Falcon LogScale
Falcon LogScale is a cloud-based SIEM and log management solution that helps organizations collect, store, and analyze large volumes of log data from a wide range of sources. It provides real-time visibility into IT infrastructure and applications, enabling security teams to quickly detect and respond to threats.
Creating a Falcon LogScale connection
Using API Token
To create the connection you need:
- An API Address
- A Token
Obtaining the credentials
On your Falcon LogScale platform, go to your personal settings and generate a personal API key.
Creating your connection
- In the Blink platform, navigate to the Connections page > Add connection. A New Connection dialog box opens displaying icons of external service providers available.
- Select the Falcon LogScale icon. A dialog box with name of the connection and connection methods appear.
- (Optional) Edit the name of the connection. At a later stage you cannot edit the name.
- Select API Token as the method to create the connection.
- Fill in the parameters:
- The API Address
- The Token
- (Optional) Click Test Connection to test it.
- Click Create connection. The new connection appears on the Connections page.