Requirements
To access unified log filter data collected by Jamf Protect, you must do one of the following:
Collect unified logs in a local log file
Send unified logs to a Kafka broker
Send unified logs to a syslog server
Integrate Jamf Protect with a security information and events management (SIEM) solution.
For more information, see macOS Security Data Integrations by Vendor.
All computers will now send logs that match your filter to your security information and event management (SIEM) solution, or a local log file depending on your action configuration.