(Deprecated) Telemetry Log Levels

Jamf Protect Offline Deployment Documentation

Solution
Application
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US
Important:

Jamf's first version of telemetry for macOS is deprecated and will be removed in a future release of Jamf Protect. Jamf recommends using the the latest version of the telemetry for macOS capability. For more information about the latest version of telemetry for macOS, see the following:

Use audit log levels to configure the amount of telemetry data collected. Telemetry has two levels: Level 1 (Standard) and Level 2 (Increased Risk). Level 1 auditing is appropriate for most computers, while level 2 is a good choice for computers that require more detailed auditing. Both audit levels are dependent on the Activate Verbose Logging option available when creating a telemetry configuration. When verbose logging is active, activity from both administrative, and non-administrative users is collected.

Note:

Jamf recommends level 1 for most computers.

If you are unsure about what level of auditing to assign, or whether to enable verbose logging, you can configure a plan with the minimum settings (Level 1 and no verbose logging) and evaluate the data received to see if it meets your needs. If you find that you need more detailed data, activate verbose logging and recheck the data to ensure it is sufficient. You can experiment with the different log levels and verbosity to find the correct settings that meet your needs in the most efficient way.

Level 1 - StandardLevel 2 - Increased Risk
  • Login events

    • Login window and screensaver
    • SSH, screen sharing, and Apple Remote Desktop
    • File sharing and any other service that requires a local account
  • Authorization and system events by users or processes

  • User and group creation and changes

  • Application and user exclusions

  • Hardware change events

  • System operation events

    • Mounting external or network drives

    • Computer reboots, shutdowns, and macOS updates

    • Basic input/output system (BIOS) and universal extensible firmware interface (UEFI) events

  • External drive and volume events

  • Jamf Protect tamper events

  • Network and firewall changes

  • Application process executions and security actions by applications

  • Terminal and shell script activity

    • Commands executed by the root, administrator, impersonated user

    • Root or administrator shell script commands

  • Processes listening for network connections

    • All connections from outside computers

    • localhost is ignored

  • Incoming network connections

  • Built-in Apple security events

    • Gatekeeper evaluations and overrides

    • XProtect evaluations and updates

Best suited for computers that handle sensitive information on a regular basis.

In addition to all data collected in level 1, level 2 collects:

  • Outgoing user network connections

  • System-level outgoing network connections