Skip to main content
Question

Jamf Cloud instance and Splunk


Forum|alt.badge.img+5

Hi,

There is probably No possibility to connect the Jamf Cloud instance to my Company's Splunk platform?

3 replies

afarnsworth
Forum|alt.badge.img+8
  • Contributor
  • 46 replies
  • December 9, 2018

I'll start by saying I have never done this before, don't use Jamf Cloud, and admit there are probably better ways of accomplishing what you want but this is a method I threw together. That being said, I think you can do it but it will be a bit messy and not the most secure.

  • Setup internet facing server somewhere (AWS/Azure or on-prem in DMZ) and install with syslog-ng
  • Configure syslog-ng work with Splunk (https://www.splunk.com/blog/2016/03/11/using-syslog-ng-with-splunk.html)
  • Forward Jamf Cloud logs (from https://jamfcloud.url/ChangeManagement.html) to server you setup with syslog-ng

All of this really banks on Jamf Cloud giving you that Change Management setting area. If not, until Jamf provides an option to forward syslog data to a 3rd party source, there is nothing that can be done.


Forum|alt.badge.img+18
  • Valued Contributor
  • 119 replies
  • March 25, 2019

Doesn't seem that JamfCloud allows for Syslog export ability...

At least not with Jamf Pro v10.10.x

I submitted a feature request here: https://www.jamf.com/jamf-nation/feature-requests/8485/syslog-with-jamfcloud


Forum|alt.badge.img+9

I have dicussed this at length with JAMF Support and the Prof Service Team. The only way, which is not the best, is listed here. https://github.com/jamf/SplunkIntegrations . I never really looked into this to be honest but I believe you can setup smart groups and pipe certain information over to splunk that way if you are on JAMFCloud. 1000% easier if you are on-prem though.


Reply


Cookie policy

We use cookies to enhance and personalize your experience. If you accept you agree to our full cookie policy. Learn more about our cookies.

 
Cookie settings