Jamf Protect Event Collector
Use this integration to fetch audit logs events, alerts events and computer assets from Jamf Protect to Cortex XSIAM.
Analytics & SIEM · JamfProtect
Details
| ID | Jamf Protect Event Collector |
|---|---|
| Provider | Jamf |
| Category | Analytics & SIEM |
| From Version | 6.9.0 |
| Docker Image | demisto/python3:3.12.13.10116658 |
| Supported Modules | XSIAM |
README
Use this integration to fetch audit logs events, alerts events and computers assets from Jamf Protect to Cortex XSIAM.
Configure Jamf Protect Event Collector in Cortex
| Parameter | Description | Required |
|---|---|---|
| Server URL (e.g., https://example.protect.jamfcloud.com) | REST API Endpoint of Jamf Protect server. | True |
| Trust any certificate (not secure) | False | |
| Use system proxy settings | False | |
| Client ID | The unique identifier for the client application, provided by Jamf when the application is registered. This is used to authenticate the client with the Jamf Protect server. | True |
| Password | The password for the client application. This is used to authenticate the client with the Jamf Protect server. | True |
| Max alert events per fetch | Maximum number of alert events to fetch at a time. Default is 1000 | False |
| Max audit events per fetch | Maximum number of audit events to fetch at a time. Default is 20,000 | False |
| Fetch Computer Assets Interval | The fetch interval. It is recommended to set it to 12 hours. The minimum interval is 1 hour. | False |
Commands
You can execute these commands from the CLI, as part of an automation, or in a playbook.
After you successfully execute a command, a DBot message appears in the War Room with the command details.
jamf-protect-get-events
Gets events from Jamf Protect.
Base Command
jamf-protect-get-events
Input
| Argument Name | Description | Required |
|---|---|---|
| limit | The number of events to return. Default is 10. | Optional |
| start_date | The start date from which to filter events. | Optional |
| end_date | The end date to which to filter events. | Optional |
| should_push_events | Set this argument to True in order to create events, otherwise the command will only display them. Possible values are: true, false. Default is false. | Optional |
Context Output
There is no context output for this command.
jamf-protect-get-computer-assets
Gets computer assets from Jamf Protect.
Base Command
jamf-protect-get-computer-assets
Input
| Argument Name | Description | Required |
|---|---|---|
| limit | The number of computer assets to return. Default is 10. | Optional |
Context Output
There is no context output for this command.
Configuration parameters
base_url— Server URL (e.g., https://example.protect.jamfcloud.com) (required)insecure— Trust any certificate (not secure)proxy— Use system proxy settingsclient— Client ID (required)max_fetch_alerts— Max alert events per fetchmax_fetch_audits— Max audit events per fetchassetsFetchInterval— Fetch Computer Assets IntervalisFetchEvents— Fetch EventsisFetchAssets— Fetch Assets
Commands (2)
-
jamf-protect-get-computer-assetsGets computer assets from Jamf Protect.
-
jamf-protect-get-eventsGets events from Jamf Protect.
## Jamf Protect Event Collector Use this integration to fetch audit logs, alerts events and computer assets from Jamf Protect to Cortex XSIAM. To fetch computer assets, enable the *Fetch assets and vulnerabilities* option. To retrieve audit logs and alert events, enable the *Fetch events*option. Computer assets dataset name: **jamf_protect_computers_raw** Events dataset name: **jamf_protect_raw** ## Creating an API Client in Jamf Protect Before you configure the integration, retrieve the API Client and Password from your Jamf Protect environment: 1. In Jamf Protect, click **Administrative** > **API Clients**. 2. Click **Create API Client**. 3. Enter a name for your API client. 4. Assign the Full Access role to the API client. 5. Copy the API client password for later use. Your API client configuration and endpoint information displays. 6. Copy the API client and password into the integration configuration. # Notes: You can assign a custom role that limits permissions by editing the API client. The minimum required permissions are: - Read access Computers. - Read access Alert endpoints. - Read access Audit Logs. - Read access Compliance. - Read access Plans. For more information refer to Jamf Protect [Documentation](https://learn.jamf.com/en-US/bundle/jamf-protect-documentation/page/Jamf_Protect_API.html).