Jamf Protect's telemetry for macOS collects system and user event log data and sends it to a security information and event management (SIEM) solution. Telemetry log data helps administrators and information security specialists proactively monitor and detect threats on macOS computers in their environments. Telemetry log data also assists with investigating user activities or malicious events by providing context for the various events that occur on each device. Telemetry data is sent to your configured data collection options in JSON format.
With an action configuration, you must configure one or more data endpoints to send telemetry data to.
With exception sets, you can the add the Ignore for Telemetry rule to exclude certain processes or events from telemetry data. This ensures the telemetry log volume in your environment is limited to an acceptable range.