Configuring a Data Stream in Jamf Security Cloud - Jamf Security Cloud Portal Setup Guide

Jamf Security Cloud Portal Setup Guide

Solution
Application
Jamf Connect
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US

Use a Jamf Security Cloud data stream to export event data to a supported target. When a stream is enabled it only exports new events; historical events cannot be exported.

Requirements
  • A provisioned destination (server, bucket, or workspace) for the target type
  • All connection details and credentials for the selected target
Some data stream targets also have additional target-specific requirements, as follows:
  • Generic syslog:
    • A server that can accept syslog over TLS and uses a certificate signed by an authority in the Common CA Database

    • (If applicable) A firewall configured to allow external connections to the configured TCP port from the data stream IP addresses

    • (If applicable) If using client authentication, add the Wandera CA as a trusted source

  • Microsoft Sentinel: A Microsoft Sentinel subscription and relevant account information. See Microsoft Sentinel Prerequisites and Field Values for more details.

  • S3: An identity access management (IAM) role with permission to upload Jamf Protect data to an Amazon S3 bucket and Jamf's AWS account listed as a trusted entity. You can download the Jamf-provided AWS CloudFormation template to create a new S3 bucket and the IAM role for Jamf Security Cloud here: JamfDataCloudFormation.prod.yaml.
  1. In Jamf Security Cloud, navigate to Integrations > Data streams.
  2. Click Add new.
  3. Select a data stream type.

    For more information about data stream types, see Jamf Security Cloud Data Stream Types and Targets.

  4. Select a Target for the data stream and then click Next.
  5. Configure the fields on the Configure data stream page.
    Note:

    The fields that display on this page vary based on the stream and target you chose on the previous page. For more information about configuring your data stream based on your target vendor integration, see Data Stream Integrations by Vendor.

  6. Click Save.

The new data stream appears on the Your data streams list. To begin sending data stream events, enable the Configuration mode.