---
title: "Send messages to Falcon LogScale"
url: "https://axoflow.com/docs/axosyslog-core/4.28/chapter-destinations/crowdstrike-falcon/"
last_modified: "2026-08-05T15:08:09+02:00"
---

> For the complete documentation index, see [llms.txt](https://axoflow.com/docs/axosyslog-core/4.28/llms.txt).

# Send messages to Falcon LogScale

AxoSyslog can send messages to [Falcon LogScale](https://library.humio.com/) using its [Ingest Structured Data API](https://library.humio.com/integrations/api-ingest.html#api-ingest-structured-data). That way you don’t have to parse the data on Falcon LogScale, because AxoSyslog already sends it in a structured format that LogScale understands and can show in a structured manner as separate columns. For a tutorial on using this destination in Kubernetes, see the [From syslog-ng to LogScale: structured logs from any source](https://axoflow.com//blog/from-syslog-ng-to-logscale-structured-logs-from-any-source) blog post.

## Prerequisites

- AxoSyslog version 4.3 or later.
- Install the `axosyslog-scl` package on [Debian/Ubuntu](https://axoflow.com/docs/axosyslog-core/4.28/install/debian-ubuntu/index.md). On [RHEL and compatible distributions](https://axoflow.com/docs/axosyslog-core/4.28/install/rhel-fedora-almalinux/index.md), the SCL files are part of the `axosyslog` base package.

  Your configuration must also contain `@include "scl.conf"`, which the default configuration file already does. If the SCL files are missing, AxoSyslog fails to start with an [`unexpected LL_IDENTIFIER` error](https://axoflow.com/docs/axosyslog-core/4.28/chapter-troubleshooting-syslog-ng/unexpected-ll-identifier/index.md).

  ```shell
  @include "scl.conf"
  ```

  The `logscale()` driver is a reusable configuration snippet (SCL). For details on using or writing such configuration snippets, see [Reusing configuration blocks](https://axoflow.com/docs/axosyslog-core/4.28/chapter-configuration-file/large-configs/config-blocks/index.md). You can find its source in [scl/logscale/logscale.conf](https://github.com/axoflow/axosyslog/blob/main/scl/logscale/logscale.conf) on GitHub.
- This feature requires a separate module. Install the `axosyslog-mod-http` package on [Debian/Ubuntu](https://axoflow.com/docs/axosyslog-core/4.28/install/debian-ubuntu/index.md), or the `axosyslog-http` package on [RHEL and compatible distributions](https://axoflow.com/docs/axosyslog-core/4.28/install/rhel-fedora-almalinux/index.md). If the module isn’t installed, AxoSyslog fails to start with an [`unexpected LL_IDENTIFIER` error](https://axoflow.com/docs/axosyslog-core/4.28/chapter-troubleshooting-syslog-ng/unexpected-ll-identifier/index.md).
- Create an [Ingest token](https://library.humio.com/falcon-logscale-self-hosted/ingesting-data-tokens.html) for AxoSyslog to use in the `token()` option of the destination. This token is specific to a LogScale repository.

## Ingest Structured Data API

The `logscale()` destination feeds LogScale via the [Ingest Structured Data API](https://library.humio.com/integrations/api-ingest.html#api-ingest-structured-data).

Minimal configuration:

```sh
@include "scl.conf"
# ...

destination d_logscale {
  logscale(
    token("your-logscale-ingest-token")
  );
};
```

## Options

The following options are specific to the `logscale()` destination. But since this destination is based on the `http()` destination, you can use the [options of the `http()` destination](https://axoflow.com/docs/axosyslog-core/4.28/chapter-destinations/configuring-destinations-http-nonjava/reference-destination-http-nonjava/index.md) as well if needed.

## attributes()

|  |  |
| --- | --- |
| Type: | string |
| Default: | `"--scope rfc5424 --exclude MESSAGE --exclude DATE --leave-initial-dot"` |

*Description:* A JSON object representing key-value pairs for the LogScale Event, formatted as [AxoSyslog value-pairs](https://axoflow.com/docs/axosyslog-core/4.28/chapter-concepts/concepts-value-pairs/option-value-pairs/index.md). By default, the `logscale()` destination sends the RFC5424 fields as attributes. If you want to send different fields, override the default template.

## content-type()

|  |  |
| --- | --- |
| Type: | string |
| Default: | `"application/json"` |

*Description:* The content-type of the HTTP request.

## extra-headers()

|  |  |
| --- | --- |
| Type: | string |
| Default: |  |

*Description:* Extra headers for the HTTP request.

## rawstring()

|  |  |
| --- | --- |
| Type: | template |
| Default: | `${MESSAGE}` |

*Description:* Accepts a template that you can use to format the [LogScale event](https://library.humio.com/integrations/api-ingest.html#api-ingest-more-events).

## timestamp()

|  |  |
| --- | --- |
| Type: | template |
| Default: | `${S_ISODATE}` |

*Description:* The timestamp added to the [LogScale event](https://library.humio.com/integrations/api-ingest.html#api-ingest-more-events).

## timezone()

|  |  |
| --- | --- |
| Type: | string |
| Default: |  |

*Description:* The timezone of the event.

## url()

|  |  |
| --- | --- |
| Type: | string |
| Default: | `"https://cloud.humio.com"` |

*Description:* The URL of the LogScale Ingest API.

Last modified August 5, 2026: [Small fixes and deduplications (99cac43a)](https://github.com/axoflow/axosyslog-core-docs/commit/99cac43a517770299b97c7ed360eb87af9fef5ab)
