Use a Jamf Security Cloud data stream to export event data to a supported target. When a stream is enabled it only exports new events; historical events cannot be exported.
- A provisioned destination (server, bucket, or workspace) for the target type
- All connection details and credentials for the selected target
- Generic syslog:
A server that can accept syslog over TLS and uses a certificate signed by an authority in the Common CA Database
(If applicable) A firewall configured to allow external connections to the configured TCP port from the data stream IP addresses
(If applicable) If using client authentication, add the Wandera CA as a trusted source
Microsoft Sentinel: A Microsoft Sentinel subscription and relevant account information. See Microsoft Sentinel Prerequisites and Field Values for more details.
- S3: An identity access management (IAM) role with permission to upload Jamf Protect data to an Amazon S3 bucket and Jamf's AWS account listed as a trusted entity. You can download the Jamf-provided AWS CloudFormation template to create a new S3 bucket and the IAM role for Jamf Security Cloud here: JamfDataCloudFormation.prod.yaml.
The new data stream appears on the Your data streams list. To begin sending data stream events, enable the Configuration mode.