Configuring the Threat Events Stream for Splunk via AWS S3

Jamf Protect Documentation

Solution
Application
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US

Jamf Security Cloud exports security events to an AWS S3 bucket. You must configure Splunk to access this bucket so that it can download and import the events into the SIEM infrastructure:

Note: Prior to completing the Splunk integration, contact Jamf Support to ensure the appropriate permissions are granted for your Jamf Security Cloud portal.