Jamf Security Cloud Data Stream Types and Targets - Jamf Security Cloud Portal Setup Guide

Jamf Security Cloud Portal Setup Guide

Solution
Application
Jamf Connect
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US

Jamf Security Cloud supports the following types of data streams:

Network traffic
The network traffic stream contains network traffic logs that can be integrated with your preferred security or business intelligence tools. Only a Super Admin can enable this integration.
Access events
The access events stream contains logs about allowed and denied requests from Jamf Connect Zero Trust Network Access (ZTNA) policies.
Threat events
The threat events stream contains detected threat events that can be integrated with your preferred security operations solutions.
App insights
The app insights stream contains information about applications installed on devices that can be integrated with your preferred security or business intelligence tools. Only a Super Admin can enable this integration.
Vulnerability data
The vulnerability data stream contains information about new, ongoing, and remediated vulnerabilities and details about the devices where they were found. Vulnerability data is sent automatically as soon as a detection event occurs. Detection events occur any time Jamf Security Cloud syncs device data with the integrated UEM solution or Jamf Trust. This data stream is only compatible with Apple devices and requires Jamf Trust or a configured UEM integration.
Device data
The device data stream contains information about devices that can be integrated with your preferred security or business intelligence tools. Only a Super Admin can enable this integration.

For more information on the field values for each type of data stream, see Data Stream Dictionary References.

You can select a target for each data stream from the following options:

  • Microsoft Sentinel

  • Splunk

  • Generic HTTP

  • Generic syslog

  • S3