2026.10 2026.08 2026.07 2026.06 2026.05 2026.04 2026.02 2026.01
2026.10 2026.08 2026.07 2026.06 2026.05 2026.04 2026.02 2026.01

Initialize the GitHub Enterprise Beat

Prerequisites

  • System Monitor version 7.26 or higher is installed.

  • JSON Parsing is enabled. For more information, refer to Configure Beats for JSON Parsing.

  • The following port is open:

Direction

Port

Protocol

Source

Outbound

443

HTTPS

githubbeat

Initialize the Beat via the Web Console (Recommended)

  1. Ensure that the Open Collector Connection to the SIEM (WebUI) setup has been completed.

  2. Ensure that the System Monitor Agent to which you intend to send these logs has been Configured for JSON Parsing.

Use either the Enable JSON Parsing on System Monitor Agents or the Enable JSON Parsing for an Existing System Monitor Agent sections at the above link to configure the System Monitor Agent for JSON Parsing.

  1. Follow the steps outlined in Add a Beat in the Web Console to create the Beat via the Web UI.

Initialize the Beat via Command Line (Legacy)

  1. In the Open Collector, run the following command:

    ./lrctl githubbeat start
    
  2. Enter a unique Beat identifier (name).

  3. Enter the hostname of your GitHub Enterprise instance.
    For example, http://api.github.com (pre populated by default).

If you access GitHub at http://GHE.com, replace http://api.github.com with your enterprise's subdomain at api.SUBDOMAIN.ghe.com.

For more information, see REST API endpoints for enterprise audit logs in the GitHub documentation.

  1. Enter the GitHub enterprise name (slug) from which audit logs will be collected.

  2. Enter Personal Access Token obtained during the steps outlined in Configure GitHub Enterprise.

  3. Select the event type for which you want the collector to fetch data: WEB for web events, GIT for Git events, or ALL for both.

  4. Specify the GitHub audit log filter conditions to include or exclude events.
    For example, operation:access, and repo:my-org/our-repo.
    You can add multiple filters by adding a space.

The query filters that search based on time of action (time at which actions occurred) are not supported. For more information, see Searching the audit log in the GitHub documentation.

  1. Enter the number of records/logs to fetch per http request, between 30 and 100.
    The default its 100.

  2. Enter number of back days data to fech, between 0 and 7.
    The default its 0.

  3. Enter the polling interval, the time period between subsequent call, between 60s and 86400s.
    The default its 60s.

  4. Enter the hostname or IP address of the System Monitor Agent that has been Configured for JSON Parsing, and then press Enter.

Use either the Enable JSON Parsing on System Monitor Agents or the Enable JSON Parsing for an Existing System Monitor Agent sections at the above link to configure the System Monitor Agent for JSON Parsing.

  1. Enter the port on which the System Monitor Agent is configured to listen for JSON data (the default is 5044), and then press Enter.
    The githubbeat service started message appears.

  2. Check the status of the service to confirm that it’s running:

    ./lrctl githubbeat status
    
  3. (Optional) Edit the GitHub Enterprise Beat configuration to update the values set above if needed.
    Ensure that you have all the needed information for each step available as you will need to re-enter it:

    ./lrctl githubbeat config edit