Jamf Protect Event Collector
Use this integration to fetch audit logs events, alerts events and computer assets from Jamf Protect to Cortex XSIAM.
- Category
- Analytics & SIEM
- Pack
- JamfProtect
Configuration parameters
- base_url — Server URL (e.g., https://example.protect.jamfcloud.com) (required)
- insecure — Trust any certificate (not secure)
- proxy — Use system proxy settings
- client — Client ID (required)
- max_fetch_alerts — Max alert events per fetch
- max_fetch_audits — Max audit events per fetch
- assetsFetchInterval — Fetch Computer Assets Interval
- isFetchEvents — Fetch Events
- isFetchAssets — Fetch Assets
Commands (2)
- jamf-protect-get-computer-assets — Gets computer assets from Jamf Protect.
- jamf-protect-get-events — Gets events from Jamf Protect.