Documentation Index
Fetch the complete documentation index at: https://docs.asymptotelabs.ai/llms.txt
Use this file to discover all available pages before exploring further.
Wazuh
Beacon writes JSONL endpoint events that Wazuh can ingest from the local runtime log. Use the Beacon Wazuh commands to print localfile configuration, generate rules, and write validation events.Runtime log paths
| Mode | Runtime log |
|---|---|
| User mode | ~/.beacon/endpoint/logs/runtime.jsonl |
| System mode | /var/log/beacon-agent/runtime.jsonl |
Configure Wazuh localfile
Print the localfile snippet for a system deployment:--log-path:
Generate Wazuh content
Generate a content pack when you want file-based rules, config snippets, and sample content:Validate ingestion
Write a known-good validation event to the runtime log:Related
Wazuh command reference
Review Beacon Wazuh commands and flags.
Endpoint event schema
Review normalized Beacon JSONL fields and example events.

