Falcon LogScale 1.260.0 GA (2026-09-29)
| Version? | Type? | Release Date? | Availability? | End of Support | Security Updates | Upgrades From? | Downgrades To? | Config. Changes? |
|---|---|---|---|---|---|---|---|---|
| 1.260.0 | GA | 2026-09-29 | Cloud | Next LTS | No | 1.177.0 | 1.177.0 | No |
Hide file download links
Download
Use docker pull humio/humio-core:1.260.0 to download the latest version
Bug fixes and updates
Breaking Changes
The following items create a breaking change in the behavior, response or operation of this release.
Functions
This release includes a previously announced breaking change to the semantics of sub-queries in the functions
worldMap()andsankey(). The result field is no longer automatically detected, and results must now be assigned to a specific field:magnitudeforworldMap()andweightforsankey().This change prevents unpredictable behavior in sub-queries and enables further development on related systems.
For example, the following query is affected by this change:
logscaleworldMap(lat=lat, lon=lon, magnitude={ w_squared := w*w | sum(w_squared) | magnitude := math:sqrt(_sum) })Previously, this query was interpreted as:
logscaleworldMap(lat=lat, lon=lon, magnitude={ w_squared := w*w | magnitude := sum(w_squared) })From this version, the
math:sqrtpart of the query is no longer discarded.
Advance Warning
The following items are due to change in a future release.
GraphQL API
The mutation deleteFeatureFlag will be removed from the code in LTS 1.270. It is replaced by resetFeature.
Deprecation
Items that have been deprecated and may be removed in a future release.
The GraphQL field meta has been deprecated and now requires authentication. It will be completely removed in LogScale 1.304. To achieve similar results, use the loginInfo and clusterConfig fields instead.
To temporarily opt out of the authentication requirement, the feature flag
UnauthenticatedMetacan be enabled.The userId parameter for the updateDashboardToken GraphQL mutation has been deprecated and will be removed in version 1.273.
Behavior Changes
Scripts or environment which make use of these tools should be checked and updated for the new configuration:
API
The endpoint
/queryjobsnow always uses pagination, even when no pagination arguments are provided. In this case, the maximum page size is returned with an offset of 0, which in most cases returns the entire query result. If theQueryResultRowCountLimitdynamic configuration has been raised above its default value, some polls may be limited to this maximum page size.All external LogScale users should switch to explicitly using query result pagination on polls.
Upgrades
Changes that may occur or be required during an upgrade.
Security
netty-bomhas been updated to version 4.2.18.Final to address CVE-2026-89044. For more information, see the official documentation here.
New features and improvements
Fleet Management
A new
Comparemode has been added to the Fleet Management Config Editor. It shows the current changes compared to the latest published configuration.
Fixed in this release
Security
An issue has been fixed where the parameter
alternativeIdpCertificatefor SAML identity provider configurations could only be provided when the parameteridpCertificatewas set, and not when the parametermetadataEndpointUrlwas provided instead. A SAML identity provider configuration is now valid as long as it specifies at least one of the following parameters:idpCertificatealternativeIdpCertificatemetadataEndpointUrl
Dashboards and Widgets
An issue has been fixed in the
Time Chartwidget that could cause duplicated data points for the same x-axis value.
Log Collector
An issue has been fixed where Falcon LogScale Collector installers were not visible to users without Fleet Management permissions in the download dialog.
Queries
An issue has been fixed where queries containing table-producing sub-queries such as
defineTable()would sometimes silently stop processing due to an error during the start of the main mapper query.
Known Issues
Storage
For clusters using secondary storage where the primary storage on some nodes in the cluster may be getting filled (that is, the storage usage on the primary disk is halfway between
PRIMARY_STORAGE_PERCENTAGEandPRIMARY_STORAGE_MAX_FILL_PERCENTAGE), those nodes may fail to transfer segments from other nodes. The failure will be indicated by the error java.nio.file.AtomicMoveNotSupportedException with message "Invalid cross-device link".This does not corrupt data or cause data loss, but will prevent the cluster from being fully healthy, and could also prevent data from reaching adequate replication.
Improvement
GraphQL API
The GraphQL mutation newFile() now supports the option to supply data for files created at the same time, and will no longer return an error when users have
createpermission but notreadpermission.The user can now supply a list of header-values, and a list-of-lists of rows of data, the length of which must match. This change is backwards compatible.
The GraphQL datatype ScheduledReport now exposes the field createdInfo, which contains structured creation metadata. Data points include author and timestamp, which is consistent with other asset types such as filter alerts, dashboards, and parsers.
The existing fields createdBy and creationDate are now deprecated and will be removed in version 1.306. Migration to the createdInfo field is recommended, as it provides richer author information (user, token, and/or system) alongside the creation timestamp.
Existing scheduled reports are automatically migrated, no action is required.
Ingestion
When a LogScale node has been unable to delete already-digested ingest records from Kafka for 30 minutes, an error is now logged with the field systemAlertId having value
IngestQueueOffsetDeletionStalled.
Queries
The maximum pipeline length allowed in a query has been doubled from 100 steps to 200 steps.
Metrics and Monitoring
The hourly organization usage logs now include additional fields per repository and per organization:
retentionDays - The time-based retention setting for the repository. When configured, the time is measured in days.
compressedStorageSize - The compressed on-disk size of live data, alongside the existing field storageSize.
falconCompressedStorageSize - The compressed size for Falcon-type repositories.
The usage job interval is now configurable using the environment variable
USAGE_JOB_INTERVAL_MINUTES. The default time interval is 60 minutes.
Auditing and Monitoring
Audit logs for query requests made using a view permissions token now include the actor.ip field, which was previously missing from these log entries.