Jamf Security Cloud supports the following types of data streams:
- Network traffic
- The network traffic stream contains network traffic logs that can be integrated with your preferred security or business intelligence tools. Only a Super Admin can enable this integration.
- Access events
- The access events stream contains logs about allowed and denied requests from Jamf Connect Zero Trust Network Access (ZTNA) policies.
- Threat events
- The threat events stream contains detected threat events that can be integrated with your preferred security operations solutions.
- App insights
- The app insights stream contains information about applications installed on devices that can be integrated with your preferred security or business intelligence tools. Only a Super Admin can enable this integration.
- Vulnerability data
- The vulnerability data stream contains information about new, ongoing, and remediated vulnerabilities and details about the devices where they were found. Vulnerability data is sent automatically as soon as a detection event occurs. Detection events occur any time Jamf Security Cloud syncs device data with the integrated UEM solution or Jamf Trust. This data stream is only compatible with Apple devices and requires Jamf Trust or a configured UEM integration.
- Device data
- The device data stream contains information about devices that can be integrated with your preferred security or business intelligence tools. Only a Super Admin can enable this integration.
For more information on the field values for each type of data stream, see Data Stream Dictionary References.
You can select a target for each data stream from the following options:
Microsoft Sentinel
Splunk
Generic HTTP
Generic syslog
S3