Falcon LogScale 1.251.0 GA (2026-07-28)

Version?Type?Release Date?Availability?End of SupportSecurity UpdatesUpgrades From?Downgrades To?Config. Changes?
1.251.0GA2026-07-28

Cloud

2027-09-30No1.177.01.177.0No

Hide file download links

Show file download links

Bug fixes and updates

Breaking Changes

The following items create a breaking change in the behavior, response or operation of this release.

  • Functions

    • LogScale LTS version 1.258 will include a breaking change to subquery semantics for the worldMap() and sankey() functions. Result fields will no longer be automatically detected, and results must be assigned to a specific field - magnitude for worldMap() and weight for sankey() respectively.

      This change avoids unpredictable behavior in sub-queries, and allows further development on related systems. The following is an example of a query that is impacted by this change:

      logscale
      worldMap(lat=lat,lon=lon,magnitude={ w_squared := w*w | sum(w_squared) | magnitude := math:sqrt(_sum) })

      Currently, the query will be interpreted as:

      logscale
      worldMap(lat=lat,lon=lon,magnitude={ w_squared := w*w | magnitude := sum(w_squared) })

      From version 1.258, the math:sqrt part of the query will no longer be discarded.

Advance Warning

The following items are due to change in a future release.

  • Documentation

    • Our documentation homepage, functionality, and content will undergo a series of improvements before the end of August 2026. As the volume of content on the site has grown significantly, we recognize that finding the right information can be challenging. These changes are designed to improve navigation, make content easier to find, and provide clearer distinctions between content areas.

      Functionality and Navigation

      • New Default Homepage โ€” Improved navigation and organization to help you find information more quickly. The existing legacy homepage will remain available.

      • Curated Content Pages โ€” Topic-specific pages that provide key resources tailored to different areas of the documentation. Each page includes:

        • Search scoped to that specific content area

        • Highlights of new and recently updated pages

      • Guided Workflow Pages โ€” Step-by-step, page-by-page guides to help you learn about specific areas of LogScale.

      • Bookmark Groups โ€” Organize bookmarks into custom groups to create your own categorized link collections.

      • Page Watching and Notifications โ€” Monitor pages and content for changes, so you're always aware of updates to the content you use most.

      • Custom Homepage โ€” Set a Curated Content page as your homepage, so visiting library.humio.com takes you directly to your preferred content area.

      Content Improvements

      • New CrowdStrike Query Language (CQL) Manual โ€” A standalone manual covering:

        • Query structure and execution context

        • Internal data representation

        • Datatypes used in queries and functions

        • Function types, input and output values, and related functions

        • Common query patterns organized by use case and challenge

        • Guides for translating SQL to CQL

      • New Getting Data Out Manual โ€” Covers the different ways to extract information from LogScale, including APIs, the search interface, dashboards, and automation.

      • New Getting Data In Manual โ€” Covers the methods, tools, and integrations available for ingesting data into LogScale.

      • New Administration Manuals โ€” Separate, dedicated manuals for Self-Hosted and Cloud customers.

      We will provide updates as each improvement becomes available โ€” we welcome your feedback as the changes roll out.

  • API

    • Starting in version 1.258, the queryjobs endpoint will always use pagination, even when no pagination arguments have been given. When no arguments are provided, the endpoint will return the maximum page size and an offset of 0. Unless the dynamic configuration parameter QueryResultRowCountLimit has been raised from its default value, this will initially be the entire result.

      All clients should begin transitioning to use the paginated polling method ahead of version 1.258.

Deprecation

Items that have been deprecated and may be removed in a future release.

  • The userId parameter for the updateDashboardToken GraphQL mutation has been deprecated and will be removed in version 1.273.

Behavior Changes

Scripts or environment which make use of these tools should be checked and updated for the new configuration:

  • GraphQL API

    • After an organization is soft deleted using the removeOrganization mutation, you can now only call the following mutations on that organization:

      Previously, you could call any mutation on a soft-deleted organization.

  • Configuration

    • The rollout of the feature covered by the feature flag UseInMemorySegmentOwnerHosts has been reverted due to performance issues occurring in certain configurations.

      The following feature flags have been removed and the mechanisms they cover have been disabled:

      • UseInMemorySegmentOwnerHosts

      • EnableInMemorySegmentOwnerHostsFeatureJob

      • UseWeightedOwnerHostsForBucketedSegments

      When rollout restarts for this feature, a new feature flag will be used.

  • Ingestion

    • Externally supplied tag values for the field #humioAutoshard will now be dropped at ingest preparation. The tag is removed from any events where this is the case, and an error will be recorded on the affected event.

New features and improvements

  • Configuration

    • The optional configuration variable FILE_INPUT_STREAM_READ_TIMEOUT has been added to configure the idle read timeout of uploaded files. If the variable is not present, the Pekko default of 5 seconds will be used instead.

      For more information, see Relative Time Syntax.

  • Queries

    • LogScale's query editor now provides auto-completion suggestions for known saved queries within the current view when entering $. Cross-view saved queries are currently not suggested.

      For more information, see Query Editor.

  • Fleet Management

    • The collector instance details dialog now displays whether a Log Collector instance supports manual or remote updates.

Fixed in this release

  • User Interface

    • Fixed an issue where a user's assets would not display in sandbox view if the user ID was removed from the URL.

  • Storage

    • Fixed an issue with Google Cloud Storage (GCS) bucketing and proxy settings, where GCS bucketing was using an HTTP proxy based only on the environment variable HTTP_PROXY_HOST when it should have also included the environment variable GCP_STORAGE_USE_HTTP_PROXY. This issue has now been resolved.

Known Issues

  • Storage

    • For clusters using secondary storage where the primary storage on some nodes in the cluster may be getting filled (that is, the storage usage on the primary disk is halfway between PRIMARY_STORAGE_PERCENTAGE and PRIMARY_STORAGE_MAX_FILL_PERCENTAGE), those nodes may fail to transfer segments from other nodes. The failure will be indicated by the error java.nio.file.AtomicMoveNotSupportedException with message "Invalid cross-device link".

      This does not corrupt data or cause data loss, but will prevent the cluster from being fully healthy, and could also prevent data from reaching adequate replication.

Improvement

  • Storage

    • The DELETE /api/v1/bucket-storage-target API has been updated to account for uploaded lookup files and baled uploaded lookup files.

      The following behaviors now apply:

      • If any uploaded lookup files exist, the deletion will be blocked.

      • If the deletion is forced by the user, the files will have their respective bucket references removed in the same manner as segments are currently handled. The files will still exist in Global Snapshot and on local disk.

  • Configuration

    • The size limit on LogScale stdout logs in the default log configuration has been increased from 16KB to 512KB.

  • Fleet Management

    • A toggle has been added to the Fleet Insights page to group similar errors by replacing IP addresses with addr and UUIDs with uuid. This reduces clutter from many unique but similar error messages. The toggle is enabled by default.

Recent Package Updates

The following LogScale packages have been updated within the last month.

  • Package Changes

    • dell/isilon has been updated to v1.3.1.

      • Updated parser version to 1.2.1

      • Enhanced regex pattern for uid and sid field extraction to handle non-numeric values using [^;]* pattern instead of \d+

      • Added new test case for handling SID values with alphanumeric format (SID:S-1-22-1-0)

      • Improved parsing reliability for API audit logs with complex user identifiers

      For more information, see Package dell/isilon Release Notes.

    • zscaler/internet-access has been updated to v2.1.3.

      • Enhanced firewall event categorization with improved match syntax for better performance

      • Updated event.action matching logic to include "bypassed" actions as allowed events

      • Improved conditional logic structure using match syntax instead of case statements

      • Updated ECS version to 9.3.0 and CPS version to 1.2.0

      • Updated parser version to 4.0.3

      For more information, see Package zscaler/internet-access Release Notes.

    • cisco/meraki has been updated to v2.0.2.

      • Refactored parser logic to use match expressions for improved readability and performance

      • Added support for anyconnect_vpn_session_manager event type with session ID and user extraction

      • Enhanced case statement structure for better maintainability

      • Improved pattern matching efficiency in event type determination

      For more information, see Package cisco/meraki Release Notes.

    • cisco/ios has been updated to v1.10.1.

      • Enhanced regex patterns to handle optional carriage return characters at end of log messages for improved parsing reliability

      For more information, see Package cisco/ios Release Notes.