security_event.v1 records to Falcon LogScale’s structured ingest
API. Each event retains its Forge identifiers, category, severity, occurrence
time, and selected detail. Humio deployments use the same API.
See Security Exports for supported categories,
filters, content detail, delivery health, and replay.
Connect LogScale
- In LogScale, select the repository that should receive Forge events and create a dedicated ingest token. An API/query token cannot replace it. Use no parser unless you intentionally want to transform the structured fields.
- Open Integrations → SIEM and exports → Falcon LogScale in Forge.
-
Enter your LogScale instance URL and ingest token. Use your deployment’s
regional URL, for example
https://cloud.us.humio.com. You may also enter the complete/api/v1/ingest/humio-structuredendpoint. - Choose event categories, minimum severity, and permitted content detail.
-
Save, send the test event, and find it in the target LogScale repository:
- Activate the destination to begin continuous delivery.
Event format
The wire payload is a JSON array of batches with constantsource=forge and
forge_schema=security_event.v1 tags. Each event’s timestamp is the UTC
occurred_at value, and its attributes contain the complete selected Forge
event. These become LogScale user fields; timestamp becomes @timestamp.
High-cardinality identifiers are attributes rather than tags.
Delivery, buffering, and deduplication
Forge batches retained source events and records a durable cursor per destination and category. A transient network failure, HTTP 408, HTTP 429, or HTTP 5xx leaves the cursor unchanged and is retried on subsequent worker polls. Other rejected HTTP responses stop delivery and require remediation. After retry exhaustion, the destination becomes unhealthy and the failure is retained in the ledger and dead letters. Other destinations and telemetry ingestion continue independently. A 2xx response marks a batch delivered: it means LogScale accepted the request, not that a search has verified indexing. The structured API has no Splunk indexer acknowledgement handshake. Verify the synthetic event in LogScale before relying on a new destination. Delivery is at least once. Forge suppresses batches already recorded as successful, but a lost response or crash after ingest acceptance can send the same records again. Replay intentionally resends matching source events with the same destination-scopedevent_id; it does not rewind live cursors. LogScale does
not receive an exactly-once key from this API. Deduplicate downstream by
event_id, for example:
source_event_id and organization_id when correlating across multiple
Forge destinations: event_id is scoped to a destination.
Buffering uses retained source data plus durable delivery state, not an unlimited
copy of every outbound payload. Default replay lookback is 90 days; available
source retention may be shorter. Replay cannot recover expired bodies. Use
retention longer than the expected outage and respond to blocked delivery promptly.
Monitoring and telemetry-loss alerts
The destination page shows status, delivered and skipped counts, per-category cursors, recent attempts, unresolved failures, and replay results. Inspect these when delivery pauses or events appear missing. Operators can load Forge’s Prometheus export alert rules into the monitoring system scraping enabled telemetry-worker replicas and route them through Alertmanager. Enable the worker’s optional internal scrape listener withSECURITY_EXPORT_METRICS_ADDRESS (for example 127.0.0.1:9091) and set
METRICS_BEARER_TOKEN. Scrape GET /metrics using Bearer authentication. Keep
this listener on the private monitoring network, and scrape maintenance replicas
that run exports, rather than the control-plane API’s process-local metrics.
The rules detect new dead letters, worker cycle errors,
and stopped polling. They apply to all export destinations, including LogScale.
Alert routing must be configured by the deployment; it is independent of the
failing SIEM destination. The delivery audit event security_export.delivery_failed
provides additional investigation context to healthy destinations that include
organization audit events. It cannot notify through a destination that is down.
After an alert: correct the endpoint or credentials, test the destination, then
resume live delivery. Recovery retains the failed batch boundaries even if new
events arrived during the outage, and resolves its delivery dead letter after
acceptance. Use replay for a bounded historical window when needed and
check any unavailable-detail counts. Skips caused by your configured filters are
intentional; dead letters indicate records or batches that require attention.
Troubleshoot
Validation without an account
The repository includes TLS receiver checks for the documented wire contract, credential safety, status handling, replay IDs, and worker persistence. They exercise Forge against an independent protocol receiver; they do not prove CrowdStrike’s hosted indexing or searches. A real ingest check is available when you have a licensed LogScale instance:LOGSCALE_URL and LOGSCALE_INGEST_TOKEN through your secret environment.
Then find the printed synthetic event_id in the selected repository.
Verify against self-hosted LogScale
CrowdStrike distributes a single-node Docker deployment for testing. It runs the actual LogScale ingest and query engine, but still requires a valid self-hosted trial or product license. The public community playground also requires a license. An open-source HTTP receiver alone cannot establish LogScale indexing or query behavior. For an isolated local Forge development environment, start the vendor demo:http://localhost:18080, install the license through the LogScale UI,
create an isolated repository and ingest token with no parser, then configure
Forge’s LogScale destination through the UI. Use Test, activate delivery, and
replay a small retained window. Search the repository for #source=forge, inspect
the v1 fields, and verify that replay retains event_id. The same search and
field checks apply to a hosted deployment.
The loopback HTTP URL and authentication-free vendor configuration are for local
validation only. Production Forge destinations require HTTPS and a public
endpoint; use the deployment’s normal authentication and TLS configuration.