Change log for JAMF_PROTECT
Date | Changes |
---|---|
2024-10-08 | Update the gsub filter to support the logs. |
2024-05-01 | Added additional mappings for deprecated labels. |
2024-02-06 | Added support for the event "GPScreenshotEvent" and the raw log fields associated with that event. - Mapped the raw log field "input.host.os" with the UDM field "principal.platform_version" - Mapped the raw log field "input.host.protectVersion" with the UDM field "principal.asset.attribute.labels" - Mapped the raw log field "input.match.facts.matchReason" with the UDM field "security_result.detection_fields" - Mapped the raw log field "input.match.version" with the UDM field "additional.fields" - Mapped the raw log field "input.related.files.objectType" with the UDM field "additional.fields" |
2024-01-03 | - Updated logic for "file.inode" raw log field.
|
2023-11-22 | - Updated logic for "file.inode" raw log field.
- Align 'principal.hostname, target.hostname, 'principal.asset.hostname, and target.asset.hostname' mapping. |
2023-06-28 | Promoted JAMF_PROTECT parser to default. For the field mapping reference, see Collect Jamf Protect logs. |