We have a request to export logs from Mac systems to a central ArcSight server.
There is a lot to unpack for this request.
What logs should be sent. All logs is not the correct answer. What logs are you exporting?
There is no Mac client for ArcSight (like Splunk). Besides Splunk, what are others doing to export logs?
Even though this is from Splunk, these instruction seem to be agnostic enough to exporting syslog data. – https://wiki.splunk.com/Community:HowTo_Configure_Mac_OS_X_Syslog_To_Forward_Data
As an alternative, I am thinking "exporting" the Jamf server's computer history logs would be good.
Is anyone exporting Jamf Server logs?
