

Below is a list of common endpoints that you may want to collect against. To use these highlight the Computer or Mobile Device tab and then in the Custom URL field enter the Name of the Advanced Search.Ĭustom API endpoints allows you to collect information from the Jamf Pro by integrating directly with the API. This allows you to reduce your logging to only values you want or can remove what you deem Personally Identifiable Information. Only Data fields that are checked will be ingested by the Splunk Event Writer. You can also control the data that goes into the Splunk engine by using the Display section. For an example you can collect on only managed devices so you don't collect on devices you no longer are responsible for. The power of these is you can use the Criteria section to narrow your selection of devices. The Computers tab and Mobile Devices tabs use a specific Jamf Pro endpoint referred to as Advanced Computer Searches. Check back in the next version where we will have improved documentation Advanced Computer and Mobile Search They use fewer API Calls, have SourceTypes, Use JSON, and allow you to filter both the device and the information on the device to reduce data being written to your Splunk Event Writer.

The Modular inputs for JamfComputers and JamfMobile devices have a set of improvements that are highly desired. Create and expand on visuals using tools in Splunks ecosystem Use JamfComputers or JamfMobile Devices Import several system settings fields using the Custom API field Import Computer and Mobile Device data from multiple Jamf Pro instances Jamf Modular Input for Splunk Current Version 2.10.8 New Features!
