Requirements
Jamf recommends testing telemetry with a small selection of computers, prior to deploying it at a wider-scale.
- Configure your SIEM integration with Jamf Protect.
- Create a telemetry configuration and assign the categories and log files to monitor.
- Assign the telemetry configuration to one or more plans and deploy the plans to the target computers.
- Review the data and logs collected by telemetry in your SIEM. Identify what data you find useful and relevant, versus data that is excessive or unnecessary.
- If necessary, implement exception sets to help streamline telemetry data collected and reduce the amount of noise or unnecessary data.
Continue to monitor the telemetry data for your environment to ensure that the exceptions are correctly filtering the desired information.