Falcon LogScale 1.261.0 GA (2026-10-06)

Version?Type?Release Date?Availability?End of SupportSecurity UpdatesUpgrades From?Downgrades To?Config. Changes?
1.261.0GA2026-10-06

Cloud

Next LTSNo1.177.01.177.0No

Hide file download links

Show file download links

Bug fixes and updates

Advance Warning

The following items are due to change in a future release.

Deprecation

Items that have been deprecated and may be removed in a future release.

  • The GraphQL field meta has been deprecated and now requires authentication. It will be completely removed in LogScale 1.304. To achieve similar results, use the loginInfo and clusterConfig fields instead.

    To temporarily opt out of the authentication requirement, the feature flag UnauthenticatedMeta can be enabled.

  • The userId parameter for the updateDashboardToken GraphQL mutation has been deprecated and will be removed in version 1.273.

Upgrades

Changes that may occur or be required during an upgrade.

  • Security

    • The following Scala 3 for Circe Core artifacts have been updated to version 0.4.16 to address known CVEs:

      • io.circe:circe-core_3

      • io.circe:circe-parser_3

      The following FasterXML Jackson BOM has been updated to 2.22.3 to address known CVEs:

      • com.fasterxml.jackson:jackson-bom to version 2.22.3

New features and improvements

  • Storage

    • A new periodic log line job has been added that reports storage usage broken down by bucket storage entity. For each configured bucket, the job logs the compressed and uncompressed size of segments, segment count, and identifying fields including provider, region, bucket, orgId, keyPrefix, and readOnly. The job interval is configurable using the environment variable BUCKET_STORAGE_SIZE_LOGGER_INTERVAL_MINUTES, which has a default value of 60 minutes.

      The job is enabled by default. To disable it, set the environment variable BUCKET_STORAGE_SIZE_LOGGER_ENABLED to false.

  • Queries

    • Zone-aware query mapper pools have been introduced to improve search locality by routing work for specific segments to specific NUMA nodes (more specifically, L3 cache zones).

      The new behavior is controlled by the feature flag ZoneAwareMapperPool, which is disabled by default. When enabled, query work for a segment routes to a zone based on segment ID hashing. When disabled, LogScale will set a fixed number of dedicated threads for query work on startup, which cannot be changed at runtime, and segment submission ignores the segment ID while routing to the least occupied pool.

      To disable zone discovery, the environment variable QUERY_EXECUTOR_ZONE_SPLIT_FACTOR should be set to -1. This reverts to a single thread pool. Users can also use this variable to further split discovered zones. For example, setting it to -2 splits each discovered zone into two pools.

Fixed in this release

  • Storage

    • The cleanup process after unregistering a node could be slow, causing missing merged segments created by that node to not be remerged. This caused the cluster to report large delays in bucket storage upload. This issue has now been fixed.

  • Ingestion

    • An issue has been fixed where table widgets on the Data Ingest Insights page retained their pagination position after running a new query in the editor.

  • Queries

    • The computed filter query behind the Source Events tab could sometimes be invalid when using multiple calls of the defineTable() function. This issue has now been fixed.

    • An issue has been fixed where cached live query results with ad-hoc dependences such as defineTable() or remoteTable() could be incorrectly reused for a new live query that different only in the query string of an ad-hoc subquery, causing the incorrect result to be returned.

    • An issue has been fixed where live queries referencing externally managed assets across views would not receive updated assets when those assets changed. Now when users reference externally managed assets across views, parsers correctly recompile and use updated assets without user intervention.

    • An issue has been fixed where the query scheduler could be blocked waiting for query state merging to complete.

  • Functions

    • Tables created using the defineTable() function with the parameter include set to * would be invalidated when a field was added as both a tag and a regular field on an event. The columns of the table would be created with different lengths, causing the query to stop or causing values from previous rows to appear in later rows. This issue has now been fixed.

    • The function readPersistedAggregation() could incorrectly rename or drop a result field that had a naming convention with the prefix @ and the suffix .original, for example @foo.original. This issue has now been fixed.

Known Issues

  • Storage

    • For clusters using secondary storage where the primary storage on some nodes in the cluster may be getting filled (that is, the storage usage on the primary disk is halfway between PRIMARY_STORAGE_PERCENTAGE and PRIMARY_STORAGE_MAX_FILL_PERCENTAGE), those nodes may fail to transfer segments from other nodes. The failure will be indicated by the error java.nio.file.AtomicMoveNotSupportedException with message "Invalid cross-device link".

      This does not corrupt data or cause data loss, but will prevent the cluster from being fully healthy, and could also prevent data from reaching adequate replication.

Improvement

  • GraphQL API

    • The GraphQL datatype ScheduledReport now exposes the field createdInfo, which contains structured creation metadata. Data points include author and timestamp, which is consistent with other asset types such as filter alerts, dashboards, and parsers.

      The existing fields createdBy and creationDate are now deprecated and will be removed in version 1.306. Migration to the createdInfo field is recommended, as it provides richer author information (user, token, and/or system) alongside the creation timestamp.

      Existing scheduled reports are automatically migrated, no action is required.

  • Ingestion

    • When deleting digested records from Kafka, digest nodes now only request information for the partitions currently being consumed, rather than all partitions. This reduces unnecessary network overhead during record deletion.

  • Log Collector

    • Introduced exponential backoff for Log Collector instances that download artifacts excessively. Backoff is capped at 6 hours.

  • Queries

    • LogScale now emits warnings for zero-width implicit AND* operations. For example, a query like foo"bar" (interpreted as foo AND "bar") now produces a warning that explains the interpretation and suggests using an explicit AND operation, or adding whitespace between the terms.

  • Fleet Management

    • When publishing a configuration containing validation errors, a warning now appears informing users of the errors, and requires explicit confirmation before proceeding.

  • Metrics and Monitoring

    • A periodic background job has been added that logs native memory allocator statistics to the non-sensitive log. The job auto-detects whether the process uses jemalloc or glibc malloc and collects the appropriate metrics. On platforms where neither allocator is available, no result is provided.

      To search for these statistics, use #kind=nonsensitive | name="native_malloc".