Creating an Ingestion Feed in Google SecOps Using a Webhook

Jamf Protect Documentation

Solution
Application
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US

You can send macOS Security data to Google SecOps by creating an ingestion feed that uses a webhook.

Requirements
Important:

Batches of data sent through webhook feeds may experience ingestion delays if the request size or QPS limits are set too low. When calling the HTTPS push endpoint, the maximum request size is 4MB, and the maximum QPS is 15K.

When the feed is is created, make sure you copy these values for use with an action configuration in the macOS Security portal:

  • Secret key

  • Feed endpoint URL

  • API key