Send MakeMeAnAdmin logs to Jamf

rangiitsp
New Contributor

We can't find a workaround to GarageBand, Logic Pro, MainStage and MuseHub requiring admin rights to install additional stuff (even running Carl Ashley's loopdown with the all parameter still results in Logic Pro wanting to download additional items although GarageBand shows everything installed).

 

So now we're considering deploying MakeMeAnAdmin and reducing the time down to 1min. All good except that the script stores the logs locally which we're concerned about the user deleting. One option is to email it out but that means leaving an unencrypted mail user password in the script which we could live with by creating a mail only account that can only send to internal addresses. But then I remembered seeing a script that sent logs to Jamf but can't remember where.

 

Does anyone know if it's possible to send the MMAA logs to Jamf (and how)? We just need to know what the user did during that window that they were an admin.

3 REPLIES 3

McAwesome
Valued Contributor

Apple provides a script to download the additional files for GarageBand and Logic Pro.  Reach out to your Apple SE and they can provide it.

Thank you. We do have the script but it doesn't download everything (Logic Pro still has several instruments that need adding; GarageBand indicates fully downloaded though which is a good step in the right direction).

 

Anyway, that's only 1 sample use. We can foresee using this script for other things as well so it's important to find a way to send logs externally, such as allowing them to run this to allow MuseHub helper to run which then allows them to install additional items for MuseScore.

ajpinton1
New Contributor

You are wanting macOS event log collection, and SIEM log redirection. Neither of these are something Jamf Pro is designed to do, and it's not possible. However, Jamf Protect can do exactly what you are wanting.

 

jamfprotect/unified_log_filters/jamf_connect/privilege_elevation_elevate_and_demote.yaml at main · j...