02-09-2023 05:17 PM - edited 02-09-2023 05:20 PM
Can anyone help me with examples of what to use so I can setup remotelogging? What companies to use, what setups? I understand if this is vague, I am actually struggling on how to ask the question.
Problem: Who should be the host for this?
Description: If RemoteLogging is used, this will send the logging for Privileges.app to a remote syslog server.
If using RemoteLogging, then the following subsidiary keys must also be set:
Sources:
https://github.com/SAP/macOS-enterprise-privileges
https://github.com/SAP/macOS-enterprise-privileges/wiki/Managing-Privileges
Posted on 02-10-2023 06:03 AM
If your organization uses a Syslog server product such as Splunk, that's what the host would be. Here's an example of what I'm using. The values of those keys should be provided by whoever manages your syslog server.
Posted on 02-10-2023 09:13 AM
Any alternatives that you think would work great for this? We don't use Splunk :(
Posted on 02-10-2023 09:25 AM
Does your organization currently have a functioning syslog server or siem? If so, the administrators of that server can provide you the necessary hostnames and severities. If not and you have the cycles to provision and manage your own, I'm sure there are plenty of available resources online. You can still use this tool without the logging if your organization doesn't have an existing logging policy.
Posted on 05-22-2023 06:29 AM
Can someone help me to find where should I paste my own configuration?