Command Overview
beacon rules fields prints the endpoint event fields that threat-rule CEL expressions can match on.
Command syntax
CEL field paths
Threat-rule expressions bind each Beacon event ase. Field paths mirror the event JSON shape, such as:
Examples
Print the field list:List rule fields
Render fields as markdown
Flags
Related
beacon rules lint
Validate CEL expressions and embedded fixtures.
Endpoint Event Schema
Review normalized Beacon endpoint events.

