Skip to main content

Documentation Index

Fetch the complete documentation index at: https://docs.asymptotelabs.ai/llms.txt

Use this file to discover all available pages before exploring further.

beacon endpoint datadog

Use beacon endpoint datadog to generate Datadog Agent custom log collection content for Beacon endpoint events. The generated pack tails Beacon’s local runtime.jsonl file with the Datadog Agent and tags events with service:beacon-endpoint-agent, source:beacon, vendor:beacon, and product:endpoint-agent. Beacon does not store Datadog API keys or site configuration. Keep Datadog credentials, site settings, and transport in the Datadog Agent or your endpoint-management secret store.
beacon endpoint datadog [command]

Commands

beacon endpoint datadog print-config

Print a Datadog Agent custom log config for the configured runtime log.

beacon endpoint datadog install-pack

Write Datadog Agent custom log integration content to a directory.

beacon endpoint datadog validate

Write and describe a Beacon Datadog validation event.

Runtime log paths

ModePath
User mode~/.beacon/endpoint/logs/runtime.jsonl
System mode/var/log/beacon-agent/runtime.jsonl

beacon endpoint datadog print-config

beacon endpoint datadog print-config prints a Datadog Agent custom log config for the configured Beacon runtime JSONL log.
beacon endpoint datadog print-config
Use this command when you want to copy the custom log configuration into an existing Datadog Agent configuration workflow.

Examples

Print config for the default per-user Beacon install:
beacon endpoint datadog print-config
Print config for a system-mode MDM deployment:
sudo /opt/beacon/bin/beacon endpoint datadog print-config --system
Print config for a custom runtime log:
beacon endpoint datadog print-config --log-path /path/to/runtime.jsonl

Flags

FlagDescription
--userUse per-user endpoint paths. Enabled by default
--systemUse system endpoint paths and launch daemon
--log-path <path>Runtime JSONL log path

beacon endpoint datadog install-pack

beacon endpoint datadog install-pack writes Datadog Agent custom log integration content to a directory.
beacon endpoint datadog install-pack --output ./beacon-datadog-pack
The pack includes Datadog Agent conf.yaml, setup instructions, and sample Beacon endpoint events.

Examples

Generate a content pack for the default per-user install:
beacon endpoint datadog install-pack --output ./beacon-datadog-pack
Generate a content pack for a system-mode deployment:
sudo /opt/beacon/bin/beacon endpoint datadog install-pack \
  --system \
  --output ./beacon-datadog-pack
Generate a content pack for a custom runtime log:
beacon endpoint datadog install-pack \
  --output ./beacon-datadog-pack \
  --log-path /path/to/runtime.jsonl

Flags

FlagDescription
--output <dir>Output directory for the Datadog content pack. Defaults to beacon-datadog-pack
--userUse per-user endpoint paths. Enabled by default
--systemUse system endpoint paths and launch daemon
--log-path <path>Runtime JSONL log path

beacon endpoint datadog validate

beacon endpoint datadog validate writes a Beacon validation event to the runtime JSONL log and prints the expected Datadog fields and validation query.
beacon endpoint datadog validate

Examples

Write a validation event for the default per-user install:
beacon endpoint datadog validate
Write a validation event for a system-mode deployment:
sudo /opt/beacon/bin/beacon endpoint datadog validate --system
Write a validation event to a custom runtime log:
beacon endpoint datadog validate --log-path /path/to/runtime.jsonl
The validation command prints a Datadog Log Explorer query:
service:beacon-endpoint-agent "Beacon endpoint datadog validation event"

Flags

FlagDescription
--userUse per-user endpoint paths. Enabled by default
--systemUse system endpoint paths and launch daemon
--log-path <path>Runtime JSONL log path

Datadog forwarding

Configure Datadog Agent custom log collection for Beacon events.

SIEM forwarding

Review forwarding patterns and validation steps.

Endpoint agent

Install and inspect the local endpoint agent.

Endpoint event schema

Review normalized Beacon JSONL fields and example events.