Use this integration to fetch audit logs events, alerts events and computer assets from Jamf Protect to Cortex XSIAM.
JamfProtect
- Details
 - Content
 - Dependencies
 - Version History
 
Apple Mobile and Mac endpoint protection
Integrations
| Name | Description | 
|---|---|
| Jamf Protect Event Collector | 
Modeling Rules
| Name | Description | 
|---|---|
JamfProtect Modeling Rule  | 
1.2.3 - R5469292 (October 20, 2025) Related pull requests:
- 40498
Integrations
Jamf Protect Event Collector
- Updated the Docker image to: demisto/python3:3.12.8.3296088.
 
- 40498
1.2.2 - R3324525 (May 6, 2025) Related pull requests:
- 38987
Integrations
Jamf Protect Event Collector
- Metadata and documentation improvements.
 
- 38987
1.2.1 - 2707769 (March 10, 2025) Related pull requests:
- 38975
Integrations
Jamf Protect Event Collector
- Fixed an issue causing duplicate entries due to a mismatch in date formatting.
 - Updated the Docker image to: demisto/python3:3.12.8.1983910.
 
- 38975
1.2.0 - 2429474 (February 11, 2025) Related pull requests:
- 38336
Integrations
Jamf Protect Event Collector
- Breaking Changes: The Fetch all computers was removed from the fetch events command. Instead, computers can now be fetched using the Fetch assets and vulnerabilities parameter.
 - Added the command fetch assets to fetch computers.
 - Added the datasets jamf_protect_computers_raw to store computers assets.
 
- 38336
1.1.6 - 1780397 (December 9, 2024) Related pull requests:
- 37150
Integrations
Jamf Protect Event Collector
Fixed an issue where the fetch-events command failed when no new events were fetched.
- 37150
1.1.5 - 1745299 (December 3, 2024) Related pull requests:
- 37532
Integrations
Jamf Protect Event Collector
- Updated the computer page size from 200 to 100 and the computer default max fetch from 1,000 to 500.
 
- 37532
1.1.4 - R1741355 (December 3, 2024) Related pull requests:
- 37219
Integrations
Jamf Protect Event Collector
- Added a fetch_all_computers parameter to enable fetch all the computers during the first fetch.
 - Updated the Docker image to: demisto/python3:3.11.10.116949.
 
- 37219
1.1.3 - 1574765 (October 31, 2024) Related pull requests:
- 37013
Integrations
Jamf Protect Event Collector
- Added logging of erroneous responses.
 
- 37013
PUBLISHER
PLATFORMS
Cortex XSIAM
INFO
| Certification | Certified | Read more | 
| Supported By | Cortex | |
| Created | March 20, 2024 | |
| Last Release | October 20, 2025 | 
WORKS WITH THE FOLLOWING INTEGRATIONS:

