Skip to content
LogoLogScale DocumentationLibraryGuidance Release Notes Integrations Query Examples Getting Started APIGraphQLSearch Archives Contact Support
🔖 🔔 ੆Help button for documentation
    • Terminology Reference
      • Actions
      • Aggregate Alert
      • Aggregation
      • Aggregation Query
      • Alert
      • Anomaly Detection
      • API (Application Programming Interface)
      • API Tokens
      • archiving
      • Arrays of Arrays
      • Arrays of Objects
      • Asset
      • Asset Permissions
      • Authentication
      • Authorization
      • Automated Actions
      • Automatic user provisioning
      • Auxiliary node
      • Backfilling
      • Backup
      • Baseline
      • Bearer Token
      • Beats
      • Blocklist
      • Bloom Filter
      • Bucket
      • Built-in Parsers
      • Cardinality
      • Cartesian Product
      • Checksum
      • Cluster
      • Cluster Management
      • Cold Storage
      • Compression
      • Configuration
      • Correlation
      • Cost Points
      • CrowdStrike Query Language (CQL)
      • Cron
      • CrowdStrike Parsing Standard (CPS)
      • Custom Resource Definitions (CRD)
      • customKey
      • Dashboard
      • Dashboard Interaction
      • Dashboard Parameter
      • Dashboard Section
      • Data Export
      • Data Ingestion
      • Data Retention
      • Data Visualization
      • Datasource
      • Deployment
      • Drilldown
      • Dynamic Configuration
      • Elastic Bulk API
      • Endpoint
      • Enrichment
      • Environment Variables
      • Ephemeral User Token
      • Event
      • Event Fields
      • Event List
      • externalQueryId
      • Extraction
      • extraLogFields
      • Field
      • Field Aliasing
      • Field Data Types
      • Field Mapping
      • Fields Panel
      • Filter
      • Filter Alert
      • Format Event List Panel
      • Function
      • Gauge
      • Geohash
      • Glob Pattern
      • GraphQL
      • Group synchronization
      • groupBy()
      • Groups
      • Heat Map
      • HEC (HTTP Event Collector)
      • Histogram
      • Hot Storage
      • Humio Operator
      • HumioCluster
      • Identity Provider (IdP)
      • Immutability
      • Indexing
      • Ingest Rate
      • Ingest Token
      • Ingestion
      • @ingesttimestamp
      • Inspection Panel
      • Installation
      • Integration
      • IP Filters
      • Join
      • Kubernetes
      • LDAP (Lightweight Directory Access Protocol)
      • License Management
      • Live Query
      • Load Balancing
      • Log Shipper
      • Falcon LogScale Collector
      • LogScale Query Language (CQL)
      • Lookup Files
      • Lookup Table
      • LZ4
      • Mandatory Query
      • Multi-Cluster-Search
      • Multi-Cluster View
      • Memory Limits
      • Metadata
      • Metadata Fields
      • Monitoring
      • Multi-Cluster Search
      • Nested Arrays
      • Node
      • Non-Sensitive Events
      • Notification
      • OAuth
      • OpenID Connect (OIDC)
      • Operator
      • Organization
      • Organization-owned queries
      • Organization Owner
      • Package
      • Parameter Panel
      • Parser
      • Parser Assignment
      • Parser Editor
      • Permissions
      • Persisted Aggregation
      • Persisted Aggregation Backfill
      • Persisted Aggregation Repository
      • Persistent queries
      • Pie Chart
      • Pipeline
      • Proxy Authentication
      • Query
      • Query Coordinator
      • Query Editor
      • Query prefix
      • Query Profiling
      • Query Quotas
      • Query Work
      • RBAC (Role-Based Access Control)
      • Real-time
      • Regex (Regular Expression)
      • Regular Expression Engine V2
      • Repository
      • Repository Permissions
      • REST API
      • Result
      • Reverse Proxy
      • Roles
      • Security Assertion Markup Language (SAML)
      • Sankey
      • Saved Search
      • Scatter Chart
      • Scheduled Search
      • Scheduled Search Backfill
      • Search
      • Search Interface
      • Security
      • Security Policies
      • Segment
      • Sensitive Events
      • Shared Time
      • SIEM (Security Information and Event Management)
      • Single Value Widget
      • Small Multiples
      • Sparkline
      • Static Query
      • Structured Array Syntax
      • Syslog
      • Tag
      • Tag Fields
      • Tagging
      • Template Expression
      • Template Language
      • Threshold
      • Throttling Period
      • Time Interval Selector
      • TimeChart
      • @timestamp
      • Timestamp Parsing
      • Token
      • Tool Panel
      • Transformation
      • Triggers
      • User Account
      • User Interface (UI)
      • User Management
      • User Roles
      • Vhost
      • View
      • View-based Access Control
      • Visualization
      • Wall Monitor
      • Webhook
      • Widget
      • Widget Selector
      • Worker Node
      • World Map
      • Zstd
Falcon LogScale Documentation
/ LogScale Terminology
Reading timeCalculating...

Multi-Cluster Search

A feature in LogScale that enables users to create views that search and aggregate data across multiple local and remote clusters, offering improved workload distribution and the ability to combine query data from different regional locations. Multi-cluster search operates through a special Multi-Cluster View that establishes secure connections between clusters using Repository Tokens, allowing queries to be executed and results to be combined from multiple configured downstream clusters. When executing searches, LogScale sends queries to each configured connection, reads event data from each connection, and combines the result set. This feature is available exclusively to Self-hosted customers and requires proper feature flags to be enabled on each participating cluster.

Related Content
  • LogScale Multi-Cluster Search

Related Terms
  • repository

  • view

Support
  • Twitter
  • LinkedIn
  • Youtube

© 2026 CrowdStrike All other marks contained herein are the property of their respective owners.

  • Other articles on this topic

    • Add a local connection (Self-Hosted)
    • Add a remote connection (Self-Hosted)
    • Advanced Multi-Cluster Topics (Self-Hosted)
    • Change Remote connections (Self-Hosted)
    • Change local connections (Self-Hosted)
    • Configure Multi-Cluster (Self-Hosted)
    • Create a Multi-Cluster View using GraphQL (Self-Hosted)
    • Create and Manage Multi-Cluster Views using LogScale UI (Self-Hosted)
    • Delete connections (Self-Hosted)
    • Enable Multi-Cluster Feature Flags (Self-Hosted)
    • Identify Queries on Remote Clusters (Self-Hosted)
    • LogScale Multi-Cluster Search (Self-Hosted)
    • Messages During Multi-Cluster Queries (Self-Hosted)
    • Multi-Cluster Security (Self-Hosted)
    • Query Function Limitations (Self-Hosted)
    • Understand Multi-Cluster Topologies (Self-Hosted)
    • Using match() in Multi-Cluster Scenarios (Self-Hosted)
  • Terminology

    • LogScale Multi-Cluster Search (Self-Hosted)
  • Related Release Notes

    • Falcon LogScale 1.256.0 GA (2026-09-01)
    • Falcon LogScale 1.258.0 GA (2026-09-15)

Enter search term