Jamf Protect Event Collector

Use this integration to fetch audit logs events, alerts events and computer assets from Jamf Protect to Cortex XSIAM.

Analytics & SIEM · JamfProtect

Details

IDJamf Protect Event Collector
ProviderJamf
CategoryAnalytics & SIEM
From Version6.9.0
Docker Imagedemisto/python3:3.12.13.10116658
Supported ModulesXSIAM

README

Use this integration to fetch audit logs events, alerts events and computers assets from Jamf Protect to Cortex XSIAM.

Configure Jamf Protect Event Collector in Cortex

Parameter Description Required
Server URL (e.g., https://example.protect.jamfcloud.com) REST API Endpoint of Jamf Protect server. True
Trust any certificate (not secure)   False
Use system proxy settings   False
Client ID The unique identifier for the client application, provided by Jamf when the application is registered. This is used to authenticate the client with the Jamf Protect server. True
Password The password for the client application. This is used to authenticate the client with the Jamf Protect server. True
Max alert events per fetch Maximum number of alert events to fetch at a time. Default is 1000 False
Max audit events per fetch Maximum number of audit events to fetch at a time. Default is 20,000 False
Fetch Computer Assets Interval The fetch interval. It is recommended to set it to 12 hours. The minimum interval is 1 hour. False

Commands

You can execute these commands from the CLI, as part of an automation, or in a playbook.
After you successfully execute a command, a DBot message appears in the War Room with the command details.

jamf-protect-get-events


Gets events from Jamf Protect.

Base Command

jamf-protect-get-events

Input

Argument Name Description Required
limit The number of events to return. Default is 10. Optional
start_date The start date from which to filter events. Optional
end_date The end date to which to filter events. Optional
should_push_events Set this argument to True in order to create events, otherwise the command will only display them. Possible values are: true, false. Default is false. Optional

Context Output

There is no context output for this command.

jamf-protect-get-computer-assets


Gets computer assets from Jamf Protect.

Base Command

jamf-protect-get-computer-assets

Input

Argument Name Description Required
limit The number of computer assets to return. Default is 10. Optional

Context Output

There is no context output for this command.

Configuration parameters

  • base_url — Server URL (e.g., https://example.protect.jamfcloud.com) (required)
  • insecure — Trust any certificate (not secure)
  • proxy — Use system proxy settings
  • client — Client ID (required)
  • max_fetch_alerts — Max alert events per fetch
  • max_fetch_audits — Max audit events per fetch
  • assetsFetchInterval — Fetch Computer Assets Interval
  • isFetchEvents — Fetch Events
  • isFetchAssets — Fetch Assets

Commands (2)

  • jamf-protect-get-computer-assets

    Gets computer assets from Jamf Protect.

  • jamf-protect-get-events

    Gets events from Jamf Protect.


## Jamf Protect Event Collector

Use this integration to fetch audit logs, alerts events and computer assets from Jamf Protect to Cortex XSIAM.

To fetch computer assets, enable the *Fetch assets and vulnerabilities* option. To retrieve audit logs and alert events, enable the *Fetch events*option.

Computer assets dataset name: **jamf_protect_computers_raw**
Events dataset name: **jamf_protect_raw**

## Creating an API Client in Jamf Protect
Before you configure the integration, retrieve the API Client and Password from your Jamf Protect environment:
1. In Jamf Protect, click **Administrative** > **API Clients**.
2. Click **Create API Client**.
3. Enter a name for your API client.
4. Assign the Full Access role to the API client.
5. Copy the API client password for later use.
    Your API client configuration and endpoint information displays.
6. Copy the API client and password into the integration configuration.

# Notes:
    You can assign a custom role that limits permissions by editing the API client.
    The minimum required permissions are:
    - Read access Computers.
    - Read access Alert endpoints.
    - Read access Audit Logs.
    - Read access Compliance.
    - Read access Plans.
For more information refer to Jamf Protect [Documentation](https://learn.jamf.com/en-US/bundle/jamf-protect-documentation/page/Jamf_Protect_API.html).