Migrating from Jamf Protect's Deprecated Telemetry

Jamf Protect Offline Deployment Documentation

Solution
Application
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US

To migrate your existing deprecated telemetry configurations to the latest version of telemetry you will need to recreate them as new telemetry configurations. If you are currently using the deprecated version of Jamf Protect telemetry, the following steps will help you transition to using the newest version of telemetry.

Note:

Existing deprecated telemetry configurations are still available on the Telemetry page. They include a deprecated tag in the upper-right of the card, designating the configuration as deprecated. Deprecated telemetry configurations are available for use at this time.

Requirements

Jamf recommends reviewing your existing telemetry configuration settings prior to migrating.

  1. Ensure that you are using the latest application for existing SIEM integrations.​​ If necessary, update your third-party application to the latest version.
    Jamf recommends using the third-party integration application when available, due to the ease of setup and compatibility.
    Note:

    If you use custom field mappings as part of your SIEM integration, you may need to manually update your field mappings. For more information, see the Jamf Protect Data Model Documentation​ (Learning Hub login required). ​​

  2. Navigate to Telemetry and create a new telemetry configuration for each of your existing deprecated configurations.

    Use the Telemetry Event Categories descriptions and the Jamf Protect Data Model Documentation (Learning Hub login required) to verify which logging categories to include.

  3. Create exceptions for the new telemetry configuration, if necessary.

    Exception sets for telemetry do not automatically migrate. You will need to recreate any existing exception sets for the latest version of telemetry. For more information see, Telemetry Exception Rules and Creating an Offline Deployment Mode Exception Set.

  4. Assign the new telemetry configuration and the exception set to the desired plans.
  5. Deploy the updated plans to the designated computers either manually, or by using an MDM solution.

Shortly after deploying the updated telemetry configurations, you will begin to receive the new telemetry events in your third-party SIEM.