Skip to main content

Command Overview

beacon endpoint test-event writes a synthetic validation event to the Beacon runtime JSONL log.
Command syntax
Use a test event to validate local write permissions and downstream file-tail pipelines before relying on real agent activity. The command checks that the configured runtime log is writable, appends a known-good Beacon endpoint event, and reports the validation stages. beacon endpoint validate-pipeline is an alias. For destination-specific validation guidance, use the SIEM commands such as beacon endpoint wazuh validate, beacon endpoint datadog validate, beacon endpoint sumo validate, or beacon endpoint rapid7 validate.

Flags

Examples

Write a validation event to the default per-user runtime log:
Write a validation event to the default per-user runtime log
Validate a custom runtime log:
Validate a custom runtime log
Print validation stages as JSON:
Print validation stages as JSON
Use the pipeline-validation alias:
Use the pipeline-validation alias
Validate a system-mode runtime log:
Validate a system-mode runtime log

Endpoint status

Inspect endpoint health and last-event state.

Log forwarding

Forward Beacon runtime JSONL to customer-managed destinations.