Falcon LogScale 1.253.0 GA (2026-08-11)

Version?Type?Release Date?Availability?End of SupportSecurity UpdatesUpgrades From?Downgrades To?Config. Changes?
1.253.0GA2026-08-11

Cloud

Next LTSNo1.177.01.177.0No

Hide file download links

Show file download links

Bug fixes and updates

Breaking Changes

The following items create a breaking change in the behavior, response or operation of this release.

  • Functions

    • LogScale LTS version 1.258 will include a breaking change to subquery semantics for the worldMap() and sankey() functions. Result fields will no longer be automatically detected, and results must be assigned to a specific field - magnitude for worldMap() and weight for sankey() respectively.

      This change avoids unpredictable behavior in sub-queries, and allows further development on related systems. The following is an example of a query that is impacted by this change:

      logscale
      worldMap(lat=lat,lon=lon,magnitude={ w_squared := w*w | sum(w_squared) | magnitude := math:sqrt(_sum) })

      Currently, the query will be interpreted as:

      logscale
      worldMap(lat=lat,lon=lon,magnitude={ w_squared := w*w | magnitude := sum(w_squared) })

      From version 1.258, the math:sqrt part of the query will no longer be discarded.

Advance Warning

The following items are due to change in a future release.

  • Documentation

    • Our documentation homepage, functionality, and content will undergo a series of improvements before the end of August 2026. As the volume of content on the site has grown significantly, we recognize that finding the right information can be challenging. These changes are designed to improve navigation, make content easier to find, and provide clearer distinctions between content areas.

      Functionality and Navigation

      • New Default Homepage โ€” Improved navigation and organization to help you find information more quickly. The existing legacy homepage will remain available.

      • Curated Content Pages โ€” Topic-specific pages that provide key resources tailored to different areas of the documentation. Each page includes:

        • Search scoped to that specific content area

        • Highlights of new and recently updated pages

      • Guided Workflow Pages โ€” Step-by-step, page-by-page guides to help you learn about specific areas of LogScale.

      • Bookmark Groups โ€” Organize bookmarks into custom groups to create your own categorized link collections.

      • Page Watching and Notifications โ€” Monitor pages and content for changes, so you're always aware of updates to the content you use most.

      • Custom Homepage โ€” Set a Curated Content page as your homepage, so visiting library.humio.com takes you directly to your preferred content area.

      Content Improvements

      • New CrowdStrike Query Language (CQL) Manual โ€” A standalone manual covering:

        • Query structure and execution context

        • Internal data representation

        • Datatypes used in queries and functions

        • Function types, input and output values, and related functions

        • Common query patterns organized by use case and challenge

        • Guides for translating SQL to CQL

      • New Getting Data Out Manual โ€” Covers the different ways to extract information from LogScale, including APIs, the search interface, dashboards, and automation.

      • New Getting Data In Manual โ€” Covers the methods, tools, and integrations available for ingesting data into LogScale.

      • New Administration Manuals โ€” Separate, dedicated manuals for Self-Hosted and Cloud customers.

      We will provide updates as each improvement becomes available โ€” we welcome your feedback as the changes roll out.

  • API

    • Starting in version 1.258, the queryjobs endpoint will always use pagination, even when no pagination arguments have been given. When no arguments are provided, the endpoint will return the maximum page size and an offset of 0. Unless the dynamic configuration parameter QueryResultRowCountLimit has been raised from its default value, this will initially be the entire result.

      All clients should begin transitioning to use the paginated polling method ahead of version 1.258.

Deprecation

Items that have been deprecated and may be removed in a future release.

  • The GraphQL field meta has been deprecated and now requires authentication. It will be completely removed in LogScale 1.304. To achieve similar results, use the loginInfo and clusterConfig fields instead.

    To temporarily opt out of the authentication requirement, the feature flag UnauthenticatedMeta can be enabled.

  • The userId parameter for the updateDashboardToken GraphQL mutation has been deprecated and will be removed in version 1.273.

Behavior Changes

Scripts or environment which make use of these tools should be checked and updated for the new configuration:

  • GraphQL API

    • After an organization is soft deleted using the removeOrganization mutation, you can now only call the following mutations on that organization:

      Previously, you could call any mutation on a soft-deleted organization.

Upgrades

Changes that may occur or be required during an upgrade.

  • Security

    • Apache Log4j has been updated to version 2.25.5 to address a medium severity Common Vulnerabilities and Exposures (CVE) item.

    • Bouncy Castle Java dependencies have been upgraded to version 1.85.

New features and improvements

Fixed in this release

  • Storage

    • An issue has been fixed where the environment variable GCP_STORAGE_ENDPOINT_BASE was not being used for requests to Google Cloud Storage (GCS).

      Note

      With this release, configured clusters will begin using this value for all GCS storage requests.

    • Fixed an issue where segment and auxiliary file downloads could leak files in a temporary directory.

  • Ingestion

    • Fixed an issue where parsers with a zero-length/empty test case could be saved successfully, resulting in a non-specific error when queried using LogScale's GraphQL API via the LogScale GUI (v1.219.1).

      In the event this occurs, the user will be notified with the error Test case #X has no text or consists only of white spaces, with X defining which test case contains the error.

Known Issues

  • Storage

    • For clusters using secondary storage where the primary storage on some nodes in the cluster may be getting filled (that is, the storage usage on the primary disk is halfway between PRIMARY_STORAGE_PERCENTAGE and PRIMARY_STORAGE_MAX_FILL_PERCENTAGE), those nodes may fail to transfer segments from other nodes. The failure will be indicated by the error java.nio.file.AtomicMoveNotSupportedException with message "Invalid cross-device link".

      This does not corrupt data or cause data loss, but will prevent the cluster from being fully healthy, and could also prevent data from reaching adequate replication.

Improvement

  • User Interface

    • The selected event panel in the Parser Editor is now resizable, allowing users to adjust its height by clicking and dragging.

  • GraphQL API

    • The GraphQL datatype ScheduledReport now exposes the field createdInfo, which contains structured creation metadata. Data points include author and timestamp, which is consistent with other asset types such as filter alerts, dashboards, and parsers.

      The existing fields createdBy and creationDate are now deprecated and will be removed in version 1.306. Migration to the createdInfo field is recommended, as it provides richer author information (user, token, and/or system) alongside the creation timestamp.

      Existing scheduled reports are automatically migrated, no action is required.

  • Configuration

    • A minimum limit of 4 GB has been added for the default value of the dynamic configuration parameter MaxTableForQuerySizeBytes.

    • When a configuration file contains invalid YAML, the Publish button on the configuration editor page is now disabled to prevent publishing invalid configurations.

  • Queries

    • The full set of nested dependencies for a query is now sent as part of the query result, and is located in the filesUsed field. This enables nested dependences to appear as table tabs in the UI.

  • Other

    • Just-In-Time (JIT) logs from the Java Virtual Machine (JVM) have been disabled by default due to disuse and cost. LogScale will now run without them.

      To continue including them, users can add the following JVM option using the environment variable JVM_LOG_DIR if defining a custom log path:

      java
      Xlog:jit*=debug:file=$JVM_LOG_DIR/jit_humio.log:time,tags:filecount=5,filesize=1024000

      If not defining a custom log path, use the default path logs.

Recent Package Updates

The following LogScale packages have been updated within the last month.

  • Package Changes

    • zscaler/private-access has been updated to v1.5.2.

      • Refactored user field handling into a unified post-processing block applied across all log types

      • User identity fields (user.email, user.name, user.domain) are now resolved from a consolidated coalesce of Vendor.User, Vendor.NameID, Vendor.Username, and Vendor.suser

      • When the resolved username contains @, user.email is set and user.name and user.domain are extracted via regex

      • user.id is now assigned using coalesce([Vendor.ModifiedBy, user.email]) for all log types

      • Removed per-dataset inline user field assignments from audit, browser-access, user-activity, and user-status log type handlers

      • Updated ECS version to 9.4.0

      • Updated CPS version to 1.2.0

      For more information, see Package zscaler/private-access Release Notes.

    • cisco/firepower has been updated to v2.0.1.

      • Enhanced regex patterns for event codes 302020 and 302021 to support optional user domain and username extraction from ICMP connection messages

      • Added support for parsing user domain (destination.user.domain, source.user.domain) and username (destination.user.name, source.user.name) fields in ICMP built/teardown connection messages

      • Added new test cases for ICMP connection events with user information (302020 outbound/inbound and 302021 teardown with domain\user format)

      For more information, see Package cisco/firepower Release Notes.

    • cisco/ios has been updated to v1.11.0.

      • Added support for AireOS/WLC (Wireless LAN Controller) style log headers with new regex pattern

      • Added parsing for DISC_INTF_ERR2 events for AP discovery request failures on wrong VLANs

      • Added parsing for DISC_AP_MGR_ERR1 events for AP manager discovery failures

      • Added parsing for MOBILESTATION_NOT_FOUND events for mobile station database lookup failures

      • Added parsing for Q_IND events for association request failures with client limit reached

      • Enhanced MAC address normalization to convert colon-separated format to dash-separated uppercase format

      • Reverted recent timezone handling change to ensure event timezone is prioritized over data connector timezone selection

      • Updated ECS version to 9.4.0

      • Updated CPS version to 1.2.0

      For more information, see Package cisco/ios Release Notes.

    • zscaler/internet-access has been updated to v2.1.4.

      • Consolidated user field handling into a unified post-processing block after all sourcetype-specific logic, replacing per-sourcetype user field extraction

      • Added user.id field assignment set equal to user.email when a valid email is detected

      • Removed per-sourcetype user field case blocks from zscalernss-dns, zscalernss-fw, zscalernss-web, zscalernss-tunnel, and zscalernss-casb sections

      • User resolution now uses coalesce([Vendor.elogin, Vendor.login, Vendor.user, Vendor.adminid]) across all sourcetypes

      • Updated ECS version to 9.4.0

      • Updated parser version to 4.0.4

      For more information, see Package zscaler/internet-access Release Notes.

    • cisco/meraki has been updated to v2.0.3.

      • Fixed content_filtering_block parsing to use flexible key-value extraction instead of a rigid positional regex, allowing optional fields such as category0 between url= and server= to be handled without breaking the match

      • Updated server.ip and server.port extraction for content_filtering_block to split from the combined Vendor.server value produced by kvParse

      • Added user.name mapping from Vendor.user for content_filtering_block events

      • Added host.name mapping from Vendor.clientName for File Scanned events

      For more information, see Package cisco/meraki Release Notes.