What all i need to log to the SIEM as security logs on macOS?

Hi, i want to cover all security events on macOS to the SIEM, can i get some help about it?

Thank you

Answered by DTS Engineer in 769959022

I presume that SIEM refers to security information and event management.

It’s not clear from your post whether:

  • You’re trying to accomplish this task directly, or

  • You want to build a product to help others accomplish this task

Please clarify.

Share and Enjoy

Quinn “The Eskimo!” @ Developer Technical Support @ Apple
let myEmail = "eskimo" + "1" + "@" + "apple.com"

Accepted Answer

I presume that SIEM refers to security information and event management.

It’s not clear from your post whether:

  • You’re trying to accomplish this task directly, or

  • You want to build a product to help others accomplish this task

Please clarify.

Share and Enjoy

Quinn “The Eskimo!” @ Developer Technical Support @ Apple
let myEmail = "eskimo" + "1" + "@" + "apple.com"

Yes, that is correct, i want to monitor all log events which are related to security, for example syscalls?

i want to monitor all log events which are related to security

Do you expect to write code to achieve this goal?

Share and Enjoy

Quinn “The Eskimo!” @ Developer Technical Support @ Apple
let myEmail = "eskimo" + "1" + "@" + "apple.com"

to write code? what for? it is option if need of course..

to write code? what for?

You asked your question on Apple Developer Forums, where our primary focus in helping developers write code. If you’re looking to use someone else’s endpoint security product, you’ll have better luck asking over in Apple Support Community, run by Apple Support, and specifically the in Business and Education topic area.

Share and Enjoy

Quinn “The Eskimo!” @ Developer Technical Support @ Apple
let myEmail = "eskimo" + "1" + "@" + "apple.com"

oh, ok. my bad, i am sorry.

What all i need to log to the SIEM as security logs on macOS?
 
 
Q