Lesson 14: Jamf Security Cloud Reports - Jamf 170 Course

Jamf 170 Course

Solution
Application
Content Type
Training Content
Utilities & Services
ft:locale
en-US

Goal

View and export security reports in the Jamf Security Cloud portal.

Video

Key points

  • Security reports are located under Reports > Security in the Jamf Security Cloud portal.

  • There are six security reports which can be used to gain insight into an organization's most common vulnerabilities:

    • The threat view report lists individual threats identified on impacted devices.

    • The device view report lists devices with one or more identified threats or vulnerabilities.

    • The vulnerability management report indicates an organization's threat risk score and vulnerabilities impacting the organization's risk profile.

    • The app insights report lists apps installed on user devices and reports them based on their risk score to the organization.

    • MI:RIAM analytics is Jamf's machine learning and mobile threat intelligence engine that analyzes information gathered online to identify threats and provides discovered analytical data back to administrators.

    • The event log is a chronological timeline of threats that devices have encountered across the organization.

  • MI:RIAM, which stands for Machine Intelligence: Real-time Insights and Analytics Machine, performs the following functions:

    • Identifies and evaluates network risks in real time

    • Uses app data collected from multiple sources to assign an app risk score

  • The event log report can be exported as a CSV file.

  • Data streams allow Jamf Security Cloud event log data to be automatically exported to a security information and event management (SIEM) solution.

Review

To view answers, click arrow next to each question.

  1. Device view
  2. App insights
  3. CSV

Practice

  1. View the devices impacted by an open threat.

    1. Navigate to Reports > Security > Threat view.

    2. Select an open threat category.

    3. Click the + icon next to the severity level to view impacted devices.

  2. Find more information about a specific vulnerability.

    1. Navigate to Reports > Security > Vulnerability management.

    2. Select the Vulnerabilities tab.

    3. Click the + icon next to a vulnerability to view more information about it.

  3. Export the event log from the past month.

    1. Navigate to Reports > Security > Event log.

    2. Click the vertical ellipsis button in the top right of the table and choose Create export.

    3. Change the Date Range to include the past month then click Save.

    4. Click the Report exports button in the top right of the page and select Ready to download for the newly-generated report.

Resources

Jamf Protect Documentation