Creating an Offline Deployment Mode Action Configuration

Jamf Protect Offline Deployment Documentation

Solution
Application
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US

Action configurations allow you to control the storage and collection of macOS Security data types.

In Offline Deployment Mode, action configurations define where unified logs and telemetry log data are sent; such as your organization's security information and event management (SIEM) solution.
Note:

The Jamf Protect Offline Deployment Mode agent does not send any data to the Jamf Protect Cloud.

Requirements

You must integrate with a SIEM or identify your remote collection endpoint information before creating an action configuration. For more information, see macOS Security Data Integrations by Vendor.

  1. In Jamf Protect, click Actions.
  2. Click Create Action at the top of the screen.
  3. Give your action configuration a name and description.
  4. Configure data endpoints by clicking + Add and selecting one of the following options:
    Jamf Protect Cloud
    Collects and stores data in the Jamf Protect Cloud. Alert data is visible directly in the macOS Security portal. To view telemetry and unified log data stored in the Jamf Protect Cloud, you must setup data forwarding.
    HTTP
    Sends data from macOS computers to an available HTTP endpoint URL from a SIEM solution.
    Log file
    Writes all data to a log file at a specified location on computers. Only one log file endpoint is allowed per action configuration.
    Syslog
    Sends data to a Syslog server, a standardized protocol for receiving messages that relies on an aggregate of various systems' messages consolidated into a centralized server for distribution. Messages typically are used for system management, monitoring, and security auditing. Syslog messages can contain a variety of log message syntax, but they usually are formatted using basic structure such as header, message severity levels, message text, and timestamp. Syslog transport protocols can use encryption.
    Kafka
    Sends data to a Kafka server, a distributed streaming platform that uses a subscriber model to listen to specific data topics from a centralized cluster. Kafka messages consist of standardized logs and can also be encoded using formats such as JSON and Avro. Messages are designed for real-time processing. Kafka provides additional durability with configurable data retention and redundancies within the cluster for persisted data. Kafka can use data encryption with x.509 certificates.
  5. Enable collection of Telemetry data to one or more data endpoints.

    For more information see Creating a Telemetry Configuration.

  6. Enable collection of Unified Logs to one or more data endpoints.

    For more information see Creating a Unified Log Filter.

  7. Click Save.
On the Actions page, the new action configuration appears in the list.
Note:

In Offline Deployment Mode, target computers do not check-in with the Jamf Protect cloud for updates. Any changes made to an action configuration, telemetry configuration, or plan will need to be manually downloaded and redeployed to the target computer.

You can now add your action configuration to a plan for deployment. See Creating an Offline Deployment Mode Plan for more information.

You can configure filters in Unified Logging. For more information, see Creating a Unified Log Filter.

You can configure telemetry data options in Telemetry. For more information, see Creating a Telemetry Configuration.