Skip to content

Security Operations with LogScale

Core workflows for security analysts: investigate threats, build detection rules, meet compliance requirements, and monitor your environment in real time

🔍 Search and Investigate
Core search and investigation skills for security analysts

Search Security Data

Find events, filter by field values, and drill into individual events. Core investigation skill for triaging alerts, correlating events across sources, and building evidence timelines.

Inspect Individual Events

Expand individual events to examine every field and value. Essential for forensic analysis and incident investigation when you need the full context of a security event.

Field Interactions and Refinement

Use contextual menus to filter and aggregate on field values, expand time windows, and interactively refine searches. Accelerates triage workflows by letting you pivot on any field value directly from results.

Save and Share Searches

Save threat hunting queries for reuse, share investigations with team members, and preserve query results for compliance documentation and incident reporting.

Export Data for Reporting

Export query results as CSV, JSON, or plain text for evidence collection, executive reporting, and sharing investigation findings with stakeholders outside LogScale.

Enrich Data with Lookup Files

Upload lookup files to enrich security events with additional context: map IP addresses to known threat actors, user IDs to names, or asset IDs to business owners. Critical for contextual investigations.

🔔 Detection and Alerting
Build detection rules, configure alert triggers, and automate incident response

Automated Alerts

Configure detection rules using three trigger types: Scheduled Searches (periodic queries), Aggregate Alerts (continuous monitoring with aggregation), and Filter Alerts (real-time event matching). Learn when to use each type and how to prevent alert fatigue.

Automated Actions

Connect alert triggers to automated response actions: send notifications to Slack, PagerDuty, or email; call webhooks; or push data to external systems. Build automated incident response workflows that reduce mean time to respond.

Security Dashboards

Build real-time security monitoring dashboards with time charts, event tables, and geographic visualizations. Create shared SOC dashboards that give your team continuous visibility into threat activity and system health.

Security Policies

Configure organization-wide security policies that apply to all users and API tokens. Set allowed actions for automated alerts, restrict which external endpoints actions can reach, and control what automated workflows can do.

📋 Compliance and Audit
Audit logging, data retention, and compliance monitoring

Audit Logging

Track all user activity, permission changes, data access, and administrative actions in the humio-audit repository. Essential for SOC 2, HIPAA, GDPR, and other compliance frameworks that require evidence of access controls and data handling.

Data Retention

Configure how long security data is retained in each repository. Set retention policies that satisfy regulatory requirements for log preservation while managing storage costs. Understand the difference between ingest and storage retention limits.

Compliance Monitoring

Use LogScale's built-in compliance monitoring features to track security posture and generate evidence for audits. Monitor for anomalous access patterns and policy violations.

IP Filters

Restrict access to LogScale by IP address or CIDR range. Enforce network-level access controls that limit who can reach the platform, supporting zero-trust and perimeter security requirements.

Session Management

Configure session timeouts, inactivity limits, and re-authentication requirements. Control how long user sessions remain active and enforce re-login policies that meet your security standards.

🔐 Access Control for SecOps
Control who can access security data, manage API tokens, and apply least-privilege principles

Role-Based Access Control

Apply least-privilege access to security repositories and views. Control which analysts can query which data sources, who can manage detection rules, and who has administrative access to security infrastructure.

API Token Management

Create, scope, and rotate API tokens used by integrations, SIEM connectors, and automated workflows. Understand token types (personal, ingest, organization) and apply the principle of least privilege to token permissions.

🧭 Guided Workflows
Step-by-step learning paths for setting up access control and security hardening

Security and Compliance Hardening

Step-by-step learning paths for securing LogScale for production, meeting regulatory compliance requirements, and implementing advanced access controls.

Role-Based Access Control

Structured learning paths for configuring RBAC: understand the permission model or jump straight into creating roles, groups, and assigning access to repositories and views.


🔔 New Pages
🔔 Recently Updated Pages