Technology add-on for macOS

Splunk Community

Technology add-on for macOS

Technology add-on for macOS
The Technology Add-on for macOS Endpoint Logs (TA-macOS) provides index-time and search-time configurations for collecting and normalizing endpoint logs from macOS systems that have the Splunk Universal Forwarder installed. It focuses on native macOS logs, specifically `/var/log/system.log` and `/var/log/install.log`, and turns them into analytics-ready data for security and operations use cases. This add-on defines consistent sourcetypes, handles multiline events correctly, extracts core fields, and provides CIM-friendly eventtypes and tags that support Splunk Enterprise Security data models such as Authentication, Change, and Endpoint.
0 topics and 0 replies mentioned Technology add-on for macOS in
Latest Topics
No posts to display.
Latest Replies
No posts to display.
Top Topics
No posts to display.
My Topics
No posts to display.