Best API's for Splunk Integration for making Detections?

jbondsec
New Contributor

Hi, currently we have JAMF Pro integrated into Splunk.

We want to see the following logs but the API documentation is not clear on what logs they provide.

List of API's: https://developer.jamf.com/jamf-pro/reference/jamf-pro-api

We want log data that reflects the following activities:

JAMF admin login

Permission changes

Malicious Software push

Exclusion groups

Presence of APIs

 

What is the best way to figure out which API can give us these logs without trying out each API manually and digging through data.

0 REPLIES 0