<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Getting Events from MAC OS in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Does-anyone-have-reference-material-on-the-inputs-conf-for-MAC/m-p/585269#M102979</link>
    <description>&lt;P&gt;You can see it &amp;nbsp;at&amp;nbsp;Universal logging and Jamf Protect&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.jamf.com/jamf-protect/documentation/Unified_Logging.html" target="_blank"&gt;https://docs.jamf.com/jamf-protect/documentation/Unified_Logging.html&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 16 Feb 2022 06:19:45 GMT</pubDate>
    <dc:creator>magichat</dc:creator>
    <dc:date>2022-02-16T06:19:45Z</dc:date>
    <item>
      <title>Does anyone have reference material on the inputs.conf for MAC OSs and how to get the events into Splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Does-anyone-have-reference-material-on-the-inputs-conf-for-MAC/m-p/550656#M91431</link>
      <description>&lt;P&gt;I'm a Windows guy working with Linux trying to get MAC OS events into Splunk.&amp;nbsp; We don't have many MACs where I work, but we do have some.&amp;nbsp; Does anyone have reference material on the inputs.conf for MAC OSs and how I get the events into Splunk?&amp;nbsp; The Splunk UF is installed, but I need to know more about what to monitor on MAC OSs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Feb 2022 00:22:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Does-anyone-have-reference-material-on-the-inputs-conf-for-MAC/m-p/550656#M91431</guid>
      <dc:creator>dokaas_2</dc:creator>
      <dc:date>2022-02-17T00:22:43Z</dc:date>
    </item>
    <item>
      <title>Re: Getting Events from MAC OS</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Does-anyone-have-reference-material-on-the-inputs-conf-for-MAC/m-p/550890#M91466</link>
      <description>&lt;P&gt;Unfortunately there is no good native way to do it after Apple changed it's logging framework without any external programs/utils.&lt;/P&gt;&lt;P&gt;Here is some like which you could look:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;A href="https://community.splunk.com/t5/Getting-Data-In/Sending-MacOS-logs-to-Splunk-without-involving-another-tool-or/m-p/507961" target="_blank" rel="noopener"&gt;https://community.splunk.com/t5/Getting-Data-In/Sending-MacOS-logs-to-Splunk-without-involving-another-tool-or/m-p/507961&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://community.splunk.com/t5/Archive/Mac-OS-X-Sierra-How-to-get-all-logs-from-the-Unified-Log/m-p/347695" target="_blank" rel="noopener"&gt;https://community.splunk.com/t5/Archive/Mac-OS-X-Sierra-How-to-get-all-logs-from-the-Unified-Log/m-p/347695&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="http://macadmins.psu.edu/wp-content/uploads/sites/24696/2016/06/psumac2016-19-osxlogs_macadmins_2016.pdf" target="_blank"&gt;http://macadmins.psu.edu/wp-content/uploads/sites/24696/2016/06/psumac2016-19-osxlogs_macadmins_2016.pdf&lt;/A&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Of course you must 1st know what you want to log from those nodes.&lt;/P&gt;&lt;P&gt;If those logs which you are interested are normal file based logs then collect those as any other logs in unix platforms.&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Fri, 07 May 2021 17:56:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Does-anyone-have-reference-material-on-the-inputs-conf-for-MAC/m-p/550890#M91466</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2021-05-07T17:56:39Z</dc:date>
    </item>
    <item>
      <title>Re: Getting Events from MAC OS</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Does-anyone-have-reference-material-on-the-inputs-conf-for-MAC/m-p/585269#M102979</link>
      <description>&lt;P&gt;You can see it &amp;nbsp;at&amp;nbsp;Universal logging and Jamf Protect&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.jamf.com/jamf-protect/documentation/Unified_Logging.html" target="_blank"&gt;https://docs.jamf.com/jamf-protect/documentation/Unified_Logging.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Feb 2022 06:19:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Does-anyone-have-reference-material-on-the-inputs-conf-for-MAC/m-p/585269#M102979</guid>
      <dc:creator>magichat</dc:creator>
      <dc:date>2022-02-16T06:19:45Z</dc:date>
    </item>
    <item>
      <title>Re: Does anyone have reference material on the inputs.conf for MAC OSs and how to get the events into Splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Does-anyone-have-reference-material-on-the-inputs-conf-for-MAC/m-p/611071#M105853</link>
      <description>&lt;P&gt;Since Splunk 9.x, Universal Forwarder supports Apple Unified Logging. But Splunk didn't release corresponding TA. So I decided to publish&lt;SPAN&gt;&amp;nbsp;technology add-on to make things CIM compliant with Splunk Enterprise Security:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://splunkbase.splunk.com/app/6561/#/details" target="_blank" rel="nofollow noopener noreferrer"&gt;https://splunkbase.splunk.com/app/6561/&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I also published an app to visualize key security-relevant events from MacOS datasource:&lt;/P&gt;&lt;P&gt;&lt;A href="https://splunkbase.splunk.com/app/6562/" target="_blank" rel="nofollow noopener noreferrer"&gt;https://splunkbase.splunk.com/app/6562/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Any improvement requests are welcome.&lt;/P&gt;</description>
      <pubDate>Sun, 28 Aug 2022 11:10:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Does-anyone-have-reference-material-on-the-inputs-conf-for-MAC/m-p/611071#M105853</guid>
      <dc:creator>MaverickT</dc:creator>
      <dc:date>2022-08-28T11:10:49Z</dc:date>
    </item>
    <item>
      <title>Re: Does anyone have reference material on the inputs.conf for MAC OSs and how to get the events into Splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Does-anyone-have-reference-material-on-the-inputs-conf-for-MAC/m-p/618986#M106756</link>
      <description>&lt;P&gt;I am VERY interested in this. What did you use for your inputs from the UFA on the Mac endpoints?&lt;/P&gt;</description>
      <pubDate>Mon, 31 Oct 2022 17:30:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Does-anyone-have-reference-material-on-the-inputs-conf-for-MAC/m-p/618986#M106756</guid>
      <dc:creator>cbastashutterfl</dc:creator>
      <dc:date>2022-10-31T17:30:41Z</dc:date>
    </item>
  </channel>
</rss>

