Skip to content
LogoLogScale DocumentationLibraryGuidance Release Notes Integrations Query Examples Training APIGraphQLSearch Archives Contact Support
🔖੆Help button for documentation
    • Terminology Reference
      • Actions
      • Aggregate Alert
      • Aggregation
      • Alert
      • Anomaly Detection
      • API (Application Programming Interface)
      • API Tokens
      • archiving
      • Arrays of Arrays
      • Arrays of Objects
      • Asset
      • Asset Permissions
      • Authentication
      • Authorization
      • Automated Actions
      • Auxiliary node
      • Backfilling
      • Backup
      • Baseline
      • Bearer Token
      • Blocklist
      • Bloom Filter
      • Bucket
      • Built-in Parsers
      • Cardinality
      • Checksum
      • Cluster
      • Cluster Management
      • Cold Storage
      • Compression
      • Configuration
      • Correlation
      • Cost Points
      • CrowdStrike Query Language (CQL)
      • Cron
      • CrowdStrike Parsing Standard (CPS)
      • Custom Resource Definitions (CRD)
      • Dashboard
      • Data Export
      • Data Ingestion
      • Data Retention
      • Data Visualization
      • Datasource
      • Deployment
      • Dynamic Configuration
      • Endpoint
      • Enrichment
      • Environment Variables
      • Ephemeral User Token
      • Event
      • Event Fields
      • Event List
      • Extraction
      • Field
      • Field Aliasing
      • Field Data Types
      • Field Mapping
      • Fields Panel
      • Filter
      • Filter Alert
      • Format Event List Panel
      • Function
      • Glob Pattern
      • GraphQL
      • Group synchronization
      • groupBy()
      • Groups
      • Histogram
      • Hot Storage
      • Humio Operator
      • HumioCluster
      • Identity Provider (IdP)
      • Immutability
      • Indexing
      • Ingest Token
      • Ingestion
      • @ingesttimestamp
      • Inspection Panel
      • Installation
      • Integration
      • IP Filters
      • Join
      • Kubernetes
      • LDAP (Lightweight Directory Access Protocol)
      • License Management
      • Live Query
      • Load Balancing
      • Log Shipper
      • LogScale Query Language (CQL)
      • Lookup Table
      • LZ4
      • Multi-Cluster-Search
      • Multi-Cluster View
      • Memory Limits
      • Metadata
      • Metadata Fields
      • Monitoring
      • Multi-Cluster Search
      • Nested Arrays
      • Node
      • Non-Sensitive Events
      • Notification
      • OAuth
      • OpenID Connect (OIDC)
      • Operator
      • Organization
      • Organization-owned queries
      • Organization Owner
      • Parser
      • Permissions
      • Pipeline
      • Proxy Authentication
      • Query
      • Query Coordinator
      • Query Editor
      • Query prefix
      • Query Profiling
      • Query Quotas
      • Query Work
      • RBAC (Role-Based Access Control)
      • Real-time
      • Regex (Regular Expression)
      • Regular Expression Engine V2
      • Repository
      • Repository Permissions
      • REST API
      • Result
      • Reverse Proxy
      • Roles
      • Security Assertion Markup Language (SAML)
      • Saved Search
      • Scheduled Search
      • Search
      • Search Interface
      • Security
      • Security Policies
      • Segment
      • Sensitive Events
      • SIEM (Security Information and Event Management)
      • Structured Array Syntax
      • Tag
      • Tag Fields
      • Tagging
      • Template Language
      • Threshold
      • Throttling Period
      • Time Interval Selector
      • TimeChart
      • @timestamp
      • Timestamp Parsing
      • Token
      • Tool Panel
      • Transformation
      • Triggers
      • User Account
      • User Interface (UI)
      • User Management
      • User Roles
      • Vhost
      • View
      • View-based Access Control
      • Visualization
      • Webhook
      • Widget
      • Widget Selector
      • Worker Node
      • Zstd
Falcon LogScale Documentation
/ LogScale Terminology

Multi-Cluster Search

A feature in LogScale that enables users to create views that search and aggregate data across multiple local and remote clusters, offering improved workload distribution and the ability to combine query data from different regional locations. Multi-cluster search operates through a special Multi-Cluster View that establishes secure connections between clusters using Repository Tokens, allowing queries to be executed and results to be combined from multiple configured downstream clusters. When executing searches, LogScale sends queries to each configured connection, reads event data from each connection, and combines the result set. This feature is available exclusively to Self-hosted customers and requires proper feature flags to be enabled on each participating cluster.

Related Content
  • LogScale Multi-Cluster Search

Related Terms
  • distributed-search

  • repository

  • view

Support
  • Twitter
  • LinkedIn
  • Youtube

© 2026 CrowdStrike All other marks contained herein are the property of their respective owners.

  • Other articles on this topic

    • Add a local connection (Self-Hosted)
    • Add a remote connection (Self-Hosted)
    • Advanced Multi-Cluster Topics (Self-Hosted)
    • Change Remote connections (Self-Hosted)
    • Change local connections (Self-Hosted)
    • Configure Multi-Cluster (Self-Hosted)
    • Create a Multi-Cluster View using GraphQL (Self-Hosted)
    • Create and Manage Multi-Cluster Views using LogScale UI (Self-Hosted)
    • Delete connections (Self-Hosted)
    • Enable Multi-Cluster Feature Flags (Self-Hosted)
    • Identify Queries on Remote Clusters (Self-Hosted)
    • LogScale Multi-Cluster Search (Self-Hosted)
    • Messages During Multi-Cluster Queries (Self-Hosted)
    • Multi-Cluster Security (Self-Hosted)
    • Query Function Limitations (Self-Hosted)
    • Understand Multi-Cluster Topologies (Self-Hosted)
    • Using match() in Multi-Cluster Scenarios (Self-Hosted)
  • Terminology

    • LogScale Multi-Cluster Search (Self-Hosted)

Enter search term