(Deprecated) Creating a Telemetry Configuration

Jamf Protect Offline Deployment Documentation

Solution
Application
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US
Important:

Jamf's first version of telemetry for macOS is deprecated and will be removed in a future release of Jamf Protect. Jamf recommends using the the latest version of the telemetry for macOS capability. For more information about the latest version of telemetry for macOS, see the following:

You can create telemetry configurations to control the telemetry data that Jamf Protect collects.

  1. In Jamf Protect, click Telemetry.
  2. Click Create Telemetry.
  3. Enter a name for the telemetry configuration in the Name field.
  4. (Optional) Enable Performance metrics to include information pertaining to the use of system resources by processes and applications.
    Note:

    The com.jamf.protect.security-extension process is always included in the performance metrics.

  5. Choose a level from the Telemetry Log Levels.

    This setting defines how much telemetry data Jamf Protect collects on computers and sends to your security information and event management (SIEM) solution.

    Best Practice:

    Jamf recommends level 1 for most computers.

  6. (Optional) Select the Activate Verbose Logging checkbox to collect log data from both administrative and non-administrative activity.

    When deselected, Jamf Protect only collects log data from administrative activity.

    Note:

    Telemetry logs will report data from potentially suspicious activity by default, regardless of whether Activate Verbose Logging is enabled.

  7. (Optional) Select Collect Diagnostic and Crash Files to enable collection of specific diagnostic and crash log files.

    When this feature is first enabled, Jamf Protect collects one report from each application right away, then uses Apple's Endpoint Security Framework to continuously monitor for any new files from your applications to your SIEM.

    See Telemetry Diagnostic and Crash File Collection for more information about diagnostic and crash file collection.

    Note:

    Versions below macOS 13 monitor for new diagnostic and crash files every ten minutes.

  8. (Optional) In the Simple log file collection field, add additional file paths to log files that you want to collect from computers.

    You can add multiple log files. When telemetry is first enabled, Jamf Protect collects all specified log files and then continuously streams any new lines in the log file to your SIEM every minute.

  9. Click Save.
The telemetry configuration is available for deployment via a Jamf Protect plan.

To configure where telemetry data on computers is collected, configure an action configuration.

To add a telemetry configuration to a plan for deployment, go to the Plans page, create or edit a plan, and then choose the telemetry configuration from the Telemetry pop-up menu.