For macOS Security data, the base event type needs to be updated so that the correct index value is set.
This is not necessary for telemetry events.
- If you use Splunk Cloud do the following:
- Navigate to .
- Select App.
- Select Jamf Protect (TA-JamfProtect).
- Select jamf_protect.
- In the Search String field, enter: index=CORRECTINDEX sourcetype=jamf:protect:alertslogs
- Click Save.
- If you use Splunk Enterprise, do the following:
The base event type index value should now match your desired index value.