager instead of environment variables

    • Concurrency: Adjust concurrent executions per instance

    • Min instances: Set minimum instances to reduce cold starts

Step 6 - Test and verify

Why? Testing confirms that the integration is working correctly before relying on it in production, ensuring proper log flow from Cloud Logging through Pub/Sub and Cloud Functions to LogScale.

Detailed steps:

  1. Generate test log entries:

    • Using gcloud CLI:

      gcloud logging write test-log "Test log entry from GCP Cloud Logging" \
        --severity=INFO \
        --resource=global
    • Using Cloud Logging API:

      from google.cloud import logging
      
      client = logging.Client()
      logger = client.logger('test-logger')
      
      logger.log_text('Test log entry from Python', severity='INFO')
      logger.log_struct({
          'message': 'Test structured log',
          'user': 'test-user',
          'action': 'test-action'
      }, severity='INFO')
    • Trigger logs from GCP services (deploy a test Cloud Function, create a GCE instance, etc.)

  2. Verify logs are routed to Pub/Sub:

    • Check Pub/Sub topic metrics in GCP Console

    • Verify message count is increasing:

      gcloud pubsub topics describe logscale-cloud-logging
    • Pull a sample message to verify format:

      gcloud pubsub subscriptions pull logscale-subscription --limit=1
  3. Verify Cloud Function is processing messages:

    • Check Cloud Function logs:

      gcloud functions logs read logscale-forwarder --region us-central1 --limit=50
    • Look for successful execution messages

    • Verify no errors in function logs

    • Check function metrics in GCP Console:

      • Invocations per second

      • Execution time

      • Error rate

      • Active instances

  4. Verify data in LogScale:

    • Navigate to your repository in LogScale

    • Run a query to find recently ingested GCP logs:

      resource_type=* OR log_name=* OR gcp_project_id=*
    • Verify events have correct timestamps

    • Confirm GCP-specific fields are present:

      • log_name

      • resource_type

      • severity

      • insert_id

      • resource labels (project_id, zone, instance_id, etc.)

    • Verify structured log fields are extracted correctly

    • Check that HTTP request fields are present (if applicable)

  5. Test different log types:

    • Verify audit logs are ingested correctly

    • Test GKE container logs

    • Test Compute Engine VM logs

    • Test Cloud Function logs

    • Test VPC Flow Logs (if enabled)

  6. Validate end-to-end latency:

    • Generate a log entry with a unique identifier

    • Measure time from log generation to availability in LogScale

    • Typical latency: 10-60 seconds depending on configuration

Step 7 - Monitoring and maintenance

Why? Ongoing monitoring ensures the reliability, performance, and cost-effectiveness of your Cloud Logging integration, enabling proactive issue detection and continuous optimization of the log ingestion pipeline.

What you should do:

  • Set up alerts in GCP Cloud Monitoring:

    • Cloud Function execution errors exceeding threshold

    • Cloud Function execution time exceeding timeout

    • Pub/Sub topic message backlog growing

    • Pub/Sub subscription oldest unacked message age increasing

    • Dead letter queue receiving messages

    • Log sink errors or failures

    • Cloud Function instance count approaching max

    • Unusual drops in log volume

  • Monitor GCP-specific metrics:

    • Cloud Logging ingestion volume and rate

    • Log sink routing success rate

    • Pub/Sub publish and delivery rates

    • Pub/Sub message age and backlog size

    • Cloud Function invocation count and rate

    • Cloud Function execution time (p50, p95, p99)

    • Cloud Function error rate and types

    • Cloud Function active instances and scaling behavior

    • Network egress from GCP to LogScale

  • Regularly review and optimize:

    • Log sink filters based on actual usage patterns

    • Exclusion filters to reduce unnecessary data and costs

    • Cloud Function memory and timeout settings

    • Cloud Function max instances based on load patterns

    • Pub/Sub subscription settings (ack deadline, retry policy)

  • Implement security best practices:

    • Rotate ingest tokens regularly (every 90 days recommended)

    • Use Secret Manager for sensitive credentials

    • Review and minimize IAM permissions regularly

    • Enable VPC Service Controls for sensitive projects

    • Audit Cloud Function code changes

    • Monitor for unauthorized access to Pub/Sub topics

    • Ensure audit logs are always forwarded (never filtered)

  • Maintain operational documentation:

    • Document all log sinks and their purposes

    • Maintain runbooks for common troubleshooting scenarios

    • Document filter logic and rationale

    • Keep inventory of monitored GCP projects and resources

    • Document Cloud Function code and transformation logic

    • Maintain change logs for configuration modifications

Support
  • Twitter
  • LinkedIn
  • Youtube

ยฉ 2026 CrowdStrike All other marks contained herein are the property of their respective owners.

Enter search term