In the macOS Security portal, use your HTTP log source address from Sumo Logic as data endpoints for each macOS Security data type you want to collect.
Requirements
The HTTP log source URL from your Sumo Logic event collector. For more information, see Creating an HTTP Event Source for macOS Security Data in Sumo Logic.
- In Jamf Protect, click Actions.
- Click Edit on an existing action configuration or click Create Action to create a new one.
- For each macOS Security data type, add a new data endpoint:
- In Data Endpoints, click + Add.
- Select HTTP.
- In URL, enter the previously generated HTTP source address.
- From Alerts, select the level of alerts want to collect.
- From Logs, select the data types you want to collect.
- In Data Endpoints, click + Add.
- Select HTTP as your endpoint configuration.
- Click Save.
The action configuration is updated and available to add to Jamf Protect plans in the macOS Security portal.