Using Syslog for Log Files

Jamf Protect Offline Deployment Documentation

Solution
Application
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US
  1. In Jamf Protect, navigate to Actions > Data Endpoints and click + Add.
  2. Select Syslog and click + Add.
  3. Configure your syslog endpoint.
    1. In the Host field, enter the syslog endpoint hostname or IP address to send log data to.

      For example, syslog.jamf.com or 192.0.2.1.

    2. In the Port field, enter the port number for your syslog endpoint that corresponds to its transport protocol. The default value changes depending on your protocol selection.

      Consult with your administrator to select the appropriate port for your syslog transport.

    3. Select the communication Protocol used by the syslog endpoint for transmitting log messages.
      Log delivery between server and client relies on a communication protocol, and should be chosen on the basis of the needs of your organization. Consult with your administrator to select the appropriate transport protocol for your syslog messages.
      Transport Layer Security (TLS) (default)
      Delivery using TCP messaging with added encryption to validate server recipients and prevent interception from third parties. TLS requires certificates for authentication, which requires additional resources. TLS maintains verification and resubmit methods used by TCP. TLS is best used over public internet connections.
      Transmission Control Protocol (TCP)
      Delivery using a reliable log transport delivered in sequential order without loss due to network connectivity with verification and resubmit methods. TCP does not utilize any transport security by default which requires less resource use. TCP is best used over private networks.
  4. Select if you want to send Telemetry and Unified Logs to the syslog server.
  5. Click Save.