Before you start
- Linux endpoints running rsyslog 8, the default on Ubuntu, Debian, RHEL, Rocky, and Alma.
- A collector that accepts syslog over TCP, and its hostname and port.
1. Install Beacon on each endpoint
Run the block for your distribution. It downloads the latest package for the endpoint’s architecture, checks it against the published checksums, and installs it.running=true and telemetry=enabled mean Beacon is recording. It writes one JSON object per line to /var/log/beacon-agent/runtime.jsonl. See Linux install for what the package sets up.
2. Configure the collector
The collector has to accept syslog over TCP and messages up to 128 KB. If it is rsyslog, add this to its configuration and restart it:/etc/rsyslog.d/10-beacon-input.conf on the collector
3. Add the forwarding file to each endpoint
Save this as/etc/rsyslog.d/60-beacon.conf, replacing collector.example.internal and 514 with your collector’s hostname and TCP port:
/etc/rsyslog.d/60-beacon.conf
- Reads Beacon’s log and keeps up with it when Beacon rotates it.
- Sends only Beacon’s events, each tagged
beacon, over their own TCP connection. They do not go to/var/log/syslogor to your existing forwarding. - Queues events on disk, up to 1 GB, while the collector is unreachable, and sends them when it comes back.
rsyslogd -N1 should end with End of config validation run and print no errors. If it reports one of these, your rsyslog configuration already has the setting:
Deploy with Salt
The file is the same on every endpoint, so Salt only needs to place it and restart rsyslog when it changes:beacon/rsyslog.sls
4. Confirm events arrive
On an endpoint, write a test event:beacon. Its body is one JSON event whose message field is Beacon endpoint pipeline validation event. Search your collector or SIEM for that text.
The first time rsyslog starts with this file, it also sends the events already in the log. After that it sends only new ones.
What gets sent
Each message is one Beacon event, unchanged, as a single line of JSON. Events can include prompt text, commands the agent ran, file paths, and tool input, after Beacon’s redaction and its 64 KB per-event limit. See Retention and redaction to control what Beacon keeps, and the event schema for the fields. rsyslog sends the events with facilitylocal0 and severity notice. To change them, add Facility="..." and Severity="..." to the input(...) block.
If events do not arrive
- Run
sudo rsyslogd -N1again and fix any error it prints. - Check
sudo journalctl -u rsyslogfor connection errors, and that the endpoint can reach the collector’s TCP port. - On RHEL-family endpoints with SELinux enforcing, rsyslog may be denied the collector’s port. If the audit log shows a denial, allow the port with
sudo semanage port -a -t syslogd_port_t -p tcp <port>. - If large events arrive cut off, raise the collector’s maximum message size to 128 KB.
Related
Linux install
What the package installs and how the service runs.
Microsoft Sentinel
Build Sentinel tables and queries for Beacon events.