Skip to main content
Beacon gives Security and IT teams local endpoint visibility into supported agent harnesses. It captures supported activity, normalizes it into a stable endpoint event schema, and writes JSONL for local inspection or customer-managed forwarding. Beacon is local-only by default. The endpoint agent does not require a Beacon-hosted account, remote policy fetch, or external network dependency during normal collection. Use Asymptote Managed when you need centralized retention, search, governance, investigations, access control, or rollout support.

Rollout Path

1

Pilot

Start with a small macOS group that represents the agent harnesses and teams you want to observe. Decide which runtimes are in scope, whether events stay local at first, and which MDM group owns the initial package rollout.
2

Validate

Confirm install coverage, collector health, runtime log freshness, configured harness scope, and expected event coverage before expanding.
3

Expand

Deploy the signed and notarized macOS package through Jamf Pro, Fleet, or another MDM. Production deployments use system mode and write events to /var/log/beacon-agent/runtime.jsonl.
4

Centralize

Keep local JSONL on the endpoint, then add forwarding into your SIEM, observability stack, object storage, or customer-managed pipeline when the destination policy is approved.

Deployment Decisions

Before broad rollout, document these decisions:
DecisionWhat to define
Runtime scopeWhich supported harnesses are approved for collection and whether optional runtime integrations are in scope.
Install modeLocal evaluation, root-managed system install, or MDM package rollout.
Event destinationLocal JSONL only, Wazuh localfile, supported forwarding destination, object storage, or customer-managed pipeline.
Access and retentionWho can read local logs, how long downstream systems retain events, and which teams own review.
Managed handoffWhether the rollout now needs centralized visibility, policy controls, investigations, SSO/RBAC, or private infrastructure.

Validation Signals

Track these signals in your device-management platform or operations dashboard:
AreaRecommended signal
Install coverageBeacon package or binary version is present
Collector healthcom.beacon.endpoint.collector is running
Event freshnessLast runtime event age is within your expected window
Runtime configurationConfigured harnesses match the approved deployment scope
Forwarding readinessRuntime log exists and is writable; downstream forwarding is configured when required
For command-level checks, see Endpoint status, Endpoint discover, and Local testing.

Guides

Enterprise security review

Answer procurement and security review questions about local collection, data inventory, content handling, endpoint behavior, and disclosure policy.

MDM deployment

Plan managed macOS rollout with the packaged system agent.

Jamf

Deploy and inventory Beacon with Jamf Pro policies and extension attributes.

Fleet

Deploy Beacon with Fleet software, policies, queries, and scripts.

SIEM forwarding

Forward Beacon events to Wazuh, Splunk HEC, Falcon LogScale, Elastic, Datadog, Sumo Logic, Rapid7 InsightIDR, or a customer-managed SIEM pipeline.

Endpoint event schema

Review the normalized JSONL contract used for endpoint events.
Also review Agent harness integrations to confirm supported runtimes, deployment modes, storage paths, and forwarding boundaries.

When to Move to Managed

Open Source works well when your team wants local endpoint telemetry and controls the downstream destination. Consider Asymptote Managed when you need:
  • centralized ingest, retention, search, and detections
  • fleet-wide visibility across endpoints, users, and teams
  • policy controls, identity mapping, approvals, and investigation workflows
  • SSO, RBAC, audit trails, onboarding, and rollout support
For dedicated infrastructure, stricter data boundaries, or residency requirements, ask about Private Deployment. Contact us to discuss Managed or Private Deployment.

Boundaries

Beacon currently focuses on endpoint telemetry for supported agent harnesses and local endpoint configuration context. It does not provide kernel or process monitoring, shell history collection, cloud audit ingestion, browser or SaaS telemetry, credential-use attribution, or automatic mutation of Factory Droid shell profiles. Use Log Forwarding for supported SIEM, observability, object-storage, local JSONL, and customer-managed destinations.