Creating a Telemetry Configuration

Jamf Protect Offline Deployment Documentation

Solution
Application
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US

You can create telemetry configurations to control the host device activity which monitors and reports telemetry data for Jamf Protect.

Note:

This topic describes configuring the latest version of telemetry, which uses the macOS Endpoint Security API for system event monitoring. Jamf recommends the latest version of telemetry for most users. For more information about migrating from deprecated telemetry to the latest version of telemetry, see Migrating from Jamf Protect's Deprecated Telemetry.

  1. In Jamf Protect, click Telemetry.
  2. Click Create Telemetry.
  3. In the General section, enter a name and description for the telemetry configuration.
  4. In the Logging section, select the event categories to include in the telemetry configuration.

    For more information about the different event categories, see Telemetry Event Categories.

    Note:

    Additional requirements must be met to use network logging in telemetry configurations. For more information, see Configuring Network Telemetry.

  5. (Optional) In the Advanced logging section, select the File hashes checkbox to enable computation and reporting of file hashes for process executable files in telemetry events. This provides additional information for security investigations and tracking unique executables present in your environment.
  6. (Optional) In the Simple log file collection section, click + Add log file to add additional file paths to log files that you want to collect from computers.

    You can add multiple log files. When telemetry is first enabled, Jamf Protect collects all specified log files and then continuously streams any new lines in the log file to your SIEM every minute.

  7. Click Save.

The telemetry configuration is available for deployment via a Jamf Protect plan.

To add a telemetry configuration to a plan for deployment, go to the Plans page, create or edit a plan, and choose the telemetry configuration from the Telemetry pop-up menu.

To configure where telemetry data on computers is collected, configure an action configuration. For more information, see Creating an Offline Deployment Mode Action Configuration.