Esta página aún no está disponible en español. Estamos trabajando en su traducción. Si tienes alguna pregunta o comentario sobre nuestro actual proyecto de traducción, no dudes en ponerte en contacto con nosotros.
Overview
Mac Audit Logs captures detailed information about system events, user actions, network and security-related activities. These logs are crucial for monitoring system integrity, identifying unauthorized access, and ensuring adherence to security policies and regulations.
This integration provides enrichment and visualization for various log types, including:
Authentication and Authorization events
Administrative activities
Network events
File Access activities
Input/Output Control
IPC (Inter-Process Communication)
This integration collects Mac audit logs and sends them to Datadog for analysis, providing visual insights through out-of-the-box dashboards and the Log Explorer. It also helps monitor and respond to security threats with ready-to-use Cloud SIEM detection rules.
To install the Mac Audit Logs integration, run the following Agent installation command and follow the steps below. For more information, see the Integration Management documentation.
Do not change the service and source values, as they are essential for proper log pipeline processing.
Default value for AUDIT_LOGS_DIR_PATH is /var/audit. In case of different BSM audit logging directory, please check dir value in /etc/security/audit_control file.