Jamf Protect Alert Data Reference

Jamf Trusted Access Solution Guide for Business

Solution
Application
Content Type
Technical Documentation
Solution Guide
Utilities & Services
ft:locale
en-US

Jamf Protect provides additional helpful information about alerts in the detail view. Click the alert title to open the detail view for that alert. Alternatively, you can click Detail View on the alerts page to view each alert's details in the current filter query.

Jamf recommends to prioritize alerts that are marked as high severity and have a status of new. You can use the information provided in the alert details to assist with remediation.

When you click on an alert the following information is displayed.

Summary

Describes the detection event and provides remediation suggestions. Includes other general information about the event such as the Host IP, Timestamp, associated Tags, domain information, signing information.

Processes

Provides detailed information about the processes involved in the event such as the signing information, path, process name and process UUID.

Files

Provides detailed information about the files involved in the event, such as the path, signing information and hash.

Binaries

Similar to the information for files. Provides detailed information about the binaries involved in the event, such as the path, signing information and hash.

Users

Lists the users involved in the event.

Groups

Lists the user groups involved in the event.

JSON

Provides the raw alert data in a JSON format.

Add Exception

Allows you to add an exception for this alert criteria using an exception set.