이 페이지는 아직 영어로 제공되지 않습니다. 번역 작업 중입니다. 현재 번역 프로젝트에 대한 질문이나 피드백이 있으신 경우 언제든지 연락주시기 바랍니다.
Overview
Mac Audit Logs captures detailed information about system events, user actions, network and security-related activities. These logs are crucial for monitoring system integrity, identifying unauthorized access, and ensuring adherence to security policies and regulations.
This integration provides enrichment and visualization for various log types, including:
Authentication and Authorization events
Administrative activities
Network events
File Access activities
Input/Output Control
IPC (Inter-Process Communication)
This integration collects Mac audit logs and sends them to Datadog for analysis, providing visual insights through out-of-the-box dashboards and the Log Explorer. It also helps monitor and respond to security threats with ready-to-use Cloud SIEM detection rules.
Do not change the service and source values, as they are essential for proper log pipeline processing.
Default value for AUDIT_LOGS_DIR_PATH is /var/audit. In case of different BSM audit logging directory, please check dir value in /etc/security/audit_control file.
Give the user running datadog-agent access to the /var/audit directory.
Edit your /etc/sudoers file to give the user the ability to run these commands as sudo: